EDBT 2026 Demo / reviewers in the wild / expert
Yih-Chun Hu
dblp:51/6805
· DBLP profile ↗
87ranked-venue papers
12as first author
14since 2021 · last 2026
0000-0002-7829-3929ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 51 · 9 first-author · 6 since 2021Security and privacy · 25 · 2 first-author · 4 since 2021Systems, architecture and hardware · 8 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Signet: Scalable Network-Driven Proof of Notification for Blockchain Systems
Elham Ehsani Moghadam, Marc Wyss, Jonghoon Kwon, Marc Frei, Yih-Chun Hu, Adrian Perrig, Alberto Sonnino |
ICDCS | 5 |
| 2026 | Lightweight Internet Bandwidth Allocation and Isolation with Fractional Fair Shares
Marc Wyss, Yih-Chun Hu, Vincent Lenders, Roland Meier, Adrian Perrig |
NDSS | 2 |
| 2025 | Polaris: End-to-End Path Optimization by End HostsabstractPath-aware networking (PAN) enables endpoints to locally select end-to-end network paths based on path properties. This approach contrasts with the traditional Internet architecture, where routers determine the next hop towards the destination based on the routing information provided by the Border Gateway Protocol (BGP). By providing this additional transparency and control, PAN opens up opportunities to optimize path selection, with the potential to enhance network performance and user experience metrics. In this paper, we evaluate the potential benefits of PAN for enhancing end-to-end performance. We design Polaris, a concrete feedback-driven path optimization mechanism for PAN, and study its impact on Quality of Service (QoS) as compared to current Internet mechanisms. Our extensive simulation results show the viability and effectiveness of Polaris, revealing that it outperforms the current Internet mechanisms by an average of${4 2 \%}$improvement in receiving rate and${8 1 \%}$reduction in median loss, in the presence of background traffic. Elham Ehsani Moghadam, Patrick Wicki, François Wirz, Jordi Subirà Nieto, Yih-Chun Hu, Adrian Perrig |
IWQoS | 5 |
| 2024 | Debuglet: Programmable and Verifiable Inter-Domain Network TelemetryabstractOn today's Internet, end-user debugging is largely limited to simple tools such as ping and traceroute, supplemented by purpose-built services such as bandwidth measurement, and website uptime monitors. Unfortunately, these tools do not provide sufficient data to isolate specific network faults, nor do they give the user results that can be validated by external entities. Furthermore, since networks disparately treat measurement packets, as our empirical results confirm, measurement packets need to be indistinguishable from data packets. In this paper, we argue for a distributed network debugging infrastructure and describe Debuglet, a deployable and incentivized architecture that allows inter-domain network debugging using real data packets and user-defined code, which facilitates accurate and flexible measurements of the network performance experienced by data packets. We implement the Debuglet system, and demonstrate its feasibility by deploying it on a network testbed, evaluating its measurement accuracy, and analyzing its deployment costs. Seyedali Tabaeiaghdaei, Filippo Costa, Jonghoon Kwon, Patrick Bamert, Yih-Chun Hu, Adrian Perrig |
ICDCS | 5 |
| 2024 | vRetention: A User Viewing Dataset for Popular Video Streaming ServicesabstractAdaptive bitrate streaming (ABR) and quality of experience (QoE) metrics are proposed to enhance video streaming quality across various Internet connections. Traditional approaches to evaluating these metrics often ignore common user behaviors like seeking, jumping, or replaying video segments, leading to gaps in QoE understanding. Addressing this, we collected 229,178 audience retention curves from YouTube and Bilibili, offering a thorough view of viewer engagement and diverse watching styles. Our analysis reveals notable behavioral differences across countries, categories, and platforms. The YouTube data highlights varied content preferences, such as gaming and entertainment in some countries, and music, travel, and pets & animals in others. Additionally, Bilibili shows trends of early video abandonment, possibly influenced by platform-specific factors and shorter video formats. This enhanced grasp of user engagement aids in refining ABR and QoE metrics. We also highlight several potential applications of our dataset. Bo-Rong Chen, Jiayu Zhu, Yanxin Jiang, Yih-Chun Hu |
MMSys | 4 |
| 2023 | FlowBot: A Learning-Based Co-bottleneck Flow Detector for Video ServersabstractRecent research has proposed that Content Delivery Networks (CDNs) can use better bandwidth allocation to improve video streaming services through congested links. Because CDNs are usually not located at the bottleneck link, shared bottleneck (co-bottleneck) detection on the video servers is necessary for joint flow shaping and the Quality of Experience (QoE) improvements. However, co-bottleneck detection is challenging in such environments due to the large number of flows, possible network topologies, and traffic patterns. Current detectors fail to balance detection accuracy, speed and overhead, and suffer performance degradation in the scale of thousands of flows on each video server. We propose FlowBot, a novel model-based passive co-bottleneck detector designed for deployment on a video server. FlowBot uses Siamese model to learn flow representations, and combines the training procedure with its clustering algorithm to continue to provide strong performance with up to thousands of flows. Our evaluations show that FlowBot can achieve consistently high accuracy (over 70% F1 with around 90% precision) in most tested scenarios, while maintaining a short detection delay of 3 s and overhead similar to the fastest benchmark algorithms. Jinhui Song, Bo-Rong Chen, Anyu Ying, Yih-Chun Hu |
ICNP | 5 |
| 2022 | FlowTele: remotely shaping traffic on internet-scale networksabstractInternet content providers often deliver content through bandwidth bottlenecks that are out of their control. Thus, despite often having massively over-provisioned upstream servers, the content providers still cannot control the end-to-end user experience. This paper explores remote traffic shaping, allowing the content provider to allocate its share of a remote bottleneck link across its users using a metric other than TCP fairness, while remaining TCP-friendly to cross traffic on the bottleneck link. To evaluate this approach, we designed FlowTele, the first system that shapes outbound traffic on an Internet-scale network to optimize provider-selected metrics, using source control with neither in-network support nor special client support. Our extensive evaluations over the Internet show that by strategically reallocating bandwidth among provider-owned co-bottlenecked flows, FlowTele improves the provider's total revenue by roughly 20%--30% in various network settings, compared with both (i) status quo TCP fairshare and (ii) recent practice by content providers that proactively throttles video quality during the COVID-19 pandemic, while being TCP-friendly to cross-traffic. Besides revenue, we also study other metrics, such as QoE fairness, that a content provider may wish to optimize using FlowTele. Bo-Rong Chen, Zhuotao Liu, Jinhui Song, Fanhui Zeng, Zhoushi Zhu, Siva Phani Keshav Bachu, Yih-Chun Hu |
CoNEXT | 7 |
| 2022 | Key Generation with Ambient AudioabstractDigital Contact Tracing (DCT) has been proposed to limit the spread of COVID-19, allowing for targeted quarantine of close contacts. The protocol is designed to be lightweight, broad-casting limited-time tokens over Bluetooth Low Energy (BLE) beacons, allowing receivers to record contacts pseudonymously. However, currently proposed protocols have vulnerabilities that permit an adversary to perform massive surveillance or cause significant numbers of false-positive alerts. In this paper, we present AcousticMask, which encrypts broadcast messages using a key derived from the audio signal present at each device with sufficient security levels. Our results show that a receiver sharing the same social space as a sender will hear all of the sender's ephemeral IDs (EphIDs) with Hamming distance at most 3, which can be decrypted at the rate of 10 Hz on a Raspberry Pi 4, while achieving a security factor of over 2108against attackers in our testing set, showing AcousticMask is lightweight for DCT and provides sufficient security levels to protect user's privacy. Bo-Rong Chen, Hsin-Tien Chiang, Heng-Cheng Kuo, Yu Tsao 0001, Yih-Chun Hu |
GLOBECOM | 5 |
| 2022 | Caching-based Multicast Message Authentication in Time-critical Industrial Control SystemsabstractAttacks against industrial control systems (ICSs) often exploit the insufficiency of authentication mechanisms. Verifying whether the received messages are intact and issued by legitimate sources can prevent malicious data/command injection by illegitimate or compromised devices. However, the key challenge is to introduce message authentication for various ICS communication models, including multicast or broadcast, with a messaging rate that can be as high as thousands of messages per second, within very stringent latency constraints. For example, certain commands for protection in smart grids must be delivered within 2 milliseconds, ruling out public-key cryptography. This paper proposes two lightweight message authentication schemes, named CMA and its multicast variant CMMA, that perform precomputation and caching to authenticate future messages. With minimal precomputation and communication overhead, C(M)MA eliminates all cryptographic operations for the source after the message is given, and all expensive cryptographic operations for the destinations after the message is received. C(M)MA considers the urgency profile (or likelihood) of a set of future messages for even faster verification of the most time-critical (or likely) messages. We demonstrate the feasibility of C(M)MA in an ICS setting based on a substation automation system in smart grids. Utku Tefek, Ertem Esiner, Daisuke Mashima, Binbin Chen 0001, Yih-Chun Hu |
INFOCOM | 5 |
| 2022 | HeadStart: Efficiently Verifiable and Low-Latency Participatory Randomness Generation at Scale
Hsun Lee, Yuming Hsu, Jing-Jie Wang, Yu-Heng Chen, Yih-Chun Hu, Hsu-Chun Hsiao |
NDSS | 6 |
| 2022 | Secure and ultra-reliable provenance recovery in sparse networks: Strategies and performance bounds
Suraj Sajeev, Manish Bansal, Sriraam S. V, Huzur Saran, Yih-Chun Hu |
Ad Hoc Networks | 6 |
| 2022 | Double-Edge Embedding Based Provenance Recovery for Low-Latency Applications in Wireless NetworksabstractA number of applications in next-generation multi-hop networks, e.g., vehicular networks, impose low-latency requirements on data transmission thereby necessitating the underlying relays to introduce negligible delay when forwarding the packets. While traditional relaying techniques such as amplify-and-forward protocols may help the packets to satisfy latency-constraints, such strategies do not facilitate the destination in learning the path traveled by the packets, which in turn could be used for either learning the topology of the network or detecting security threats on the network. In addition to low-latency constraints, vehicular networks also result in variable network topology owing to the mobility of the nodes, which in turn imposes additional challenges to the destination in learning the path traveled by the packets. Thus, with potential applications to vehicular networks, we address the problem of designing provenance embedding algorithms that reduce the delays on the packets and yet assist the destination in determining the path traveled by the packets with no knowledge of the network topology. We propose a new class of provenance embedding techniques, referred to as double-edge (DE) embedding techniques, wherein a subset of the relay nodes in the path strategically skip the provenance embedding process to reduce the delays on the packets. Using fixed-size bloom filters as tools to implement the double-edge embedding ideas, first, we derive upper bounds on the error-rates of the DE embedding techniques so that the parameters of the bloom filter can be chosen to facilitate provenance recovery within a given quality of service. Subsequently, we present experimental results on a test bed of XBee devices and Raspberry Pis to demonstrate the efficacy of the proposed techniques, and show that the DE embedding techniques offer latency benefits upto 17 percent along with remarkable reduction in error-rates in comparison with the baselines. We also present a security analysis of the proposed provenance embedding methods to asses their vulnerabilities against various attacks including impersonation threats. Amogh Vithalkar, Naman Jhunjhunwala, Manthan Kabra, Prafull Manav, Yih-Chun Hu |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2022 | Make Web3.0 Connectedabstract${\mathsf Web3.0}$, often cited to drastically shape our lives, is ubiquitous. However, few literatures have discussed the crucial differentiators that separate${\mathsf Web3.0}$from the era we are currently living in. Via a thorough analysis of the recent blockchain infrastructure evolution, we capture a key invariant featuring the evolution, based on which we provide the first academic definition for${\mathsf Web3.0}$. Our definition is not the only way of understanding${\mathsf Web3.0}$, yet, it captures the fundamental and defining trait of${\mathsf Web3.0}$, and meanwhile it is has two desirable properties. Under this definition, we articulate three key categories of infrastructural enablers for${\mathsf Web3.0}$: individual smart-contract capable blockchains, federated or centralized platforms capable of publishing verifiable states, and an interoperability platform to hyperconnect those state publishers to provide a unified and connected computing platform for${\mathsf Web3.0}$applications. While innovations in all categories are necessary to fully enable${\mathsf Web3.0}$, in this article, we present a design for the third enabler, i.e., the first interoperability platform, namely${\mathsf HyperService}$, that advances the state-of-the-art by simultaneously deliversinteroperabilityandprogrammabilityacrossheterogeneousblockchains and state publishers.${\mathsf HyperService}$is powered by two innovative designs:${\mathsf (i)}$a developer-facing programming framework that allows developers to build cross-chain applications in a unified programming model; and${\mathsf (ii)}$a secure blockchain-facing cryptography protocol that provably realizes those applications on blockchains. We implement a prototype of${\mathsf HyperService}$in approximately 62,000 lines of code to demonstrate its practicality, usability and scalability. Zhuotao Liu, Yangxi Xiang, Peng Gao 0008, Haoyu Wang 0001, Xusheng Xiao, Bihan Wen, Qi Li 0002, Yih-Chun Hu |
IEEE Trans. Dependable Secur. Comput. | 9 |
| 2021 | HASA-Net: A Non-Intrusive Hearing-Aid Speech Assessment NetworkabstractWithout the need of a clean reference, non-intrusive speech assessment methods have caught great attention for objective evaluations. Recently, deep neural network (DNN) models have been applied to build non-intrusive speech assessment approaches and confirmed to provide promising performance. However, most DNN-based approaches are designed for normal-hearing listeners without considering hearing-loss factors. In this study, we propose a DNN-based hearing aid speech assessment network (HASA-Net), formed by a bidirectional long short-term memory (BLSTM) model, to predict speech quality and intelligibility scores simultaneously according to input speech signals and specified hearing-loss patterns. To the best of our knowledge, HASA-Net is the first work to incorporate quality and intelligibility assessments utilizing a unified DNN-based non-intrusive model for hearing aids. Experimental results show that the predicted speech quality and intelligibility scores of HASA-Net are highly correlated to two well-known intrusive hearing-aid evaluation metrics, hearing aid speech quality index (HASQI) and hearing aid speech perception index (HASPI), respectively. Hsin-Tien Chiang, Yi-Chiao Wu, Tomoki Toda, Hsin-Min Wang, Yih-Chun Hu, Yu Tsao 0001 |
ASRU | 6 |
| 2020 | DefRec: Establishing Physical Function Virtualization to Disrupt Reconnaissance of Power Grids' Cyber-Physical Infrastructures
Jianing Zhuang, Yih-Chun Hu, Huayu Zhou |
NDSS | 3 |
| 2020 | Mitigating denial-of-service attacks on digital contact tracing: poster abstractabstractDue to the COVID-19 pandemic, many researchers have proposed privacy-preserving smartphone proximity tracing. Current projects, based on ephemeral IDs, are vulnerable to DoS attacks. In this paper, we present BlindSignedIDs that can be verified in-place through a TESLA server. We will demonstrate our BlindSignedIDs can effectively mitigate such DoS attacks. Bo-Rong Chen, Yih-Chun Hu |
SenSys | 2 |
| 2020 | Bloom Filter Based Low-Latency Provenance Embedding Schemes in Wireless NetworksabstractA number of applications in next-generation multi-hop networks impose low-latency requirements on data transmission thereby necessitating the underlying relays to introduce negligible delay when forwarding the packets. While traditional relaying techniques such as amplify-and-forward may help the packets to satisfy latency-constraints, such strategies do not facilitate the destination in determining security threats, if any, during the packet’s journey. Inspired by the problem of relaying packets that have low-latency constraints, we revisit the design of provenance embedding algorithms to reduce delays on the packets and yet assist the destination in determining the provenance with no knowledge on the network topology. We propose a new class of provenance embedding techniques, referred to as double-edge (DE) embedding techniques, wherein a subset of the relay nodes in the path strategically skip the provenance embedding process to reduce the delays on the packets. Under the framework of DE embedding techniques, we propose a deterministic skipping strategy among the nodes such that the destination can recover the provenance of every packet. Using fixed-size bloom filters as tools to implement the double-edge embedding ideas, we propose upper bounds on the error-rates of the DE embedding technique as a function of the number of nodes in the network, number of hops, bloom filter size, and the number of hash functions used by each node. Subsequently, we demonstrate the efficacy of the DE embedding technique on a testbed of Digi XBee devices, and show that it outperforms competitive baselines both in terms of latency as well as error-rates. Amogh Vithalkar, Naman Jhunjhunwala, Manthan Kabra, Prafull Manav, Yih-Chun Hu |
WCNC | 6 |
| 2019 | HyperService: Interoperability and Programmability Across Heterogeneous BlockchainsabstractBlockchain interoperability, which allows state transitions across different blockchain networks, is critical functionality to facilitate major blockchain adoption. Existing interoperability protocols mostly focus on atomic token exchanges between blockchains. However, as blockchains have been upgraded from passive distributed ledgers into programmable state machines (thanks to smart contracts), the scope of blockchain interoperability goes beyond just token exchanges. In this paper, we present HyperService, the first platform that delivers interoperability and programmability across heterogeneous blockchains. HyperService is powered by two innovative designs: (i) a developer-facing programming framework that allows developers to build cross-chain applications in a unified programming model; and (ii) a secure blockchain-facing cryptography protocol that provably realizes those applications on blockchains. We implement a prototype of HyperService in approximately 35,000 lines of code to demonstrate its practicality. Our experiments show that (i) HyperService imposes reasonable latency, in order of seconds, on the end-to-end execution of cross-chain applications; (ii) the HyperService platform is scalable to continuously incorporate new large-scale production blockchains. Zhuotao Liu, Yangxi Xiang, Peng Gao 0008, Haoyu Wang 0001, Xusheng Xiao, Bihan Wen, Yih-Chun Hu |
CCS | 8 |
| 2019 | SmartCrowd: Decentralized and Automated Incentives for Distributed IoT System DetectionabstractInternet of Things (IoT) devices achieve the rapid development and have been widely deployed recently. Meanwhile, inherent vulnerabilities of IoT systems (including firmware and software) have been continually uncovered and thus the systems are always exposed to various attacks. The root cause of the issue is that IoT systems always have design flaws and implementation bugs. In particular, the released systems (e.g., by third-party marketplaces and IoT vendors) may be maliciously repackaged with malware. Unfortunately, IoT consumers are not able to effectively capture such vulnerabilities because of the limited detection capabilities. In this paper, we propose SmartCrowd, a blockchain-based platform that aims to outsource security detection of IoT systems to distributed detectors with strong detection incentives. SmartCrowd enables built-in accountability for IoT providers and authoritative references of detection results for IoT consumers. By building smart contracts, we can incentivize the efficient and high-coverage security detection of IoT systems, while providing decentralized and automated incentives for both IoT providers releasing secure IoT systems and detectors uncovering vulnerabilities. We present the security and theoretical analysis that demonstrates the security of SmartCrowd and the incentives for participators. We prototype SmartCrowd by using Ethereum and the experimental results show that SmartCrowd has both technical feasibility and financial benefits, which can be applied to build a secure IoT ecosystem. Bo Wu 0002, Ke Xu 0002, Qi Li 0002, Zhuotao Liu, Yih-Chun Hu, Xinle Du, Bingyang Liu, Shoushou Ren |
ICDCS | 5 |
| 2019 | Power-Positive Networking: Wireless-Charging-Based Networking to Protect Energy against Battery DoS AttacksabstractEnergy is required for networking and computation and is a valuable resource for unplugged systems such as mobile, sensor, and embedded systems. Energy denial-of-service (DoS) attack where a remote attacker exhausts the victim’s battery via networking remains a critical challenge for the device availability. While prior literature proposes mitigation- and detection-based solutions, we propose to eliminate the vulnerability entirely by offloading the power requirements to the entity who makes the networking requests. To do so, we build communication channels using wireless charging signals (as opposed to the traditional radio-frequency signals), so that the communication and the power transfer are simultaneous and inseparable, and use the channels to build power-positive networking (PPN). PPN also offloads the computation-based costs to the requester, enabling authentication and other tasks considered too power-hungry for battery-operated devices. In this article, we study the energy DoS attack impacts on off-the-shelf embedded system platforms (Raspberry Pi and the ESP 8266 system-on-chip (SoC) module), present PPN, implement and build a Qi-charging-technology-compatible prototype, and use the prototype for evaluations and analyses. Our prototype, built on the hardware already available for wireless charging, effectively defends against energy DoS and supports simultaneous power and data transfer. Sang-Yoon Chang, Sristi Lakshmi Sravana Kumar, Yih-Chun Hu, Younghee Park |
ACM Trans. Sens. Networks | 3 |
| 2018 | CLEF: Limiting the Damage Caused by Large Flows in the Internet Core
Hao Wu 0018, Hsu-Chun Hsiao, Daniele Enrico Asoni, Simon Scherrer, Adrian Perrig, Yih-Chun Hu |
CANS | 6 |
| 2018 | Enabling Work-Conserving Bandwidth Guarantees for Multi-Tenant Datacenters via Dynamic Tenant-Queue BindingabstractToday's cloud networks are shared among many tenants. Bandwidth guarantees and work conservation are two key properties to ensure predictable performance for tenant applications and high network utilization for providers. Despite significant efforts, very little prior work can really achieve both properties simultaneously even some of them claimed so. In this paper, we present QShare, a comprehensive in-network solution to achieve bandwidth guarantees and work conservation simultaneously. QShare leverages weighted fair queuing on commodity switches to slice network bandwidth for tenants, and solves the challenge of queue scarcity through balanced tenant placement and dynamic tenant-queue binding. We have implemented a QShare prototype and evaluated it extensively via both testbed experiments and simulations. Our results show that QShare ensures bandwidth guarantees while driving network utilization to over 91% even under unpredictable traffic demands. Zhuotao Liu, Kai Chen 0005, Shuihai Hu, Yih-Chun Hu, Yi Wang 0004, Gong Zhang 0001 |
INFOCOM | 5 |
| 2018 | Enabling Efficient Source and Path Verification via Probabilistic Packet MarkingabstractThe Internet lacks verification of source authenticity and path compliance between the planned packet delivery paths and the real delivery paths, which allows attackers to construct attacks like source spoofing and traffic hijacking attacks. Thus, it is essential to enable source and path verification in networks to detect forwarding anomalies and ensure correct packet delivery. However, most of the existing security mechanisms can only capture anomalies but are unable to locate the detected anomalies. Besides, they incur significant computation and communication overhead, which exacerbates the packet delivery performance. In this paper, we propose a high-efficient packet forwarding verification mechanism called PPV for networks, which verifies packet source and their forwarding paths in real time. PPV enables probabilistic packet marking in routers instead of verifying all packets. Thus, it can efficiently identify forwarding anomalies by verifying markings. Moreover, it localizes packet forwarding anomalies, e.g., malicious routers, by reconstructing packet forwarding paths based on the packet markings. We implement PPV prototype in Click routers and commodity servers, and conducts real experiments in a real testbed built upon the prototype. The experimental results demonstrate the efficiency and performance of PPV. In particular, PPV significantly improves the throughput and the goodput of forwarding verification, and achieves around 2 times and 3 times improvement compared with the-state-of-art OPT scheme, respectively. Bo Wu 0002, Ke Xu 0002, Qi Li 0002, Zhuotao Liu, Yih-Chun Hu, Martin J. Reed, Meng Shen 0001 |
IWQoS | 5 |
| 2018 | Cognitive radio from hell: Flipping attack on direct-sequence spread spectrumabstractIn this paper, we introduce a strong adversarial attack, referred to as the flipping attack, on Direct-Sequence Spread Spectrum (DSSS) systems. In this attack, the attacker, which is appropriately positioned between the transmitter and the receiver, instantaneously flips the transmitted symbols in the air at 50% rate, thereby driving the channel capacity to zero. Unlike the traditional jamming attack, this attack, when perfectly executed, cannot be detected at the receiver using signal-to-noise-ratio measurements. However, this attack necessitates the attacker to perfectly know the realizations of all the channels in the model. We first introduce the consequences of the flipping attack on narrowband frequency-flat channels, and subsequently discuss its feasibility in wideband frequency-selective channels. From the legitimate users' perspective, we present a method to detect this attack and also propose heuristics to improve the error-performance under the attack. We emphasize that future cyber-physical systems that employ DSSS should design transceivers to detect the proposed flipping attack, and then apply appropriate countermeasures. Yih-Chun Hu |
WCNC | 2 |
| 2018 | Signal Jamming Attacks Against Communication-Based Train Control: Attack Impact and CountermeasureabstractWe study the impact of signal jamming attacks against the communication based train control (CBTC) systems and develop the countermeasures to limit the attacks' impact. CBTC supports the train operation automation and moving-block signaling, which improves the transport efficiency. We consider an attacker jamming the wireless communication between the trains or the train to wayside access point, which can disable CBTC and the corresponding benefits. In contrast to prior work studying jamming only at the physical or link layer, we study the real impact of such attacks on end users, namely train journey time and passenger congestion. Our analysis employs a detailed model of leaky medium-based communication system (leaky waveguide or leaky feeder/coaxial cable) popularly used in CBTC systems. To counteract the jamming attacks, we develop a mitigation approach based on frequency hopping spread spectrum taking into account domain-specific structure of the leaky-medium CBTC systems. Specifically, compared with existing implementations of FHSS, we apply FHSS not only between the transmitter-receiver pair but also at the track-side repeaters. To demonstrate the feasibility of implementing this technology in CBTC systems, we develop a FHSS repeater prototype using software-defined radios on both leaky-medium and open-air (free-wave) channels. We perform extensive simulations driven by realistic running profiles of trains and real-world passenger data to provide insights into the jamming attack's impact and the effectiveness of the proposed countermeasure. Subhash Lakshminarayana, Jabir Shabbir Karachiwala, Sang-Yoon Chang, Girish Revadigar, Sristi Lakshmi Sravana Kumar, David K. Y. Yau, Yih-Chun Hu |
WISEC | 7 |
| 2018 | Practical Proactive DDoS-Attack Mitigation via Endpoint-Driven In-Network Traffic Control
Zhuotao Liu, Yih-Chun Hu, Michael D. Bailey |
IEEE/ACM Trans. Netw. | 3 |
| 2017 | The Case for In-Network Replay SuppressionabstractWe make a case for packet-replay suppression at the network layer, a concept that has been generally neglected. Our contribution is twofold. First, we demonstrate a new attack, the router-reflection attack, that can be launched using compromised routers. In this attack, a compromised router degrades the connectivity of a remote Internet region just by replaying packets. The attack is feasible even if all packets are attributed to their sources, i.e., source authentication is in place, and our evaluation shows that the threat is pervasive---candidate routers for compromise are in the order of hundreds or thousands. Second, we design an in-network mechanism for replay suppression. We start by showing that designing such a mechanism poses unsolved challenges and simple adaptations of end-to-end solutions are not sufficient. Then, we devise, analyze, and implement a highly efficient protocol that suppresses replayed traffic at the network layer without global time synchronization. Our software-router prototype can saturate a 10 Gbps link using only two CPU cores for packet processing. Taeho Lee 0003, Christos Pappas, Adrian Perrig, Virgil D. Gligor, Yih-Chun Hu |
AsiaCCS | 5 |
| 2017 | Deadline-Aware Multipath Communication: An Optimization ProblemabstractMultipath communication not only allows improved throughput but can also be used to leverage different path characteristics to best fulfill each application's objective. In particular, certain delay-sensitive applications, such as real-time voice and video communications, can usually withstand packet loss and aim to maximize throughput while keeping latency at a reasonable level. In such a context, one hard problem is to determine along which path the data should be transmitted or retransmitted. In this paper, we formulate this problem as a linear optimization, show bounds on the performance that can be obtained in a multipath paradigm, and show that path diversity is a strong asset for improving network performance. We also discuss how these theoretical limits can be approached in practice and present simulation results. Laurent Chuat, Adrian Perrig, Yih-Chun Hu |
DSN | 3 |
| 2017 | Cognitive Wireless Charger: Sensing-Based Real-Time Frequency Control For Near-Field Wireless ChargingabstractA recent increase in mobile and IoT devices has led to the advancement of wireless charging. The state-of-the-art wireless charging systems operate at a particular frequency, controlled by the explicit networking from the power-receiving device (which relays the battery status information, useful for the frequency selection), but such control is not designed to cope with the variations in the power receiving device's placements and alignments (which are more significant in near-field and pseudo-tightly coupled charging applications, as more charging pads are being deployed in the public domains and serving heterogeneous clients). In this work, we analyze the impact of the power transfer performance caused by the power receiver's load, distance, and coil alignment/overlap and introduce cognitive wireless charger (CWC), which adaptively controls the operating frequency in real-time using implicit feedback from sensing for optimal operations. In addition to the theoretical and LTSpice-based simulation analysis, we build a prototype compatible to the Qi standard and analyze the performance of CWC with it. Through our analyses, we establish that frequency control achieves performance gains in inductive-coupling charging applications and is sensitive to the variations in the placement and alignment between the power-transmitting and the power-receiving coils. Our prototype, when CWC is turned off, has comparable performance to the commercial-grade Qi wireless chargers and, with CWC enabled, demonstrates significant improvement over modern wireless chargers. Sang-Yoon Chang, Sristi Lakshmi Sravana Kumar, Yih-Chun Hu |
ICDCS | 3 |
| 2017 | Performance of Cognitive Wireless Charger for Near-Field Wireless ChargingabstractWireless charging provides a convenient way to charge various mobile and IoT devices. Prior work in state-of-theart wireless charging systems operates at a frequency controlled by explicit networking from the power-receiving devices and is designed for the environment when the participating devices are perfectly aligned with each other. The need for the finer control due to the devices’ misalignment is increasing in near-field and pseudo-tightly coupled charging applications, as more charging pads, are being deployed in the public domains and serving heterogeneous clients. Because inductive-coupled charging applications are sensitive to the placement and alignment variations between the power-transmitting and the power-receiving coils, we design and build Cognitive Wireless Charger (CWC). CWC adaptively controls the operating frequency in real time using implicit feedback for optimal power transfer operations. This demo is to supplement our paper about CWC [1]. In this demo, we showcase the impact on power transfer performance caused by the variations in the placement and alignment between the charging coils of power transmitter and power receiver and demonstrate the performance improvement provided by CWC. Sang-Yoon Chang, Sristi Lakshmi Sravana Kumar, Yih-Chun Hu |
ICDCS | 3 |
| 2017 | TorPolice: Towards enforcing service-defined access policies for anonymous communication in the Tor networkabstractTor is the most widely used anonymity network, currently serving millions of users each day. However, there is no access control in place for all these users, leaving the network vulnerable to botnet abuse and attacks. For example, criminals frequently use exit relays as stepping stones for attacks, causing service providers to serve CAPTCHAs to exit relay IP addresses or blacklisting them altogether, which leads to severe usability issues for legitimate Tor users. To address this problem, we propose TorPolice, the first privacy-preserving access control framework for Tor. TorPolice enables abuse-plagued service providers such as Yelp to enforce access rules to police and throttle malicious requests coming from Tor while still providing service to legitimate Tor users. Further, TorPolice equips Tor with global access control for relays, enhancing Tor's resilience to botnet abuse. We show that TorPolice preserves the privacy of Tor users, implement a prototype of TorPolice, and perform extensive evaluations to validate our design goals. Zhuotao Liu, Yushan Liu 0004, Philipp Winter, Prateek Mittal, Yih-Chun Hu |
ICNP | 5 |
| 2017 | Insider-Attacks on Physical-Layer Group Secret-Key Generation in Wireless NetworksabstractPhysical-layer group secret-key (GSK) generation is an effective way of generating secret keys in wireless networks, wherein the nodes exploit inherent randomness in the wireless channels to generate group keys, which are subsequently applied to secure messages while broadcasting, relaying, and other network-level communications. While existing GSK protocols focus on securing the common source of randomness from external eavesdroppers, they assume that the legitimate nodes of the group are trusted. In this paper, we address insider attacks from the legitimate participants of the wireless network during the key generation process. Instead of addressing conspicuous attacks such as switching-off communication, injecting noise, or denying consensus on group keys, we introduce stealth attacks that can go undetected against state-of- the-art GSK schemes. We propose two forms of attacks, namely: (i) different-key attacks, wherein an insider attempts to generate different keys at different nodes, especially across nodes that are out of range so that they fail to recover group messages despite possessing the group key, and (ii) low-rate key attacks, wherein an insider alters the common source of randomness so as to reduce the key-rate. We also discuss various detection techniques, which are based on detecting anomalies and inconsistencies on the channel measurements at the legitimate nodes. Through simulations we show that GSK generation schemes are vulnerable to insider-threats, especially on topologies that cannot support additional secure links between neighbouring nodes to verify the attacks. Sang-Yoon Chang, Yih-Chun Hu |
WCNC | 3 |
| 2017 | Power-positive networking using wireless charging: protecting energy against battery exhaustion attacksabstractEnergy is required for networking and computation and is a valuable resource for unplugged embedded systems. Energy DoS attack where a remote attacker exhausts the victim's battery by sending networking requests remains a critical challenge for the device availability. While prior literature proposes mitigation- and detection-based solutions, we propose to eliminate the vulnerability entirely by offloading the power requirements to the entity who makes the networking requests. To do so, we build communication channels using wireless charging signals, so that the communication and the power transfer are simultaneous and inseparable, and use the channels to build power-positive networking (PPN). PPN also offloads the computation-based costs to the requester, enabling authentication and other tasks considered too power-hungry for battery-operated devices. Furthermore, because we use the charging signal for bidirectional networking, the design requires no additional hardware beyond that for wireless charging. In this paper, we present PPN, implement a Qi-compatible prototype, and use the prototype to analyze the performance. Sang-Yoon Chang, Sristi Lakshmi Sravana Kumar, Bao Anh N. Tran, Sreejaya Viswanathan, Younghee Park, Yih-Chun Hu |
WISEC | 6 |
| 2017 | SecureMAC: Securing Wireless Medium Access Control Against Insider Denial-of-Service AttacksabstractWireless network dynamically allocates channel resources to improve spectral efficiency and, to avoid collisions, has its users cooperate with each other using a medium access control (MAC) protocol. However, MAC assumes user compliance and can be detrimental when a user misbehaves. An attacker who compromised the network can launch more devastating denial-of-service (DoS) attacks than a network outsider by sending excessive reservation requests to waste bandwidth, by listening to the control messages and conducting power-efficient jamming, by falsifying information to manipulate the network control, and so on. We build SecureMAC to defend against such insider threats while retaining the benefits of coordination between the cooperative users. SecureMAC is comprised of four components: channelization to prevent excessive reservations, randomization to thwart reactive targeted jamming, coordination to counter control-message aware jamming and resolve over-reserved and under-reserved spectrum, and power attribution to determine each node's contribution to the received power. Our theoretical analyses and implementation evaluations demonstrate superior performance over previous approaches, which either ignore security issues or give up the benefit of cooperation when under attack by disabling user coordination (such as the Nash equilibrium of continuous wideband transmission). In realistic scenarios, our SecureMAC implementation outperforms such schemes by 76-159 percent. Sang-Yoon Chang, Yih-Chun Hu |
IEEE Trans. Mob. Comput. | 2 |
| 2016 | MiddlePolice: Toward Enforcing Destination-Defined Policies in the Middle of the InternetabstractVolumetric attacks, which overwhelm the bandwidth of a destination, are amongst the most common DDoS attacks today. One practical approach to addressing these attacks is to redirect all destination traffic (e.g., via DNS or BGP) to a third-party, DDoS-protection-as-a-service provider (e.g., CloudFlare) that is well provisioned and equipped with filtering mechanisms to remove attack traffic before passing the remaining benign traffic to the destination. An alternative approach is based on the concept of network capabilities, whereby source sending rates are determined by receiver consent, in the form of capabilities enforced by the network. While both third-party scrubbing services and network capabilities can be effective at reducing unwanted traffic at an overwhelmed destination, DDoS-protection-as-a-service solutions outsource all of the scheduling decisions (e.g., fairness, priority and attack identification) to the provider, while capability-based solutions require extensive modifications to existing infrastructure to operate. In this paper we introduce MiddlePolice, which seeks to marry the deployability of DDoS-protection-as-a-service solutions with the destination-based control of network capability systems. We show that by allowing feedback from the destination to the provider, MiddlePolice can effectively enforce destination-chosen policies, while requiring no deployment from unrelated parties. Zhuotao Liu, Yih-Chun Hu, Michael D. Bailey |
CCS | 3 |
| 2016 | Key Update at Train Stations: Two-Layer Dynamic Key Update Scheme for Secure Train Communications
Sang-Yoon Chang, Shaoying Cai, Hwajeong Seo, Yih-Chun Hu |
SecureComm | 4 |
| 2016 | Location Privacy with Randomness ConsistencyabstractAbstract Location-Based Social Network (LBSN) applications that support geo-location-based posting and queries to provide location-relevant information to mobile users are increasingly popular, but pose a location-privacy risk to posts. We investigated existing LBSNs and location privacy mechanisms, and found a powerful potential attack that can accurately locate users with relatively few queries, even when location data is well secured and location noise is applied. Our technique defeats previously proposed solutions including fake-location detection and query rate limits. To protect systems from this attack, we propose a simple, scalable, yet effective defense that quantizes the map into squares using hierarchical subdivision, consistently returns the same random result to multiple queries from the same square for posts from the same user, and responds to queries with different distance thresholds in a correlated manner, limiting the information gained by attackers, and ensuring that an attacker can never accurately know the quantized square containing a user. Finally, we verify the performance of our defense and analyze the trade-offs through comprehensive simulation in realistic settings. Surprisingly, our results show that in many environments, privacy level and user accuracy can be tuned using two independent parameters; in the remaining environments, a single parameter adjusts the tradeoff between privacy level and user accuracy. We also thoroughly explore the parameter space to provide guidance for actual deployments. Hao Wu 0018, Yih-Chun Hu |
Proc. Priv. Enhancing Technol. | 2 |
| 2016 | SimpleMAC: A Simple Wireless MAC-Layer Countermeasure to Intelligent and Insider JammersabstractIn wireless networks, users share a transmission medium. For efficient channel use, wireless systems often use a Medium Access Control (MAC) protocol to perform channel coordination by having each node announce its usage intentions and other nodes avoid making conflicting transmissions. Traditionally, such announcements are made on a common control channel. However, this control channel is vulnerable to jamming because its location is pre-assigned and known to attackers. Furthermore, the announcements themselves provide information useful for jamming. We focus on a situation where transmitters share spectrum in the presence of intelligent and insider jammers capable of adaptively changing their jamming patterns. Despite the complex threat model, we propose a simple MAC scheme, called SimpleMAC, that effectively counters network compromise and MAC-aware jamming attacks. We then study the optimal adversarial behavior and analyze the performance of the proposed scheme theoretically, through Monte Carlo simulations, and by implementation on the WARP software-defined radio platform. In comparison to the Nash equilibrium alternative of disabling the MAC protocol, SimpleMAC quickly attains vastly improved performance and converges to the optimal solution (over six-fold improvement in SINR and 50% gains in channel capacity in a realistic mobile scenario). Sang-Yoon Chang, Yih-Chun Hu, Nicola Laurenti |
IEEE/ACM Trans. Netw. | 2 |
| 2015 | Jamming with Power Boost: Leaky Waveguide Vulnerability in Train SystemsabstractModern-day train operations rely on wireless communications. Unlike other mobile systems, the train vehicle operations are tightly interwound with and remain physically close to the railway and the trackside infrastructure, providing a suitable platform to deploy leaky-waveguide-based communication. Due to the train system's safety-critical application and its exposure to the public, it is critical to address security in train communications. To investigate the availability of leaky waveguide communications, we first study prior leaky waveguide implementations in train systems and, based on those studies, construct a model to characterize the path loss of inside-waveguide propagation and the repeater implementations. Using our model, we analyze the jamming impact and contrast with jamming in free space without a waveguide. As a result, we establish that jamming the waveguide takes advantage of the waveguide infrastructure to extend its impact beyond the traditional jamming range and breaks the spatial dependence on the jamming source. Sang-Yoon Chang, Bao Anh N. Tran, Yih-Chun Hu, Douglas L. Jones |
ICPADS | 3 |
| 2015 | A clean slate design for secure wireless ad-hoc networks - Part 1: Closed synchronized networksabstractWe propose a clean-slate, holistic approach to the design of secure protocols for wireless ad-hoc networks. We design a protocol that enables a collection of distributed nodes to emerge from a primordial birth and form a functioning network. We consider the case when nodes are synchronized and the network is closed, in that no other nodes can join. We define a game between protocols and adversarial nodes, and describe a protocol that is guaranteed to achieve the max-min payoff regardless of what the adversarial nodes do. Moreover, even though the adversarial nodes always know the protocol a priori, we show an even stronger result; the protocol is guaranteed to achieve the min-max payoff. Hence there is a saddle point in the game between protocols and adversarial strategies. Finally, we show that the adversarial nodes are in effect, strategically confined to either jamming or conforming to the protocol. These guarantees are contingent on a set of underlying model assumptions, and cease to be valid if the assumptions are violated. Jonathan Ponniah, Yih-Chun Hu, P. R. Kumar 0001 |
WiOpt | 2 |
| 2015 | A clean slate design for secure wireless ad-hoc networks - Part 2: Open unsynchronized networksabstractWe build upon the clean-slate, holistic approach to the design of secure protocols for wireless ad-hoc networks proposed in part one. We consider the case when the nodes are not synchronized, but instead have local clocks that are relatively affine. In addition, the network is open in that nodes can enter at arbitrary times. To account for this new behavior, we make substantial revisions to the protocol in part one. We define a game between protocols for open, unsynchronized nodes and the strategies of adversarial nodes. We show that the same guarantees in part one also apply in this game: the protocol not only achieves the max-min utility, but the min-max utility as well. That is, there is a saddle point in the game, and furthermore, the adversarial nodes are effectively limited to either jamming or conforming with the protocol. Jonathan Ponniah, Yih-Chun Hu, P. R. Kumar 0001 |
WiOpt | 2 |
| 2014 | Mechanized Network Origin and Path Authenticity ProofsabstractA secure routing infrastructure is vital for secure and reliable Internet services. Source authentication and path validation are two fundamental primitives for building a more secure and reliable Internet. Although several protocols have been proposed to implement these primitives, they have not been formally analyzed for their security guarantees. In this paper, we apply proof techniques for verifying cryptographic protocols (e.g., key exchange protocols) to analyzing network protocols. We encode LS2, a program logic for reasoning about programs that execute in an adversarial environment, in Coq. We also encode protocol-specific data structures, predicates, and axioms. To analyze a source-routing protocol that uses chained MACs to provide origin and path validation, we construct Coq proofs to show that the protocol satisfies its desired properties. To the best of our knowledge, we are the first to formalize origin and path authenticity properties, and mechanize proofs that chained MACs can provide the desired authenticity properties. Fuyuan Zhang, Limin Jia 0001, Cristina Basescu, Tiffany Hyun-Jin Kim, Yih-Chun Hu, Adrian Perrig |
CCS | 5 |
| 2014 | Efficient Large Flow Detection over Arbitrary Windows: An Algorithm Exact Outside an Ambiguity RegionabstractMany networking and security applications can benefit from exact detection of large flows over arbitrary windows (i.e. any possible time window). Existing large flow detectors that only check the average throughput over certain time period cannot detect bursty flows and are therefore easily fooled by attackers. However, no scalable approaches provide exact classification in one pass. To address this challenge, we consider a new model of exactness outside an ambiguity region, which is defined to be a range of bandwidths below a high-bandwidth threshold and above a low-bandwidth threshold. Given this new model, we propose a deterministic algorithm, EARDet, that detects all large flows (including bursty flows) and avoids false accusation against any small flows, regardless of the input traffic distribution. EARDet monitors flows over arbitrary time windows and is built on a frequent items finding algorithm based on average frequency. Despite its strong properties, EARDet has low storage overhead regardless of input traffic and is surprisingly scalable because it focuses on accurate classification of large flows and small flows only. Our evaluations confirm that existing approaches suffer from high error rates (e.g., misclassifying 1% of small flows as large flows) in the presence of large flows and bursty flows, whereas EARDet can accurately detect both at gigabit line rate using a small amount of memory that fits into on-chip SRAM. Hao Wu 0018, Hsu-Chun Hsiao, Yih-Chun Hu |
Internet Measurement Conference | 3 |
| 2014 | Lightweight source authentication and path validationabstractIn-network source authentication and path validation are fundamental primitives to construct higher-level security mechanisms such as DDoS mitigation, path compliance, packet attribution, or protection against flow redirection. Unfortunately, currently proposed solutions either fall short of addressing important security concerns or require a substantial amount of router overhead. In this paper, we propose lightweight, scalable, and secure protocols for shared key setup, source authentication, and path validation. Our prototype implementation demonstrates the efficiency and scalability of the protocols, especially for software-based implementations. Tiffany Hyun-Jin Kim, Cristina Basescu, Limin Jia 0001, Soo Bum Lee, Yih-Chun Hu, Adrian Perrig |
SIGCOMM | 5 |
| 2014 | A Study on False Channel Condition Reporting Attacks in Wireless NetworksabstractWireless networking protocols are increasingly being designed to exploit a user's measured channel condition; we call such protocols channel-aware. Each user reports the measured channel condition to a manager of wireless resources and a channel-aware protocol uses these reports to determine how resources are allocated to users. In a channel-aware protocol, each user's reported channel condition affects the performance of every other user. The deployment of channel-aware protocols increases the risks posed by false channel-condition feedback. In this paper, we study what happens in the presence of an attacker that falsely reports its channel condition. We perform case studies on channel-aware network protocols to understand how an attack can use false feedback and how much the attack can affect network performance. The results of the case studies show that we need a secure channel condition estimation algorithm to fundamentally defend against the channel-condition misreporting attack. We design such an algorithm and evaluate our algorithm through analysis and simulation. Our evaluation quantifies the effect of our algorithm on system performance as well as the security and the performance of our algorithm. Yih-Chun Hu |
IEEE Trans. Mob. Comput. | 2 |
| 2013 | Secure cooperative spectrum sensing based on Sybil-resilient clusteringabstractThe Sybil attack has devastating effect on many distributed decision protocols such as voting: By disguising with multiple identities, a Sybil attacker can amplify his impact on the final outcome. A cooperative spectrum sensing protocol, which aims to enhance the sensing performance over the individual sensing protocols, is a kind of cooperative decision protocol. If not carefully designed, cooperative spectrum sensing can also be very vulnerable to the false-reporting Sybil attack, in which an attacker seeks to degrade the sensing performance by submitting multiple incorrect measurements using multiple identities. In this paper, we exploit the attacker's limited radio resources and propose a Sybil-resilient clustering mechanism, and adopt it as the basis of a secure cluster-based cooperative sensing protocol. We perform extensive simulation and show that naïve soft data combination and statistics-based false-report-resilient cooperative sensing protocols are susceptible to the Sybil attack; however, our proposed protocol can still provide reasonable sensing outcome despite the presence of Sybil attackers. Jerry T. Chiang, Yih-Chun Hu, Pulkit Yadav |
GLOBECOM | 2 |
| 2013 | Did you also hear that? Spectrum sensing using Hermitian inner productabstractSpectrum sensing is one of the most important enabling techniques on which to build a cognitive radio network. However, previously proposed techniques often have shortcomings in non-ideal environments: 1) An energy detector is simple but cannot perform in face of uncertain noise power; 2) A matched filter is the optimal detector, but performs poorly with clock drifts; 3) Eigenvalue-based blind feature detectors show great promise, but cannot detect signals that are noise-like; and 4) Above protocols all rely on field survey to determine the proper decision thresholds. We propose HIPSS and its extension Δ-HIPSS that are based on the Hermitian-inner-product of two observations acquired by a wireless receiver over multiple radio paths. HIPSS and Δ-HIPSS are lightweight and through extensive analysis and evaluation, we show that 1) HIPSS and Δ-HIPSS are robust in the presence of noise power uncertainties; 2) HIPSS and ΔHIPSS require neither a much longer observation duration nor complex computation compared to an energy detector in ideal setting; 3) HIPSS and Δ-HIPSS can detect noise-like primary signals; and 4) Δ-HIPSS can reliably return sensing decisions without necessitating any field surveys. Jerry T. Chiang, Yih-Chun Hu |
INFOCOM | 2 |
| 2012 | Bankrupting the jammer in WSNabstractThe high vulnerability of the wireless sensor nodes to jamming arises from the low resilience and easy differentiability of protocol control messages, and the high predictability of node wakeup schedules. In this paper, we propose Jam-Buster - a jam-resistant solution for WSN, orthogonal to the existing antijamming solutions, that increases resilience by using multi-block payloads, eliminates differentiation by using equal size packets and reduces predictability by randomizing the wakeup times of the sensors. While each of these individual components is quite simple, the combination of the three components results in a jam-resilient system that forces the jammer to transmit more enabling faster detection of the jammer by the sensors, and to spend more energy to be effective and so reduce its own lifetime. By modeling our system using game theory and then evaluating the system in a TmoteSky testbed, we show that Jam-Buster reduces the overall efficiency of an intelligent jammer. Farhana Ashraf, Yih-Chun Hu, Robin Kravets |
MASS | 2 |
| 2012 | SimpleMAC: a jamming-resilient MAC-layer protocol for wireless channel coordinationabstractIn wireless networks, users share a transmission medium. To increase the efficiency of channel usage, wireless systems often use a Medium Access Control (MAC) protocol to perform channel coordination by having each node announce its usage intentions; other nodes avoid making conflicting transmissions minimizing interference both to the node that has announced its intentions and to a node that cooperates by avoiding transmissions during the reserved slot. Traditionally, in a multi-channel environment, such announcements are made on a common control channel. However, this control channel is vulnerable to jamming because its location is pre-assigned and known to attackers. Furthermore, the announcements themselves provide information useful for jamming. In this paper, we focus on a situation where multiple wireless transmitters share spectrum in the presence of intelligent and possibly insider jammers capable of dynamically and adaptively changing their jamming patterns. Sang-Yoon Chang, Yih-Chun Hu, Nicola Laurenti |
MobiCom | 2 |
| 2012 | JIM-beam: using spatial randomness to build jamming-resilient wireless flooding networksabstractSince a transmitter can only be at one location at a time, a jammer must jam in a narrowband fashion in the spatial domain. We propose JIM-Beam, a narrowband jamming-resilient flooding protocol that randomizes the orientation of a node's directional antenna over time. We use ns-2 simulations to show that JIM-Beam provides improvements in packet delivery ratio over flooding naively and flooding using the uncoordinated frequency hopping protocol. Jerry T. Chiang, Yih-Chun Hu |
MobiHoc | 3 |
| 2012 | Power control for fair dynamic channel reservation in VANETsabstractProviding safety applications is one of the principal motivations behind deploying vehicular ad hoc networks (VANETs). These applications require fair (i.e., all vehicles get equal fraction of time allocation for their transmissions) and reliable (i.e., transmissions are received with high probably by the intended receivers) broadcasting of relevant driving data. In this paper we compare the performance of IEEE 802.11p and a recent time-division based medium access control protocol, Dynamic Channel Reservation (DCR) in realistic high-density traffic scenarios. We focus on the communication requirements that allow vehicles to receive safety messages well enough in advance to warn the driver in a timely manner and avoid crashes. We observe performance degradation in both schemes as we examine them in congested environments. In such scenarios, in 802.11p, broadcast reliability decreases, while in DCR, some vehicles face starvation, thus the fairness requirement is not met. In order to avoid this situation, we propose a modified version of DCR, fDCR, in which time channels can be occupied by several vehicles, thus fostering a fair channel reservation scheme. Our channel reservation scheme is designed in a way that minimizes packet collisions due to a transmission, in receivers which are close to that transmitter. Furthermore, to enhance the probability of reception in nearby vehicles, which is one of the main communication requirements of safety applications, we propose a low-overhead transmission power control scheme. Our fully distributed power control scheme leverages on the extra transmitted information by DCR to estimate the number of vehicles in its transmission range, and accordingly adjust the transmission power. Experimental results show significant performance gains in cases of both cross-through and non-cross-through traffic for our proposed scheme in comparison with 802.11p and DCR. Parisa Haghani, Yih-Chun Hu |
SECON | 2 |
| 2012 | Secure Location Verification Using Simultaneous MultilaterationabstractSubstantial effort has been invested on secure location verification in hope to enable mobile wireless systems to optimize system performance or securely confer rights based on the participants' locations. However, most previous studies do not address the impact of, and are often susceptible to, collusion attacks in which adversaries share their private keys. In this paper, we propose a secure multilateration scheme. Given the same processing delay, detection threshold, and assuming zero synchronization error between verifiers, our proposed scheme achieves the highest rate of false-location detection by any verification system based solely on time-of-flight measurements. We also show that our scheme is resilient to collusion attacks if the verification system can detect the distance enlargement attack. We propose using other physical measurements to mitigate the distance enlargement, and thus also the collusion, attacks. To the best of our knowledge, this is the first attempt to prevent collusion attacks by mitigating the distance enlargement attack. Jerry T. Chiang, Jason J. Haas, Jihyuk Choi, Yih-Chun Hu |
IEEE Trans. Wirel. Commun. | 4 |
| 2011 | A Lightweight Deterministic MAC Protocol Using Low Cross-Correlation SequencesabstractIn traditional wireless networks, two nodes cannot simultaneously transmit their packets to each other with one radio device (having no machinery enabling full duplex). To ensure bidirectional communications, we need a medium access protocol to coordinate neighboring nodes' transmissions. Two conflicting design goals for the medium access protocol are the ease of implementation and performance guarantees. We propose a novel medium access protocol which is easily implementable (not requiring clock synchronization) and guarantees performance (the fraction of available slots). Our basic idea is to exploit a set of binary sequences having provably low cross-correlation. Each node has its own code sequence and determines whether to transmit or receive a packet by sequentially examining each bit of the code sequence. As an example, we consider the application of Gold code sequences and theoretically analyze the the fraction of available slots that a Gold-code- based MAC can provide. Our simulation verifies our analysis and shows that a Gold-code-based MAC guarantees the fraction of available slots even on a short time scale. Danesh J. Esteki, Yih-Chun Hu, P. R. Kumar 0001 |
GLOBECOM | 3 |
| 2011 | Secure MAC-Layer Protocol for Captive Portals in Wireless HotspotsabstractWireless access points largely fall into three categories: home and small business networks, enterprise networks, and hotspots. Wi-Fi Protected Access (WPA) provides solutions to home, small business, and enterprise networks, but hotspots typically are not secured at the Medium Access Control (MAC) layer because they are open to the public. In this paper, we present a scheme that establishes a secure wireless connection between a client device and an access point in these open environments. In our approach, we use hierarchical identity-based cryptography, and each user uses its MAC address as its public key. Our scheme ensures confidentiality and integrity even in the presence of colluding attackers. Jihyuk Choi, Sang-Yoon Chang, Diko Ko, Yih-Chun Hu |
ICC | 4 |
| 2011 | Demo: bankrupting the jammerabstractNo abstract available. Farhana Ashraf, Yih-Chun Hu, Robin Kravets |
MobiSys | 2 |
| 2011 | Bankrupting the jammerabstractThe high vulnerability of nodes in a WSN to jamming arises from the low resilience to jamming signals, easy differentiability of packet types and high predictability of wakeup schedules. In this paper, we propose Jam-Buster - a jam-resistant solution for a single channel WSN that increases resilience by using multi-block payload, eliminates differentiation by using equal size packets and reduces predictability by randomizing the wakeup times of the sensors. While each of these individual components is quite simple, the combination of the three components results in a jam-resilient system that forces the jammer to spend more energy to be effective and so reduce its own lifetime. Farhana Ashraf, Yih-Chun Hu, Robin Kravets |
SECON | 2 |
| 2011 | Short paper: a practical view of "mixing" identities in vehicular networksabstractIn a Vehicular Ad hoc NETwork (VANET), vehicles broadcast safety messages disclosing their trajectory information in order to warn drivers of impending accidents. Precise location information needed for these safety applications, combined with the need to exclude attackers through the use of authentication, creates a significant privacy risk. One method proposed to improve privacy is the use of many pseudonyms, and changing pseudonyms while in a mix zone where all other vehicles also change pseudonyms. Previous work has evaluated the effectiveness of mix zones using traces generated based on traffic theory. In this paper, we analyze the privacy obtainable from using mix zones in VANETs based on actual recordings of vehicle movements. We choose rank instead of entropy as our privacy metric because, as we will show, entropy is difficult to measure in our scenarios. Bisheng Liu, Jerry T. Chiang, Jason J. Haas, Yih-Chun Hu |
WISEC | 4 |
| 2011 | Optimal physical carrier sense in wireless networks
Kyung-Joon Park, Jihyuk Choi, Jennifer C. Hou, Yih-Chun Hu, Hyuk Lim |
Ad Hoc Networks | 4 |
| 2011 | Efficient Certificate Revocation List Organization and DistributionabstractIn this paper, we propose a lightweight mechanism for revoking security certificates that is appropriate for the limited bandwidth and hardware cost constraints of a VANET. A Certificate Authority (CA) issues certificates to trusted nodes, i.e., vehicles. If the CA looses trust in a vehicle (e.g., due to evidence of malfunction or malicious behavior), the CA must promptly revoke the certificates of the distrusted vehicle. To distribute revocation information quickly even during incremental deployment, we propose that CAs use Certificate Revocation Lists (CRLs). The CRL should be composed in a secure manner, and it should be exchanged in a way such that the CRL is both quickly and widely distributed. We previously proposed a mechanism for the quick distribution of CRL updates that also covers a wide area by using vehicle-to-vehicle (V2V) communication . In this paper, we additionally investigate the performance of V2V communication in partial deployment scenarios, that is, where only a certain percentage of vehicles are equipped with VANET radios. We provide simulation results that show our V2V exchange mechanism is quicker than distributing CRLs or CRL updates through road-side units (RSUs) alone. However, this revocation process, which involves both the CA and vehicles, must conform to the aforementioned bandwidth and hardware restrictions. In this paper, we present mechanisms that achieve the goals of reduced CRL size, a computationally efficient mechanism for determining if a certificate is on the CRL, and a lightweight mechanism for exchanging CRL updates. Additionally, we expand on our previous work to provide privacy to revoked vehicles prior to their revocation. Jason J. Haas, Yih-Chun Hu, Kenneth P. Laberteaux |
IEEE J. Sel. Areas Commun. | 2 |
| 2011 | Cross-layer jamming detection and mitigation in wireless broadcast networksabstractWireless communication systems are often susceptible to the jamming attack where adversaries attempt to overpower transmitted signals by injecting a high level of noise. Jamming is difficult to mitigate in broadcast networks because transmitting and receiving are inherently symmetric operations: A user that possesses the key to decode a transmission can also use that key to jam the transmission. We describe a code tree system that provides input to the physical layer and helps the physical layer circumvent jammers. In our system, the transmitter has more information than any proper subset of receivers. Each receiver cooperates with the transmitter to detect any jamming that affects that receiver. In the resulting system, each benign user is guaranteed to eliminate the impact of the attacker after some finite number of losses with arbitrarily high probability. We show that any system that relies on only using spreading code, and no other physical factors, to mitigate jamming must use at least$j+1$codes, where$j$is the number of jammers. We then propose an optimized scheme that is power-efficient: Each transmission is sent on at most$2j+1$codes simultaneously. Finally, we demonstrate that our scheme approaches the best possible performance by performing an extensive analysis of the system using both event-driven ns-2 and chip-accurate MATLAB simulations. Jerry T. Chiang, Yih-Chun Hu |
IEEE/ACM Trans. Netw. | 2 |
| 2010 | CRAFT: a new secure congestion control architectureabstractCongestion control algorithms seek to optimally utilize network resources by allocating a certain rate for each user. However, malicious clients can disregard the congestion control algorithms implemented at the clients and induce congestion at bottleneck links. Thus, in an adversarial environment, the network must enforce the congestion control algorithm in order to attain the optimal network utilization offered by the algorithm. Prior work protects only a single link incident on the enforcement routers neglecting damage inflicted upon other downstream links. We present CRAFT, a capability-based scheme to secure all downstream links of a deploying router. Our goal is to enforce a network-wide congestion control algorithm on all flows. As a reference design, we develop techniques to enforce the TCP congestion control. Our design regulates all flows to share bandwidth resources in a TCP-fair manner by emulating the TCP state machine in a CRAFT router. As a result, once a flow passes a single CRAFT router, it is TCP-fair on all downstream links of that router. Jerry T. Chiang, Yih-Chun Hu, Adrian Perrig, P. R. Kumar 0001 |
CCS | 3 |
| 2010 | Partial Deafness: A Novel Denial-of-Service Attack in 802.11 Networks
Jihyuk Choi, Jerry T. Chiang, Yih-Chun Hu |
SecureComm | 4 |
| 2010 | A Study on False Channel Condition Reporting Attacks in Wireless Networks
Yih-Chun Hu |
SecureComm | 2 |
| 2010 | The impact of key assignment on VANET privacyabstractAbstract There are two underlying principles that guide how a vehicular ad hoc network (VANET) is built: there will be misbehavior and the extent to which vehicles can misbehave should be bounded. Additionally, the main use for VANETs currently is to enable safety applications where vehicles' position, velocity, and acceleration are broadcast to other vehicles in the VANET. Combining these guiding principles with this application results in the privacy of vehicles and users being an important concern for VANET design. Safety application messages are signed using keys and therefore linked to vehicles. In this work, we investigate how to assign keys to vehicles in order to preserve privacy and maintain our guiding VANET design principles. Specifically, we investigate the design space where individual keys may be given to multiple vehicles and vehicles may have multiple keys. Through a simple security analysis, we eliminate the case where all keys are common. Through mathematical and logical analysis, we conclude that keys should not be owned by multiple vehicles, that is, keys should be unique to vehicles and vehicles should be given multiple keys. Specifically, we show that it is impossible to provide good privacy and fast revocation when keys are shared among vehicles. Copyright © 2009 John Wiley & Sons, Ltd. Jason J. Haas, Yih-Chun Hu, Kenneth P. Laberteaux |
Secur. Commun. Networks | 2 |
| 2009 | Secure Unified Cellular Ad Hoc Network RoutingabstractPrevious simulations have shown substantial performance gains can be achieved by using hybrid cellular and wireless LAN (WLAN) approaches. In a hybrid system, a proxy in an area of strong connectivity (and therefore higher bandwidth) forwards traffic on behalf of a client in an area of weaker connectivity (and therefore lower bandwidth). The proxy routes traffic between the base station (over a cellular link) and the client (over a WLAN). Such approaches have had limited practical applicability due to substantial security risks, including eavesdropping, intentional performance degradation and cheating the incentive schemes. The secure unified cellular ad hoc network (SUCAN) protocol is designed to address these risks, allowing the deployment of hybrid networks. SUCAN uses incentives and cryptographic techniques to eliminate cheating by self-interested hosts, while limiting the damage caused by malicious hosts. We implemented SUCAN on Verizon's broadband access network. To our knowledge, this is the first realworld implementation of a hybrid cellular network protocol. Our implementation results show that the SUCAN system can provide substantial performance increases and protects against performance degradation even in the presence of malicious behavior. Jason J. Haas, Yih-Chun Hu |
GLOBECOM | 2 |
| 2009 | Real-World VANET Security Protocol PerformanceabstractMany results have been published in the literature based on performance measurements obtained from simulations of vehicular networks (VANETs). These simulations use as input traces of vehicle movements that have been generated by traffic simulators which are based on traffic theory models. To our knowledge, no one has published any work based on actual large-scale recordings of vehicle movements. We use recordings of actual vehicle movements on various roadways. In order to enable analysis on this scale, we have developed a new VANET simulator, which can handle many more vehicles than NS-2. To enable us to use our own simulator, we present results of a cross-validation between NS-2 and our simulator, showing that both simulators produce results that are statistically the same. We use our simulator to analyze the proposed authentication mechanism, which relies on ECDSA signatures, comparing it to broadcast authentication using TESLA. We perform our evaluations using real vehicle mobility, which we believe to be the first simulations using real vehicle mobility. Our comparison shows strengths and weaknesses for each of these authentication schemes in terms of the resulting reception rates and latency of broadcast packets. Jason J. Haas, Yih-Chun Hu, Kenneth P. Laberteaux |
GLOBECOM | 2 |
| 2009 | Fundamental Limits on Secure Clock Synchronization and Man-In-The-Middle Detection in Fixed Wireless NetworksabstractIn this paper we present fundamental results on secure clock synchronization and man-in-the-middle detection using only timing information. Under the assumption of afflne clocks, we present a clock synchronization protocol that can operate on any channel on which data can be sent. We present a clock synchronization protocol from the literature and add verification steps on top of this protocol. These verification steps force man- in-the-middle attackers, who want to delay traffic between the endpoints and yet remain undetected, to impose only constant delays on packets. In a special case, we show that it is possible to identify and ignore attacker-delayed packets. We then show three different types of attackers: a half-duplex attacker that can always be caught using timing information alone, a double full-duplex attacker that can never be caught using only timing information, and a full-duplex attacker whose capability to perform man-in-the- middle attacks depends on its location relative to the endpoints and on the turnaround times of the endpoints. In particular, we prove that certain attackers are impossible to detect using only timing, and we construct defensive protocols that prevent all other man-in- the-middle delay attacks. A particularly noteworthy result is that a single attacker using the same radio technology as the endpoints can never successfully perform a man-in-the-middle attack to delay traffic. These results form a lightweight man-in-the-middle attack detection protocol, on top of which a wide variety of protocols can be built, including routing protocols and more sophisticated heavyweight protocols. Jerry T. Chiang, Jason J. Haas, Yih-Chun Hu, P. R. Kumar 0001, Jihyuk Choi |
INFOCOM | 3 |
| 2009 | Secure and precise location verification using distance bounding and simultaneous multilaterationabstractDue to the widespread adoption of the Global Positioning System (GPS), many systems have been designed to use the location information of participants. When these systems confer rights (such as access rights) based on location, such claim must be securely verified in order to prevent attackers from gaining access to resources that should be restricted. Substantial effort has been made on secure location verification; however, previous work does not address the impact of collusion attacks where adversaries share their private keys nor do they address a possible jamming attack where attackers inject a high amount of noise to prevent successful challenge and response receptions. In this paper, we propose a secure multilateration scheme that provides maximal security achievable by any time-of-flight based system that does not employ other verification methods. Jerry T. Chiang, Jason J. Haas, Yih-Chun Hu |
WISEC | 3 |
| 2009 | SEAR: a secure efficient ad hoc on demand routing protocol for wireless networksabstractAbstract Multi‐hop routing is essential to the operation of wirelessad hocnetworks. Unfortunately, it is very easy for an adversary to forge or modify routing messages to inflict severe damage on the underlying routing protocol. In this paper, we present SEAR, a secure efficientad hocrouting (SEAR) protocol forad hocnetworks that is mainly based on efficient symmetric cryptography, with asymmetric cryptography used only for the distribution of initial key commitments. SEAR uses one‐way hash functions to protect the propagation of the routing messages. Intermediate nodes verify the routing messages by applying one‐way functions, while malicious nodes cannot construct beneficial false routing messages when forwarding them. Route error (RERR) messages are protected through a variation of the TESLA broadcast authentication scheme. The SEAR protocol does not require any additional routing packet formats, and thus follows the same basic design asad hocon‐demand distance vector (AODV). We show, through both theoretical examination and simulations, that SEAR provides better security with significantly less overhead than other existing secure AODV (SAODV) protocols. Copyright © 2008 John Wiley & Sons, Ltd. Qing Li 0005, Meiyuan Zhao, Jesse Walker, Yih-Chun Hu, Adrian Perrig, Wade Trappe |
Secur. Commun. Networks | 4 |
| 2008 | SEAR: a secure efficient ad hoc on demand routing protocol for wireless networksabstractMulti-hop routing is essential to the operation of wireless ad hoc networks. Unfortunately, it is very easy for an adversary to forge or modify routing messages to inflict severe damage on the underlying routing protocol. In this paper, we present SEAR, a Secure Efficient Ad hoc Routing protocol for ad hoc networks that is mainly based on efficient symmetric cryptography, with asymmetric cryptography used only for the distribution of initial key commitments. We show, through both theoretical examination and simulations, that SEAR provides better security with significantly less overhead than other existing secure AODV protocols. Qing Li 0034, Yih-Chun Hu, Meiyuan Zhao, Adrian Perrig, Jesse Walker, Wade Trappe |
AsiaCCS | 2 |
| 2008 | Dynamic Jamming Mitigation for Wireless Broadcast NetworksabstractWireless communications are inherently symmetric; that is, it takes an attacker the same amount of power to modulate a signal as it does for a legitimate node to modulate the same signal. As a result, wireless communications are often susceptible to the jamming attack in which the attacker injects a high level of noise into the system. Spread spectrum has long been used to resist jamming attacks in unicast environments, or when the jammer has less information than the other receivers. Recently, we proposed a scheme for broadcast jamming mitigation based on spread spectrum and a binary key tree and showed some improvements over a multiple-unicast system. In this paper, we extend our previous work in five ways. First, we provide a theoretical result that under our scheme, jammers can cause only a limited number of losses. Second, we develop a dynamic tree-remerging scheme that achieves higher power efficiency than previously proposed schemes, and scales to an arbitrary number of receivers without increasing the number of codes in use; in particular, we send each transmission on at most 2j + 1 codes, where j is the number of jammers. Third, we show that our scheme is close to optimal, demonstrating that under certain realistic restrictions, the system cannot escape jamming without using at least j +1 codes. Fourth, we provide a detailed analysis of false alarm rates, showing both experimental and theoretical results. Finally, we perform a more extensive analysis of our system using both a chip-accurate MATLAB simulation and a bit-accurate event-driven simulation in the ns-2 network simulator; these simulations demonstrate that our scheme approaches the best possible performance. Jerry T. Chiang, Yih-Chun Hu |
INFOCOM | 2 |
| 2007 | Cross-layer jamming detection and mitigation in wireless broadcast networksabstractMobile communication systems are often susceptible to high level of noise injected by adversaries, known as jamming attack. Jamming is difficult to prevent in broadcast networks because a user that can decode a transmission can also jam the transmission. In this paper, we describe a code tree system that helps the physical layer circumvent jammers. This system works with any spread-spectrum communications system. In our system, the transmitter has more information than any single receiver. Each receiver cooperates with the transmitter to detect any jamming that affects that receiver. Our scheme mitigates the jamming attack while allowing the transmitter to transmit on fewer codes than the number of users. We simulated our system in a theoretical setting using MATLAB. The result shows significant improvement over naively transmitting on a single shared code. Jerry T. Chiang, Yih-Chun Hu |
MobiCom | 2 |
| 2007 | Preserving location privacy in wireless lansabstractThe broadcast and tetherless nature of wireless networks and the widespread deployment of Wi-Fi hotspots makes it easy to remotely locate a user by observing her wireless signals. Location is private information and can be used by malicious individuals for blackmail, stalking, and other privacy violations. In this paper, we analyze the problem of location privacy in wireless networks and present a protocol for improving location privacy. Our basic approach is to obfuscate several types of privacy-compromising information revealed by a mobile node, including sender identity, time of transmission, and signal strength. Our design is driven by real-system implementation and field experiments along with analysis and simulations. Our system allows users to choose the level of privacy they desire, thereby increasing the performance of less private users (while not sacrificing private users' privacy at the same time). We evaluated our system based on real-life mobility data and wireless LAN coverage. Our results show that a user of our system can be indistinguishable from a thousand users in the same coverage area. Tao Jiang 0004, Helen J. Wang, Yih-Chun Hu |
MobiSys | 3 |
| 2007 | Portcullis: protecting connection setup from denial-of-capability attacksabstractSystems using capabilities to provide preferential service to selected flows have been proposed as a defense against large-scale network denial-of-service attacks. While these systems offer strong protection for established network flows, the Denial-of-Capability (DoC) attack, which prevents new capability-setup packets from reaching the destination, limits the value of these systems. Bryan Parno, Dan Wendlandt, Elaine Shi, Adrian Perrig, Bruce M. Maggs, Yih-Chun Hu |
SIGCOMM | 6 |
| 2006 | (R)Evolutionary Bootstrapping of a Global PKI for Securing BGP
Yih-Chun Hu, David A. McGrew, Adrian Perrig, Brian Weis, Dan Wendlandt |
HotNets | 1 |
| 2006 | Wormhole attacks in wireless networksabstractAs mobile ad hoc network applications are deployed, security emerges as a central requirement. In this paper, we introduce the wormhole attack, a severe attack in ad hoc networks that is particularly challenging to defend against. The wormhole attack is possible even if the attacker has not compromised any hosts, and even if all communication provides authenticity and confidentiality. In the wormhole attack, an attacker records packets (or bits) at one location in the network, tunnels them (possibly selectively) to another location, and retransmits them there into the network. The wormhole attack can form a serious threat in wireless networks, especially against many ad hoc network routing protocols and location-based wireless security systems. For example, most existing ad hoc network routing protocols, without some mechanism to defend against the wormhole attack, would be unable to find routes longer than one or two hops, severely disrupting communication. We present a general mechanism, called packet leashes, for detecting and, thus defending against wormhole attacks, and we present a specific protocol, called TIK, that implements leashes. We also discuss topology-based wormhole detection, and show that it is impossible for these approaches to detect some wormhole topologies. Yih-Chun Hu, Adrian Perrig, David B. Johnson 0001 |
IEEE J. Sel. Areas Commun. | 1 |
| 2005 | Efficient Constructions for One-Way Hash Chains
Yih-Chun Hu, Markus Jakobsson, Adrian Perrig |
ACNS | 1 |
| 2005 | Ariadne: A Secure On-Demand Routing Protocol for Ad Hoc Networks
Yih-Chun Hu, Adrian Perrig, David B. Johnson 0001 |
Wirel. Networks | 1 |
| 2004 | Exploiting Congestion Information in Network and Higher Layer Protocols in Multihop Wireless Ad Hoc NetworksabstractWith most routing protocols for ad hoc networks, shorter paths are generally considered more desirable, making some areas of network more prone to congestion and decreasing overall network throughput. We examine the use of congestion information to avoid these network hotspots. By locally monitoring the network interface transmission queue length and MAC layer behavior at each node, a node can establish an approximation of the degree to which the wireless medium around it is busy; this measurement reflects not only the behavior of the node itself, but also the behavior of other nearby nodes sharing the wireless medium. We suggest a number of uses of such congestion information in an ad hoc network, in the network, transport, and higher layers, and we evaluate a set of such uses through simulation. Our results based on modifications to the dynamic source routing protocol (DSR) and TCP demonstrate substantial performance improvement in terms of scalability, packet delivery, overhead, and fairness resulting from this use of congestion information. Yih-Chun Hu, David B. Johnson 0001 |
ICDCS | 1 |
| 2004 | SPV: secure path vector routing for securing BGPabstractAs our economy and critical infrastructure increasingly relies on the Internet, the insecurity of the underlying border gateway routing protocol (BGP) stands out as the Achilles heel. Recent misconfigurations and attacks have demonstrated the brittleness of BGP. Securing BGP has become a priority.In this paper, we focus on a viable deployment path to secure BGP. We analyze security requirements, and consider tradeoffs of mechanisms that achieve the requirements. In particular, we study how to secure BGP update messages against attacks. We design an efficient cryptographic mechanism that relies only on symmetric cryptographic primitives to guard an ASPATH from alteration, and propose the Secure Path Vector (SPV) protocol. In contrast to the previously proposed S-BGP protocol, SPV is around 22 times faster. With the current effort to secure BGP, we anticipate that SPV will contribute several alternative mechanisms to secure BGP, especially for the case of incremental deployments. Yih-Chun Hu, Adrian Perrig, Marvin A. Sirbu |
SIGCOMM | 1 |
| 2003 | Packet Leashes: A Defense against Wormhole Attacks in Wireless NetworksabstractAs mobile ad hoc network applications are deployed, security emerges as a central requirement. In this paper, we introduce the wormhole attack, a severe attack in ad hoc networks that is particularly challenging to defend against. The wormhole attack is possible even if the attacker has not compromised any hosts, and even if all communication provides authenticity and confidentiality. In the wormhole attack, an attacker records packets (or bits) at one location in the network, tunnels them (possibly selectively) to another location, and retransmits them there into the network. The wormhole attack can form a serious threat in wireless networks, especially against many ad hoc network routing protocols and location-based wireless security systems. For example, most existing ad hoc network routing protocols, without some mechanism to defend against the wormhole attack, would be unable to find routes longer than one or two hops, severely disrupting communication. We present a new, general mechanism, called packet leashes, for detecting and thus defending against wormhole attacks, and we present a specific protocol, called TIK, that implements leashes. Yih-Chun Hu, Adrian Perrig, David B. Johnson 0001 |
INFOCOM | 1 |
| 2003 | Efficient Security Mechanisms for Routing Protocolsa
Yih-Chun Hu, Adrian Perrig, David B. Johnson 0001 |
NDSS | 1 |
| 2003 | SEAD: secure efficient distance vector routing for mobile wireless ad hoc networks
Yih-Chun Hu, David B. Johnson 0001, Adrian Perrig |
Ad Hoc Networks | 1 |
| 2002 | Ariadne: a secure on-demand routing protocol for ad hoc networksabstracta secure on-demand routing protocol for ad hoc networks. Yih-Chun Hu, Adrian Perrig, David B. Johnson 0001 |
MobiCom | 1 |
| 2001 | Implicit source routes for on-demand ad hoc network routingabstractIn an ad hoc network, the use of source routing has many advanctages, including simplicity, correctness, and flexibility. For example, all routing decisions for a packet are made by the sender of the packet, avoiding the need for up-to-date routing information at intermediate nodes and allowing the routes used to be trivially guaranteed loop-free. It is also possible for the sender to use different routes for different packets, without requiring coordination or explicit support by the imtermediate nodes. In addition, on-demand source routing has performed very strongly when compared against other proposed protocol designs. However, source routing has the disadvantage of increased per-packet overhead due to the source route header that must be present in every packet orginated or forwarded. In this paper, we propose and analyze the use in ad hoc networks of implicit source routing while avoiding the associated per-packet overhead in most cases. We evaluated this technique through detailed simulations of ad hoc networks based on the Dynamic Source Routing protocol (DSR), an on-demand ad hoc network routing protocol based on source routing. Although routing packet overhead increased slightly with implicit source routing, by about 12.3%, the total number of bytes of overhead decreased substantially, by between 44 and 86%. On all other metrics evaluated, the performance or DSR either did not change significantly or actually improved somewhat, due to indirect effects of of the reduced routing overhead Yih-Chun Hu, David B. Johnson 0001 |
MobiHoc | 1 |
| 2000 | Caching strategies in on-demand routing protocols for wireless ad hoc networksabstractAn on-demand routing protocol for wireless and hoc networks is one that searches for and attempts to discover a route to some destination node only when a sending node originates a data packet addressed to that node. In order to avoid the need for such a route discovery to be performed before each data packet is sent, such routing protocols must cache routes previously discovered. This paper presents an analysis of the effects of different design choices for this caching in on-demand routing protocols in wireless ad hoc networks, dividing the problem into choices of cache structure, cache capacity, and cache timeout. Our analysis is based on the Dynamic Source Routing protocol (DSR), which operates entirely on-demand. Using detailed simulations of wireless ad hoc networks of 50 mobile nodes, we studied a large number of different caching algorithms that utilize a range of design choices, and simulated each cache primarily over a set of 50 different movement scenarios drawn from 5 different types of mobility models. We also define a set of new mobility metrics that allow accurate characterization of the relative difficulty that a given movement scenario presents to an ad hoc network routing protocol, and we analyze each mobility metric's ability to predict the actual difficulty in terms of routing overhead experienced by the routing protocol across the scenarios in our study. Yih-Chun Hu, David B. Johnson 0001 |
MobiCom | 1 |
| 1998 | A Performance Comparison of Multi-Hop Wireless Ad Hoc Network Routing ProtocolsabstractAn ad hoc networkis a collwtion of wirelessmobile nodes dynamically forminga temporarynetworkwithouttheuse of anyexistingnetworkirrfrastructureor centralizedadministration.Dueto the limitedtransmissionrange of ~vlreless nenvorkinterfaces,multiplenetwork"hops"maybe neededfor onenodeto exchangedata ivithanotheracrox the network.In recentyears, a ttiery of nelvroutingprotocols~geted specificallyat this environment have been developed.butlittle pcrfomrartwinformationon mch protocol and no ralistic performancecomparisonbehvwrrthem ISavailable.~Is paper presentsthe results of a derailedpacket-levelsimulationcomparing fourmulti-hopwirelessad hoc networkroutingprotocolsthatcovera range of design choices: DSDV,TORA, DSR and AODV.\Vehave extended the /~r-2networksimulatorto accuratelymodelthe MACand physical-layer behaviorof the IEEE 802.1I wirelessLAN standard,includinga realistic wtrelesstransmissionchannelmodel, and present the resultsof simulations of net(vorksof 50 mobilenodes.This work was supported in Josh Broch, David A. Maltz, David B. Johnson 0001, Yih-Chun Hu, Jorjeta G. Jetcheva |
MobiCom | 4 |