Chi-Yu Li 0001

dblp:63/4474-1 · DBLP profile ↗
← Back
60ranked-venue papers
7as first author
35since 2021 · last 2026
0000-0002-1077-6801ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 49 · 6 first-author · 28 since 2021Security and privacy · 6 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Acoustic Attacks against MEMS Gyroscope on UAVs
Kuan-Cheng Chen, Yen-Chia Chen, Yu-Xun Tang, Li-Ping Tung, Chi-Yu Li 0001
ICC5
2026 Edge Resilient Agent (ERA) : An Edge AI-Driven Framework for B5G and Wi-Fi 6 Heterogeneous MEC Networks
Hsu Liang Shu, Zhengen Chen, Tan Tai Phan, Chi-Yu Li 0001, Li-Chun Wang 0001
ICC4
2026 Hiaeml: A High-Throughput Adaptive Scheduler for EMLSR-Based Multi-Link Operation in Wi-Fi 7
Ming-Huang Hsieh, Yu-Po Wang, Chi-Yu Li 0001
INFOCOM3
2026 Enabling Edge AI Offloading for XR Devices in Cost-Effective Private 5G Networks
Chia-Yen Hsu, Cheng-En Wu, Rui-Quan Zeng, Yu-Xun Tang, Chuan-Yi Cheng, Chi-Yu Li 0001
INFOCOM6
2026 Is Multi-Link Operation TCP-Friendly in Wi-Fi 7 Networks?
Jing-Shiuan Shiang, Min-Chih Hsu, Yu-Xun Tang, Chi-Yu Li 0001
INFOCOM4
2026 Insecurity of Lost/Stolen Phone Reporting Services: Vulnerabilities, Attacks, and Countermeasures
abstract
Lost and stolen phone reporting services are widely deployed to prevent unauthorized device use by blacklisting International Mobile Equipment Identities (IMEIs). However, through an extensive experimental study across three major U.S. carriers and diverse mobile devices, we discover that these services unexpectedly introduce severe and previously unexplored security risks. Specifically, we identify six new vulnerabilities spanning the device, carrier, and cross-carrier domains, which together enable attackers to arbitrarily block cellular devices from accessing carrier networks. Building on these findings, we design and validate two practical denial-of-service (DoS) attacks: Home Security System Freezing, which disables cellular-based home security gateways and blocks alarm delivery, and Zero-Day Flagship Phone Ambush, which preemptively blocks brand-new flagship phones from accessing mobile services at launch. Both attacks are experimentally validated on operational 5G/4G networks. Finally, we propose practical, backward-compatible countermeasures and implement a prototype to evaluate their effectiveness.
Min-Yue Chen, Yiwen Hu 0002, Yu-An Chen, Chi-Yu Li 0001, Tian Xie 0001, Guan-Hua Tu
MobiSys4
2026 When Mobile Equipment Security Lags Behind Infrastructure: Vulnerabilities, Attacks, and Countermeasures in IMS Services
Jingwen Shi, Min-Yue Chen, Sihan Wang 0002, Guan-Hua Tu, Tian Xie 0001, Yiwen Hu 0002, Man-Hsin Chen, Haitian Yan, Chi-Yu Li 0001, Chunyi Peng 0001
IEEE Trans. Netw.9
2025 PDCA: Practical Dynamic Client Association in Wi-Fi Mesh Networks Using Easymesh
abstract
Wi-Fi mesh networks have become critical for extending Wi-Fi coverage. Their underlying technologies have evolved from the decentralized IEEE 802.11s standard to the newly introduced EasyMesh, which operates in a centralized manner. However, neither approach can dynamically adapt Access Point (AP) and client association control to optimize throughput performance. Although EasyMesh can steer clients to a mesh AP from a centralized controller based on Wi-Fi signal strength, it overlooks other key factors such as AP load, channel congestion, and backhaul link capacity. In this paper, we propose a practical solution called Practical Dynamic Client Association (PDCA), which offers dynamic client association control over time to achieve max-min fairness in throughput performance while accounting for these critical factors. PDCA employs a heuristic-based approach to determine the optimal AP-client associations and then uses the EasyMesh client steering feature to execute association control. Our prototype demonstrates that PDCA consistently outperforms the default EasyMesh operation, achieving improvements of up to 165.2 % in minimum throughput and 60.0 % in aggregate throughput.
Yu-Shao Su, Ming-Huang Hsieh, Tzu-Chi Yu, Chi-Yu Li 0001, Guan-Hua Tu
ICC5
2025 LOMAS: Latency-driven OFDMA Scheduling Design in Wi-Fi 6 Networks
Yi-An Tai, Yao-Wen Liu, Ping-Kuan Kao, Ting-Yu Lee, Cheng-I Hu, Chi-Yu Li 0001
ICNP6
2025 BLuEMan: A Stateful Simulation-based Fuzzing Framework for Open-Source RTOS Bluetooth Low Energy Protocol Stacks
Wei-Che Kao, Yen-Chia Chen, Chi-Yu Li 0001, Chun-Ying Huang
USENIX Security Symposium5
2024 QUIC-HOA: A Cross-layer, Handover-aware Design for QUIC Connection Migration
abstract
QUIC (Quick UDP Internet Connection), a secure general-purpose transport protocol over UDP, has been introduced for a decade and standardized recently. Its operation is akin to the integration of TCP and TLS 1.3, while resolving some conventional transport-layer problems. One key feature is connection migration, which addresses the issue of TCP connections being interrupted when an endpoint’s IP address changes. In this work, we conduct a case study to examine its performance during client handover. The experimental results indicate that QUIC connection migration may fail with a probability as high as 76% during a hard handover, such as when the client disassociates from one Wi-Fi network and connects to another. The root cause of this issue lies in its initialization, which is passively based on the delivery timing of application data and a loss detection mechanism. We thus propose a simple yet effective solution called QUIC-HOA (QUIC Handover-Awareness). It enables the active initialization of connection migration with a cross-layer, handover-aware design. Our evaluation results confirm its effectiveness: QUIC-HOA consistently achieves successful connection migration while reducing average migration time by up to 98% compared to default QUIC.
Po-Jui Chen, Ren-Chieh Hsu, Tzu-Chi Yu, Chi-Yu Li 0001
GLOBECOM4
2024 Stealthy Remote Collection of Call Statistics in 4G/5G Mobile Networks
abstract
Currently, 90% of the global population relies on 4G/5G networks, with smartphones being an indispensable part of daily life. Call statistics, which are vital for billing purposes and treated as sensitive personal information, are safeguarded by legal regulations. One method of remotely obtaining call statistics involves initiating consecutive probing phone calls, which results in numerous missed calls on the recipient’s device. This paper adopts a stealthy phone call solution that utilizes the Session Initiation Protocol (SIP) vulnerabilities, enabling data collection without raising alarms for the callee. Through this approach, the paper distinguishes between calling and remaining states by analyzing the data returned from the callee. Furthermore, the paper introduces a two-level classifier to translate each call response into a state prediction, thus forming a sequence of state predictions over time to derive call statistics. To bolster the prediction accuracy of classification, two domains of knowledge, such as call state machines and typical human call behavior tendencies, are considered. This integration significantly enhances prediction accuracy to an impressive 98%. However, despite these advancements, there remain challenges. The prediction accuracy for call duration still requires improvement due to low probing frequency and occasional incorrect state predictions.
Kai-Wen Chen, Li-Ping Tung, Tai Tan Phan, Chi-Yu Li 0001
ISCC4
2024 Automatic Bridging for Mobile Wireless Backhaul System
abstract
Backhaul networks, serving as the intermediary link from the front-end radio network to the central core network, play a crucial role in end-to-end communication by transporting significant traffic volumes. Apparently, packet transmission efficiency depends on their deployment scenarios; indeed, the more flexibility often translates to the better user experience for the end-user in critical situations. In this work, we propose an automatic bridging system for mobile wireless backhaul designed for high flexibility and compatibility. It features a fully automated establishment of wireless backhaul links, supported by a VXLAN-based packet transmission pipeline and an auto-binding mechanism. We prototype the system on Linux-based operating system with standard packages to ensure the compatibility operation and WiGig modules; the evaluation demonstrates that the VXLAN-based system can achieve lower latency, with a reduction ranging from 15% to 38% compared to the static forwarding-based system.
Tan Tai Phan, Shang-Chun Tai, Yu-Shuo Chang, Wei-Xun Chen, Chi-Yu Li 0001
ISCC5
2024 Uncovering Problematic Designs Hindering Ubiquitous Cellular Emergency Services Access
abstract
Cellular networks provide the most accessible emergency services with ubiquitous coverage, yet their emergency-specific designs remain largely unexplored. To systematically explore potential design defects that lead to failures or delays in emergency services, we introduce M911-Verifier, an emergency-specific model checking tool. It reveals many counterintuitive findings regarding the ubiquitous access support for cellular emergency services. Our study shows that, despite sufficient wireless signal coverage, users may still experience prolonged emergency call setup times, call initiation failures, or call drops due to flaws in the design of cellular emergency services. These design defects arise from three major causes: problematic network selection for initiating emergency calls, emergency-unaware call operation, and network escalation forbidden during emergency calls. The impacts of these defects have been experimentally validated across three U.S. carriers and two Taiwan carriers using commodity smartphones. Finally, we propose solutions and evaluate their effectiveness.
Yiwen Hu 0002, Min-Yue Chen, Haitian Yan, Chuan-Yi Cheng, Guan-Hua Tu, Chi-Yu Li 0001, Tian Xie 0001, Chunyi Peng 0001, Li Xiao 0001, Jiliang Tang
MobiCom6
2024 IMS is Not That Secure on Your 5G/4G Phones
abstract
IMS (IP Multimedia Subsystem) is vital for delivering IP-based multimedia services in mobile networks. Despite constant upgrades by 3GPP over the past two decades to support heterogeneous radio access networks (e.g., 4G LTE, 5G NR, and Wi-Fi) and enhance IMS security, the focus has primarily been on cellular infrastructure. Consequently, IMS security measures on mobile equipment (ME), such as smartphones, lag behind rapid technological advancements. Our study reveals that mandated IMS security measures on ME fail to keep pace, resulting in new vulnerabilities and attack vectors, including denial of service (DoS) across all networks, named SMS source spoofing, and covert communications over Video-over-IMS attacks. All vulnerabilities and proof-of-concept attacks have been experimentally validated in operational 5G/4G networks across various phone models and network operators. Finally, we propose and prototype standard-compliant remedies for these vulnerabilities.
Jingwen Shi, Sihan Wang 0002, Min-Yue Chen, Guan-Hua Tu, Tian Xie 0001, Man-Hsin Chen, Yiwen Hu 0002, Chi-Yu Li 0001, Chunyi Peng 0001
MobiCom8
2024 Practical Latency-Aware Scheduling for Low-Latency Elephant VR Flows in Wi-Fi Networks
abstract
Virtual reality (VR) applications are increasingly popular. With high-quality video streams and interactive content, they require both low-latency and high-bandwidth performance demands on the communication from the edge-based VR server to the VR headsets. Although most VR headsets are equipped with dedicated wired or wireless modules connected to the VR server, using common Wi-Fi networks to support them can be a promising trend due to convenience and low cost. However, current Wi-Fi Access Points (APs) cannot meet latency demands of low-latency elephant VR flows, especially in traffic congestion cases. We thus design a practical Wi-Fi scheduling solution, designated as LAST-PQ (Latency-Aware Scheduler with Two-level Priority Queueing), to support VR flows at the Wi-Fi AP. It monitors the runtime latency performance of VR flows while prioritizing scheduling for urgent flows, whose latency demands are at risk of violation. We implement LAST-PQ in Linux on a commodity Wi-Fi platform using an open-source Wi-Fi driver; it is compliant to the current Wi-Fi scheduling framework. The evaluation result shows that it can reduce latency by up to 79.89% in various congested scenarios; moreover, it consistently meets the latency demands of VR flows in cases of mobility at runtime.
Shao-Jung Lu, Wei-Xun Chen, Yu-Shao Su, Yu-Shou Chang, Yao-Wen Liu, Chi-Yu Li 0001, Guan-Hua Tu
PerCom6
2024 IPA-DASH: Intelligent Proactive Adaptation for DASH Video Streaming at 5G Network Edge
abstract
Edge computing has been determined as a key feature for achieving low-latency performance in 5G networks. It enables application servers to be deployed next to base stations, thus offering services without experiencing Internet delays or congestion. Thanks to the O-RAN (Open Radio Access Network) architecture, the edge server can obtain RAN information at run time and employ it to enhance the quality of edge-based services. In this work, we develop a proactive adaptation solution, designated as IPA-DASH (Intelligent Proactive Adaptation for Dynamic Adaptive Streaming over HTTP), for DASH video streaming services. By utilizing the radio access information for each UE (User Equipment), IPA-DASH applies deep reinforcement learning to estimate the best video quality at present, while enabling video segment reselection along with an in-band, low-overhead segment cancellation method. This allows IPA-DASH to proactively adapt video streaming before its quality suffers, in contrast to conventional video adaptation solutions that reactively adapt video streaming based solely on application-layer performance. These solutions have no access to radio access conditions, so the adaptation is triggered after the video quality degrades. We implement and evaluate IPA-DASH on both a simulator and an emulated 5G edge platform. The results demonstrate that IPA-DASH outperforms other video adaptation solutions, achieving gains of 1.1% to 55.6% in terms of average QoE (Quality of Experience) and reducing rebuffering time by 35.0% to 97.3%.
Shun-Ting Lei, Yu-An Chen, Ren-Cheng Chen, Chih-Chien Lo, Chi-Yu Li 0001
PIMRC5
2024 Transparent Third-Party Authentication With Application Mobility for 5G Mobile-Edge Computing
abstract
Mobile Edge Computing (MEC) is a key technology for supporting low latency applications close to the end user. Users can access application servers in MEC instead of routing to the Internet by passing through a core cellular network. Few security challenges arise as the traffic does not traverse through the core network, and these can be solved by providing authentication services in the MEC. However, authentication and application mobility issues arise in the case of multiple MECs where a user is mobile and needs continuous service from application servers, without needing to establish a new session and providing authentication information repeatedly to every new MEC the user connects with. In this work, we propose two solutions, a TC3A (Token-based Cookie transfer & 3rd-party Authentication) and a TS3A (Token-based State transfer & 3rd-party Authentication) for resolution of authentication and application mobility issues while achieving low latency. We conducted experiments on a testbed that had MECs deployed in a real-time cellular network (emulated via OpenAirInterface) and performed user handover between two MECs. The experimental results show that TC3A and TS3A successfully re-authenticate the users, without provision of login credentials with target MEC, while reducing the latency by approximately 49.76–59.72% as compared to simple login method. The TC3A and TS3A also eliminate the need of keeping multiple accounts for applications at different MECs and most importantly provide application service continuity, through state transfer during cross-system handover, which is not provided by a simple login method. TC3A provides the application service continuity without any loss of session state, which is suitable for applications that cannot afford state loss, and TS3A provides the same while reducing the latency by 47.05–51.25% as compared to TC3A, which is suitable for applications that require low latency.
Ying-Dar Lin, Chi-Yu Li 0001, Yuan-Cheng Lai
IEEE Trans. Netw. Serv. Manag.3
2024 Taming the Insecurity of Cellular Emergency Services (9-1-1): From Vulnerabilities to Secure Designs
abstract
Cellular networks, vital for delivering emergency services, enable mobile users to dial emergency calls (e.g., 9–1-1 in the U.S.), which are forwarded to public safety answer points (PSAPs). Regulatory requirements allow anonymous user equipment (UE) without a SIM card or valid mobile subscription to access these services. However, supporting emergency services for anonymous UEs introduces different operations, expanding the attack surface of cellular infrastructure. In this study, we explore the insecurity of cellular emergency services, identifying six security vulnerabilities. These vulnerabilities can be exploited for free data service attacks against carriers and data DoS/overcharge and denial of cellular emergency service (DoCES) attacks against mobile users. Experimental validation in networks of three major U.S. carriers and two major Taiwan carriers demonstrates the global impact of our findings. Finally, we propose and prototype standard-compliant remedies to mitigate these vulnerabilities.
Min-Yue Chen, Yiwen Hu 0002, Guan-Hua Tu, Chi-Yu Li 0001, Sihan Wang 0002, Jingwen Shi, Tian Xie 0001, Ren-Chieh Hsu, Li Xiao 0001, Chunyi Peng 0001, Zhaowei Tan, Songwu Lu
IEEE/ACM Trans. Netw.4
2024 Dissecting Operational Cellular IoT Service Security: Attacks and Defenses
abstract
More than 150 cellular networks worldwide have rolled out LTE-M (LTE-Machine Type Communication) and/or NB-IoT (Narrow Band Internet of Things) technologies to support massive IoT services such as smart metering and environmental monitoring. Such cellular IoT services share the existing cellular network architecture with non-IoT (e.g., smartphone) ones. When they are newly integrated into the cellular network, new security vulnerabilities may happen from imprudent integration. In this work, we explore the security vulnerabilities of the cellular IoT from both system-integrated and service-integrated aspects. We discover several vulnerabilities spanning cellular standard design defects, network operation slips, and IoT device implementation flaws. Threateningly, they allow an adversary to remotely identify IP addresses and phone numbers assigned to cellular IoT devices, interrupt their power saving services, and launch various attacks, including data/text spamming, battery draining, device hibernation against them. We validate these vulnerabilities over five major cellular IoT carriers in the U.S. and Taiwan using their certified cellular IoT devices. The attack evaluation result shows that the adversary can raise an IoT data bill by up to${\$}226$with less than 120 MB spam traffic, increase an IoT text bill at a rate of${\$}5$per second, and prevent an IoT device from entering/leaving power saving mode; moreover, cellular IoT devices may suffer from denial of IoT services. We finally propose, prototype, and evaluate recommended solutions.
Sihan Wang 0002, Tian Xie 0001, Min-Yue Chen, Guan-Hua Tu, Chi-Yu Li 0001, Po-Yi Chou, Fu-Cheng Hsieh, Yiwen Hu 0002, Li Xiao 0001, Chunyi Peng 0001
IEEE/ACM Trans. Netw.5
2024 Reliability Engineering in a Time of Rapidly Converging Technologies
abstract
The convergence of technologies is happening across various aspects, such as communication, computing, medicine, and transportation. The smartphone is a perfect example of convergence, packing features, such as a camera, GPS, artificial intelligence, and Internet connectivity into one sleek device. Autonomous driving is another good example. In a time of rapidly converging technologies, reliability engineering must take into account the potential for cyber threats, the need for cyber trust, the importance of cyber security, and the criticality of cyber resilience. In this way, reliability engineers can ensure the confidentiality, integrity, and availability of computer systems and networks in the face of evolving threats and changing technologies. In this article, we introduce the challenges and current progress of reliability engineering in emerging technologies, including practices and applications of cyber trust and security, AI-empowered autonomous driving systems, modern mobile networks, blockchains and distributed ledger technologies, prognostic and health management, integrated circuit and hardware, and enterprise cybersecurity and threat hunting.
Shiuh-Pyng Shieh, Jeffrey M. Voas, Phillip A. Laplante, Jason W. Rupe, Christian K. Hansen, Yu-Sung Wu, Yi-Ting Chen 0001, Chi-Yu Li 0001, Kai-Chiang Wu
IEEE Trans. Reliab.8
2023 Congestion-Avoidance Adaptation for Edge-based UAV Video Frame Delivery
abstract
Many critical UAV (Unmanned Aerial Vehicle) applications, such as military and infrastructure inspection, offload the detection of video frames captured at each UAV to an edge server, and then feedback next actions based on detection results to the UAV. Apparently, the response time, which is from the capture of a video frame to the receipt of the corresponding feedback at the UAV, needs to be as low as possible so that the UAV can be agile to take actions guided by the edge server. However, we experimentally discover that conventional video streaming methods that do not downgrade frame quality to hurt detection accuracy may lead to either long response time or very small processed FPS (Frame Per Second), which may cause missing information. We then propose a congestion-avoidance adaptation (CAA) method for the UAV video frame delivery to minimize the response time while maximizing the processed FPS. We prototype the CAA on a UAV platform; the evaluation result confirms its effectiveness by showing that it can keep response times low while maintaining high processed FPS.
Meng-Shou Wu, Tan Tai Phan, Ping-Kuan Kao, Chi-Yu Li 0001
GLOBECOM4
2023 MPKIX: Towards More Accountable and Secure Internet Application Services via Mobile Networked Systems
abstract
Nowadays, both Internet Application Service (IAS) providers and users face various security threats and legal issues. Due to the lack of reliable user information verification mechanisms, adversaries can abuse IASs to launch various cyberattacks, such as misinformation distributing and phishing, by using fake user accounts. IAS providers may thus inadvertently offer inappropriate content to restricted users, thereby suffering a serious risk of prosecution under local or international laws. Also, IAS users may suffer from nefarious ID theft attacks. In this paper, we proposed a novel security framework,${{\sf MPKIX}}$, designated as Mobile-assisted PKIX (Public-Key Infrastructure X.509).${{\sf MPKIX}}$secures both IAS providers and users by leveraging the broadly used PKIX services and mobile networked systems. It not only provides IAS providers with a reliable user verification mechanism while simultaneously enabling cross-IAS user privacy protection, but also largely mitigates the possibility of ID theft attacks and benefits other involved parties, such as cellular network operators and PKIX service providers. We further conduct a security analysis of${{\sf MPKIX}}$and implement an${{\sf MPKIX}}$prototype. The evaluation results based on the prototype confirm the effectiveness and efficiency of${{\sf MPKIX}}$with low overhead.
Tian Xie 0001, Sihan Wang 0002, Jingwen Shi, Guan-Hua Tu, Chi-Yu Li 0001
IEEE Trans. Mob. Comput.6
2023 Insecurity of Operational IMS Call Systems: Vulnerabilities, Attacks, and Countermeasures
abstract
IMS (IP Multimedia Subsystem) is an essential 4G/5G component to offer multimedia services. It is used worldwide to support two call services: VoLTE (Voice over LTE) and VoWiFi (Voice over WiFi). In this study, it is shown that the signaling and voice sessions of VoWiFi can both be hijacked by a malicious adversary. By hijacking the signaling session, s(he) gains the ability to make ghost calls to launch stealthy DoS (Denial of Service) or caller-ID spoofing attacks against specific cellular users. Such attacks can be carried out without any malware or network information, and require only the victim’s phone number to be known. It is shown that phones vulnerable to the call DoS attacks can be detected at run time by exploiting a vulnerability of cellular network infrastructures referred to as call information leakage, which is exposed based on a machine learning method. Especially, the call DoS attacks can prevent victims from receiving incoming calls for up to 99.0% time without user awareness. Moreover, by hijacking the voice session, an adversary can launch stealthy free data transfer attacks based on phone numbers alone rather than IP addresses. The identified vulnerabilities/attacks are validated in the operational 4G networks of four top-tier carriers across Asia and North America with seven phone brands. The study concludes by presenting a suite of solutions to address them.
Yu-Han Lu, Sandy H. Hsiao, Chi-Yu Li 0001, Yi-Chen Hsieh, Po-Yi Chou, Yao-Yu Li, Tian Xie 0001, Guan-Hua Tu
IEEE/ACM Trans. Netw.3
2022 Prioritized Traffic Shaping for Low-latency MEC Flows in MEC-enabled Cellular Networks
abstract
Multi-access edge computing (MEC) has been introduced as an enabler of low-latency performance in 4G/5G cellular networks. For the MEC-enabled cellular networks, several deployment options have been proposed by ETSI. One promising deployment option called Bump-in-the-wire does not require changes on the base station or the core network, so it has the advantage of easy deployment and low cost. However, the unchanged base station connecting to an MEC platform cannot differentiate MEC traffic from Internet traffic or prioritize it; its traffic congestion may thus cause the MEC traffic to suffer from high latency. In this work, we thus design a solution, designated PTS-MEC (Prioritized Traffic Shaping for MEC), to control the forwarding of downlink MEC/Internet traffic at the MEC and prioritize the MEC traffic based on a hierarchical MEC-prioritized fair service model. PTS-MEC alleviates the base station’s traffic congestion with a latency-aware service rate adaptor at run time by applying the service curve concept to delaying or/and skipping the Internet traffic. We prototype PTS-MEC on an open source MEC platform and evaluate it with congested cases. The evaluation result confirms the effectiveness of PTS-MEC; it can satisfy latency goals, e.g., 50 ms at the 90th percentile, within 3.70% error for MEC flows while fairly allocating remaining resource to non-MEC UEs.
Po-Hao Huang, Fu-Cheng Hsieh, Wen-Jen Hsieh, Chi-Yu Li 0001, Ying-Dar Lin
CCNC4
2022 UAV-FAP: User Fairness-Driven Access Point on UAV for Wi-Fi Networks
abstract
Unmanned aerial vehicle (UAV) has been an emerging technology used for various applications. Enabling wireless base station (e.g., Wi-Fi AP) on UAV can be one of promising UAV applications. In this work, we focus on a performance fairness issue on ground Wi-Fi users and aim to maximize the minimum throughput performance among them. To this end, we propose a solution, designated UAV-FAP (UAV with user Fairness-driven AP), to drive UAV-AP to reach a location that can offer max-min throughput performance. It employs a heuristic-based hierarchical search method to search for the target location efficiently. By conducting experiments on a real UAV-AP platform, we first study the issues of antenna pointing direction and vertical/horizontal UAV-AP placement, and then collect Wi-Fi throughput statistics for a trace-driven simulator in the evaluation. The evaluation result shows that UAV-FAP can outperform the default case, where the UAV-AP stays at the center of a serving area, by 2.0%-21.5% throughput gains; in some cases, it takes as small as only 7% of the moving distance needed by a fine-grained exhaustive search to reach target max-min locations.
Yung-Chuan Wu, Hong-Rong Chang, Meng-Shou Wu, Chi-Yu Li 0001, Kuochen Wang
CCNC4
2022 Uncovering insecure designs of cellular emergency services (911)
abstract
Cellular networks that offer ubiquitous connectivity have been the major medium for delivering emergency services. In the U.S., mobile users can dial an emergency call with 911 for emergency uses in cellular networks, and the call can be forwarded to public safety answer points (PSAPs), which deal with emergency service requests. According to regulatory authority requirements for the cellular emergency services, anonymous user equipment (UE), which does not have a SIM (Subscriber Identity Module) card or a valid mobile subscription, is allowed to access them. Such support of emergency services for anonymous UEs requires different operations from conventional cellular services, and can therefore increase the attack surface of the cellular infrastructure. In this work, we are thus motivated to study the insecurity of the cellular emergency services and then discover four security vulnerabilities from them. Threateningly, they can be exploited to launch not only free data service attacks against cellular carriers, but also data DoS/overcharge and denial of cellular emergency service (DoCES) attacks against mobile users. All vulnerabilities and attacks have been validated experimentally as practical security issues in the networks of three major U.S. carriers. We finally propose and prototype standard-compliant remedies to mitigate the vulnerabilities.
Yiwen Hu 0002, Min-Yue Chen, Guan-Hua Tu, Chi-Yu Li 0001, Sihan Wang 0002, Jingwen Shi, Tian Xie 0001, Li Xiao 0001, Chunyi Peng 0001, Zhaowei Tan, Songwu Lu
MobiCom4
2022 Modeling Control Delays for Edge-Enabled UAVs in Cellular Networks
abstract
Real-time control solutions for unmanned aerial vehicles (UAVs) have attracted great interest in recent years. Most existing control methods use Wi-Fi technology. While Wi-Fi is inexpensive and easy to use, it has only a limited transmission range. Thus, 4G/5G cellular networks have been proposed as an alternative enabling technology. This study focuses on the problem of improving the appropriateness of the control commands sent by the ground control station (GCS) to the UAV over the control and nonpayload communication (CNPC) link of the UAV through the cellular network. To satisfy the low-latency requirement of the CNPC link, multiaccess edge computing (MEC) technology is leveraged to collocate the GCS and base station. The effectiveness of the proposed edge-based approach is demonstrated by conducting experiments on two LTE platforms with different MEC deployment methods. An edge-enabled UAV control solution is proposed in which each end-to-end control delay in the UAV-GCS system is estimated based on the preceding delay such that the location of the UAV at the moment it receives the control command from the GCS can be predicted in advance and taken into consideration by the GCS when formulating an appropriate control decision. To this end, an analytical modeling method is proposed for estimating the expected error range of each control delay based on a bimodal distribution approximation of the empirical control delays observed at the UAV. Finally, an event-driven simulator is developed to confirm the accuracy of the analytical predictions of the control delay based on the expected error between consecutive delays.
Yu-Hsuan Wu, Chi-Yu Li 0001, Yi-Bing Lin, Kuochen Wang, Meng-Shou Wu
IEEE Internet Things J.2
2022 P4-TINS: P4-Driven Traffic Isolation for Network Slicing With Bandwidth Guarantee and Management
abstract
Network slicing is an essential technology for 5G mobile networks. It partitions network resource logically into multiple isolated slices, each of which can satisfy a suite of network requirements for one specific service. However, it cannot be fulfilled by the current SDN (Software-Defined Networks), since the conventional SDN data-plane technology, OpenFlow, is not flexible enough to offer fine-grained network resource control or queue/packet scheduling. It leads to many research studies developing corresponding solutions on programmable switches. In this work, we focus on the support of the bandwidth guarantee and management for network slices. Although several studies with the similar goal have been proposed, they do not consider interference among different flow types or use the built-in meter for easy deployment on COTS (Commercial Off-The-Shelf) P4 switches. To this end, we first conduct a case study to examine the interference cases. We then propose a solution, designated as P4-TINS (P4-driven Traffic Isolation for Network Slicing), to resolve the interference by isolating different types of traffic flows in priority queues and set the P4 switch’s bucket size based on the time granularity of its bandwidth management operation. It cannot only ensure the guaranteed bandwidth for each slice but also enable coexistent slices to fairly share residual bandwidth. We have confirmed its effectiveness experimentally based on our prototype over an ONOS (Open Network Operating System) controller and a COTS P4 switch.
Chi-Yu Li 0001, Chien-Chao Tseng, Min-Zhi Hu
IEEE Trans. Netw. Serv. Manag.2
2021 Security Threats from Bitcoin Wallet Smartphone Applications: Vulnerabilities, Attacks, and Countermeasures
abstract
Nowadays, Bitcoin is the most popular cryptocurrency. With the proliferation of smartphones and the high-speed mobile Internet, more and more users have started accessing their Bitcoin wallets on their smartphones. Users can download and install a variety of Bitcoin wallet applications (e.g., Coinbase, Luno, Bitcoin Wallet) on their smartphones and access their Bitcoin wallets anytime and anywhere. However, it is still unknown whether these Bitcoin wallet smartphone applications are secure or if they are new attack surfaces for adversaries to attack these application users. In this work, we explored the insecurity of the 10 most popular Bitcoin wallet smartphone applications and discovered three security vulnerabilities. By exploiting them, adversaries can launch various attacks including Bitcoin deanonymization, reflection and amplification spamming, and wallet fraud attacks. To address the identified security vulnerabilities, we developed a phone-side Bitcoin Security Rectifier to secure Bitcoin wallet smartphone application users. The developed rectifier does not require any modifications to current wallet applications and is compliant with Bitcoin standards.
Yiwen Hu 0002, Sihan Wang 0002, Guan-Hua Tu, Li Xiao 0001, Tian Xie 0001, Chi-Yu Li 0001
CODASPY7
2021 An Experience Driven Design for IEEE 802.11ac Rate Adaptation based on Reinforcement Learning
abstract
The IEEE 802.11ac supports gigabit speeds by extending 802.11n air-interface features and increases the number of rate options by more than two times. Enabling so many rate options can be a challenge to rate adaptation (RA) solutions. Particularly, they need to adapt rates to various fast-changing channels; they would suffer without scalability. In this work, we identify three limitations of current 802.11ac RAs on commodity network interface cards (NICs): no joint rate and bandwidth adaptation, lack of scalability, and no online learning capability. To address the limitations, we apply deep reinforcement learning (DRL) into designing a scalable, intelligent RA, designated as experience driven rate adaptation (EDRA). DRL enables the online learning capability of EDRA, which not only automatically identifies useful correlations between important factors and performance for the rate search, but also derives low-overhead avenues to approach highest-goodput (HG) rates by learning from experience. It can make EDRA scalable to timely locate HG rates among many rate options over time. We implement and evaluate EDRA using the Intel Wi-Fi driver and Google TensorFlow on Intel 802.11ac NICs. The evaluation result shows that EDRA can outperform the Intel and Linux default RAs by up to 821.4% and 242.8%, respectively, in various cases.
Syuan-Cheng Chen, Chi-Yu Li 0001, Chui-Hao Chiu
INFOCOM2
2021 Insecurity of operational cellular IoT service: new vulnerabilities, attacks, and countermeasures
abstract
More than 150 cellular networks worldwide have rolled out massive IoT services such as smart metering and environmental monitoring. Such cellular IoT services share the existing cellular network architecture with non-IoT (e.g., smartphone) ones. When they are newly integrated into the cellular network, new security vulnerabilities may happen from imprudent integration. In this work, we explore the security vulnerabilities of the cellular IoT from both system-integrated and service-integrated aspects. We discover five vulnerabilities spanning cellular standard design defects, network operation slips, and IoT device implementation flaws. Threateningly, they allow an adversary to remotely identify IP addresses and phone numbers assigned to cellular IoT devices and launch data/text spamming attacks against them. We experimentally validate these vulnerabilities and attacks with three major U.S. IoT carriers. The attack evaluation result shows that the adversary can raise an IoT data bill by up to $226 with less than 120 MB spam traffic and increase an IoT text bill at a rate of $5 per second; moreover, cellular IoT devices may suffer from denial of IoT services. We finally propose, prototype, and evaluate recommended solutions.
Sihan Wang 0002, Guan-Hua Tu, Tian Xie 0001, Chi-Yu Li 0001, Po-Yi Chou, Fu-Cheng Hsieh, Yiwen Hu 0002, Li Xiao 0001, Chunyi Peng 0001
MobiCom5
2021 How Can IoT Services Pose New Security Threats In Operational Cellular Networks?
abstract
Carriers are rolling out Internet of Things (IoT) services including various IoT devices and use scenarios. Compared with conventional non-IoT devices such as smartphones and tablets, IoT devices have limited network capabilities (e.g., low rates) and specific use scenarios (e.g., inside vehicles only). These specialized use scenarios lead to carries often offering cheaper device access fees for IoT devices. However, the aforementioned disparity of service charging between IoT and non-IoT devices may lead to security issues. In this work, we conduct the first empirical security study on cellular IoT service charging over two major US carriers and make three major contributions. First, we discover four security vulnerabilities and analyze their root causes, which help us identify two significant security threats, IoT masquerading and IoT use scenario abuse. Second, we devise three proof-of-concept attacks and assess their real-world impact. We determine that they can be exploited to allow adversaries to pay 43.75-80.00 percent less for cellular data services. Third, we analyze the challenges in addressing these vulnerabilities and develop an anti-abuse solution to mitigate attack incentives. The solution is standard-compliant and can be used immediately in practice. Our prototype and evaluation confirm its effectiveness.
Tian Xie 0001, Guan-Hua Tu, Chi-Yu Li 0001, Chunyi Peng 0001
IEEE Trans. Mob. Comput.3
2021 The Untold Secrets of WiFi-Calling Services: Vulnerabilities, Attacks, and Countermeasures
abstract
Since 2016, all of four major U.S. operators have rolled out Wi-Fi calling services. They enable mobile users to place cellular calls over Wi-Fi networks based on the 3GPP IMS technology. Compared with conventional cellular voice solutions, the major difference lies in that their traffic traverses untrusted Wi-Fi networks and the Internet. This exposure to insecure networks can cause the Wi-Fi calling users to suffer from security threats. Its security mechanisms are similar to the VoLTE, because both of them are supported by the IMS. They include SIM-based security, 3GPP AKA, IPSec, etc. However, are they sufficient to secure Wi-Fi calling services? Unfortunately, our study yields a negative answer. We conduct the first security study on the operational Wi-Fi calling services in three major U.S. operators networks using commodity devices. We disclose that current Wi-Fi calling security is not bullet-proof and uncover three vulnerabilities. By exploiting the vulnerabilities, we devise two proof-of-concept attacks: telephony harassment or denial of voice service and user privacy leakage; both of them can bypass the existing security defenses. We have confirmed their feasibility using real-world experiments, as well as assessed their potential damages and proposed a solution to address all identified vulnerabilities.
Tian Xie 0001, Guan-Hua Tu, Bangjie Yin, Chi-Yu Li 0001, Chunyi Peng 0001, Mi Zhang 0002, Hui Liu 0031, Xiaoming Liu 0002
IEEE Trans. Mob. Comput.4
2021 Privacy Leakage and Protection of InputConnection Interface in Android
Chi-Yu Li 0001, Hsin-Yi Wang, Wei-Ching Wang, Chun-Ying Huang
IEEE Trans. Netw. Serv. Manag.1
2020 WBF-PS: WiGig Beam Fingerprinting for UAV Positioning System in GPS-denied Environments
abstract
Unmanned aerial vehicles (UAVs) are being investigated to substitute for labor in many indoor applications, e.g., asset tracking and surveillance, where the global positioning system (GPS) is not available. Also, emerging autonomous UAVs are expected to land in indoor parking aprons automatically. Such GPS-denied environments require alternative non-GPS positioning methods. Although there have been some vision-based solutions for UAVs, they perform poorly in the scenes with bad illumination conditions or estimate only relative locations but not global positions. Other common indoor localization methods do not cover UAV factors, such as low power and flying behaviors. To this end, we propose a practical non-GPS positioning system for UAVs, named WBF-PS (WiGig Beam Fingerprinting based Positioning System), using low-power, off-the-shelf WiGig devices. We formulate a 3-dimensional beam fingerprint for the positioning by leveraging the diversity of available transmitter/receiver beams and the link quality. To augment the positioning accuracy, we not only use a weighted k-nearest neighbors algorithm to overcome partial fingerprint inaccuracy but also apply the particle filtering technique into considering the UAV motion. We prototype and evaluate WBF-PS on a UAV platform. The result shows that the positioning errors at the 90th percentile are below 1 m in various cases.
Pei-Yuan Hong, Chi-Yu Li 0001, Hong-Rong Chang, YuanHao Hsueh, Kuochen Wang
INFOCOM2
2020 Ghost calls from operational 4G call systems: IMS vulnerability, call DoS attack, and countermeasure
abstract
IMS (IP Multimedia Subsystem) is an essential framework for providing 4G/5G multimedia services. It has been deployed worldwide to support two call services: VoLTE (Voice over LTE) and VoWi-Fi (Voice over Wi-Fi). VoWi-Fi enables telephony calls over the Wi-Fi network to complement VoLTE. In this work, we uncover that the VoWi-Fi signaling session can be hijacked to maliciously manipulate the IMS call operation. An adversary can easily make ghost calls to launch a stealthy call DoS (Denial of Service) attack against specific cellular users. Only phone numbers, but not any malware or network information, are required from the victims. This sophisticated attack harnesses a design defect of the IMS call state machine, but not simply flooding or a crash trigger. To stealthily detect attackable phones at run time, we exploit a vulnerability of the 4G network infrastructure, call information leakage, which we explore using machine learning. We validate these vulnerabilities in operational 4G networks of 4 top-tier carriers across Asia and North America countries with 7 phone brands. Our result shows that the call DoS attack can prevent the victims from receiving incoming calls up to 99.0% time without user awareness. We finally propose and evaluate recommended solutions.
Yu-Han Lu, Chi-Yu Li 0001, Yao-Yu Li, Sandy H. Hsiao, Tian Xie 0001, Guan-Hua Tu, Wei-Xun Chen
MobiCom2
2020 SecWIR: securing smart home IoT communications via wi-fi routers with embedded intelligence
abstract
Smart home Wi-Fi IoT devices are prevalent nowadays and potentially bring significant improvements to daily life. However, they pose an attractive target for adversaries seeking to launch attacks. Since the secure IoT communications are the foundation of secure IoT devices, this study commences by examining the extent to which mainstream security protocols are supported by 40 of the best selling Wi-Fi smart home IoT devices on the Amazon platform. It is shown that 29 of these devices have either no security protocols deployed, or have problematic security protocol implementations. Seemingly, these vulnerabilities can be easily fixed by installing security patches. However, many IoT devices lack the requisite software/hardware resources to do so. To address this problem, the present study proposes a SecWIR (Secure Wi-Fi IoT communication Router) framework designed for implementation on top of the users' existing home Wi-Fi routers to provide IoT devices with a secure IoT communication capability. However, it is way challenging for SecWIR to function effectively on all home Wi-Fi routers since some routers are resource-constrained. Thus, several novel techniques for resolving this implementation issue are additionally proposed. The experimental results show that SecWIR performs well on a variety of commercial off-the-shelf (COTS) Wi-Fi routers at the expense of only a small reduction in the non-IoT data service throughput (less than 8%), and small increases in the CPU usage (4.5%~7%), RAM usage (1.9 MB~2.2 MB), and the IoT device access delay (24 ms~154 ms) while securing 250 IoT devices.
Guan-Hua Tu, Chi-Yu Li 0001, Tian Xie 0001, Mi Zhang 0002
MobiSys3
2019 Mobility Support for Networks on Trains Using Commercial Off-the-shelf Routers
abstract
The following topics are dealt with: telecommunication traffic; software defined networking; learning (artificial intelligence); resource allocation; virtualisation; quality of service; cloud computing; computer network security; Internet; mobile computing.
Sandy H. Hsiao, Hong-Rong Chang, Yu-Han Lu, Chi-Yu Li 0001
APNOMS4
2018 V2PSense: Enabling Cellular-Based V2P Collision Warning Service through Mobile Sensing
abstract
The C-V2X (Cellular Vehicle-to-Everything) technology is developing in full swing. One of its mainstream services can be the Vehicle-to- Pedestrian (V2P) service. It can protect pedestrians who are mostly vulnerable on the road. In this work, we seek to enable a V2P service that can identify which pedestrians may be nearby a dangerous driving event and then notify them of warning messages. To enable this V2P service, there are two major challenges. First, a low-latency V2P message transport is required for this infrastructure-based service. Second, the pedestrian's smartphone requires an energy- efficient outdoor positioning method instead of power-hungry GPS due to its limited battery life. We thus propose a novel solution, V2PSense, which trades off positioning precision for energy savings while achieving low-latency message transport with LTE high-priority bearers. It does a coarse-grained positioning by leveraging intermittent GPS information and mobile sensing data, which includes step count from the pedometer and cellular signal strength changes. Though the V2PSense's positioning is not as precise as the GPS, it can still ensure that all the pedestrians nearby dangerous spots can be notified. Our results show that it can achieve the average precision ratio 92.6% for estimating where the pedestrian is while saving 20.8% energy, compared with the GPS always-on case.
Chi-Yu Li 0001, Giovanni Salinas, Po-Hao Huang, Guan-Hua Tu, Guo-Huang Hsu, Tien-Yuan Hsieh
ICC1
2018 How Voice Service Threatens Cellular-Connected IoT Devices in the Operational 4G LTE Networks
abstract
LTE networks are rolling out cellular Internet-of- Things (IoT) services. Cellular-connected IoT devices are becoming increasingly popular and the number is forecasted to grow almost fourfold from 2015 to 2021. Since they share the same infrastructure with non-IoT devices such as smartphones, we may expect no big differences between them in terms of voice/data service accounting/charging (e.g., paying for what you get) and security risks. However, our study shows that cellular IoT users may pay more than what they get, as well as are vulnerable to voice signaling spams and thus suffer from an overcharging attack which leads to financial loss or denial of service. We validate our proof-of- concept attack in a major U.S. cellular network operator which takes higher than 35% market share. We finally propose a solution to address the identified security vulnerabilities.
Tian Xie 0001, Chi-Yu Li 0001, Jiliang Tang, Guan-Hua Tu
ICC2
2018 A Fast Converging Mechanism for Load Balancing among SDN Multiple Controllers
abstract
Load balancing among multiple controllers is a critical issue in the software-defined networking (SDN), since traffic dynamics prevent control-plane loads from being evenly distributed among controllers. Load imbalance may cause some controllers to be overloaded while the other controllers are still underutilized. Though there have been several proposed solutions, theydo not consider the convergence time of load balancing. We thus propose a fast-converging loadbalancing (FCLB) mechanism that seeks to achieve fast convergence for balancing loads (i.e., assigning switches) among the SDN controllers. Fast convergence can rapidly release controllersfrom being overloaded, thereby shortly recovering network performance and preventing some unanticipated results (e.g., controller crash). Searching for the optimal solution from a large set of switch-controller combinations can lead to a large delay, which can aggravate negative impacts from overloading. We thus leverage the genetic algorithm to lind a near-optimal solutionOur simulation results show that FCLB has at least 20.7% faster convergence time than the other mechanisms while achieving better load balancing performance.
Chi-Yu Li 0001, Kuochen Wang
ISCC2
2017 ReSDN: A lightweight solution for data-plane state recovery in software-defined networks
abstract
Software-Defined Networking (SDN) benefits from the development flexibility of control-plane applications (SDN-Apps), which allows third parties to make contributions. Such flexibility may expose SDN networks to security threats, since SDN-Apps may be malicious or prone to implementation bugs. These buggy/malicious SDN-Apps may contaminate the data plane with abnormal network actions, which may not be prevented before they are committed to the data plane. This contamination may lead to network crash or poor network performance. We thus present ReSDN, a lightweight solution for data-plane state recovery, to recover an SDN data plane from a contaminated state. It requires neither switch modification nor the intervention of SDN-Apps, both of which current recovery solutions rely on. It leverages the concept of FP-tree (Frequent Pattern tree) to maintain the dependency of event transactions and network actions to achieve correct recovery. Our evaluations validate the viability of our ReSDN design, and show that it can recover more than twice as fast as the other type of recovery approach, rollback recovery.
Chi-Yu Li 0001, Kuochen Wang
ICC2
2017 Enabling seamless WiGig/WiFi handovers in tri-band wireless systems
abstract
WiGig enables wireless multi-gigabit communication over 60GHz band. However, its usage scenarios may be constrained by two major limitations: line-of-sight propagation and very short transmission range. We seek to boost the WiGig's usability by using WiFi to complement its limitations in tri-band (2.4/5/60GHz) wireless systems. Our goal is to let a tri-band client have multimedia services at the WiGig's very high speed without any hassle. When the WiGig link is down or performs bad, not only can the client temporarily handover to WiFi without service interruption, but its ongoing multimedia services can also adapt to the WiFi's slower link. Though the IEEE 802.11ad standard has proposed an FST (Fast Session Transfer) mechanism to support handover operations at the link layer, it does not satisfy our goal due to two reasons. First, it does not specify when to perform WiGig/WiFi handovers. Second, it is not application-aware to achieve the service adaptation. To this end, we design and implement an application-aware, seamless WiGig/WiFi handover solution above the network layer. It ensures timely handover trigger for the WiGig's abrupt link interruption, keeps service continuity during handovers, and adapts multimedia service qualities to different WiGig/WiFi links. Our demo confirms its viability. We show that a video streaming service at the client is not interrupted during WiGig/WiFi handovers, which are triggered by mobility or the WiGig's signal blockage, but smoothly switches between different resolutions according to different links.
Yao-Yu Li, Chi-Yu Li 0001, Chia-Jui Yeh, Kuochen Wang
ICNP2
2016 New Security Threats Caused by IMS-based SMS Service in 4G LTE Networks
abstract
SMS (Short Messaging Service) is a text messaging service for mobile users to exchange short text messages. It is also widely used to provide SMS-powered services (e.g., mobile banking). With the rapid deployment of all-IP 4G mobile networks, the underlying technology of SMS evolves from the legacy circuit-switched network to the IMS (IP Multimedia Subsystem) system over packet-switched network. In this work, we study the insecurity of the IMS-based SMS. We uncover its security vulnerabilities and exploit them to devise four SMS attacks: silent SMS abuse, SMS spoofing, SMS client DoS, and SMS spamming. We further discover that those SMS threats can propagate towards SMS-powered services, thereby leading to three malicious attacks: social network account hijacking, unauthorized donation, and unauthorized subscription. Our analysis reveals that the problems stem from the loose security regulations among mobile phones, carrier networks, and SMS-powered services. We finally propose remedies to the identified security issues.
Guan-Hua Tu, Chi-Yu Li 0001, Chunyi Peng 0001, Yuanjie Li, Songwu Lu
CCS2
2016 An Energy Efficiency Perspective on Rate Adaptation for 802.11n NIC
abstract
Rate adaptation (RA) has been traditionally used to achieve high goodput. In this work, we design RA for 802.11n NICs from an energy-efficiency perspective. We show that current MIMO RA algorithms are not energy efficient for NICs despite ensuring high throughput. The fundamental problem is that, the high-throughput setting is not equivalent to the energy-efficient one. Marginal throughput gain may be realized at high energy cost. We then propose EERA and EERA+, two energy-based RA schemes that trade off goodput for energy savings at NICs. EERA applies multidimensional ternary search and simultaneous pruning to speed up its runtime convergence in single-client operations, and uses fair airtime sharing to handle multiple-client operations. EERA+ further searches for multiple, staged rates to yield more energy savings over EERA. Our experiments have confirmed their effectiveness in various scenarios.
Chi-Yu Li 0001, Chunyi Peng 0001, Peng Cheng 0005, Songwu Lu, Xinbing Wang, Fengyuan Ren, Tao Wang 0004
IEEE Trans. Mob. Comput.1
2016 Detecting Problematic Control-Plane Protocol Interactions in Mobile Networks
abstract
The control-plane protocols in 3G/4G mobile networks communicate with each other, and provide a rich set of control functions, such as radio resource control, mobility support, connectivity management, to name a few. Despite their significance, the problem of verifying protocol correctness remains largely unaddressed. In this paper, we examine control-plane protocol interactions in mobile networks. We propose CNetVerifier, a two-phase signaling diagnosis tool to detect problematic interactions in both design and practice. CNetVerifier first performs protocol screening based on 3GPP standards via domain-specific model checking, and then conducts phone-based empirical validation in operational 3G/4G networks. With CNetVerifier, we have uncovered seven types of troublesome interactions, along three dimensions of cross (protocol) layers, cross (circuit-switched and packet-switched) domains, and cross (3G and 4G) systems. Some are caused by necessary yet problematic cooperation (i.e., protocol interactions are needed but they misbehave), whereas others are due to independent yet unnecessary coupled operations (i.e., protocols interactions are not required but actually coupled). These instances span both design defects in 3GPP standards and operational slips by carriers and vendors. They all result in performance penalties or functional incorrectness. We deduce root causes, present empirical results, propose solutions, and summarize learned lessons.
Guan-Hua Tu, Yuanjie Li, Chunyi Peng 0001, Chi-Yu Li 0001, Songwu Lu
IEEE/ACM Trans. Netw.4
2015 Insecurity of Voice Solution VoLTE in LTE Mobile Networks
abstract
VoLTE (Voice-over-LTE) is the designated voice solution to the LTE mobile network, and its worldwide deployment is underway. It reshapes call services from the traditional circuit-switched telecom telephony to the packet-switched Internet VoIP. In this work, we conduct the first study on VoLTE security before its full rollout. We discover several vulnerabilities in both its control-plane and data-plane functions, which can be exploited to disrupt both data and voice in operational networks. In particular, we find that the adversary can easily gain free data access, shut down continuing data access, or subdue an ongoing call, etc. We validate these proof-of-concept attacks using commodity smartphones (rooted and unrooted) in two Tier-1 US mobile carriers. Our analysis reveals that, the problems stem from both the device and the network. The device OS and chipset fail to prohibit non-VoLTE apps from accessing and injecting packets into VoLTE control and data planes. The network infrastructure also lacks proper access control and runtime check.
Chi-Yu Li 0001, Guan-Hua Tu, Chunyi Peng 0001, Zengwen Yuan, Yuanjie Li, Songwu Lu, Xinbing Wang
CCS1
2015 Latency-aware rate adaptation in 802.11n home networks
abstract
Latency-sensitive applications (e.g., wireless gaming and TV remote play) are increasingly popular in home WiFi networks. Such millisecond-level latency requirements call for new fine-grained approaches at the link layer. In this paper, we show that current solutions work well for throughput but not for latency due to the long tail of the packet delay distribution. We thus propose LLRA, a new latency-aware rate adaptation scheme that reduces the tail latency for delay-sensitive applications. LLRA takes concerted design in rate control, frame aggregation scheduling and software/hardware retransmission dispatching. Our implementation and evaluation confirm the viability of LLRA in 802.11n home networks.
Chi-Yu Li 0001, Chunyi Peng 0001, Songwu Lu, Xinbing Wang, Ranveer Chandra
INFOCOM1
2014 Real Threats to Your Data Bills: Security Loopholes and Defenses in Mobile Data Charging
abstract
Secure mobile data charging (MDC) is critical to cellular network operations. It must charge the right user for the right volume that (s)he authorizes to consume (i.e., requirements of authentication, authorization, and accounting (AAA)). In this work, we conduct security analysis of the MDC system in cellular networks. We find that all three can be breached in both design and practice, and identify three concrete vulnerabilities: authentication bypass, authorization fraud and accounting volume inaccuracy. The root causes lie in technology fundamentals of cellular networks and the Internet IP design, as well as imprudent implementations. We devise three showcase attacks to demonstrate that, even simple attacks can easily penetrate the operational 3G/4G cellular networks. We further propose and evaluate defense solutions.
Chunyi Peng 0001, Chi-Yu Li 0001, Guan-Hua Tu, Songwu Lu
CCS2
2014 Control-plane protocol interactions in cellular networks
abstract
Control-plane protocols are complex in cellular networks. They communicate with one another along three dimensions of cross layers, cross (circuit-switched and packet-switched) domains, and cross (3G and 4G) systems. In this work, we propose signaling diagnosis tools and uncover six instances of problematic interactions. Such control-plane issues span both design defects in the 3GPP standards and operational slips by carriers. They are more damaging than data-plane failures. In the worst-case scenario, users may be out of service in 4G, or get stuck in 3G. We deduce root causes, propose solutions, and summarize learned lessons.
Guan-Hua Tu, Yuanjie Li, Chunyi Peng 0001, Chi-Yu Li 0001, Songwu Lu
SIGCOMM4
2013 CMES: Collaborative Energy Save for MIMO 802.11 wireless networks
abstract
This work experimentally studies the energy consumption of multiple-antenna MIMO 802.11 devices. Our measurements reveal an increase in power consumption and speed with the number of antennas. State of the art proposals have limitations to save energy in MIMO 802.11 networks. First, they focus on either maximizing speed or minimizing power consumption. Second, they only seek to minimize energy for the receiver side of mobile devices. As a result, they present limitations to utilize MIMO speed gains and to save energy in MIMO 802.11 infrastructure. To this end, we design Collaborative MIMO Energy Save (CMES), which seeks to identify the transmitter-receiver most energy efficient antenna setting, at runtime. Our experiments with commodity MIMO 802.11n testbeds confirm that CMES can provide energy savings in real scenarios.
Ioannis Pefkianakis, Chi-Yu Li 0001, Chunyi Peng 0001, Suk-Bok Lee, Songwu Lu
ICNP2
2013 How voice calls affect data in operational LTE networks
abstract
Both voice and data are indispensable services in current cellular networks. In this work, we study the inter-play of voice and data in operational LTE networks. We assess how the popular CSFB-based voice service affects the IP-based data sessions in 4G LTE networks, and visa versa. Our findings reveal that the interference between them is mutual. On one hand, voice calls may incur throughput drop, lost 4G connectivity, and application aborts for data sessions. One the other hand, users may miss incoming voice calls when turning on data access. The fundamental problem is that, signaling and control for circuit-switched voice and packet-switched data have dependency and coupling effect via the LTE phone client. We further propose fixes to the identified issues.
Guan-Hua Tu, Chunyi Peng 0001, Chi-Yu Li 0001, Songwu Lu
MobiCom4
2013 Accounting for roaming users on mobile data access: issues and root causes
abstract
In this paper, we study how mobility affects mobile data accounting, which records the usage volume for each roaming user. We find out that, current 2G/3G/4G systems have well-tested mobility support solutions and generally work well. However, under certain biased, less common yet possible scenarios, accounting gap between the operator's log and the user's observation indeed exists. The gap can be as large as 69.6% in our road tests. We further discover that the root causes are diversified. In addition to the no-signal case reported in the prior work [23], they also include handoffs, as well as insufficient coverage of hybrid 2G/3G/4G systems. Inter-system handoffs (that migrate user devices between radio access technologies of 2G, 3G, and 4G) may incur non-negligible accounting discrepancy.
Guan-Hua Tu, Chunyi Peng 0001, Chi-Yu Li 0001, Tao Wang 0004, Songwu Lu
MobiSys3
2012 Mobile data charging: new attacks and countermeasures
abstract
3G/4G cellular networks adopt usage-based charging. Mobile users are billed based on the traffic volume when accessing data service. In this work, we assess both this metered accounting architecture and application-specific charging policies by operators from the security perspective. We have identified loopholes in both, and discovered two effective attacks exploiting the loopholes. The "toll-free-data-access-attack" enables the attacker to access any data service for free. The "stealth-spam-attack" incurs any large traffic volume to the victim, while the victim may not be even aware of such spam traffic.Our experiments on two operational 3G networks have confirmed the feasibility and simplicity of such attacks. We also propose defense remedies.
Chunyi Peng 0001, Chi-Yu Li 0001, Guan-Hua Tu, Songwu Lu, Lixia Zhang 0001
CCS2
2012 A multimedia service migration protocol for single user multiple devices
abstract
This paper describes a new protocol SMP, which supports multimedia transfer for single-user, multiple-device scenarios. Through its novel naming and control/data plane designs, SMP is able to retain the current client and server protocol operations while placing new functions at the proxy. Our initial evaluation has confirmed its viability.
Chi-Yu Li 0001, Ioannis Pefkianakis, Bojie Li, Chenghui Peng, Songwu Lu
ICC1
2012 Energy-based rate adaptation for 802.11n
abstract
Rate adaptation (RA) has been used to achieve high goodput. In this work, we explore to use RA for energy efficiency in 802.11n NICs. We show that current MIMO RA algorithms are not energy efficient for NICs despite ensuring high throughput. The fundamental problem is that, the high-throughput setting is not equivalent to the energy-efficient one. Marginal throughput gain may be realized at high energy cost. We propose EERA, an energy-based RA solution that trades off goodput for energy savings at NICs. Our experiments have confirmed its energy savings at NICs while keeping the cost at the device level and across clients acceptable.
Chi-Yu Li 0001, Chunyi Peng 0001, Songwu Lu, Xinbing Wang
MobiCom1
2012 Can we pay for what we get in 3G data access?
abstract
Data-plan subscribers are charged based on the used traffic volume in 3G/4G cellular networks. This usage-based charging system has been operational and received general success. In this work, we conduct experiments to critically assess both this usage-based accounting architecture and application-specific charging policies by operators. Our evaluation compares the network-recorded volume with the delivered traffic at the end device. We have found that, both generally work in common scenarios but may go wrong in the extreme cases: We are charged for what we never get, and we can get what we want for free. In one extreme case, we are charged for at least three hours and 450MB or more data despite receiving no single bit. In another extreme case, we are able to transfer 200MB or any amount we specify for free. The root causes lie in lack of both coordination between the charging system and the end device, and prudent policy enforcement by certain operators. We propose immediate fixes and discuss possible future directions.
Chunyi Peng 0001, Guan-Hua Tu, Chi-Yu Li 0001, Songwu Lu
MobiCom3
2011 What is wrong/right with IEEE 802.11n Spatial Multiplexing Power Save feature?
abstract
The IEEE 802.11n standard has proposed a new Spatial Multiplexing Power Save (SMPS) feature, which allows for a station to retain one active receive chain, to mitigate MIMO circuitry power consumption. But does it work in all cases? Our experiments reveal that SMPS may not always save power compared with multiple active chains at the receiver. Even when it does, it may be proven more energy hungry. In this work, we seek to uncover the “good”, the “bad” and the “ugly” of SMPS using real experiments. We further devise a MIMO Receiver Energy Save (MRES) algorithm, which seeks to identify and set the most energy-efficient receive chain setting, by using a novel, low-overhead sampling scheme. Our prototype experiments show that, MRES outperforms SMPS with energy savings up to 37%.
Ioannis Pefkianakis, Chi-Yu Li 0001, Songwu Lu
ICNP2
2011 Release-time-based multi-channel MAC protocol for wireless mesh networks
Andy An-Kai Jeng, Rong-Hong Jan, Chi-Yu Li 0001, Chien Chen
Comput. Networks3