EDBT 2026 Demo / reviewers in the wild / expert
Songwu Lu
dblp:55/758
· DBLP profile ↗
156ranked-venue papers
7as first author
19since 2021 · last 2026
0000-0003-3779-0918ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 126 · 5 first-author · 16 since 2021Systems, architecture and hardware · 14 · 1 since 2021Security and privacy · 9 · 1 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 3Applied, interdisciplinary, general and emerging computing · 3Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AnyPro: Preference-Preserving Anycast Optimization based on Strategic AS-Path Prepending
Minyuan Zhou, Yuning Chen, Jiaqi Zheng 0001, Yongping Tang, Wendong Yin, Qingyan Yu, Yuanchao Su, Guihai Chen, Wan-Chun Dou, Songwu Lu, Wan Du |
NSDI | 13 |
| 2025 | RLTHF: Targeted Human Feedback for LLM AlignmentabstractFine-tuning large language models (LLMs) to align with user preferences is challenging due to the high cost of quality human annotations in Reinforcement Learning from Human Feedback (RLHF) and the generalizability limitations of AI Feedback. To address these challenges, we propose RLTHF, a human-AI hybrid framework that combines LLM-based initial alignment with selective human annotations to achieve full-human annotation alignment with minimal effort. RLTHF identifies hard-to-annotate samples mislabeled by LLMs using a reward model's reward distribution and iteratively enhances alignment by integrating strategic human corrections while leveraging LLM's correctly labeled samples. Evaluations on HH-RLHF and TL;DR datasets show that RLTHF reaches full-human annotation-level alignment with only 6-7% of the human annotation effort. Furthermore, models trained on RLTHF's curated datasets for downstream tasks outperform those trained on fully human-annotated datasets, underscoring the effectiveness of RLTHF. Tusher Chakraborty, Emre Kiciman, Bibek Aryal, Srinagesh Sharma, Songwu Lu, Ranveer Chandra |
ICML | 6 |
| 2025 | Roaming Free in the VR World with MP2
Xumiao Zhang, Yuning Chen, Xuan Zeng 0002, Zhilong Zheng, Xianshang Lin, Yanmei Liu, Songwu Lu, Z. Morley Mao, Wan Du, Dennis Cai, Ennan Zhai |
USENIX ATC | 9 |
| 2024 | LDRP: Device-Centric Latency Diagnostic and Reduction for Cellular Networks Without RootabstractWe design and implementLDRP, a device-based, standard-compliant solution to latency diagnosis and reduction in mobile networks without root privilege.LDRPtakes a data-driven approach and works with a variety of latency-sensitive applications. After identifying elements in LTE uplink latency, we designLDRPthat can infer the critical parameter used in data transmission and infer them for diagnosis. In addition,LDRPdesignates small dummy messages, which precede uplink data transmissions, thus eliminating latency elements due to power-saving, scheduling, etc. It imposes proper timing control among dummy messages and data packets to handle various conflicts. We achieve the latency diagnosis and reduction without requiring root privilege and ensure the latency is no worse than the legacy LTE design. The design ofLDRPis also applicable for 5G. The evaluation shows that,LDRPinfers the latency with at most 4% error and reduces the median LTE uplink latency by a factor up to 7.4× (from 42 to 5 ms) for four apps over 4 mobile carriers. Zhaowei Tan, Yuanjie Li, Yunqi Guo, Songwu Lu |
IEEE Trans. Mob. Comput. | 6 |
| 2024 | Taming the Insecurity of Cellular Emergency Services (9-1-1): From Vulnerabilities to Secure DesignsabstractCellular networks, vital for delivering emergency services, enable mobile users to dial emergency calls (e.g., 9–1-1 in the U.S.), which are forwarded to public safety answer points (PSAPs). Regulatory requirements allow anonymous user equipment (UE) without a SIM card or valid mobile subscription to access these services. However, supporting emergency services for anonymous UEs introduces different operations, expanding the attack surface of cellular infrastructure. In this study, we explore the insecurity of cellular emergency services, identifying six security vulnerabilities. These vulnerabilities can be exploited for free data service attacks against carriers and data DoS/overcharge and denial of cellular emergency service (DoCES) attacks against mobile users. Experimental validation in networks of three major U.S. carriers and two major Taiwan carriers demonstrates the global impact of our findings. Finally, we propose and prototype standard-compliant remedies to mitigate these vulnerabilities. Min-Yue Chen, Yiwen Hu 0002, Guan-Hua Tu, Chi-Yu Li 0001, Sihan Wang 0002, Jingwen Shi, Tian Xie 0001, Ren-Chieh Hsu, Li Xiao 0001, Chunyi Peng 0001, Zhaowei Tan, Songwu Lu |
IEEE/ACM Trans. Netw. | 12 |
| 2023 | Sign-to-911: Emergency Call Service for Sign Language Users with Assistive AR GlassesabstractSign-to-911 offers a compact mobile system solution to fast and runtime American Sign Language (ASL) and English translations. It is designated as 911 call services for ASL users with hearing disabilities upon emergencies. It enables bidirectional translations of ASL-to-English and English-to-ASL. The signer wears the AR glasses, runs Sign-to-911 on his/her smartphone and glasses, and interacts with a 911 operator. The design of Sign-to-911 departs from the popular deep learning based solution paradigm, and adopts simpler traditional AI/machine learning (ML) models. The key is to exploit ASL linguistic features to simplify the model structures and improve accuracy and speed. It further leverages recent component solutions from graphics, vision, natural language processing, and AI/ML. Our evaluation with six ASL signers and 911 call records has confirmed its viability. Yunqi Guo, Boyan Ding, Congkai Tan, Weichong Ling, Zhaowei Tan, Jennifer Miyaki, Hongzhe Du, Songwu Lu |
MobiCom | 9 |
| 2023 | CA++: Enhancing Carrier Aggregation Beyond 5GabstractCarrier aggregation (CA) is an important component technology in 5G and beyond. It aggregates multiple spectrum fragments to serve a mobile device. However, the current CA suffers under both high mobility and increased spectrum space. The limitations are rooted in its sequential, cell-by-cell operations. In this work, we propose CA++, which departs from the current paradigm and explores a group-based design scheme. We thus propose new algorithms that enable concurrent channel inference by measuring one or few cells but inferring all, while minimizing measurement cost via set cover approximations. Our evaluations have confirmed the effectiveness of CA++. Our solution can also be adapted to fit in the current 5G OFDM PHY and the 3GPP framework. Qianru Li 0002, Zhehui Zhang, Yanbing Liu 0002, Zhaowei Tan, Chunyi Peng 0001, Songwu Lu |
MobiCom | 6 |
| 2023 | CellDAM: User-Space, Rootless Detection and Mitigation for 5G Data Plane
Zhaowei Tan, Boyan Ding, Songwu Lu |
NSDI | 4 |
| 2023 | Movement-Based Reliable Mobility Management for Beyond 5G Cellular NetworksabstractExtreme mobility becomes a norm rather than an exception with emergent high-speed rails, drones, industrial IoT, and many more. However, 4G/5G mobility management is not always reliable in extreme mobility, with non-negligible failures and policy conflicts. The root cause is that, existing mobility management is primarily based on wireless signal strength. While reasonable in static and low mobility, it is vulnerable to dramatic wireless dynamics from extreme mobility in triggering, decision, and execution. We deviseREM, Reliable Extreme Mobility management for beyond 5G cellular networks while maintaining backward compatibility to 4G/5G.REMshifts to movement-based mobility management in the delay-Doppler domain. Its signaling overlay relaxes feedback via cross-band estimation, simplifies policies with provable conflict freedom, and stabilizes signaling via scheduling-based OTFS modulation. Our evaluation with operational high-speed rail datasets shows that,REMreduces failures comparable to static and low mobility, with low signaling and latency cost.REMreduces the network failures by up to an order of magnitude, eliminates policy conflicts, and improves application performance by 31.8% - 88.3% compared to legacy 4G/5G. Zhehui Zhang, Yuanjie Li, Qianru Li 0002, Ghufran Baig, Lili Qiu, Songwu Lu |
IEEE/ACM Trans. Netw. | 7 |
| 2022 | Uncovering insecure designs of cellular emergency services (911)abstractCellular networks that offer ubiquitous connectivity have been the major medium for delivering emergency services. In the U.S., mobile users can dial an emergency call with 911 for emergency uses in cellular networks, and the call can be forwarded to public safety answer points (PSAPs), which deal with emergency service requests. According to regulatory authority requirements for the cellular emergency services, anonymous user equipment (UE), which does not have a SIM (Subscriber Identity Module) card or a valid mobile subscription, is allowed to access them. Such support of emergency services for anonymous UEs requires different operations from conventional cellular services, and can therefore increase the attack surface of the cellular infrastructure. In this work, we are thus motivated to study the insecurity of the cellular emergency services and then discover four security vulnerabilities from them. Threateningly, they can be exploited to launch not only free data service attacks against cellular carriers, but also data DoS/overcharge and denial of cellular emergency service (DoCES) attacks against mobile users. All vulnerabilities and attacks have been validated experimentally as practical security issues in the networks of three major U.S. carriers. We finally propose and prototype standard-compliant remedies to mitigate the vulnerabilities. Yiwen Hu 0002, Min-Yue Chen, Guan-Hua Tu, Chi-Yu Li 0001, Sihan Wang 0002, Jingwen Shi, Tian Xie 0001, Li Xiao 0001, Chunyi Peng 0001, Zhaowei Tan, Songwu Lu |
MobiCom | 11 |
| 2022 | Extracting and predicting multipath profiles under high mobilityabstractThe wireless signal propagates via multipath arising from different reflections and penetration between a transmitter and receiver. Extracting multipath profiles (e.g., delay and Doppler along each path) from received signals enables many important applications, such as channel prediction and crossband channel estimation (i.e., estimating the channel on a different frequency). The benefit of multipath estimation further increases with mobility since the channel in that case is less stable and more important to track. Yet high-speed mobility poses significant challenges to multipath estimation. In this paper, instead of using time-frequency domain channel representation, we leverage the delay-Doppler domain representation to accurately extract and predict multipath properties. Specifically, we use impulses in the delay-Doppler domain as pilots to estimate the multipath parameters and apply the multipath information to predicting wireless channels as an example application. Our design rationale is that mobility is more predictable than the wireless channel since mobility has inertial while the wireless channel is the outcome of a complicated interaction between mobility, multipath, and noise. We evaluate our approach via both acoustic and RF experiments, including vehicular experiments using USRP. Our results show that the estimated multipath matches the ground truth, and the resulting channel prediction is more accurate than the traditional channel prediction schemes. Ghufran Baig, Changhan Ge, Lili Qiu, Yuanjie Li, Wangyang Li, Jian He 0002, Zhehui Zhang, Songwu Lu |
MobiHoc | 9 |
| 2022 | SEED: a SIM-based solution to 5G failuresabstractFailures in 5G mobile networks are becoming the norm with the ongoing global rollout. If left unattended, they affect mobile user experiences and the proper functioning of applications. In this work, we describe SEED, which offers a novel SIM-based solution to 5G failure diagnosis and handling. SEED infers failure causes by exploiting current standardized 5G error codes and decision-tree/online learning algorithms. It further takes corresponding multi-tier reset/redo actions (reset protocol operations, refresh outdated configurations, reload profiles, etc.) once the failure cause is inferred. SEED takes the operator's perspective in its design for fast deployment. SEED design works within the 5G standard framework and does not require changes on the device firmware or infrastructure hardware. Our evaluation has confirmed the viability of SEED. Zhaowei Tan, Zhehui Zhang, Songwu Lu |
SIGCOMM | 5 |
| 2022 | Breaking Cellular IoT with Forged Data-plane Signaling: Attacks and CountermeasureabstractWe devise new attacks exploiting the unprotected data-plane signaling in cellular IoT networks (a.k.a. both NB-IoT and Cat-M). We show that, despite the deployed security mechanisms on both control-plane signaling and data-plane packet forwarding, novel data-plane signaling attacks are still feasible. The attacker can forge both uplink and downlink data-plane signaling messages that pass the current security checks used by the receiver. With the capability of forging messages, the attacker can launch attacks that exhibit a variety of attack forms beyond simplistic packet-blasting, denial-of-service (DoS) threats, including location privacy breach, packet delivery loop, prolonged data delivery, throughput limiting, radio resource draining, connection reset, and multicast disabling. Our testbed evaluation and operational network validation have confirmed the attack viability. To combat the threat, we further propose a new defense solution within the 3GPP C-IoT standard framework. It leverages the synchronized timer clock information to protect the data-plane signaling messages with low overhead. Zhaowei Tan, Boyan Ding, Yunqi Guo, Songwu Lu |
ACM Trans. Sens. Networks | 5 |
| 2021 | On Key Reinstallation Attacks over 4G LTE Control-Plane: Feasibility and Negative ImpactabstractThis paper studies the feasibility of key reinstallation attacks in the 4G LTE network.It is well known that LTE uses session keys for confidentiality and integrity protection of its control-plane signaling packets.However, if the keys are not updated and counters are reset, key reinstallation attacks may arise.In this paper, we show that several design choices in the current LTE security setup are vulnerable to key reinstallation attacks.Specifically, on the control plane, the LTE security association setup procedures, which establish security between the device and the network, are disconnected.The keys are installed through one procedure, whereas their associated parameters (such as uplink and downlink counters) are reset through another different procedure.The adversary can thus exploit the disjoint security setup procedures, and launch the key stream reuse attacks.He consequently breaks message encryption, when he tricks the victim to use the same pair of keys and counter value to encrypt multiple messages.This control-plane attack hijacks the location update procedure, thus rendering the device to be unreachable from the Internet.Moreover, it may also deregister the victim from the LTE network.We have confirmed our findings with two major US operators, and found that such attacks can be launched with software-defined radio devices that cost about $299.We further propose remedies to defend against such threats. Muhammad Taqi Raza, Yunqi Guo, Songwu Lu, Fatima M. Anwar 0001 |
ACSAC | 3 |
| 2021 | Sonica: an open-source NB-IoT prototyping platformabstractIn this demo, we describe Sonica, an open-source NB-IoT prototype platform. Both radio access and core network components are designed and implemented with the features and characteristics of NB-IoT into account. With its eNB and core network (EPC) components, Sonica can function as an NB-IoT testbed which interacts with commercial off-the-shelf NB-IoT devices. Moreover, Sonica provides a flexible framework that supports quick prototyping for MAC/PHY layers. Boyan Ding, Zhaowei Tan, Songwu Lu |
MobiCom | 4 |
| 2021 | Experience: a five-year retrospective of MobileInsightabstractThis paper reports our five-year lessons of developing and using MobileInsight, an open-source community tool to enable software-defined full-stack, runtime mobile network analytics inside our phones. We present how MobileInsight evolves from a simple monitor to a community toolset with cross-layer analytics, energy-efficient real-time user-plane analytics, and extensible user-friendly analytics at the control and user planes. These features are enabled by various novel techniques, including cross-layer state machine tracking, missing data inference, and domain-specific cross-layer sampling. Their powerfulness is exemplified with a 5-year longitudinal study of operational mobile network latency using a 6.4TB dataset with 6.1 billion over-the-air messages. We further share lessons and insights of using MobileInsight by the community, as well as our visions of MobileInsight's past, present, and future. Yuanjie Li, Chunyi Peng 0001, Zhehui Zhang, Zhaowei Tan, Haotian Deng 0001, Qianru Li 0002, Yunqi Guo, Kai Ling, Boyan Ding, Hewu Li, Songwu Lu |
MobiCom | 12 |
| 2021 | Data-plane signaling in cellular IoT: attacks and defenseabstractIn this paper, we devise new attacks exploiting the unprotected data-plane signaling in cellular IoT networks (aka both NB-IoT and Cat-M). We show that, despite the deployed security mechanisms on both control-plane signaling and data-plane packet forwarding, novel data-plane signaling attacks are still feasible. Such attacks exhibit a variety of attack forms beyond simplistic packet-blasting, denial-of-service (DoS) threats, including location privacy breach, packet delivery loop, prolonged data delivery, throughput limiting, radio resource draining, and connection reset. Our testbed evaluation and operational network validation have confirmed the viability. We further propose a new defense solution within the 3GPP C-IoT standard framework. Zhaowei Tan, Boyan Ding, Yunqi Guo, Songwu Lu |
MobiCom | 5 |
| 2021 | SecureSIM: rethinking authentication and access control for SIM/eSIMabstractThe SIM/eSIM card stores critical information for a mobile user to access the 4G/5G network. In this work, we uncover three vulnerabilities of the current SIM practice. We show that the PIN-based access control may expose the in-SIM data to an adversary through both hardware and software. Once exposed, such in-SIM information can be used to reconstruct various keys used for device authentication, data encryption, etc. They thus enable a number of attacks, including traffic eavesdropping, man-in-the-middle attack, impersonation, etc. The fundamental problem is that, the current SIM design does not offer proper authentication and fine-grained access control to hundreds of in-SIM files for various in-card applets and off-card units. We next propose a new solution that offers both authentication and fine-grained access control. Our implementation and evaluation have confirmed the viability of our proposal. Boyan Ding, Yunqi Guo, Zhaowei Tan, Songwu Lu |
MobiCom | 5 |
| 2021 | Device-Based LTE Latency Reduction at the Application Layer
Zhaowei Tan, Yuanjie Li, Songwu Lu |
NSDI | 5 |
| 2020 | Towards Model-Centric Security for IoT SystemsabstractIn this paper, we make a case for a novel model-centric security approach to the IoT application systems. We thus depart from the popular device-centric and data-centric schemes. Our proposal is based on the premise that the trained model, rather than the fine-grained input and output data streams, plays the pivotal role in many IoT application systems. We thus seek to obfuscate the model directly, but not the individual data items or sensory data streams. We present our initial design of sampling-based model obfuscation. Both evaluations and analysis have partially confirmed our design to date. Yunqi Guo, Zhaowei Tan, Songwu Lu |
ICCCN | 3 |
| 2020 | De-anonymization of Social Networks: the Power of CollectivenessabstractThe interaction among users in different social networks raises deep concern on user privacy, as it may facilitate the assailants to identify user identities by matching the anonymized networks with a correlated sanitized one. Prior arts regarding such de-anonymization problem can be primarily divided into a seeded case or a seedless one, depending on whether or not there are a subset of pre-identified nodes. The seedless case is much more complicated since the adjacency matrix representation of one-hop user relations delivers limited structural information. To address this issue, we, for the first time, integrate the multi-hop neighborhood relationships, which exhibit more structural commonness between the anonymized and the sanitized networks, into seedless de-anonymization process. Our aim is to sufficiently leverage these multi-hop neighbors of all nodes and minimize the total disagreements of these multi-hop adjacency matrices, which we call collective adjacency disagreements (CADs), between two networks of different sizes. Theoretically, we demonstrate that CAD enlarges the difference between wrongly matched node pairs and correctly matched pairs, whereby two networks can be correctly matched with high probability even when the network density is below logn. Algorithmically, we adopt the conditional gradient descending method on a collective-form objective, which can efficiently find the minimal CADs for networks with broad degree distributions. Experiments on both synthetic and realworld networks return desirable de-anonymization accuracies thanks to the rich structural information manifested by such collectiveness, since most nodes can be correctly matched with their correspondences, especially in sparse networks where merely utilizing adjacency relations might fail to work. Jiapeng Zhang 0001, Luoyi Fu, Xinbing Wang, Songwu Lu |
INFOCOM | 4 |
| 2020 | Beyond 5G: Reliable Extreme Mobility ManagementabstractExtreme mobility has become a norm rather than an exception. However, 4G/5G mobility management is not always reliable in extreme mobility, with non-negligible failures and policy conflicts. The root cause is that, existing mobility management is primarily based on wireless signal strength. While reasonable in static and low mobility, it is vulnerable to dramatic wireless dynamics from extreme mobility in triggering, decision, and execution. We devise REM, Reliable Extreme Mobility management for 4G, 5G, and beyond. REM shifts to movement-based mobility management in the delay-Doppler domain. Its signaling overlay relaxes feedback via cross-band estimation, simplifies policies with provable conflict freedom, and stabilizes signaling via scheduling-based OTFS modulation. Our evaluation with operational high-speed rail datasets shows that, REM reduces failures comparable to static and low mobility, with low signaling and latency cost. Yuanjie Li, Qianru Li 0002, Zhehui Zhang, Ghufran Baig, Lili Qiu, Songwu Lu |
SIGCOMM | 6 |
| 2020 | Uninterruptible IMS: Maintaining Users Access During Faults in Virtualized IP Multimedia SubsystemabstractNetwork function virtualization (NFV) of IP Multimedia Subsystem (IMS) pose promise to service increasing multimedia traffic demand. In this paper, we show that virtualized IMS (vIMS) is unable to provide session-level resilience under faults and becomes the bottleneck to high service availability. We propose a design to provide fault-tolerance for vIMS operations. In control-plane, our system decomposes single IMS operation into different atomic actions, and partition these actions into critical and non-critical actions. Only the critical actions are then monitored in real time and the system can easily resume IMS operations after failure. In data-plane, we decompose multimedia traffic flows and partition each multimedia service as a separate Virtualized Network Function (VNF). Through data-plane partitioning, our design restricts the damage from faults to only failed VNF. Thereafter, impacted service flow is merged with other ongoing service flows. We build our system prototype of open source IMS over virtualized platform. Our results show that we can achieve session-level resilience by performing fail-over procedure within tens of milliseconds under different combinations of IMS failures in both control-plane and data-plane operations. Muhammad Taqi Raza, Songwu Lu |
IEEE J. Sel. Areas Commun. | 2 |
| 2019 | Evolving Knowledge GraphsabstractMany practical applications have observed knowledge evolution, i.e., continuous born of new knowledge, with its formation influenced by the structure of historical knowledge. This observation gives rise to evolving knowledge graphs whose structure temporally grows over time. However, both the modal characterization and the algorithmic implementation of evolving knowledge graphs remain unexplored. To this end, we propose EvolveKG, a framework that reveals cross-time knowledge interaction with desirable performance of storage and computation. The novelty of EvolveKG lies in Derivative Graph - a static weighted snapshot of evolution at a certain time. Particularly, each weight quantifies knowledge effectiveness with a temporarily decaying function of consistency and attenuation, two proposed factors depicting whether or not the effectiveness of a fact fades away with time. Thanks to the cross-time interaction, EvolveKG allows future knowledge prediction by virtue of the influence from the historical ones. Empirically tested under two real datasets, the superiority of EvolveKG is confirmed via its prediction accuracy. Jiaqi Liu 0002, Luoyi Fu, Xinbing Wang, Songwu Lu |
INFOCOM | 5 |
| 2019 | A Systematic Way to LTE TestingabstractLTE test cases are standardized by 3GPP. They must be executed on every LTE-capable device model before commercial release. In this work, we examine the LTE testing practices in terms of completeness and efficiency. We discover that the standardized tests are incomplete in that a number of test cases related to multiple protocol interactions are missing. Our analysis also shows that, the isolated treatment of test cases, but not from the system perspective, incurs repetitive executions of test operations, thus resulting in testing inefficiencies. We thus make a case for a paradigm shift from ad hoc testing to a methodical approach to LTE testing. We follow a few guidelines from the LTE standards and propose an algorithmic approach to systematic testing. In the process, we address various challenges, provide complete list of test cases, and present the related algorithms. Our evaluation shows that, by eliminating repetitive operations, our new scheme reduces up to 70% of LTE testing steps. We also find 87 new, yet valid test cases that are not defined by the LTE standards. Muhammad Taqi Raza, Songwu Lu |
MobiCom | 2 |
| 2019 | vEPC-sec: Securing LTE Network Functions Virtualization on Public CloudabstractPublic cloud offers economy of scale to adapt workload changes in an autonomic manner, maximizing the use of resources. Through network function virtualization (NFV), network operators can move LTE core to the cloud; hence removing their dependency on carrier-grade LTE network functions. Recent research efforts discuss performance, latency, and fault tolerance of LTE NFV, largely ignoring the security aspects. In this paper, we discover new vulnerabilities that LTE NFV face today with no standard solutions to address them. These vulnerabilities span at both LTE control and user planes. To address them, we propose vEPC-sec that cryptographically secures LTE control-plane signaling messages in the cloud. It provides distributed key management and key derivation schemes to derive shared-symmetric keys for securing the communication between any two network functions. Our approach provides encryption and integrity protection to the messages even during virtual machines scalability and failure recovery scenarios. vEPC-sec also prevents user-plane vulnerabilities by ensuring that LTE routing modules should faithfully forward the LTE subscriber packets. Muhammad Taqi Raza, Songwu Lu, Mario Gerla |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2018 | A Machine Learning Based Approach to Mobile Network AnalysisabstractIn this paper, we present our recent work in progress on 4G mobile network analysis. In order to provide an in-depth study on the closed network operations, we advocate a novel approach via two-level, device-centric machine learning that can open up the system behaviors and facilitate fine-grained analysis . We describe our proposed approach, and use the latency analysis on two popular mobile apps (Web browsing and Instant Messaging) to illustrate how our scheme works. We further preliminary results and discuss the open issues. Zengwen Yuan, Yuanjie Li, Chunyi Peng 0001, Songwu Lu, Haotian Deng 0001, Zhaowei Tan, Muhammad Taqi Raza |
ICCCN | 4 |
| 2018 | Social Network De-anonymization with Overlapping Communities: Analysis, Algorithm and ExperimentsabstractThe advent of social networks poses severe threats on user privacy as adversaries can de-anonymize users' identities by mapping them to correlated cross-domain networks. Without ground-truth mapping, prior literature proposes various cost functions in hope of measuring the quality of mappings. However, there is generally a lacking of rationale behind the cost functions, whose minimizer also remains algorithmically unknown. We jointly tackle above concerns under a more practical social network model parameterized by overlapping communities, which, neglected by prior art, can serve as side information for de-anonymization. Regarding the unavailability of ground-truth mapping to adversaries, by virtue of the Minimum Mean Square Error (MMSE), our first contribution is a well-justified cost function minimizing the expected number of mismatched users over all possible true mappings. While proving the NP-hardness of minimizing MMSE, we validly transform it into the weighted-edge matching problem (WEMP), which, as disclosed theoretically, resolves the tension between optimality and complexity: (i) WEMP asymptotically returns a negligible mapping error in large network size under mild conditions facilitated by higher overlapping strength; (ii) WEMP can be algorithmically characterized via the convex-concave based de-anonymization algorithm (CBDA), finding the optimum of WEMP. Extensive experiments further confirm the effectiveness of CBDA under overlapping communities, in terms of averagely 90% re-identified users in the rare true cross-domain co-author networks when communities overlap densely, and roughly 70% enhanced reidentification ratio compared to non-overlapping cases. Zhongzhao Hu, Xinzhe Fu, Luoyi Fu, Xinbing Wang, Songwu Lu |
INFOCOM | 6 |
| 2018 | Resolving Policy Conflicts in Multi-Carrier Cellular AccessabstractMulti-carrier cellular access dynamically selects a preferred wireless carrier by leveraging the availability and diversity of multiple carrier networks at a location. It offers an alternative to the dominant single-carrier paradigm, and shows early signs of success through the operational Project Fi by Google. In this paper, we study the important, yet largely unexplored, problem of inter-carrier switching for multi-carrier access. We show that policy conflicts can arise between inter- and intra-carrier switching, resulting in oscillations among carriers in the worst case akin to BGP looping. We derive the conditions under which such oscillations occur for three categories of popular policy, and validate them with Project Fi whenever possible. We provide practical guidelines to ensure loop-freedom and assess them via trace-driven emulations. Zengwen Yuan, Qianru Li 0002, Yuanjie Li, Songwu Lu, Chunyi Peng 0001, George Varghese |
MobiCom | 4 |
| 2018 | Refactoring Network Functions Modules to Reduce Latencies and Improve Fault Tolerance in NFVabstractNetwork functions virtualization (NFV) allows service providers to deliver new services to their customers more quickly by adopting software-centric network functions implementation over commercial, off-the-shelf hardwares. This NFV-based software-centric approach cannot use dedicated mechanisms implemented over custom built boxes to reduce latencies and tolerate faults. We present a case study of IP multimedia subsystem (IMS), which is the most complex NFV instance, requires extremely low end-to-end latency (40 msec), and demands system availability as high as five nines. Through an empirical study, we discover that highly modular IMS network functions implementation over virtualized platform: 1) incurs latencies and 2) does not tolerate faults. NFV-based IMS modules incur high latencies by creating a feedback loop among each other while executing delay sensitive data-plane traffic. These IMS modules are also susceptible to failure, causing the control-plane to terminate the application session while keeping the data-plane to forward data packets. To address these issues, we propose to refactor network function modules. We reduce latencies by pipelining the IMS modules, and recover failed modules by reconfiguring their neighboring modules. We build our system prototype of open source IMS over OpenStack platform. Our results show that our scheme reduces latencies and failure recovery time up to 12× and 10×, respectively, when compared with the state-of-the-art virtualized IMS implementation. Muhammad Taqi Raza, Songwu Lu, Mario Gerla, Xi Li 0003 |
IEEE J. Sel. Areas Commun. | 2 |
| 2018 | Joint Optimization of Multicast Energy in Delay-Constrained Mobile Wireless NetworksabstractThis paper studies the problem of optimizing multicast energy consumption in delay-constrained mobile wireless networks, where information from the source needs to be delivered to all the k destinations within an imposed delay constraint. Most existing works simply focus on deriving transmission schemes with the minimum transmitting energy, overlooking the energy consumption at the receiver side. Therefore, in this paper, we propose ConMap, a novel and general framework for efficient transmission scheme design that jointly optimizes both the transmitting and receiving energy. In doing so, we formulate our problem of designing minimum energy transmission scheme, called DeMEM, as a combinatorial optimization one, and prove that the approximation ratio of any polynomial time algorithm for DeMEM cannot be better than (1/4) lnk. Aiming to provide more efficient approximation schemes, the proposed ConMap first converts DeMEM into an equivalent directed Steiner tree problem through creating auxiliary graph gadgets to capture energy consumption, then maps the computed tree back into a transmission scheme. The advantages of ConMap are threefolded: 1) Generality- ConMap exhibits strong applicability to a wide range of energy models; 2) Flexibility- Any algorithm designed for the problem of directed Steiner tree can be embedded into our ConMap framework to achieve different performance guarantees and complexities; 3) Efficiency- ConMap preserves the approximation ratio of the embedded Steiner tree algorithm, to which only slight overhead will be incurred. The three features are then empirically validated, with ConMap also yielding near-optimal transmission schemes compared to a brute-force exact algorithm. To our best knowledge, this is the first work that jointly considers both the transmitting and receiving energy in the design of multicast transmission schemes in mobile wireless networks. Luoyi Fu, Xinzhe Fu, Zesen Zhang, Zhiying Xu, Xinbing Wang, Songwu Lu |
IEEE/ACM Trans. Netw. | 7 |
| 2018 | Device-Customized Multi-Carrier Network Access on Commodity SmartphonesabstractAccessing multiple carrier networks (T-Mobile, Sprint, AT&T, and so on) offers a promising paradigm for smartphones to boost its mobile network quality. However, the current practice does not achieve the full potential of this approach because it has not utilized fine-grained, cellular-specific domain knowledge. Our experiments and code analysis discover three implementation-independent issues: 1) it may not trigger the anticipated switch when the serving carrier network is poor; 2) the switch takes a much longer time than needed; and 3) the device fails to choose the high-quality network (e.g., selecting 3G rather than 4G). To address them, we propose iCellular, which exploits low-level cellular information at the device to improve multi-carrier access. iCellular is proactive and adaptive in its multi-carrier selection by leveraging existing end-device mechanisms and standards-complaint procedures. It performs adaptive monitoring to ensure responsive selection and minimal service disruption and enhances carrier selection with online learning and runtime decision fault prevention. It is readily deployable on smartphones without infrastructure/hardware modifications. We implement iCellular on commodity phones and harness the efforts of Project Fi to assess multi-carrier access over two U.S. carriers: T-Mobile and Sprint. Our evaluation shows that, iCellular boosts the devices' throughput with up to 3.74× throughput improvement, 6.9× suspension reduction, and 1.9× latency decrement over the state of the art, with moderate CPU, and memory and energy overheads. Yuanjie Li, Chunyi Peng 0001, Haotian Deng 0001, Zengwen Yuan, Guan-Hua Tu, Songwu Lu, Xi Li 0003 |
IEEE/ACM Trans. Netw. | 7 |
| 2017 | Throughput optimization for streaming applications on CPU-FPGA heterogeneous systemsabstractStreaming processing is an important technology that finds applications in networking, multimedia, signal processing, etc. However, it is very challenging to design and implement streaming applications as they impose complex constraints. First, the tasks involved in the streaming applications must complete the computation under a latency constraint. Second, streaming systems are built under more and more stringent power budget. Hence, power capping technique is employed to manage the power consumption for streaming systems. To accommodate these needs, heterogeneous systems that consist of CPUs and FPGAs are becoming increasingly popular due to their performance and power benefits. In this paper, we optimize the throughput for streaming applications on CPU-FPGA heterogeneous system under latency and power constraints. We develop two algorithms to map the tasks onto the heterogeneous system and order their execution by exploiting the heterogeneity in architectural capabilities and task characteristics. We also employ pipelining to improve the throughput by overlapping the execution of different frames and use frequency scaling to adjust the execution of tasks for power saving. Experiments using a variety of streaming applications show that our heterogeneous solution can successfully meet the latency and power constraints for the cases where the CPU implementation fails. Furthermore, our technique can improve the throughput by 37.32% on average. Xuechao Wei, Yun Liang 0001, Tao Wang 0004, Songwu Lu, Jason Cong |
ASP-DAC | 4 |
| 2017 | Dependency analysis of cloud applications for performance monitoring using recurrent neural networksabstractPerformance monitoring of cloud-native applications that consist of several micro-services involves the analysis of time series data collected from the infrastructure, platform, and application layers of the cloud software stack. The analysis of the runtime dependencies amongst the component microservices is an essential step towards performing cloud resource management, detecting anomalous behavior of cloud applications, and meeting customer Service Level Agreements (SLAs). Finding such dependencies is challenging due to the non-linear nature of interactions, aberrant data measurements and lack of domain knowledge. In this paper, we propose a novel use of the modeling capability of Long-Short Term Memory (LSTM) recurrent neural networks, which excel in capturing temporal relationships in multi-variate time series data and being resilient to noisy pattern representations. Our proposed technique looks into the LSTM model structure, to uncover dependencies amongst performance metrics, which were learned during training. We further apply this technique in three monitoring use cases, namely finding the strongest performance predictors, discovering lagged/temporal dependencies, and improving the accuracy of forecasting for a given metric. We demonstrate the viability of our approach, by comparing the results of our proposed method in the three use cases with those obtained from previously proposed methods, such as Granger causality and the classical statistical time series analysis models, such as ARIMA and Holt-Winters. For our experiments and analysis, we use performance monitoring data collected from two sources: a controlled experiment involving a sample cloud application that we deployed in a public cloud infrastructure and cloud monitoring data collected from the monitoring service of an operational, public cloud service provider. Syed Yousaf Shah, Zengwen Yuan, Songwu Lu, Petros Zerfos |
IEEE BigData | 3 |
| 2017 | Enabling low latency and high reliability for IMS-NFVabstractNetwork Functions Virtualization (NFV) allows service providers to deliver new services to their customers more quickly by adopting software centric network functions implementation over commercial, off-the-shelf hardwares. IP Multimedia Subsystem (IMS) which is one of the most complex NFV instances requires extremely low end-to-end latency (up to 40 msec), and demands system availability as high as five nines. We discover that highly modular 3GPP standardized IMS network functions implementation over virtualized platform (1) incurs latencies, and (2) does not tolerate faults. NFV-based IMS modules incur high latencies by creating a feedback loop among each other while executing delay sensitive data-plane traffic. These IMS modules are also susceptible to failures, causing the control-plane to terminate the application session while keeping the data-plane to forward data packets. To address these issues, we propose to refactor network function modules. We reduce latencies by pipelining the communication between IMS modules, and achieve fault tolerance by reconfiguring their neighboring modules. We build our system prototype of open source 3GPP compliant IMS over OpenStack platform. Our results show that our scheme reduces latencies and failure recovery time upto 12X and 10X, respectively, when compared to the stat-of-the-art 3GPP compliant virtualized IMS implementation. Muhammad Taqi Raza, Songwu Lu |
CNSM | 2 |
| 2017 | GRT 2.0: An FPGA-based SDR Platform for Cognitive Radio Networks (Abstract Only)
Tao Wang 0004, Boyan Ding, Tianfu Jiang, Jun Liu 0063, Songwu Lu |
FPGA | 8 |
| 2017 | Towards Automated Intelligence in 5G SystemsabstractIn this paper, we call for a paradigm shift away from the wireless-access focused research efforts on 5G networked systems. We believe that the architectural limitations should share equal blame on issues of performance, reliability, and security. We thus identify architectural weakness on both sides of the mobile clients and the 4G network infrastructure. Our recent findings show that, contrary to commonly held perceptions, many design and operational issues arise not due to poor wireless link qualities. Instead, they are rooted in such architectural downsides. To address these issues, we further propose a new approach of enabling automated intelligence inside the 4G/5G network systems. We next describe our ongoing efforts along two dimensions: empowering date-driven smart clients and constructing verifiable network infrastructure. We report some early results and discuss possible next steps. Haotian Deng 0001, Qianru Li 0002, Yuanjie Li, Songwu Lu, Chunyi Peng 0001, Muhammad Taqi Raza, Zhaowei Tan, Zengwen Yuan, Zhehui Zhang |
ICCCN | 4 |
| 2017 | Rethinking LTE network functions virtualizationabstractLTE Network Function Virtualization (LTE-NFV) scales user services in a low cost fashion by transforming the centralized legacy LTE Core architecture to a distributed architecture. This distributed architecture makes multiple instances of LTE Network Functions (NFs) and virtualizes them on commodity data-center network. The functionality of LTE-NFV architecture breaks however, since the distributed NF instances connected via unreliable IP links delay the execution of critical events. The failure of time-critical events results in users' quality of service degradation and temporary service unavailability. In this paper, we propose a new way to virtualize LTE core network. We argue that logic-based NFs segregation should be done for NFV, instead of instance-based NFs segregation done in current NFV implementation. Our approach of ‘logic-based NFs segregation’ combines the logic of an event into a single NF, thus localizing the execution of critical events to one virtual machine. This way, only the localized entities exchange signalling messages, and the events do not experience large delays. We further reduce the delays by exploiting the parallelism in LTE network protocols; and partition these protocols such that their signalling messages run in parallel. In addition, we eliminate unnecessary messages to reduce the signalling overhead. We build our system prototype over OpenEPC LTE core network in virtualized platform. Our results show that we can reduce event execution time and signalling overhead up to 50% and 40%, respectively. Muhammad Taqi Raza, Kyu-Han Kim, Songwu Lu, Mario Gerla |
ICNP | 4 |
| 2017 | The Tick Programmable Low-Latency SDR SystemabstractTick is a new SDR system that provides programmability and ensures low latency at both PHY and MAC. It supports modular design and element-based programming, similar to the Click router framework [23]. It uses an accelerator-rich architecture, where an embedded processor executes control flows and handles various MAC events. User-defined accelerators offload those tasks, which are either computation-intensive or communication-heavy, or require fine-grained timing control, from the processor, and accelerate them in hardware. Tick applies a number of hardware and software co-design techniques to ensure low latency, including multi-clock-domain pipelining, field-based processing pipeline, separation of data and control flows, etc. We have implemented Tick and validated its effectiveness through extensive evaluations as well as two prototypes of 802.11ac SISO/MIMO and 802.11a/g full-duplex. Tao Wang 0004, Zengwen Yuan, Chunyi Peng 0001, Zhaowei Tan, Boyan Ding, Yuanjie Li, Jun Liu 0063, Songwu Lu |
MobiCom | 11 |
| 2017 | ConMap: A Novel Framework for Optimizing Multicast Energy in Delay-constrained Mobile Wireless NetworksabstractThis paper studies the problem of optimizing multicast energy consumption in delay-constrained mobile wireless networks, where information from the source needs to be delivered to all the k destinations within an imposed delay constraint. Most existing works simply focus on deriving transmission schemes with the minimum transmitting energy, overlooking the energy consumption at the receiver side. Therefore, in this paper, we propose ConMap, a novel and general framework for efficient transmission scheme design that jointly optimizes both the transmitting and receiving energy. In doing so, we formulate our problem of designing minimum energy transmission scheme, called DeMEM, as a combinatorial optimization one, and prove that the approximation ratio of any polynomial time algorithm for DeMEM cannot be better than ¼ ln k. Aiming to provide more efficient approximation schemes, the proposed ConMap first converts DeMEM into an equivalent directed Steiner tree problem through creating auxiliary graph gadgets to capture energy consumption, then maps the computed tree back into a transmission scheme. The advantages of ConMap are threefolded: i) Generality-- ConMap exhibits strong applicability to a wide range of energy models; ii) Flexibility-- Any algorithm designed for the problem of directed Steiner tree can be embedded into our ConMap framework to achieve different performance guarantees and complexities; iii) Efficiency-- ConMap preserves the approximation ratio of the embedded Steiner tree algorithm, to which only slight overhead will be incurred. The three features are then empirically validated, with ConMap also yielding near-optimal transmission schemes compared to a brute-force exact algorithm. To our best knowledge, this is the first work that jointly considers both the transmitting and receiving energy in the design of multicast transmission schemes in mobile wireless networks. Xinzhe Fu, Zhiying Xu, Qianyang Peng, Luoyi Fu, Xinbing Wang, Songwu Lu |
MobiHoc | 7 |
| 2017 | Exposing LTE Security Weaknesses at Protocol Inter-layer, and Inter-radio Interactions
Muhammad Taqi Raza, Fatima M. Anwar 0001, Songwu Lu |
SecureComm | 3 |
| 2017 | Special focus on machine-type communications
Xiaofeng Tao 0001, Ping Zhang 0003, Victor C. M. Leung, Songwu Lu, Yu Chen 0006 |
Sci. China Inf. Sci. | 4 |
| 2017 | Determining Source-Destination Connectivity in Uncertain Networks: Modeling and SolutionsabstractDetermination of source-destination connectivity in networks has long been a fundamental problem, where most existing works are based on deterministic graphs that overlook the inherent uncertainty in network links. To overcome such limitation, this paper models the network as an uncertain graph, where each edge e exists independently with some probability p(e). The problem examined is that of determining whether a given pair of nodes, a source s and a destination t, are connected by a path or separated by a cut. Assuming that during each determining process we are associated with an underlying graph, the existence of each edge can be unraveled through edge testing at a cost of c(e). Our goal is to find an optimal strategy incurring the minimum expected testing cost with the expectation taken over all possible underlying graphs that form a product distribution. Formulating it into a combinatorial optimization problem, we first characterize the computational complexity of optimally determining source-destination connectivity in uncertain graphs. Specifically, through proving the NP-hardness of two closely related problems, we show that, contrary to its counterpart in deterministic graphs, this problem cannot be solved in polynomial time unless P = NP. Driven by the necessity of designing an exact algorithm, we then apply the Markov decision process framework to give a dynamic programming algorithm that derives the optimal strategies. As the exact algorithm may have prohibitive time complexity in practical situations, we further propose two more efficient approximation schemes compromising the optimality. The first one is a simple greedy approach with linear approximation ratio. Interestingly, we show that naive as it is, and it enjoys significantly better performance guarantee than some other seemingly more sophisticated algorithms. Second, by harnessing the submodularity of the problem, we further design a more elaborate algorithm with better approximation ratio. The effectiveness of the proposed algorithms is justified through extensive simulations on three real network data sets, from which we demonstrate that the proposed algorithms yield strategies with smaller expected cost than conventional heuristics. Luoyi Fu, Xinzhe Fu, Zhiying Xu, Qianyang Peng, Xinbing Wang, Songwu Lu |
IEEE/ACM Trans. Netw. | 6 |
| 2016 | New Security Threats Caused by IMS-based SMS Service in 4G LTE NetworksabstractSMS (Short Messaging Service) is a text messaging service for mobile users to exchange short text messages. It is also widely used to provide SMS-powered services (e.g., mobile banking). With the rapid deployment of all-IP 4G mobile networks, the underlying technology of SMS evolves from the legacy circuit-switched network to the IMS (IP Multimedia Subsystem) system over packet-switched network. In this work, we study the insecurity of the IMS-based SMS. We uncover its security vulnerabilities and exploit them to devise four SMS attacks: silent SMS abuse, SMS spoofing, SMS client DoS, and SMS spamming. We further discover that those SMS threats can propagate towards SMS-powered services, thereby leading to three malicious attacks: social network account hijacking, unauthorized donation, and unauthorized subscription. Our analysis reveals that the problems stem from the loose security regulations among mobile phones, carrier networks, and SMS-powered services. We finally propose remedies to the identified security issues. Guan-Hua Tu, Chi-Yu Li 0001, Chunyi Peng 0001, Yuanjie Li, Songwu Lu |
CCS | 5 |
| 2016 | In-device, runtime cellular network information extraction and analysis: demoabstractWe present the demonstration of MobileInsight, a software tool that collects, analyzes and exploits runtime information from operational cellular network. MobileInsight runs on commercial off-the-shelf phones without extra hardware or additional support from cellular network operators. It exposes cellular protocol messages from the 3G/4G chipset, and performs in-device protocol analysis. We demonstrate the in-device runtime cellular message collection, analysis of the protocol states, visualization of runtime wireless channel and mobility dynamics, and how mobile applications benefit from MobileInsight. Yuanjie Li, Haotian Deng 0001, Yuanbo Xiangli, Zengwen Yuan, Chunyi Peng 0001, Songwu Lu |
MobiCom | 6 |
| 2016 | iCellular: Device-Customized Cellular Network Access on Commodity Smartphones
Yuanjie Li, Haotian Deng 0001, Chunyi Peng 0001, Zengwen Yuan, Guan-Hua Tu, Songwu Lu |
NSDI | 7 |
| 2016 | Instability in Distributed Mobility Management: Revisiting Configuration Management in 3G/4G Mobile NetworksabstractMobility support is critical to offering seamless data service to mobile devices in 3G/4G cellular networks. To accommodate policy requests by users and carriers, micro-mobility management scheme among cells (i.e., handoff) is designated to be configurable. Each cell and mobile device can configure or even customize its own handoff procedure. In this paper, we examine the handoff misconfiguration issues in 3G/4G networks. We show that they may incur handoff instability in the form of persistent loops, where the device oscillates between cells even without radio-link and location changes. Such instability is mainly triggered by uncoordinated parameter configurations and inconsistent decision logic in the hand- off procedure. It can degrade user data performance, incur excessive signaling overhead, and violate network's expected handoff goals. We derive the instability conditions, and validate them on two major US mobile carrier networks. We further design a soft- ware tool for automatic loop detection, and run it over operational networks. We discuss possible fixes to such uncoordinated configurations among devices and cells. Yuanjie Li, Haotian Deng 0001, Chunyi Peng 0001, Songwu Lu |
SIGMETRICS | 5 |
| 2016 | GRT-duplex: A Novel SDR Platform for Full-Duplex WiFi
Tao Wang 0004, Jiahua Chen, Sanjun Liu, Shuyi Tian, Songwu Lu, Lingyang Song, Bingli Jiao |
Mob. Networks Appl. | 6 |
| 2016 | An Energy Efficiency Perspective on Rate Adaptation for 802.11n NICabstractRate adaptation (RA) has been traditionally used to achieve high goodput. In this work, we design RA for 802.11n NICs from an energy-efficiency perspective. We show that current MIMO RA algorithms are not energy efficient for NICs despite ensuring high throughput. The fundamental problem is that, the high-throughput setting is not equivalent to the energy-efficient one. Marginal throughput gain may be realized at high energy cost. We then propose EERA and EERA+, two energy-based RA schemes that trade off goodput for energy savings at NICs. EERA applies multidimensional ternary search and simultaneous pruning to speed up its runtime convergence in single-client operations, and uses fair airtime sharing to handle multiple-client operations. EERA+ further searches for multiple, staged rates to yield more energy savings over EERA. Our experiments have confirmed their effectiveness in various scenarios. Chi-Yu Li 0001, Chunyi Peng 0001, Peng Cheng 0005, Songwu Lu, Xinbing Wang, Fengyuan Ren, Tao Wang 0004 |
IEEE Trans. Mob. Comput. | 4 |
| 2016 | Detecting Problematic Control-Plane Protocol Interactions in Mobile NetworksabstractThe control-plane protocols in 3G/4G mobile networks communicate with each other, and provide a rich set of control functions, such as radio resource control, mobility support, connectivity management, to name a few. Despite their significance, the problem of verifying protocol correctness remains largely unaddressed. In this paper, we examine control-plane protocol interactions in mobile networks. We propose CNetVerifier, a two-phase signaling diagnosis tool to detect problematic interactions in both design and practice. CNetVerifier first performs protocol screening based on 3GPP standards via domain-specific model checking, and then conducts phone-based empirical validation in operational 3G/4G networks. With CNetVerifier, we have uncovered seven types of troublesome interactions, along three dimensions of cross (protocol) layers, cross (circuit-switched and packet-switched) domains, and cross (3G and 4G) systems. Some are caused by necessary yet problematic cooperation (i.e., protocol interactions are needed but they misbehave), whereas others are due to independent yet unnecessary coupled operations (i.e., protocols interactions are not required but actually coupled). These instances span both design defects in 3GPP standards and operational slips by carriers and vendors. They all result in performance penalties or functional incorrectness. We deduce root causes, present empirical results, propose solutions, and summarize learned lessons. Guan-Hua Tu, Yuanjie Li, Chunyi Peng 0001, Chi-Yu Li 0001, Songwu Lu |
IEEE/ACM Trans. Netw. | 5 |
| 2015 | Insecurity of Voice Solution VoLTE in LTE Mobile NetworksabstractVoLTE (Voice-over-LTE) is the designated voice solution to the LTE mobile network, and its worldwide deployment is underway. It reshapes call services from the traditional circuit-switched telecom telephony to the packet-switched Internet VoIP. In this work, we conduct the first study on VoLTE security before its full rollout. We discover several vulnerabilities in both its control-plane and data-plane functions, which can be exploited to disrupt both data and voice in operational networks. In particular, we find that the adversary can easily gain free data access, shut down continuing data access, or subdue an ongoing call, etc. We validate these proof-of-concept attacks using commodity smartphones (rooted and unrooted) in two Tier-1 US mobile carriers. Our analysis reveals that, the problems stem from both the device and the network. The device OS and chipset fail to prohibit non-VoLTE apps from accessing and injecting packets into VoLTE control and data planes. The network infrastructure also lacks proper access control and runtime check. Chi-Yu Li 0001, Guan-Hua Tu, Chunyi Peng 0001, Zengwen Yuan, Yuanjie Li, Songwu Lu, Xinbing Wang |
CCS | 6 |
| 2015 | VSMC MIMO: A spectral efficient scheme for cooperative relay in cognitive radio networksabstractMultiple-Input Multiple-Output (MIMO) technology has become an efficient way to improve the capacity and reliability of wireless networks. Traditional MIMO schemes are designed mainly for the scenario of contiguous spectrum ranges. However, in cognitive radio networks, the available spectrum is discontiguous, making traditional MIMO schemes inefficient for spectrum usage. This motivates the design of new MIMO schemes that apply to networks with discontiguous spectrum ranges. In this paper, we propose a scheme called VSMC MIMO, which enables MIMO nodes to transmit variable numbers of streams in multiple discontinuous spectrum ranges. This scheme can largely improve the spectrum utilization and meanwhile maintain the same spatial multiplexing and diversity gains as traditional MIMO schemes. To implement this spectral-efficient scheme on cooperative MIMO relays in cognitive radio networks, we propose a joint relay selection and spectrum allocation algorithm and a corresponding MAC protocol for the system. We also build a testbed by the Universal Software Radio Peripherals (USRPs) to evaluate the performances of the proposed scheme in practical networks. The experimental results show that VSMC MIMO can efficiently utilize the discontiguous spectrum and greatly improve the throughput of cognitive radio networks. Chao Kong, Zengwen Yuan, Xushen Han, Feng Yang 0006, Xinbing Wang, Tao Wang 0004, Songwu Lu |
INFOCOM | 7 |
| 2015 | Latency-aware rate adaptation in 802.11n home networksabstractLatency-sensitive applications (e.g., wireless gaming and TV remote play) are increasingly popular in home WiFi networks. Such millisecond-level latency requirements call for new fine-grained approaches at the link layer. In this paper, we show that current solutions work well for throughput but not for latency due to the long tail of the packet delay distribution. We thus propose LLRA, a new latency-aware rate adaptation scheme that reduces the tail latency for delay-sensitive applications. LLRA takes concerted design in rate control, frame aggregation scheduling and software/hardware retransmission dispatching. Our implementation and evaluation confirm the viability of LLRA in 802.11n home networks. Chi-Yu Li 0001, Chunyi Peng 0001, Songwu Lu, Xinbing Wang, Ranveer Chandra |
INFOCOM | 3 |
| 2015 | Fundamental limits of RSS fingerprinting based indoor localizationabstractIndoor localization has been an active research field for decades, where the received signal strength (RSS) fingerprinting based methodology is widely adopted and induces many important localization techniques such as the recently proposed one building the fingerprint database with crowd-sourcing. While efforts have been dedicated to improve the accuracy and efficiency of localization, the fundamental limits of RSS fingerprinting based methodology itself is still unknown in a theoretical perspective. In this paper, we present a general probabilistic model to shed light on a fundamental question: how good the RSS fingerprinting based indoor localization can achieve? Concretely, we present the probability that a user can be localized in a region with certain size, given the RSS fingerprints submitted to the system. We reveal the interaction among the localization accuracy, the reliability of location estimation and the number of measurements in the RSS fingerprinting based location determination. Moreover, we present the optimal fingerprints reporting strategy that can achieve the best accuracy for given reliability and the number of measurements, which provides a design guideline for the RSS fingerprinting based indoor localization facilitated by crowdsourcing paradigm. Yutian Wen, Xiaohua Tian, Xinbing Wang, Songwu Lu |
INFOCOM | 4 |
| 2014 | Real Threats to Your Data Bills: Security Loopholes and Defenses in Mobile Data ChargingabstractSecure mobile data charging (MDC) is critical to cellular network operations. It must charge the right user for the right volume that (s)he authorizes to consume (i.e., requirements of authentication, authorization, and accounting (AAA)). In this work, we conduct security analysis of the MDC system in cellular networks. We find that all three can be breached in both design and practice, and identify three concrete vulnerabilities: authentication bypass, authorization fraud and accounting volume inaccuracy. The root causes lie in technology fundamentals of cellular networks and the Internet IP design, as well as imprudent implementations. We devise three showcase attacks to demonstrate that, even simple attacks can easily penetrate the operational 3G/4G cellular networks. We further propose and evaluate defense solutions. Chunyi Peng 0001, Chi-Yu Li 0001, Guan-Hua Tu, Songwu Lu |
CCS | 5 |
| 2014 | EPEE: an efficient PCIe communication library with easy-host-integration property for FPGA accelerators (abstract only)abstractThe rapid growth in the resources and processing power of FPGA has made it more and more attractive as accelerator platforms. Due to its high performance, the PCIe bus is the preferred interconnection between the host computer and loosely-coupled FPGA accelerators. To fully utilize the high performance of PCIe, developers have to write significant amount of PCIe related code. In this paper, we present the design of EPEE, an efficient PCIe communication library that can integrate with hosts easily to alleviate developers from such burden. It is not trivial to make a PCIe communication library highly efficient and easy-host-integration simultaneously. We have identified several challenges in the work: 1) the conflict between efficiency and functionality; 2) the support for multi-clock domain interface; 3) the solution to DMA data out-of-order transfer; 4) the portability. Few existing systems have addressed all the challenges. EEPE has a highly efficient core library that is extensible. We provide a set of APIs abstracted at high levels to ease the learning curve of developers, and divide the hardware library into device dependent and independent layers for portability. We have implemented EEPE in various generations of Xilinx FPGAs with up to 12.7 Gbps half-duplex and 20.8 Gbps full-duplex data rates in PCIe Gen2X4 mode (79.4% and 64.0% of the theoretical maximum data rates respectively). EEPE has already been used in four different FPGA applications, and it can be integrated with high-level synthesis tools, in particular Vivado-HLS. Jiahua Chen, Fan Ye 0003, Songwu Lu, Jason Cong, Tao Wang 0004 |
FPGA | 5 |
| 2014 | An efficient and flexible host-FPGA PCIe communication libraryabstractA high-performance interconnection between a host processor and FPGA accelerators is in much demand. Among various interconnection methods, a PCIe bus is an attractive choice for loosely coupled accelerators. Because there is no standard host-FPGA communication library, FPGA developers have to write significant amounts of PCIe related code at both the FPGA side and the host processor side. A high-performance host-FPGA PCIe communication library holds the key to broadening the use of FPGA accelerators. In this paper we target efficiency and flexibility as two important features in such a library. We discuss the challenges in providing these features, and present our solution to these challenges. We propose EPEE, an efficient and flexible host-FPGA PCIe communication library and describe its design. We implemented EPEE in various generations of Xilinx FPGAs with up to 26.24 Gbps half-duplex and 43.02 Gbps full-duplex aggregate throughput in the PCIe Gen2 X8 mode; these are at the best utilization levels that a host-FPGA PCIe library can achieve. The EPEE library has been integrated into four different FPGA applications with different data usage patterns in various institutes. Tao Wang 0004, Jiahua Chen, Fan Ye 0003, Songwu Lu, Jason Cong |
FPL | 6 |
| 2014 | A high-performance and high-programmability reconfigurable wireless development platformabstractThe ongoing mobile Internet revolution calls for quick adoptions of new wireless communication and networking technologies. To enable such fast innovations, a software-defined platform is needed to validate and refine new algorithms, protocols, and architectures in communications and networking. Unfortunately, no current systems can meet both requirements of high programmability and high performance. In this work, we report our recent effort on building such a reconfigurable platform. We show that our proposed platform, GRT, can support both high-performance and high-programmability in a unified framework. Moreover, GRT is seamlessly integrated into the standard TCP/IP network protocol stack under Linux, and can act as a WiFi-capable, network interface card. Furthermore, it ensures backward compatibility with the popular GNU Radio platform, a user-friendly, yet low-performance system. In the demo, we will demonstrate the full functionalities of the 802.11a/g WiFi on GRT, including (1) wireless file transfer between two GRT systems at the speed of tens of Mbps; (2) execution of default Linux TCP/IP applications without changes (e.g. SSH); (3) access point (AP) operation mode, where commodity WiFi devices access the Internet via the GRT-converted AP over the WiFi channel. Jiahua Chen, Tao Wang 0004, Gaohan Zhang, Jackie Yang, Songwu Lu |
FPT | 10 |
| 2014 | INDAPSON: An incentive data plan sharing system based on self-organizing networkabstractThe contradiction between dynamic user traffic and fixed data plans has drawn increasing attention in the field of mobile applications. In this paper we build a data plan sharing system named INDAPSON to consider a scenario where some smartphone users have surplus data traffic and are willing to help others download data. Virtual credits can be gained as reward, which can be used to ask for future help in downloading. To realize this model, we make the following contributions: 1) A dynamic self-organization strategy to adapt to mobile terminals; 2) An incentive mechanism named RAP to encourage participation; 3) Power-saving strategies to reduce power consumption. The main advantage of our system is that users gain improvement in download rate while being able to convert their surplus data traffic to virtual credits. The results of experiment and simulation show that users in our system can manage their surplus data plan more efficiently while a highspeed download rate can be achieved. Tuo Yu, Xinbing Wang, Songwu Lu |
INFOCOM | 6 |
| 2014 | Control-plane protocol interactions in cellular networksabstractControl-plane protocols are complex in cellular networks. They communicate with one another along three dimensions of cross layers, cross (circuit-switched and packet-switched) domains, and cross (3G and 4G) systems. In this work, we propose signaling diagnosis tools and uncover six instances of problematic interactions. Such control-plane issues span both design defects in the 3GPP standards and operational slips by carriers. They are more damaging than data-plane failures. In the worst-case scenario, users may be out of service in 4G, or get stuck in 3G. We deduce root causes, propose solutions, and summarize learned lessons. Guan-Hua Tu, Yuanjie Li, Chunyi Peng 0001, Chi-Yu Li 0001, Songwu Lu |
SIGCOMM | 6 |
| 2014 | Impact of correlated mobility and cluster scalability on connectivity of wireless networksabstractWe propose the correlated mobile k-hop clustered networks model to implement correlated node movements and scalable clusters. We divide network states into three categories, i.e., cluster-sparse state, cluster-dense state and cluster-inferior dense state, and achieve the critical transmission range for the last two states. Furthermore, we find that correlated mobility and cluster scalability are closely related with each other and the impact of these two properties on connectivity is mainly through influencing network state transition. Jinbei Zhang, Xinyu Wang 0019, Xinbing Wang, Songwu Lu |
SIGMETRICS | 6 |
| 2014 | GreenBSN: Enabling Energy-Proportional Cellular Base Station NetworksabstractBase station (BS) networks in 3G cellular infrastructure do not consume energy in proportion to their carried traffic load. Our measurements show that the 3G traffic exhibits high fluctuations both in time and over space, thus incurring energy waste. In this paper, we propose Green base station networks (GreenBSN) to approximate network-wide energy proportionality using non-load-adaptive BSes. The instrument is a traffic-driven approach. By leveraging the inherent temporal-spatial traffic dynamics and node deployment heterogeneity, we power off under-utilized BSes under light traffic. Our evaluation on four regional 3G networks shows that GreenBSN yields up to 53 percent energy savings in dense large cities and 23 percent in sparsely deployed regions. Chunyi Peng 0001, Suk-Bok Lee, Songwu Lu, Haiyun Luo |
IEEE Trans. Mob. Comput. | 3 |
| 2014 | Function Computation over Heterogeneous Wireless Sensor NetworksabstractThe problem of function computation in large scale heterogeneous wireless sensor networks (WSNs) is studied. Suppose n sensors are placed in a disk network area with radius nα, where α is a positive constant. The sensors are located heterogeneously around the sink node, i.e, the density of sensors decreases as the distance from the sink node increases. At one instant, each sensor is assigned an input bit. The target of the sink is to compute a function f of the input bits, where f is either a symmetric or the identity function. Energy-efficient algorithms based on inhomogeneous tessellation of the network are designed and the corresponding optimal energy consumption scaling laws are derived. We show that the proposed algorithms are indeed optimal (except for some polylogarithmic terms) by deriving matching lower bounds on the energy consumption required to compute f. At last, based on the results obtained in this paper as well as those obtained by previous works, some discussions and comparisons are presented. We observe that 1) the heterogeneity extent has a great impact on the computation of both symmetric function and identity function, and 2) the energy usage of computing symmetric function can be significantly smaller than that of computing identity function under certain parameter condition, i.e, performing in-network computation helps save energy. Xuanyu Cao, Xinbing Wang, Songwu Lu |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2013 | CMES: Collaborative Energy Save for MIMO 802.11 wireless networksabstractThis work experimentally studies the energy consumption of multiple-antenna MIMO 802.11 devices. Our measurements reveal an increase in power consumption and speed with the number of antennas. State of the art proposals have limitations to save energy in MIMO 802.11 networks. First, they focus on either maximizing speed or minimizing power consumption. Second, they only seek to minimize energy for the receiver side of mobile devices. As a result, they present limitations to utilize MIMO speed gains and to save energy in MIMO 802.11 infrastructure. To this end, we design Collaborative MIMO Energy Save (CMES), which seeks to identify the transmitter-receiver most energy efficient antenna setting, at runtime. Our experiments with commodity MIMO 802.11n testbeds confirm that CMES can provide energy savings in real scenarios. Ioannis Pefkianakis, Chi-Yu Li 0001, Chunyi Peng 0001, Suk-Bok Lee, Songwu Lu |
ICNP | 5 |
| 2013 | How voice calls affect data in operational LTE networksabstractBoth voice and data are indispensable services in current cellular networks. In this work, we study the inter-play of voice and data in operational LTE networks. We assess how the popular CSFB-based voice service affects the IP-based data sessions in 4G LTE networks, and visa versa. Our findings reveal that the interference between them is mutual. On one hand, voice calls may incur throughput drop, lost 4G connectivity, and application aborts for data sessions. One the other hand, users may miss incoming voice calls when turning on data access. The fundamental problem is that, signaling and control for circuit-switched voice and packet-switched data have dependency and coupling effect via the LTE phone client. We further propose fixes to the identified issues. Guan-Hua Tu, Chunyi Peng 0001, Chi-Yu Li 0001, Songwu Lu |
MobiCom | 5 |
| 2013 | Accounting for roaming users on mobile data access: issues and root causesabstractIn this paper, we study how mobility affects mobile data accounting, which records the usage volume for each roaming user. We find out that, current 2G/3G/4G systems have well-tested mobility support solutions and generally work well. However, under certain biased, less common yet possible scenarios, accounting gap between the operator's log and the user's observation indeed exists. The gap can be as large as 69.6% in our road tests. We further discover that the root causes are diversified. In addition to the no-signal case reported in the prior work [23], they also include handoffs, as well as insufficient coverage of hybrid 2G/3G/4G systems. Inter-system handoffs (that migrate user devices between radio access technologies of 2G, 3G, and 4G) may incur non-negligible accounting discrepancy. Guan-Hua Tu, Chunyi Peng 0001, Chi-Yu Li 0001, Tao Wang 0004, Songwu Lu |
MobiSys | 7 |
| 2013 | Window-based Rate Adaptation in 802.11n Wireless Networks
Ioannis Pefkianakis, Suk-Bok Lee, Chunyi Peng 0001, Sofia Sakellaridi, Songwu Lu |
Mob. Networks Appl. | 6 |
| 2013 | Toward History-Aware Robust 802.11 Rate AdaptationabstractRate adaptation is a mechanism unspecified by the IEEE 802.11 standards, yet critical to the system performance by exploiting the multirate capability at the physical layer. In this paper, we conduct a systematic experimental study on rate adaptation over 802.11 wireless networks. Our key contributions are as follows: First, we present a critique on popular design guidelines adopted by many practical algorithms and we uncover their limitations. Our study reveals that these seemingly correct guidelines can be misleading in practice, thus incurring significant performance penalty in certain scenarios. Second, we study the short-term channel dynamics and explore how they guide rate adaptation. To this end, we design and implement a new History-Aware Robust Rate Adaptation Algorithm (HA-RRAA). HA-RRAA uses short-term loss ratio to opportunistically guide its rate change decisions, a cost-effective adaptive RTS filter to prevent collision losses from triggering rate decrease and an adaptive time window to limit transmissions at high loss rates. Our extensive experiments show that HA-RRAA outperforms popular algorithms in all tested scenarios, with goodput gains up to 51.9 percent in field trials. Ioannis Pefkianakis, Starsky H. Y. Wong, Hao Yang 0004, Suk-Bok Lee, Songwu Lu |
IEEE Trans. Mob. Comput. | 5 |
| 2013 | Towards MIMO-Aware 802.11n Rate AdaptationabstractIn this paper, we use real experiments to study multiple-input-multiple-output (MIMO) 802.11n rate adaptation (RA) on a programmable access point (AP) platform. Our case study shows that existing RA solutions offer much lower throughput than even a fixed-rate scheme. It is proven that all such algorithms are MIMO-mode oblivious; they do not differentiate spatial diversity and spatial multiplexing modes. We first design MiRA, a novel MIMO RA scheme that zigzags between intra- and inter-MIMO modes to address MIMO 802.11n dynamics. Second, we examine a window-based RA solution, which runs an independent RA in each MIMO mode in parallel and a signal-to-noise ratio (SNR)-based MIMO RA that differentiates modes using SNR measurements. Our experiments show that MIMO-mode aware designs outperform MIMO-mode oblivious RAs in various settings, with goodput gains up to 73.5% in field trials. Ioannis Pefkianakis, Suk-Bok Lee, Songwu Lu |
IEEE/ACM Trans. Netw. | 3 |
| 2012 | Mobile data charging: new attacks and countermeasuresabstract3G/4G cellular networks adopt usage-based charging. Mobile users are billed based on the traffic volume when accessing data service. In this work, we assess both this metered accounting architecture and application-specific charging policies by operators from the security perspective. We have identified loopholes in both, and discovered two effective attacks exploiting the loopholes. The "toll-free-data-access-attack" enables the attacker to access any data service for free. The "stealth-spam-attack" incurs any large traffic volume to the victim, while the victim may not be even aware of such spam traffic.Our experiments on two operational 3G networks have confirmed the feasibility and simplicity of such attacks. We also propose defense remedies. Chunyi Peng 0001, Chi-Yu Li 0001, Guan-Hua Tu, Songwu Lu, Lixia Zhang 0001 |
CCS | 4 |
| 2012 | A multimedia service migration protocol for single user multiple devicesabstractThis paper describes a new protocol SMP, which supports multimedia transfer for single-user, multiple-device scenarios. Through its novel naming and control/data plane designs, SMP is able to retain the current client and server protocol operations while placing new functions at the proxy. Our initial evaluation has confirmed its viability. Chi-Yu Li 0001, Ioannis Pefkianakis, Bojie Li, Chenghui Peng, Songwu Lu |
ICC | 6 |
| 2012 | Threshold compression for 3G scalable monitoringabstractWe study the problem of scalable monitoring of operational 3G wireless networks. Threshold-based performance monitoring in large 3G networks is very challenging for two main factors: large network scale and dynamics in both time and spatial domains. A fine-grained threshold setting (e.g., perlocation hourly) incurs prohibitively high management complexity, while a single static threshold fails to capture the network dynamics, thus resulting in unacceptably poor alarm quality (up to 70% false/miss alarm rates). In this paper, we propose a scalable monitoring solution, called threshold-compression that can characterize the location- and time-specific threshold trend of each individual network element (NE) with minimal threshold setting. The main insight is to identify groups of NEs with similar threshold behaviors across location and time dimensions, forming spatial-temporal clusters to reduce the number of thresholds while maintaining acceptable alarm accuracy in a large-scale 3G network. Our evaluations based on the operational experience on a commercial 3G network have demonstrated the effectiveness of the proposed solution. We are able to reduce the threshold setting up to 90% with less than 10% false/miss alarms. Suk-Bok Lee, Dan Pei, Mohammad Hajiaghayi, Ioannis Pefkianakis, Songwu Lu, Zihui Ge, Jennifer Yates, Mario Kosseifi |
INFOCOM | 5 |
| 2012 | Energy-based rate adaptation for 802.11nabstractRate adaptation (RA) has been used to achieve high goodput. In this work, we explore to use RA for energy efficiency in 802.11n NICs. We show that current MIMO RA algorithms are not energy efficient for NICs despite ensuring high throughput. The fundamental problem is that, the high-throughput setting is not equivalent to the energy-efficient one. Marginal throughput gain may be realized at high energy cost. We propose EERA, an energy-based RA solution that trades off goodput for energy savings at NICs. Our experiments have confirmed its energy savings at NICs while keeping the cost at the device level and across clients acceptable. Chi-Yu Li 0001, Chunyi Peng 0001, Songwu Lu, Xinbing Wang |
MobiCom | 3 |
| 2012 | Can we pay for what we get in 3G data access?abstractData-plan subscribers are charged based on the used traffic volume in 3G/4G cellular networks. This usage-based charging system has been operational and received general success. In this work, we conduct experiments to critically assess both this usage-based accounting architecture and application-specific charging policies by operators. Our evaluation compares the network-recorded volume with the delivered traffic at the end device. We have found that, both generally work in common scenarios but may go wrong in the extreme cases: We are charged for what we never get, and we can get what we want for free. In one extreme case, we are charged for at least three hours and 450MB or more data despite receiving no single bit. In another extreme case, we are able to transfer 200MB or any amount we specify for free. The root causes lie in lack of both coordination between the charging system and the end device, and prudent policy enforcement by certain operators. We propose immediate fixes and discuss possible future directions. Chunyi Peng 0001, Guan-Hua Tu, Chi-Yu Li 0001, Songwu Lu |
MobiCom | 4 |
| 2012 | Transmission delay in large scale ad hoc cognitive radio networksabstractThere has been recent interest within the networking research area to understand the transmission delay in Cognitive Radio (CR) Networks with overlapping primary network and secondary network. In this paper, we investigate the scaling behavior of transmission delay in large scale ad hoc CR networks. We take different scenarios of CR networks into consideration and thus obtain a wind range of results. We first neglect propagation delay and study the ratio of transmission delay to distance, denoted by γ (λsAp and figure out its exact value in supercritical secondary network. In case of subcritical secondary network, we introduce a multi-cluster hop transmission process to get the lower bound of γ (λsAp. Then we take propagation delay into consideration to obtain further results. Finally, we use simulation results to verify our theoretical analysis. The results present the scaling behavior of transmission delay in CR networks and provide the design guidelines for large scale wireless networks. Zhuotao Liu, Xinbing Wang, Wentao Luan, Songwu Lu |
MobiHoc | 4 |
| 2012 | Exploiting Spatial, Frequency, and Multiuser Diversity in 3GPP LTE Cellular NetworksabstractThis paper addresses the problem of frequency domain packet scheduling (FDPS) incorporating spatial division multiplexing (SDM) multiple input multiple output (MIMO) techniques on the 3GPP Long-Term Evolution (LTE) downlink. We impose the LTE MIMO constraint of selecting only one MIMO mode (spatial multiplexing or transmit diversity) per user per transmission time interval (TTI). First, we address the optimal MIMO mode selection (multiplexing or diversity) per user in each TTI in order to maximize the proportional fair (PF) criterion adapted to the additional frequency and spatial domains. We prove that both single-user (SU-) and multi-user (MU-) MIMO FDPS problems under the LTE requirement are NP-hard. We therefore develop two types of approximation algorithms (ones with full channel feedback and the others with partial channel feedback), all of which guarantee provable performance bounds for both SU- and MU-MIMO cases. Based on 3GPP LTE system model simulations, our approximation algorithms that take into account both spatial and frequency diversity gains outperform the exact algorithms that do not exploit the potential spatial diversity gain. Moreover, the approximation algorithms with partial channel feedback achieve comparable performance (with only 1-6 percent performance degradation) to the ones with full channel feedback, while significantly reducing the channel feedback overhead by nearly 50 percent. Suk-Bok Lee, Ioannis Pefkianakis, Sayantan Choudhury, Shugong Xu, Songwu Lu |
IEEE Trans. Mob. Comput. | 5 |
| 2012 | DAC: Generic and Automatic Address Configuration for Data Center NetworksabstractData center networks encode locality and topology information into their server and switch addresses for performance and routing purposes. For this reason, the traditional address configuration protocols such as DHCP require a huge amount of manual input, leaving them error-prone. In this paper, we present DAC, a generic and automatic Data center Address Configuration system. With an automatically generated blueprint that defines the connections of servers and switches labeled by logical IDs, e.g., IP addresses, DAC first learns the physical topology labeled by device IDs, e.g., MAC addresses. Then, at the core of DAC is its device-to-logical ID mapping and malfunction detection. DAC makes an innovation in abstracting the device-to-logical ID mapping to the graph isomorphism problem and solves it with low time complexity by leveraging the attributes of data center network topologies. Its malfunction detection scheme detects errors such as device and link failures and miswirings, including the most difficult case where miswirings do not cause any node degree change. We have evaluated DAC via simulation, implementation, and experiments. Our simulation results show that DAC can accurately find all the hardest-to-detect malfunctions and can autoconfigure a large data center with 3.8 million devices in 46 s. In our implementation, we successfully autoconfigure a small 64-server BCube network within 300 ms and show that DAC is a viable solution for data center autoconfiguration. Kai Chen 0005, Chuanxiong Guo, Zhenqian Feng, Yan Chen 0004, Songwu Lu, Wenfei Wu |
IEEE/ACM Trans. Netw. | 7 |
| 2011 | What is wrong/right with IEEE 802.11n Spatial Multiplexing Power Save feature?abstractThe IEEE 802.11n standard has proposed a new Spatial Multiplexing Power Save (SMPS) feature, which allows for a station to retain one active receive chain, to mitigate MIMO circuitry power consumption. But does it work in all cases? Our experiments reveal that SMPS may not always save power compared with multiple active chains at the receiver. Even when it does, it may be proven more energy hungry. In this work, we seek to uncover the “good”, the “bad” and the “ugly” of SMPS using real experiments. We further devise a MIMO Receiver Energy Save (MRES) algorithm, which seeks to identify and set the most energy-efficient receive chain setting, by using a novel, low-overhead sampling scheme. Our prototype experiments show that, MRES outperforms SMPS with energy savings up to 37%. Ioannis Pefkianakis, Chi-Yu Li 0001, Songwu Lu |
ICNP | 3 |
| 2011 | Content management in a mobile ad hoc network: Beyond opportunistic strategyabstractWe study the challenging problem of strategic content placement in a dynamic MANET. Existing content placement techniques cannot cope with such network dynamics since they are designed for fixed networks. Opportunistic caching approaches are insufficient as they do not actively manage contents for certain goals. In this paper, we present a novel content management approach called LACMA, which leverages the location information available to mobile devices via GPS. The main idea of LACMA is to bind data to geographic location (as opposed to network nodes). This location-based strategy decouples the content placement problem from the changing network topology, and allows us to design an optimization framework even in a dynamic MANET environment. We present key components of LACMA used for strategic content placement and content-location binding (through proactive content push). We evaluate LACMA and compare its performance with existing caching schemes and show that LACMA considerably outperforms existing schemes over a wide range of scenarios. Suk-Bok Lee, Starsky H. Y. Wong, Kang-Won Lee 0002, Songwu Lu |
INFOCOM | 4 |
| 2011 | History-aware rate adaptation in 802.11 wireless networksabstractRate adaptation (RA) is a mechanism unspecified by the 802.11 standards, yet critical to the system performance. Although many different design directions have been studied the past years, there are still little insights learned of how short-term channel's past performance can be utilized to limit transmissions at low throughput rates. In this paper, we conduct a systematic experimental study to expose the importance of history aware rate adaptation and explore new techniques to address this space. To this end, we design and implement HA-RRAA, a new robust RA algorithm which uses short-term loss ratio to opportunistically guide its rate selection, a cost-effective, adaptive RTS filter to prevent collision losses from triggering rate decrease and an adaptive probe time window to limit excessive probing at high lossy rates. Our experimental results show gains up to 63% of HA-RRAA over RRAA, RRAA+, SampleRate and ARF, in realistic field trials. Ioannis Pefkianakis, Songwu Lu |
ISCC | 3 |
| 2011 | Traffic-driven power saving in operational 3G cellular networksabstractBase stations (BSes) in the 3G cellular network are not energy proportional with respect to their carried traffic load. Our mea- surements show that 3G traffic exhibits high fluctuations both in time and over space, thus incurring energy waste. In this paper, we propose a profile-based approach to green cellular infrastruc- ture. We profile BS traffic and approximate network-wide energy proportionality using non-load-adaptive BSes. The instrument is to leverage temporal-spatial traffic diversity and node deployment heterogeneity, and power off under-utilized BSes under light traf- fic. Our evaluation on four regional 3G networks shows that this simple scheme yields up to 53% energy savings in a dense large city and 23% in a sparse, mid-sized city. Chunyi Peng 0001, Suk-Bok Lee, Songwu Lu, Haiyun Luo, Hewu Li |
MobiCom | 3 |
| 2011 | Scalable monitoring via threshold compression in a large operational 3G networkabstractThreshold-based performance monitoring in large 3G networks is very challenging for two main factors: large network scale and dynamics in both time and spatial domains. There exists a fundamental tradeoff between the size of threshold settings and the alarm quality. In this paper, we propose a scalable monitoring solution, called threshold-compression that characterizes the tradeoff via intelligent threshold aggregation. The main insight behind our solution is to identify groups of network elements with similar threshold behaviors across location and time dimensions, thus forming spatial-temporal clusters and generating the associated compressed thresholds within the optimization framework. Our evaluations on a commercial 3G network have demonstrated the effectiveness of our threshold-compression solution, e.g., threshold setting reduction up to 90% within 10% false/miss alarms. Suk-Bok Lee, Dan Pei, Mohammad Hajiaghayi, Ioannis Pefkianakis, Songwu Lu, Zihui Ge, Jennifer Yates, Mario Kosseifi |
SIGMETRICS | 5 |
| 2011 | Deploying Cryptography in Internet-Scale Systems: A Case Study on DNSSECabstractThe DNS Security Extensions (DNSSEC) are among the first attempts to deploy cryptographic protections in an Internet-scale operational system. DNSSEC applies well-established public key cryptography to ensure data integrity and origin authenticity in the DNS system. While the cryptographic design of DNSSEC is sound and seemingly simple, its development has taken the IETF over a decade and several protocol revisions, and even today its deployment is still in the early stage of rolling out. In this paper, we provide the first systematic examination of the design, deployment, and operational challenges encountered by DNSSEC over the years. Our study reveals a fundamental gap between cryptographic designs and operational Internet systems. To be deployed in the global Internet, a cryptographic protocol must possess several critical properties including scalability, flexibility, incremental deployability, and ability to function in face of imperfect operations. We believe that the insights gained from this study can offer valuable inputs to future cryptographic designs for other Internet-scale systems. Hao Yang 0004, Eric Osterweil, Daniel Massey, Songwu Lu, Lixia Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2011 | Scalable and cost-effective interconnection of data-center servers using dual server portsabstractThe goal of data-center networking is to interconnect a large number of server machines with low equipment cost while providing high network capacity and high bisection width. It is well understood that the current practice where servers are connected by a tree hierarchy of network switches cannot meet these requirements. In this paper, we explore a new server-interconnection structure. We observe that the commodity server machines used in today's data centers usually come with two built-in Ethernet ports, one for network connection and the other left for backup purposes. We believe that if both ports are actively used in network connections, we can build a scalable, cost-effective interconnection structure without either the expensive higher-level large switches or any additional hardware on servers. We design such a networking structure called FiConn. Although the server node degree is only 2 in this structure, we have proven that FiConn is highly scalable to encompass hundreds of thousands of servers with low diameter and high bisection width. We have developed a low-overhead traffic-aware routing mechanism to improve effective link utilization based on dynamic traffic state. We have also proposed how to incrementally deploy FiConn. Dan Li 0001, Chuanxiong Guo, Kun Tan 0001, Yongguang Zhang, Songwu Lu |
IEEE/ACM Trans. Netw. | 6 |
| 2010 | MIMO rate adaptation in 802.11n wireless networksabstractThis paper studies MIMO based rate adaptation (RA) in 802.11n wireless networks. Our case study shows that existing RA algorithms offer much lower throughput than even a fixed-rate scheme. The fundamental problem is that, all such algorithms are MIMO oblivious; they do not consider the characteristics of diversity-oriented, single-stream mode and the spatial multiplexing driven, double-stream mode. We propose MiRA, a novel MIMO RA scheme that zigzags between intra- and inter-mode rate options. Our experiments show that MiRA consistently outperforms three representative RA algorithms, SampleRate, RRAA and Atheros MIMO RA, in static, mobility and collision settings. Ioannis Pefkianakis, Starsky H. Y. Wong, Hao Yang 0004, Songwu Lu |
MobiCom | 5 |
| 2010 | Generic and automatic address configuration for data center networksabstractData center networks encode locality and topology information into their server and switch addresses for performance and routing purposes. For this reason, the traditional address configuration protocols such as DHCP require huge amount of manual input, leaving them error-prone.In this paper, we present DAC, a generic and automatic Data center Address Configuration system. With an automatically generated blueprint which defines the connections of servers and switches labeled by logical IDs, e.g., IP addresses, DAC first learns the physical topology labeled by device IDs, e.g., MAC addresses. Then at the core of DAC is its device-to-logical ID mapping and malfunction detection. DAC makes an innovation in abstracting the device-to-logical ID mapping to the graph isomorphism problem, and solves it with low time-complexity by leveraging the attributes of data center network topologies. Its malfunction detection scheme detects errors such as device and link failures and miswirings, including the most difficult case where miswirings do not cause any node degree change.We have evaluated DAC via simulation, implementation and experiments. Our simulation results show that DAC can accurately find all the hardest-to-detect malfunctions and can autoconfigure a large data center with 3.8 million devices in 46 seconds. In our implementation, we successfully autoconfigure a small 64-server BCube network within 300 milliseconds and show that DAC is a viable solution for data center autoconfiguration. Kai Chen 0005, Chuanxiong Guo, Zhenqian Feng, Yan Chen 0004, Songwu Lu, Wenfei Wu |
SIGCOMM | 7 |
| 2009 | Downlink MIMO with Frequency-Domain Packet Scheduling for 3GPP LTEabstractThis paper addresses the problem of frequency domain packet scheduling (FDPS) incorporating spatial division multiplexing (SDM) multiple input multiple output (MIMO) techniques on the 3GPP long term evolution (LTE) downlink. We impose the LTE MIMO constraint of selecting only one MIMO mode (spatial multiplexing or transmit diversity) per user per transmission time interval (TTI). First, we address the optimal MIMO mode selection (multiplexing or diversity) per user in each TTI in order to maximize the proportional fair (PF) criterion extended to frequency and spatial domains. We prove that the SU-MIMO (single-user MIMO) FDPS problem under the LTE requirement is NP-hard and therefore, we develop two approximation algorithms (one with full channel feedback and the other with partial channel feedback) with provable performance bounds. Based on 3GPP LTE system model simulations, the approximation algorithm with partial channel feedback is shown to have comparable performance to the one with full channel feedback, while significantly reducing the channel feedback overhead by nearly 50%. Suk-Bok Lee, Sayantan Choudhury, Ahmad Khoshnevis, Shugong Xu, Songwu Lu |
INFOCOM | 5 |
| 2009 | Proportional Fair Frequency-Domain Packet Scheduling for 3GPP LTE UplinkabstractWith the power consumption issue of mobile handset taken into account, single-carrier FDMA (SC-FDMA) has been selected for 3GPP long-term evolution (LTE) uplink multiple access scheme. Like in OFDMA downlink, it enables multiple users to be served simultaneously in uplink as well. However, its single carrier property requires that all the subcarriers allocated to a single user must be contiguous in frequency within each time slot. This contiguous allocation constraint limits the scheduling flexibility, and frequency-domain packet scheduling algorithms in such system need to incorporate this constraint while trying to maximize their own scheduling objectives. In this paper we explore this fundamental problem of LTE SC-FDMA uplink scheduling by adopting the conventional time-domain proportional fair algorithm to maximize its objective (i.e. proportional fair criteria) in the frequency-domain setting. We show the NP-hardness of the frequency-domain scheduling problem under this contiguous allocation constraint and present a set of practical algorithms fine tuned to this problem. We demonstrate that competitive performance can be achieved in terms of system throughput as well as fairness perspective, which is evaluated using 3GPP LTE system model simulations. Suk-Bok Lee, Ioannis Pefkianakis, Adam Meyerson, Shugong Xu, Songwu Lu |
INFOCOM | 5 |
| 2009 | FiConn: Using Backup Port for Server Interconnection in Data CentersabstractThe goal of data center networking is to interconnect a large number of server machines with low equipment cost, high and balanced network capacity, and robustness to link/server faults. It is well understood that, the current practice where servers are connected by a tree hierarchy of network switches cannot meet these requirements (Fares et al., 2008 and Guo et al., 2008). In this paper, we explore a new server-interconnection structure. We observe that the commodity server machines used in today's data centers usually come with two built-in Ethernet ports, one for network connection and the other left for backup purpose. We believe that, if both ports are actively used in network connections, we can build a low-cost interconnection structure without the expensive higher-level large switches. Our new network design, called FiConn, utilizes both ports and only the low-end commodity switches to form a scalable and highly effective structure. Although the server node degree is only two in this structure, we have proven that FiConn is highly scalable to encompass hundreds of thousands of servers with low diameter and high bisection width. The routing mechanism in FiConn balances different levels of links. We have further developed a low-overhead traffic-aware routing mechanism to improve effective link utilization based on dynamic traffic state. Simulation results have demonstrated that the routing mechanisms indeed achieve high networking throughput. Dan Li 0001, Chuanxiong Guo, Kun Tan 0001, Songwu Lu |
INFOCOM | 5 |
| 2009 | A scalable micro wireless interconnect structure for CMPsabstractThis paper describes an unconventional way to apply wireless networking in emerging technologies. It makes the case for using a two-tier hybrid wireless/wired architecture to interconnect hundreds to thousands of cores in chip multiprocessors (CMPs), where current interconnect technologies face severe scaling limitations in excessive latency, long wiring, and complex layout. We propose a recursive wireless interconnect structure called the WCube that features a single transmit antenna and multiple receive antennas at each micro wireless router and offers scalable performance in terms of latency and connectivity. We show the feasibility to build miniature on-chip antennas, and simple transmitters and receivers that operate at 100 − 500 GHz sub-terahertz frequency bands. We also devise new two-tier wormhole based routing algorithms that are deadlock free and ensure a minimum-latency route on a 1000core on-chip interconnect network. Our simulations show that our protocol suite can reduce the observed latency by 20 % to 45%, and consumes power that is comparable to or less than current 2-D wiredmeshdesigns. Suk-Bok Lee, Sai-Wang Tam, Ioannis Pefkianakis, Songwu Lu, Mau-Chung Frank Chang, Chuanxiong Guo, Glenn Reinman, Chunyi Peng 0001, Mishali Naik, Lixia Zhang 0001, Jason Cong |
MobiCom | 4 |
| 2009 | Point&Connect: intention-based device pairing for mobile phone usersabstractPoint&Connect (P&C) offers an intuitive and resilient device pairing solution on standard mobile phones. Its operation follows the simple sequence of point-andconnect: when a user plans to pair her mobile phone with another device nearby, she makes a simple hand gesture that points her phone towards the intended target. The system will capture the user's gesture, understand the target selection intention, and complete the device pairing. P&C is intention-based, intuitive, and reduces user efforts in device pairing. The main technical challenge is to come up with a simple system technique to effectively capture and understand the intention of the user, and pick the right device among many others nearby. It should further work on any mobile phones or small devices without relying on infrastructure or special hardware. P&C meets this challenge with a novel collaborative scheme to measure maximum distance change based on acoustic signals. Using only a speaker and a microphone, P&C can be implemented solely in user-level software and work on COTS phones. P&C adds additional mechanisms to improve resiliency against imperfect user actions, acoustic disturbance, and even certain malicious attacks. We have implemented P&C in Windows Mobile phones and conducted extensive experimental evaluation, and showed that it is a cool and effective way to perform device pairing. Chunyi Peng 0001, Guobin Shen, Yongguang Zhang, Songwu Lu |
MobiSys | 4 |
| 2009 | BCube: a high performance, server-centric network architecture for modular data centersabstractThis paper presents BCube, a new network architecture specifically designed for shipping-container based, modular data centers. At the core of the BCube architecture is its server-centric network structure, where servers with multiple network ports connect to multiple layers of COTS (commodity off-the-shelf) mini-switches. Servers act as not only end hosts, but also relay nodes for each other. BCube supports various bandwidth-intensive applications by speeding-up one-to-one, one-to-several, and one-to-all traffic patterns, and by providing high network capacity for all-to-all traffic. Chuanxiong Guo, Guohan Lu, Dan Li 0001, Yunfeng Shi, Chen Tian 0001, Yongguang Zhang, Songwu Lu |
SIGCOMM | 9 |
| 2009 | Impact of configuration errors on DNS robustnessabstractDuring the past twenty years the Domain Name System (DNS) has sustained phenomenal growth while maintaining satisfactory user-level performance. However, the original design focused mainly on system robustness against physical failures, and neglected the impact of operational errors such as mis-configurations. Our measurement efforts have revealed a number of mis-configurations in DNS today: delegation inconsistency, lame delegation, diminished server redundancy, and cyclic zone dependency. Zones with configuration errors suffer from reduced availability and increased query delays up to an order of magnitude. The original DNS design assumed that redundant DNS servers fail independently, but our measurements show that operational choices create dependencies between servers. We found that, left unchecked, DNS configuration errors are widespread. Specifically, lame delegation affects 15% of the measured DNS zones, delegation inconsistency appears in 21% of the zones, diminished server redundancy is even more prevalent, and cyclic dependency appears in 2% of the zones. We also noted that the degrees of mis-configuration vary from zone to zone, with the most popular zones having the lowest percentage of errors. Our results indicate that DNS, as well as any other truly robust large-scale system, must include systematic checking mechanisms to cope with operational errors. Vasileios Pappas, Duane Wessels, Daniel Massey, Songwu Lu, Andreas Terzis, Lixia Zhang 0001 |
IEEE J. Sel. Areas Commun. | 4 |
| 2008 | Dcell: a scalable and fault-tolerant network structure for data centers
Chuanxiong Guo, Kun Tan 0001, Lei Shi 0002, Yongguang Zhang, Songwu Lu |
SIGCOMM | 6 |
| 2007 | Design and Implementation of Cross-Domain Cooperative FirewallabstractSecurity and privacy are two major concerns in supporting roaming users across administrative domains. In current practices, a roaming user often uses encrypted tunnels, e.g., Virtual Private Networks (VPNs), to protect the secrecy and privacy of her communications. However, due to its encrypted nature, the traffic flowing through these tunnels cannot be examined and regulated by the foreign network's firewall, which may lead the foreign network widely open to various attacks from the Internet. This threat can be alleviated if the users reveal their traffic to the foreign network or the foreign network reveals its firewall rules to the tunnel endpoints. However, neither approach is desirable in practice due to privacy concerns. In this paper, we propose a Cross-Domain Cooperative Firewall (CDCF) that allows two collaborative networks to enforce each other's firewall rules in an oblivious manner. In CDCF, when a roaming user establishes an encrypted tunnel between his home network and the foreign network, the tunnel endpoint (e.g., a VPN server) can regulate the traffic and enforce the foreign network's firewall rules, without knowing these rules. The key ingredients in CDCF are the distribution of firewall primitives across network domains, and the enabling technique of efficient oblivious membership verification. We have implemented CDCF and integrated it with the OpenVPN software, and evaluated its performance using extensive experiments. Our results show that CDCF can protect the foreign network from encrypted tunnel traffic with minimal overhead. Jerry Q. Cheng, Hao Yang 0004, Starsky H. Y. Wong, Petros Zerfos, Songwu Lu |
ICNP | 5 |
| 2007 | Analysis of the Reliability of a Nationwide Short Message ServiceabstractSMS has been arguably the most popular wireless data service for cellular networks. Due to its ubiquitous availability and universal support by mobile handsets and cellular carriers, it is also being considered for emergency notification and other mission-critical applications. Despite its increased popularity, the reliability of SMS service in real-world operational networks has received little study so far. In this work, we investigate the reliability of SMS by analyzing traces collected from a nationwide cellular network over a period of three weeks. Although the SMS service incorporates a number of reliability mechanisms such as delivery acknowledgement and multiple retries, our study shows that its reliability is not as good as we expected. For example the message delivery failure ratio is as high as 5.1% during normal operation conditions. We also analyze the performance of the service under stressful conditions, and in particular during a "flash-crowd" event that occurred in New Year's Eve of 2005. Two important factors that adversely affect reliability of SMS are also examined: bulk message delivery that may induce network-wide congestion, and the topological structure of the social network formed by SMS users, which may facilitate quick propagation of viruses or other malware. Xiaoqiao Meng, Petros Zerfos, Vidyut Samanta, Starsky H. Y. Wong, Songwu Lu |
INFOCOM | 5 |
| 2007 | Secure incentives for commercial ad dissemination in vehicular networksabstractVehicular ad hoc networks (VANETs) are envisioned to provide us with numerous interesting services in the near future. One of the most promising applications is the dissemination of commercial advertisements via car-to-car communication. However, due to non-cooperative behavior of selfish nodes or even malicious ones in the real-world scenario, such vehicular advertisement system cannot be realized unless proper incentives and security mechanisms are taken into consideration. This paper presents Signature-Seeking Drive (SSD), a secure incentive framework for commercial ad dissemination in VANETs. Unlike currently proposed incentive systems, SSD does not rely on tamper-proof hardware or game theoretic approaches, but leverages a PKI (Public Key Infrastructure) to provide secure incentives for cooperative nodes. With a set of ad dissemination designs proposed, we demonstrate that our SSD is robust in both incentive and security perspectives. Suk-Bok Lee, Gabriel Pan, Joon-Sang Park, Mario Gerla, Songwu Lu |
MobiHoc | 5 |
| 2007 | SmartSiren: virus detection and alert for smartphonesabstractSmartphones have recently become increasingly popular because they provide "all-in-one" convenience by integrating traditional mobile phones with handheld computing devices. However, the flexibility of running third-party softwares also leaves the smartphones open to malicious viruses. In fact, hundreds of smartphone viruses have emerged in the past two years, which can quickly spread through various means such as SMS/MMS, Bluetooth and traditional IP-based applications. Our own implementations of two proof-of-concept viruses on Windows Mobile have confirmed the vulnerability of this popular smartphone platform. Jerry Q. Cheng, Starsky H. Y. Wong, Hao Yang 0004, Songwu Lu |
MobiSys | 4 |
| 2007 | Scheduling Delay-Constrained Data in Wireless Data NetworksabstractIn modern cellular networks, the channel quality is dynamic among users and also over time. The time-granularity for such dynamics is significantly diverse - either slow or fast compared to packet transmission time. Because of these issues most existing scheduling policies can not work consistently well. In this work, we propose a scheduling policy with performance relatively insensitive to the time-granularity of the dynamics of channel quality. Our policy is self-adaptive to the scale of channel variations by using an ensemble of proposed algorithms. The proposed scheduling policy is proved to have a worst-case performance bound in the existence of both slow and fast time-varying channels. Simulation results confirm that the policy better tolerates channel variations than other popular schemes such as EDF and the Greedy algorithm. Xiaoqiao Meng, Thyaga Nandagopal, Starsky H. Y. Wong, Hao Yang 0004, Songwu Lu |
WCNC | 5 |
| 2007 | Guest editorial
Elizabeth M. Belding, Songwu Lu |
Wirel. Networks | 2 |
| 2006 | Secure Diffusion for Wireless Sensor NetworksabstractData dissemination is an indispensible protocol component for the emerging large-scale sensor networks. In this paper, we propose a secure data dissemination protocol that enhances directed diffusion to operate in the presence of compromised sensors. Our proposed solution, secure diffusion, utilizes a novel security primitive called location-binding keys, and exploits the available end-to-end feedback loop in directed diffusion. In secure diffusion, sensor nodes use pairwise neighbor keys to establish secure gradients, and the sink uses location-binding keys to authenticate the received sensing data. By differentiating authentic data from fabricated ones, the sink can selectively reinforce data paths and assist intermediate nodes in local reinforcement decisions to combat compromised nodes. Our security analysis shows that, in the presence of compromised nodes, secure diffusion can ensure both high-quality delivery of authentic data and local containment of malicious traffic. Hao Yang 0004, Starsky H. Y. Wong, Songwu Lu, Lixia Zhang 0001 |
BROADNETS | 3 |
| 2006 | A study of the short message service of a nationwide cellular networkabstractIn recent years, cellular networks have experienced an astronomical increase in the use of Short Message Service (SMS), making it a popular communication means for inter-personal as well as content provider-to-person usage. Yet little is known about the traffic and message user behavior in real SMS systems. In this paper, we present a measurement study of SMS based on traces collected from a nationwide cellular carrier during a three-week period. We characterize message traffic at both the message level and the conversation thread level. We also examine the "store-and-forward" mechanism of SMS and present initial measurements on how messages are actually delivered. Petros Zerfos, Xiaoqiao Meng, Starsky H. Y. Wong, Vidyut Samanta, Songwu Lu |
Internet Measurement Conference | 5 |
| 2006 | Robust rate adaptation for 802.11 wireless networksabstractRate adaptation is a mechanism unspecified by the 802.11 standards, yet critical to the system performance by exploiting the multi-rate capability at the physical layer.I n this paper, we conduct a systematic and experimental study on rate adaptation over 802.11 wireless networks. Our main contributions are two-fold. First, we critique five design guidelines adopted by most existing algorithms. Our study reveals that these seemingly correct guidelines can be misleading in practice, thus incur significant performance penalty in certain scenarios. The fundamental challenge is that rate adaptation must accurately estimate the channel condition despite the presence of various dynamics caused by fading, mobility and hidden terminals. Second, we design and implement a new Robust Rate Adaptation Algorithm (RRAA)that addresses the above challenge. RRAA uses short-term loss ratio to opportunistically guide its rate change decisions, and an adaptive RTS filter to prevent collision losses from triggering rate decrease. Our extensive experiments have shown that RRAA outperforms three well-known rate adaptation solutions (ARF, AARF, and SampleRate) in all tested scenarios, with throughput improvement up to 143%. Starsky H. Y. Wong, Songwu Lu, Hao Yang 0004, Vaduvur Bharghavan |
MobiCom | 2 |
| 2006 | Contour maps: Monitoring and diagnosis in sensor networks
Xiaoqiao Meng, Thyaga Nandagopal, Li Erran Li, Songwu Lu |
Comput. Networks | 4 |
| 2006 | SCAN: self-organized network-layer security in mobile ad hoc networksabstractProtecting the network layer from malicious attacks is an important yet challenging security issue in mobile ad hoc networks. In this paper, we describe SCAN, a unified network-layer security solution for such networks that protects both routing and data forwarding operations through the same reactive approach. SCAN does not apply any cryptographic primitives on the routing messages. Instead, it protects the network by detecting and reacting to the malicious nodes. In SCAN, local neighboring nodes collaboratively monitor each other and sustain each other, while no single node is superior to the others. SCAN also adopts a novel credit strategy to decrease its overhead as time evolves. In essence, SCAN exploits localized collaboration and information cross-validation to protect the network in a self-organized manner. Through both analysis and simulation results, we demonstrate the effectiveness of SCAN even in a highly mobile and hostile environment. Hao Yang 0004, James Shu, Xiaoqiao Meng, Songwu Lu |
IEEE J. Sel. Areas Commun. | 4 |
| 2006 | Securing a Wireless WorldabstractSecuring wireless networks poses unique research challenges. In this paper, we survey the state-of-the-art approaches to providing security for three popular wireless networking paradigms, namely, IEEE 802.11 based WLANs, third-generation cellular networks, and mobile ad hoc networks. We identify the security threats as well as examine the current solutions. We further summarize lessons learned, discuss open issues, and identify future research directions. Hao Yang 0004, Fabio Ricciato, Songwu Lu, Lixia Zhang 0001 |
Proc. IEEE | 3 |
| 2006 | A randomized energy-conservation protocol for resilient sensor networks
Fan Ye 0003, Honghai Zhang, Songwu Lu, Lixia Zhang 0001, Jennifer C. Hou |
Wirel. Networks | 3 |
| 2005 | Toward resilient security in wireless sensor networksabstractNode compromise poses severe security threats in wireless sensor networks. Unfortunately, existing security designs can address only a small, fixed threshold number of compromised nodes; the security protection completely breaks down when the threshold is exceeded. In this paper, we seek to overcome the threshold limitation and achieve resiliency against an increasing number of compromised nodes. To this end, we propose a novel location-based approach in which the secret keys are bound to geographic locations, and each node stores a few keys based on its own location. The location-binding property constrains the scope for which individual keys can be (mis)used, thus limiting the damages caused by a collection of compromised nodes. We illustrate this approach through the problem of report fabrication attacks, in which the compromised nodes forge non-existent events. We evaluate our design through extensive analysis, implementation and simulations, and demonstrate its graceful performance degradation in the presence of an increasing number of compromised nodes. Hao Yang 0004, Fan Ye 0003, Yuan Yuan 0035, Songwu Lu, William A. Arbaugh |
MobiHoc | 4 |
| 2005 | A topology-independent wireless fair queueing model in ad hoc networksabstractFair queueing of rate and delay-sensitive packet flows in a shared-medium, multihop wireless network is challenging due to the unique design issues. These issues include: 1) spatial contention among transmitting flows in a spatial locality, as well as spatial reuse of bandwidth through concurrent flow transmissions in different network locations; 2) conflicts between ensuring fairness and maximizing spatial channel reuse; and 3) the distributed nature of ad hoc fair queueing. In this paper, we propose a new topology-independent fair queueing model for a shared-medium ad hoc network. Our fairness model ensures coordinated fair channel access among spatially contending flows, while seeking to maximize spatial reuse of bandwidth. We describe packetized algorithms that realize the fluid fairness model with analytical performance bounds. We further design a distributed implementation which approximates the ideal centralized algorithm. We present simulations and analysis on the performance of our proposed algorithms. Haiyun Luo, Songwu Lu |
IEEE J. Sel. Areas Commun. | 2 |
| 2005 | Statistical en-route filtering of injected false data in sensor networksabstractIn a large-scale sensor network individual sensors are subject to security compromises. A compromised node can be used to inject bogus sensing reports. If undetected, these bogus reports would be forwarded to the data collection point (i.e., the sink). Such attacks by compromised nodes can result in not only false alarms but also the depletion of the finite amount of energy in a battery powered network. In this paper, we present a statistical en-route filtering (SEF) mechanism to detect and drop false reports during the forwarding process. Assuming that the same event can be detected by multiple sensors, in SEF each of the detecting sensors generates a keyed message authentication code (MAC) and multiple MACs are attached to the event report. As the report is forwarded, each node along the way verifies the correctness of the MAC's probabilistically and drops those with invalid MACs. SEF exploits the network scale to filter out false reports through collective decision-making by multiple detecting nodes and collective false detection by multiple forwarding nodes. We have evaluated SEF's feasibility and performance through analysis, simulation, and implementation. Our results show that SEF can be implemented efficiently in sensor nodes as small as Mica2. It can drop up to 70% of bogus reports injected by a compromised node within five hops, and reduce energy consumption by 65% or more in many cases. Fan Ye 0003, Haiyun Luo, Songwu Lu, Lixia Zhang 0001 |
IEEE J. Sel. Areas Commun. | 3 |
| 2005 | A software support infrastructure for wireless access routersabstractRouters are expected to play an important role in the Internet protocol-based wireless data network. Although a substantial number of adaptive and intercell coordination techniques have been proposed to improve wireless network performance under dynamic wireless channel conditions and host mobility, a system support framework is still missing. In this paper, we describe DIRAC, a software-based router system that is designed for wireless networks to facilitate the implementation and evaluation of various channel-adaptive and mobility-aware protocols. DIRAC adopts a distributed architecture that is composed of two parts: a router core (RC) shared by the wireless subnets, and a router agent (RA) at each access point/base station. RAs expose wireless link-layer information to the RC and enforce the control commands issued by the RC. This approach allows the router to make adaptive decisions based on link-layer information feedback on both data and control planes. It also permits the router to enforce its policies (e.g., policing) more effectively through underlying link-layer mechanisms. It further enables interaccess-point coordination at the RC. As showcases, we implement under DIRAC the prototypes of three wireless network services: link-layer assisted fast handover, channel-adaptive scheduling, and link-layer enforced policing. Our implementation and experiments show that our distributed wireless router provides a flexible framework, which enables advanced network-layer wireless services that are adaptive to channel conditions and host mobility. Petros Zerfos, Gary Zhong, Songwu Lu |
IEEE J. Sel. Areas Commun. | 3 |
| 2005 | The Impact of Multihop Wireless Channel on TCP PerformanceabstractThis paper studies TCP performance in a stationary multihop wireless network using IEEE 802.11 for channel access control. We first show that, given a specific network topology and flow patterns, there exists an optimal window size W* at which TCP achieves the highest throughput via maximum spatial reuse of the shared wireless channel. However, TCP grows its window size much larger than W* leading to throughput reduction. We then explain the TCP throughput decrease using our observations and analysis of the packet loss in an overloaded multihop wireless network. We find out that the network overload is typically first signified by packet drops due to wireless link-layer contention, rather than buffer overflow-induced losses observed in the wired Internet. As the offered load increases, the probability of packet drops due to link contention also increases, and eventually saturates. Unfortunately the link-layer drop probability is insufficient to keep the TCP window size around W'*. We model and analyze the link contention behavior, based on which we propose link RED that fine-tunes the link-layer packet dropping probability to stabilize the TCP window size around W*. We further devise adaptive pacing to better coordinate channel access along the packet forwarding path. Our simulations demonstrate 5 to 30 percent improvement of TCP throughput using the proposed two techniques. Zhenghua Fu, Haiyun Luo, Petros Zerfos, Songwu Lu, Lixia Zhang 0001, Mario Gerla |
IEEE Trans. Mob. Comput. | 4 |
| 2005 | TTDD: Two-Tier Data Dissemination in Large-Scale Wireless Sensor Networks
Haiyun Luo, Fan Ye 0003, Jerry Q. Cheng, Songwu Lu, Lixia Zhang 0001 |
Wirel. Networks | 4 |
| 2005 | GRAdient Broadcast: A Robust Data Delivery Protocol for Large Scale Sensor Networks
Fan Ye 0003, Gary Zhong, Songwu Lu, Lixia Zhang 0001 |
Wirel. Networks | 3 |
| 2004 | HOURS: Achieving DoS Resilience in an Open Service HierarchyabstractHierarchical systems have been widely used to provide scalable distributed services in the Internet. Unfortunately, such a service hierarchy is vulnerable to DoS attacks. This paper presents HOURS that achieves DoS resilience in an open service hierarchy. HOURS ensures high degree of service accessibility for each surviving node by: 1) augmenting the service hierarchy with hierarchical overlay networks with rich connectivity; 2) making the connectivity of each overlay highly unpredictable; and 3) recovering the overlay when its normal operations are disrupted. We analyze an HOURS-protected open service hierarchy, and demonstrate its high degree of resilience to even large-scale, topology-aware DoS attacks. Hao Yang 0004, Haiyun Luo, Songwu Lu, Lixia Zhang 0001 |
DSN | 4 |
| 2004 | Statistical En-route Filtering of Injected False Data in Sensor NetworksabstractIn a large-scale sensor network individual sensors are subject to security compromises. A compromised node can inject into the network large quantities of bogus sensing reports which, if undetected, would be forwarded to the data collection point (i.e. the sink). Such attacks by compromised sensors can cause not only false alarms but also the depletion of the finite amount of energy in a battery powered network. We present a statistical en-route filtering (SEF) mechanism that can detect and drop such false reports. SEF requires that each sensing report be validated by multiple keyed message authentication codes (MACs), each generated by a node that detects the same event. As the report is forwarded, each node along the way verifies the correctness of the MACs probabilistically and drops those with invalid MACs at earliest points. The sink further filters out remaining false reports that escape the en-route filtering. SEF exploits the network scale to determine the truthfulness of each report through collective decision-making by multiple detecting nodes and collective false-report-detection by multiple forwarding nodes. Our analysis and simulations show that, with an overhead of 14 bytes per report, SEF is able to drop 80/spl sim/90% injected false reports by a compromised node within 10 forwarding hops, and reduce energy consumption by 50% or more in many cases. Fan Ye 0003, Haiyun Luo, Songwu Lu, Lixia Zhang 0001 |
INFOCOM | 3 |
| 2004 | Characterizing flows in large wireless data networksabstractSeveral studies have recently been performed on wireless university campus networks, corporate and public networks. Yet little is known about the flow-level characterization in such networks. In this paper, we statistically characterize both static flows and roaming flows in a large campus wireless network using a recently-collected trace. For static flows, we take a two-tier approach to characterizing the flow arrivals, which results a Weibull regression model. We further discover that the static flow arrivals in spatial proximity show strong similarity. As for roaming flows, they can also be well characterized statistically.We explain the results by user behaviors and application demands, and further cross-validate the modeling results by three other traces. Finally, we use two examples to illustrate how to apply our models for performance evaluation in the wireless context. Xiaoqiao Meng, Starsky H. Y. Wong, Yuan Yuan 0035, Songwu Lu |
MobiCom | 4 |
| 2004 | Impact of configuration errors on DNS robustnessabstractDuring the past twenty years the Domain Name System (DNS) has sustained phenomenal growth while maintaining satisfactory performance. However, the original design focused mainly on system robustness against physical failures, and neglected the impact of operational errors such as misconfigurations. Our recent measurement effort revealed three specific types of misconfigurations in DNS today: lame delegation, diminished server redundancy, and cyclic zone dependency. Zones with configuration errors suffer from reduced availability and increased query delays up to an order of magnitude. Furthermore, while the original DNS design assumed that redundant DNS servers fail independently, our measurements show that operational choices made at individual zones can severely affect the availability of other zones. We found that, left unchecked, DNS configuration errors are widespread, with lame delegation affecting 15% of the DNS zones, diminished server redundancy being even more prevalent, and cyclic dependency appearing in 2% of the zones. We also noted that the degrees of misconfiguration vary from zone to zone, with most popular zones having the lowest percentage of errors. Our results indicate that DNS, as well as any other truly robust large-scale system, must include systematic checking mechanisms to cope with operational errors. Vasileios Pappas, Songwu Lu, Daniel Massey, Andreas Terzis, Lixia Zhang 0001 |
SIGCOMM | 3 |
| 2004 | A Packet Scheduling Approach to QoS Support in Multihop Wireless Networks
Haiyun Luo, Songwu Lu, Vaduvur Bharghavan, Jerry Q. Cheng, Gary Zhong |
Mob. Networks Appl. | 2 |
| 2004 | Robust Packet Scheduling in Wireless Cellular Networks
Xiaoqiao Meng, Zhenghua Fu, Songwu Lu |
Mob. Networks Appl. | 3 |
| 2004 | Self-Coordinating Localized Fair Queueing in Wireless Ad Hoc NetworksabstractDistributed fair queueing in a multihop, wireless ad hoc network is challenging for several reasons. First, the wireless channel is shared among multiple contending nodes in a spatial locality. Location-dependent channel contention complicates the fairness notion. Second, the sender of a flow does not have explicit information regarding the contending flows originated from other nodes. Fair queueing over ad hoc networks is a distributed scheduling problem by nature. Finally, the wireless channel capacity is a scarce resource. Spatial channel reuse, i.e., simultaneous transmissions of flows that do not interfere with each other, should be encouraged whenever possible. In this paper, we reexamine the fairness notion in an ad hoc network using a graph-theoretic formulation and extract the fairness requirements that an ad hoc fair queueing algorithm should possess. To meet these requirements, we propose maximize-local-minimum fair queueing (MLM-FQ), a novel distributed packet scheduling algorithm where local schedulers self-coordinate their scheduling decisions and collectively achieve fair bandwidth sharing. We then propose enhanced MLM-FQ (EMLM-FQ) to further improve the spatial channel reuse and limit the impact of inaccurate scheduling information resulted from collisions. EMLM-FQ achieves statistical short-term throughput and delay bounds over the shared wireless channel. Analysis and extensive simulations confirm the effectiveness and efficiency of our self-coordinating localized design in providing global fair channel access in wireless ad hoc networks. Haiyun Luo, Jerry Q. Cheng, Songwu Lu |
IEEE Trans. Mob. Comput. | 3 |
| 2004 | URSA: ubiquitous and robust access control for mobile ad hoc networksabstractRestricting network access of routing and packet forwarding to well-behaving nodes and denying access from misbehaving nodes are critical for the proper functioning of a mobile ad-hoc network where cooperation among all networking nodes is usually assumed. However, the lack of a network infrastructure, the dynamics of the network topology and node membership, and the potential attacks from inside the network by malicious and/or noncooperative selfish nodes make the conventional network access control mechanisms not applicable. We present URSA, a ubiquitous and robust access control solution for mobile ad hoc networks. URSA implements ticket certification services through multiple-node consensus and fully localized instantiation. It uses tickets to identify and grant network access to well-behaving nodes. In URSA, no single node monopolizes the access decision or is completely trusted. Instead, multiple nodes jointly monitor a local node and certify/revoke its ticket. Furthermore, URSA ticket certification services are fully localized into each node's neighborhood to ensure service ubiquity and resilience. Through analysis, simulations, and experiments, we show that our design effectively enforces access control in the highly dynamic, mobile ad hoc network. Haiyun Luo, Jiejun Kong, Petros Zerfos, Songwu Lu, Lixia Zhang 0001 |
IEEE/ACM Trans. Netw. | 4 |
| 2003 | Random flow network modeling and simulations for DDoS attack mitigationabstractRecent events show that distributed denial-of-service (DDoS) attack imposes great threat to availability of Internet services. In this paper, we study and evaluate DDoS attacks in a random flow network model, a novel and general approach to DDoS attack prevention and tolerance. The model can be used to evaluate the effectiveness of a DDoS countermeasure framework. Following the random flow network model and state-of-art Internet topology and traffic models, our simulation reveals that general relationship among several metrics derived from the model. Based on the simulation results, we suggest to build a more complete and effective DDoS countermeasure framework using complementary solutions to achieve DDoS attack detection, prevention, and tolerance at same time. Jiejun Kong, Mansoor Mirza, James Shu, Christian Yoedhana, Mario Gerla, Songwu Lu |
ICC | 6 |
| 2003 | Achieving delay and throughput decoupling in distributed fair queueing over ad hoc networksabstractThis paper describes an algorithm that achieves delay and throughput decoupling in distributed fair scheduling in multihop ad-hoc wireless networks. The solution allows to support both low-bandwidth, low-delay and high-bandwidth, high delay applications in a single framework, without wasting much bandwidth to realize the low-delay requirement. We demonstrate the effectiveness of our algorithm in servicing various types of applications through ns-2 simulations. Jerry Q. Cheng, Songwu Lu |
ICCCN | 2 |
| 2003 | PEAS: A Robust Energy Conserving Protocol for Long-lived Sensor NetworksabstractIn this paper we present PEAS, a robust energy-conserving protocol that can build long-lived, resilient sensor networks using a very large number of small sensors with short battery lifetime. PEAS extends the network lifetime by maintaining a necessary set of working nodes and turning off redundant ones. PEAS operations are based on individual node's observation of the local environment and do not require any node to maintain per neighbor node state. PEAS performance possesses a high degree of robustness in the presence of both node power depletions and unexpected failures. Our simulations and analysis show that PEAS can maintain an adequate working node density in the face of up to 38% node failures, and it can maintain roughly a constant overhead level under various deployment conditions ranging from sparse to very dense node deployment by using less than 1% of total energy consumption. As a result, PEAS can extend a sensor network's functioning time in linear proportion to the deployed sensor population. Fan Ye 0003, Gary Zhong, Jesse Cheng, Songwu Lu, Lixia Zhang 0001 |
ICDCS | 4 |
| 2003 | The Impact of Multihop Wireless Channel on TCP Throughput and LossabstractThis paper studies TCP performance over multihop wireless networks that use the IEEE 802.11 protocol as the access method. Our analysis and simulations show that, given a specific network topology and flow patterns, there exists a TCP window size W*, at which TCP achieves best throughput via improved spatial channel reuse. However, TCP does not operate around W*, and typically grows its average window size much larger; this leads to decreased throughput and increased packet loss. The TCP throughput reduction can be explained by its loss behavior. Our results show that network overload is mainly signified by wireless link contention in multihop wireless networks. As long as the buffer size at each node is reasonably large (say, larger than 10 packets), buffer overflow-induced packet loss is rare and packet drops due to link-layer contention dominate. Link-layer drops offer the first sign for network overload. We further show that multihop wireless links collectively exhibit graceful drop behavior: as the offered load increases, the link contention drop probability also increases, but saturates eventually. In general, the link drop probability is insufficient to stabilize the average TCP window size around W*. Consequently, TCP suffers from reduced throughput due to reduced spatial reuse. We further propose two techniques, link RED and adaptive pacing, through which we are able to improve TCP throughput by 5% to 30% in various simulated topologies. Some simulation results are also validated by real hardware experiments. Zhenghua Fu, Petros Zerfos, Haiyun Luo, Songwu Lu, Lixia Zhang 0001, Mario Gerla |
INFOCOM | 4 |
| 2003 | UCAN: a unified cellular and ad-hoc network architectureabstractIn third-generation (3G) wireless data networks, mobile users experiencing poor channel quality usually have low data-rate connections with the base-station. Providing service to low data-rate users is required for maintaining fairness, but at the cost of reducing the cell's aggregate throughput. In this paper, we propose the Unified Cellular and Ad-Hoc Network (UCAN) architecture for enhancing cell throughput, while maintaining fairness. In UCAN, a mobile client has both 3G cellular link and IEEE 802.11-based peer-to-peer links. The 3G base station forwards packets for destination clients with poor channel quality to proxy clients with better channel quality. The proxy clients then use an ad-hoc network composed of other mobile clients and IEEE 802.11 wireless links to forward the packets to the appropriate destinations, thereby improving cell throughput. We refine the 3G base station scheduling algorithm so that the throughput gains of active clients are distributed proportional to their average channel rate, thereby maintaining fairness. With the UCAN architecture in place, we propose novel greedy and on-demand protocols for proxy discovery and ad-hoc routing that explicitly leverage the existence of the 3G infrastructure to reduce complexity and improve reliability. We further propose a secure crediting mechanism to motivate users to participate in relaying packets for others. Through extensive simulations with HDR and IEEE 802.11b, we show that the UCAN architecture can improve individual user's throughput by up to 310% and the aggregate throughput of the HDR downlink by up to 60%. Haiyun Luo, Ramachandran Ramjee, Prasun Sinha, Li Erran Li, Songwu Lu |
MobiCom | 5 |
| 2003 | DIRAC: a software-based wireless router systemabstractRouters are expected to play an important role in the IP-based wireless data network. Although a substantial number of techniques have been proposed to improve wireless network performance under dynamic wireless channel conditions and host mobility, a system support framework is still missing. In this paper, we describe DIRAC, a software-based router system that is designed for wireless networks to facilitate the implementation and evaluation of various channel-adaptive and mobility-aware protocols. DIRAC adopts a distributed architecture that is composed of two parts: a Router Core (RC) shared by the wireless subnets, and a Router Agent (RA) at each access point/base station. RAs expose wireless link-layer information to the RC and enforce the control commands issued by the RC. This approach allows the router to make adaptive decisions based on link-layer information feedback. It also permits the router to enforce its policies (e.g., policing) more effectively through underlying link-layer mechanisms. As showcases, we implement under DIRAC the prototypes of three wireless network services: link-layer assisted fast handover, channel-adaptive scheduling, and link-layer enforced policing. Our implementation and experiments show that our distributed wireless router provides a flexible framework, which enables advanced network-layer wireless services that are adaptive to channel conditions and host mobility. Petros Zerfos, Gary Zhong, Jerry Q. Cheng, Haiyun Luo, Songwu Lu, Jia-Ru Li |
MobiCom | 5 |
| 2003 | Statistical en-route filtering in large scale sensor networksabstractNo abstract available. Fan Ye 0003, Haiyun Luo, Songwu Lu, Lixia Zhang 0001 |
SenSys | 3 |
| 2003 | A transport protocol for supporting multimedia streaming in mobile ad hoc networksabstractTransport protocol design for supporting multimedia streaming in mobile ad hoc networks is challenging because of unique issues, including mobility-induced disconnection, reconnection, and high out-of-order delivery ratios; channel errors and network congestion. In this paper, we describe the design and implementation of a transmission control protocol (TCP)-friendly transport protocol for ad hoc networks. Our key design novelty is to perform multimetric joint identification for packet and connection behaviors based on end-to-end measurements. Our NS-2 simulations show significant performance improvement over wired TCP friendly congestion control and TCP with explicit-link-failure-notification support in ad hoc networks. Zhenghua Fu, Xiaoqiao Meng, Songwu Lu |
IEEE J. Sel. Areas Commun. | 3 |
| 2002 | A security architecture for application session handoffabstractUbiquitous computing across a variety of wired and wireless connections still lacks an effective security architecture. In our research work, we address the specific issue of designing and building a security architecture for application session handoff, a functionality which we envision will be a key component enabling ubiquitous computing. Our architecture incorporates a number of proven approaches into the new context of ubiquitous computing. We employ the Bell-LaPadula (1976) and capability models to realise access control and adopt public key infrastructure (PKI)-based approaches to provide efficient and authenticated end-to-end security. To demonstrate the effectiveness of our design, we implemented an application enabled with this security architecture and showed that it incurred low latency. Erik Skow, Jiejun Kong, Thomas Phan, Fred Cheng, Richard G. Guy, Rajive L. Bagrodia, Mario Gerla, Songwu Lu |
ICC | 8 |
| 2002 | Application-oriented multimedia scheduling over lossy wireless networksabstractThis work seeks a better understanding of the relations between the better network service provided by QoS-oriented wireless packet scheduling and the actual benefits perceived by the multimedia applications that use them. Through extensive simulations driven by real (multimedia and wireless channel error) traces, we observe that in general, there is a performance gap between application perceived QoS and network QoS provided by the wireless fair packet scheduler. This gap tends to increase further as the channel error rate aggravates. The exact distribution of channel errors greatly affects the multimedia application performance, but its impact on network QoS is much smaller. We then present the solution, which is based on idealized weighted fair queuing (IWFQ) to further improve three popular multimedia applications' performance. Xiaoqiao Meng, Hao Yang 0004, Songwu Lu |
ICCCN | 3 |
| 2002 | Design and Implementation of a TCP-Friendly Transport Protocol for Ad Hoc Wireless NetworksabstractTransport protocol design for mobile ad hoc networks is challenging because of unique issues, including mobility-induced disconnection, reconnection, and high out-of-order delivery ratios; channel errors; and network congestion. We describe the design and implementation of a TCP-friendly transport protocol for ad hoc networks. Our key design novelty is to perform multi-metric joint identification for packet and connection behaviors based on end-to-end measurements. Our testbed measurements and ns-2 simulations show a significant performance improvement over standard TCP in ad hoc networks. Zhenghua Fu, Ben Greenstein, Xiaoqiao Meng, Songwu Lu |
ICNP | 4 |
| 2002 | PEAS: A Robust Energy Conserving Protocol for Long-lived Sensor NetworksabstractSmall, inexpensive sensors with limited memory, computing power and short battery lifetimes are turning into reality. Due to adverse conditions such as high noise levels, extreme humidity or temperatures, or even destructions from unfriendly entities, sensor node failures may become norms rather than exceptions in real environments. To be practical, sensor networks must last for much longer times than that of individual nodes, and have yet to be robust against potentially frequent node failures. This paper presents the design of PEAS, a simple protocol that can build a long-lived sensor network and maintain robust operations using large quantities of economical, short-lived sensor nodes. PEAS extends system functioning time by keeping only a necessary set of sensors working and putting the rest into sleep mode. Sleeping ones wake up now and then, probing the local environment and replacing failed ones. The sleeping periods are self-adjusted dynamically, so as to keep the sensors' wakeup rate roughly constant, thus adapting to high node densities. Fan Ye 0003, Gary Zhong, Songwu Lu, Lixia Zhang 0001 |
ICNP | 3 |
| 2002 | How bad TCP can perform in mobile ad hoc networksabstractSeveral recent studies have indicated that TCP performance degrades significantly in mobile ad hoc networks. This paper examines how badly TCP may perform in such networks and provides a quantitative characterization of this performance gap. Previous approaches typically made comparisons by ignoring the inherent dynamics such as mobility, channel error and shared-channel contention. Our work provides a realistic, achievable TCP throughput upper bound, and may serve as a benchmark for future TCP modifications in ad hoc networks. Our simulation findings indicate that node mobility, especially mobility-induced network disconnection and reconnection events, has the most significant impact on TCP performance. TCP NewReno merely achieves about 10% of a reference TCPs throughput in such cases. As mobility increases, the relative throughput drop ranges from almost 0% in the static case to 1000% in a highly mobile scenario (mobility speed is 20 m/sec). In contrast, congestion and mild channel error (say, 1%) have less visible effect on TCP (with less than 10% performance drop compared with the reference TCP). Zhenghua Fu, Xiaoqiao Meng, Songwu Lu |
ISCC | 3 |
| 2002 | Self-securing ad hoc wireless networksabstractMobile ad hoc networking offers convenient infrastructure-free communication over the shared wireless channel. However, the nature of ad hoc networks makes them vulnerable to security attacks. Examples of such attacks include passive eavesdropping over the wireless channel, denial of service attacks by malicious nodes as well as attacks from compromised nodes or stolen devices. Unlike their wired counterpart, infrastructureless ad hoc networks do not have a clear line of defense, and every node must be prepared for encounters with an adversary. Therefore, a centralized or hierarchical network security solution does not work well. This work provides scalable, distributed authentication services in ad hoc networks. Our design takes a self-securing approach, in which multiple nodes (say, k) collaboratively provide authentication services for any node in the network. This paper follows the design guidelines of [7] and makes several new contributions. We first formalize a localized trust model that lays the foundation for the design, and then expand the adversary model that the system should handle. We further propose refined localized certification services, and develop a new scalable solution of share updates to resist more powerful adversaries. Finally, the new solution is evaluated through simulations. 1 Haiyun Luo, Petros Zerfos, Jiejun Kong, Songwu Lu, Lixia Zhang 0001 |
ISCC | 4 |
| 2002 | A two-tier data dissemination model for large-scale wireless sensor networksabstractSink mobility brings new challenges to large-scale sensor networking. It suggests that information about each mobile sink's location be continuously propagated through the sensor field to keep all sensor nodes updated with the direction of forwarding future data reports. Unfortunately frequent location updates from multiple sinks can lead to both excessive drain of sensors' limited battery power supply and increased collisions in wireless transmissions. In this paper we describe TTDD, a Two-Tier Data Dissemination approach that provides scalable and efficient data delivery to multiple mobile sinks. Each data source in TTDD proactively builds a grid structure which enables mobile sinks to continuously receive data on the move by flooding queries within a local cell only. TTDD's design exploits the fact that sensor nodes are stationary and location-aware to construct and maintain the grid structures with low overhead. We have evaluated TTDD performance through both analysis and extensive simulation experiments. Our results show that TTDD handles multiple mobile sinks efficiently with performance comparable with that of stationary sinks. Fan Ye 0003, Haiyun Luo, Jerry Q. Cheng, Songwu Lu, Lixia Zhang 0001 |
MobiCom | 4 |
| 2002 | Adaptive Quality of Service Support for Packet-Switched Wireless Cellular Networks
Songwu Lu, Kang-Won Lee 0002, Vaduvur Bharghavan |
Multim. Tools Appl. | 1 |
| 2002 | Adaptive security for multilevel ad hoc networksabstractAbstract Secure communication is critical in military environments in which the network infrastructure is vulnerable to various attacks and compromises. A conventional centralized solution breaks down when the security servers are destroyed by the enemies. In this paper we design and evaluate a security framework for multilevel ad hoc wireless networks with unmanned aerial vehicles (UAVs). In battlefields, the framework adapts to the contingent damages on the network infrastructure. Depending on the availability of the network infrastructure, our design is composed of two modes. In infrastructure mode, security services, specifically the authentication services, are implemented on UAVs that feature low overhead and flexible managements. When the UAVs fail or are destroyed, our system seamlessly switches to infrastructureless mode, a backup mechanism that maintains comparable security services among the surviving units. In the infrastructureless mode, the security services are localized to each node's vicinity to comply with the ad hoc communication mechanism in the scenario. We study the instantiation of these two modes and the transitions between them. Our implementation and simulation measurements confirm the effectiveness of our design. Copyright © 2002 John Wiley & Sons, Ltd. Jiejun Kong, Haiyun Luo, Kaixin Xu, Daniel Lihui Gu, Mario Gerla, Songwu Lu |
Wirel. Commun. Mob. Comput. | 6 |
| 2002 | A Unified Architecture for the Design and Evaluation of Wireless Fair Queueing Algorithms
Thyaga Nandagopal, Songwu Lu, Vaduvur Bharghavan |
Wirel. Networks | 2 |
| 2001 | A self-organizing approach to data forwarding in large-scale sensor networksabstractThe large number of networked sensors, frequent sensor failures and stringent energy constraints pose unique design challenges for data forwarding in wireless sensor networks. In this paper, we present a new approach to data forwarding in sensor networks that effectively addresses these design issues. Our approach organizes sensors into a dynamic, self-optimizing multicast tree-based forwarding hierarchy, which is data centric and robust to node failures. We demonstrate the effectiveness of our design through simulations. Jelena Mirkovic, Geetha Priya Venkataramani, Songwu Lu, Lixia Zhang 0001 |
ICC | 3 |
| 2001 | A scalable solution to minimum cost forwarding in large sensor networksabstractWireless sensor networks offer a wide range of challenges to networking research, including unconstrained network scale, limited computing, memory and energy resources, and wireless channel errors. We study the problem of delivering messages from any sensor to an interested client user along the minimum-cost path in a large sensor network. We propose a new cost field based approach to minimum cost forwarding. In the design, we present a novel backoff-based cost field setup algorithm that finds the optimal costs of all nodes to the sink with one single message overhead at each node. Once the field is established, the message, carrying dynamic cost information, flows along the minimum cost path in the cost field. Each intermediate node forwards the message only if it finds itself to be on the optimal path, based on dynamic cost states. Our design does not require an intermediate node to maintain explicit "forwarding path" states. It requires a few simple operations and scales to any network size. We show the correctness and effectiveness of the design by both simulations and analysis. Fan Ye 0003, Alvin Chen, Songwu Lu, Lixia Zhang 0001 |
ICCCN | 3 |
| 2001 | Providing Robust and Ubiquitous Security Support for Mobile Ad Hoc NetworksabstractProviding security support for mobile ad-hoc networks is challenging for several reasons: (a) wireless networks are susceptible to attacks ranging from passive eavesdropping to active interfering, occasional break-ins by adversaries may be inevitable in a large time window; (b) mobile users demand "anywhere, anytime" services; (c) a scalable solution is needed for a large-scale mobile network. In this paper, we describe a solution that supports ubiquitous security services for mobile hosts, scales to network size, and is robust against break-ins. In our design, we distribute the certification authority functions through a threshold secret sharing mechanism, in which each entity holds a secret share and multiple entities in a local neighborhood jointly provide complete services. We employ localized certification schemes to enable ubiquitous services. We also update the secret shares to further enhance robustness against break-ins. Both simulations and implementation confirm the effectiveness of our design. Jiejun Kong, Petros Zerfos, Haiyun Luo, Songwu Lu, Lixia Zhang 0001 |
ICNP | 4 |
| 2001 | A Self-Coordinating Approach to Distributed Fair Queueing in Ad Hoc Wireless NetworksabstractDistributed fair queueing in shared-medium ad hoc wireless networks is non-trivial because of the unique design challenges in such networks, such as location-dependent contention, distributed nature of ad hoc fair queueing, channel spatial reuse, and scalability in the presence of node mobility. In this paper, we seek to devise new distributed, localized, scalable and efficient solutions to this problem. We first analyze an ideal centralized fair queueing algorithm developed for ad hoc networks, and extract the desired global properties that the localized algorithms should possess. We then propose three localized fair queueing models, in which local schedulers self-coordinate their local interactions and collectively achieve the desired global properties. We further describe a novel implementation of the proposed models within the framework of the popular CSMA/CA paradigm and address several practical issues. Our simulations and analysis demonstrate the effectiveness of our proposed design. Haiyun Luo, Paul Medvedev, Jerry Q. Cheng, Songwu Lu |
INFOCOM | 4 |
| 2000 | A Topology-Independent Fair Queueing Model in Ad Hoc Wireless NetworksabstractFair queueing of rate and delay-sensitive packet flows in a shared-medium, multihop wireless network remains largely unaddressed because of the unique design issues such as location-dependent contention, spatial channel reuse, conflicts between ensuring fairness and maximizing channel utilization, and distributed fair scheduling. In this paper we propose a new topology-independent fair queueing model for a shared-medium ad hoc network. Our model ensures coordinated fair channel access among spatially contending flows while seeking to maximize spatial channel reuse. We describe packetized algorithms that realize the fluid fairness model with analytically provable performance bounds. We further design distributed implementations that approximate the ideal centralized algorithm. We evaluate our design through both simulations and analysis. Haiyun Luo, Songwu Lu |
ICNP | 2 |
| 2000 | A new model for packet scheduling in multihop wireless networksabstractThe goal of packet scheduling disciplines is to achieve fair and maximum allocation of channel bandwidth. However, these two criteria can potentially be in conflict in a generic-topology multihop wireless network where a single logical channel is shared among multiple contending flows and spatial reuse of the channel bandwidth is possible. In this paper, we propose a new model for packet scheduling that addresses this conflict. The main results of this paper are the following: (a) a two-tier service model that provides a minimum “fair” allocation of the channel bandwidth for each packet flow and additionally maximizes spatial reuse of bandwidth, (b) an ideal centralized packet scheduling algorithm that realizes the above service model, and (c) a practical distributed backoff-based channel contention mechanism that approximates the ideal service within the framework of the CSMA/CA protocol. Haiyun Luo, Songwu Lu, Vaduvur Bharghavan |
MobiCom | 2 |
| 2000 | Design and analysis of an algorithm for fair service in error-prone wireless channels
Songwu Lu, Thyaga Nandagopal, Vaduvur Bharghavan |
Wirel. Networks | 1 |
| 1999 | Improving congestion control performance through loss differentiationabstractLinear increase/multiplicative decrease (LIMD) has typically been the congestion control paradigm of choice in the Internet. However, a major drawback of LIMD is that it reacts identically (and aggressively) to all packet losses, irrespective of the cause of loss. In this paper, we try to augment the basic LIMD congestion control with additional mechanisms to predict the cause of packet losses and react accordingly. To this end, we present the LIMD/H algorithm, which has the following features: (a) LIMD/H uses the "history" of packet losses and the evolution of transmission rate for a connection in order to distinguish between congestion-induced and non-congestion-induced packet losses; (b) LIMD/H reacts gently to non-congestion-induced losses and aggressively to congestion-induced losses, thereby achieving high efficiency, fairness, as well as quick reaction to the onset of congestion. We present an initial performance evaluation of LIMD/H using simulations and analysis. Tae-eun Kim, Songwu Lu, Vaduvur Bharghavan |
ICCCN | 2 |
| 1999 | A Unified Architecture for the Design and Evaluation of Wireless Fair Queueing AlgorithmsabstractFair queueing in the wireless domain poses significant challenges due to unique issues in the wireless channel such as location-dependent and bursty channel error. In this paper, we present a wireless fair service model that captures the scheduling requirements of wireless scheduling algorithms, and present a unied wireless fair queueing architecture in which scheduling algorithms can be designed to achieve wireless fair service. We map seven recently proposed wireless fair scheduling algorithms to the unied architecture, and compare their properties through simulation and analysis. We conclude that some of these algorithms achieve the properties of wireless fair service including short-term and long-term fairness, short-term and long-term throughput bounds, and tight delay bounds for channel access. Thyaga Nandagopal, Songwu Lu, Vaduvur Bharghavan |
MobiCom | 2 |
| 1999 | Fair scheduling in wireless packet networksabstractFair scheduling of delay and rate-sensitive packet flows over a wireless channel is not addressed effectively by most contemporary wireline fair-scheduling algorithms because of two unique characteristics of wireless media: (1) bursty channel errors and (2) location-dependent channel capacity and errors. Besides, in packet cellular networks, the base station typically performs the task of packet scheduling for both downlink and uplink flows in a cell; however, a base station has only a limited knowledge of the arrival processes of uplink flows. We propose a new model for wireless fair-scheduling based on an adaptation of fluid fair queueing (FFQ) to handle location-dependent error bursts. We describe an ideal wireless fair-scheduling algorithm which provides a packetized implementation of the fluid mode, while assuming full knowledge of the current channel conditions. For this algorithm, we derive the worst-case throughput and delay bounds. Finally, we describe a practical wireless scheduling algorithm which approximates the ideal algorithm. Through simulations, we show that the algorithm achieves the desirable properties identified in the wireless FFQ model. Songwu Lu, Vaduvur Bharghavan, R. Srikant 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 1998 | A Wireless Fair Service Algorithm for Packet Cellular Networksabstractb order to support diverse communication-intensive redtirne and non red-time data flows over a scarce, varying and shared wireless channel with location-dependent and bursty errors, we defie a service model that has the following charxteristi~short-tern fairness among flows which perceive a clean channel, worst-case delay bounds for packets, short-term throughput bounds for flows with clean channels and Iong-tem throughput bounds for dl flows with bounded channel error, optimal schedulable region, and support for both delay sensitive and error sensitive data flows.We present a wireless fair service algorithm, and show that it achieves the requirements of the service model through both analysis and simulation.The key aspects of the dg~ rithm are the following (a) an enhanced fair queueing based service scheme that supports decoupling of delay and bandwidth, (b) graceful service compensation for lagging flows and graceful service degradation for leading flows, (c) support for red-time delay sensitive flows as well as non realtime error sensitive flows, and (d) implementation of the wireless fair service rdgorithm within the fiarnework of the simple and robust CSMA/CA wireless medium access pro tocol. Songwu Lu, Thyaga Nandagopal, Vaduvur Bharghavan |
MobiCom | 1 |
| 1998 | Robust nonlinear system identification using neural-network modelsabstractWe study the problem of identification for nonlinear systems in the presence of unknown driving noise, using both feedforward multilayer neural network and radial basis function network models. Our objective is to resolve the difficulty associated with the persistency of excitation condition inherent to the standard schemes in the neural identification literature. This difficulty is circumvented here by a novel formulation and by using a new class of identification algorithms recently obtained by Didinsky et al. We show how these algorithms can be exploited to successfully identify the nonlinearity in the system using neural-network models. By embedding the original problem in one with noise-perturbed state measurements, we present a class of identifiers (under L1 and L2 cost criteria) which secure a good approximant for the system nonlinearity provided that some global optimization technique is used. In this respect, many available learning algorithms in the current neural-network literature, e.g., the backpropagation scheme and the genetic algorithms-based scheme, with slight modifications, can ensure the identification of the system nonlinearity. Subsequently, we address the same problem under a third, worst case L(infinity) criterion for an RBF modeling. We present a neural-network version of an H(infinity)-based identification algorithm from Didinsky et al and show how, along with an appropriate choice of control input to enhance excitation, under both full-state-derivative information (FSDI) and noise-perturbed full-state-information (NPFSI), it leads to satisfaction of a relevant persistency of excitation condition, and thereby to robust identification of the nonlinearity. Results from several simulation studies have been included to demonstrate the effectiveness of these algorithms. Songwu Lu, Tamer Basar |
IEEE Trans. Neural Networks | 1 |
| 1997 | Fair Scheduling in Wireless Packet NetworksabstractFair scheduling of delay and rate-sensitive packet flows over a wireless channel is not addressed effectively by most contemporary wireline fair scheduling algorithms because of two unique characteristics of wireless media: (a) bursty channel errors, and (b) location-dependent channel capacity and errors. Besides, in packet cellular networks, the base station typically performs the task of packet scheduling for both downlink and uplink flows in a cell; however a base station has only a limited knowledge of the arrival processes of uplink flows.In this paper, we propose a new model for wireless fair scheduling based on an adaptation of fluid fair queueing to handle location-dependent error bursts. We describe an ideal wireless fair scheduling algorithm which provides a packetized implementation of the fluid model while assuming full knowledge of the current channel conditions. For this algorithm, we derive the worst-case throughput and delay bounds. Finally, we describe a practical wireless scheduling algorithm which approximates the ideal algorithm. Through simulations, we show that the algorithm achieves the desirable properties identified in the wireless fluid fair queueing model. Songwu Lu, Vaduvur Bharghavan, R. Srikant 0001 |
SIGCOMM | 1 |
| 1996 | Adaptive Resource Management Algorithms for Indoor Mobile Computing EnvironmentsabstractEmerging indoor mobile computing environments seek to provide a user with an advanced set of communication-intensive applications, which require sustained quality of service in the presence of wireless channel error, user mobility, and scarce available resources. In this paper, we investigate two related approaches for the management of critical networking resources in indoor mobile computing environments:• adaptively re-adjusting the quality of service within pre-negotiated bounds in order to accommodate network dynamics and user mobility.• classifying cells based on location and handoff profiles, and designing advance resource reservation algorithms specific to individual cell characteristics.Preliminary simulation results are presented in order to validate the approaches for algorithmic design. A combination of the above approaches provide the framework for resource management in an ongoing indoor mobile computing environment project at the University of Illinois. Songwu Lu, Vaduvur Bharghavan |
SIGCOMM | 1 |
| 1995 | New Algorithm for Structurally Balanced Model Reduction of 2-D Discrete SystemsabstractA new structurally balanced model reduction algorithm that leads to a stable reduced-order system with improved approximation error is proposed. The algorithm is developed by formulating the problem at hand as an unconstrained optimization problem in which the objective function includes a term that depends on the sum of discarded 2-D Hankel singular values. An example is given to illustrate the performance of the reduced-order system obtained using the new algorithm. Haiyun Luo, Songwu Lu, Andreas Antoniou |
ISCAS | 2 |
| 1995 | A Weighted Balanced Realization of 2-D Discrete SystemsabstractAn innovative weighted structurally balanced realization of two-dimensional (2-D) discrete systems is proposed. Two auxiliary transfer-function matrices called the weighted-input-to-state and the state-to-weighted-output transfer-function matrices are first introduced. Based on these matrices, the controllability and observability grammians of the weighted system are defined and the existence of the grammians is justified. The resulting 2-D weighted structurally balanced realization method can be applied for the reduction of the system order of 2-D discrete systems. Haiyun Luo, Songwu Lu, Andreas Antoniou |
ISCAS | 2 |