EDBT 2026 Demo / reviewers in the wild / expert
Bin Yuan 0002
dblp:64/1812-2
· DBLP profile ↗
33ranked-venue papers
14as first author
24since 2021 · last 2026
0000-0002-5365-904XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 5 first-author · 13 since 2021Computer networks · 7 · 4 first-author · 4 since 2021Systems, architecture and hardware · 4 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From Intention to Practice: Towards Systematic Validation of NIDS Rule Enforcement
Haoyu Chen 0004, Biang Xu, Jingyao Zhou, Bin Yuan 0002, Qiankun Zhang 0001, Deqing Zou, Hai Jin 0001 |
NSDI | 5 |
| 2026 | DMCGuard: risky perils and fine-grained control on IoT multiple device management channels
Bin Yuan 0002, Kaimin Zheng, Yan Jia 0009, Jiajun Ren, Kunming Wang 0003, Shengjiu Shi, Deqing Zou, Hai Jin 0001 |
Frontiers Comput. Sci. | 1 |
| 2026 | Forseti: A Decentralized Permission Transfer Framework for IoT LeasingabstractThe widespread use of IoT devices in the accommodation and hospitality sectors has created demand for temporary device-permission sharing and transfer. Prior work has largely focused on security issues in device permission sharing, with far less attention devoted to device permission transfer. However, inappropriate access control management during device permission transfer can also lead to violations of the users' expectations of control over their devices. For example, a malicious host retaining or regaining access to a camera after its permission has been transferred to a tenant. In this paper, we present the first systematic study on understanding and enhancing the security of device permission transfer in IoT leasing. To this end, we propose Forseti, a new authorization framework that leverages zero-knowledge proof and a decentralized ledger to ensure that the rights of both hosts and tenants are not violated. Our evaluation demonstrates that Forseti is effective, efficient, scalable, and compatible with existing IoT platforms. Bin Yuan 0002, Weizhong Qiang, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Understanding the Unfairness in Network QuantizationabstractNetwork quantization, one of the most widely studied model compression methods, effectively quantizes a floating-point model to obtain a fixed-point one with negligible accuracy loss. Although great success was achieved in reducing the model size, it may exacerbate the unfairness in model accuracy across different groups of datasets. This paper considers two widely used algorithms: Post-Training Quantization (PTQ) and Quantization-Aware Training (QAT), with an attempt to understand how they cause this critical issue. Theoretical analysis with empirical verifications reveals two responsible factors, as well as how they influence a metric of fairness in depth. A comparison between PTQ and QAT is then made, explaining an observation that QAT behaves even worse than PTQ in fairness, although it often preserves a higher accuracy at lower bit-widths in quantization. Finally, the paper finds out that several simple data augmentation methods can be adopted to alleviate the disparate impacts of quantization, based on a further observation that class imbalance produces distinct values of the aforementioned factors among different attribute classes. We experiment on either imbalanced (UTK-Face and FER2013) or balanced (CIFAR-10 and MNIST) datasets using ResNet and VGG models for empirical evaluation. Wenjun Miao, Qiankun Zhang 0001, Bin Yuan 0002, Jing Wang 0036, Shenghao Liu, Xianjun Deng |
ICML | 5 |
| 2025 | DiMa: Understanding the Hardness of Online Matching Problems via Diffusion ModelsabstractWe explore the potential of \emph{AI-enhanced combinatorial optimization theory}, taking online bipartite matching (OBM) as a case study.
In the theoretical study of OBM, the \emph{hardness} corresponds to a performance \emph{upper bound} of a specific online algorithm or any possible online algorithms.
Typically, these upper bounds derive from challenging instances meticulously designed by theoretical computer scientists.
Zhang et al. (ICML 2024) recently provide an example demonstrating how reinforcement learning techniques enhance the hardness result of a specific OBM model.
Their attempt is inspiring but preliminary.
It is unclear whether their methods can be applied to other OBM problems with similar breakthroughs.
This paper takes a further step by introducing DiMa, a unified and novel framework that aims at understanding the hardness of OBM problems based on denoising diffusion probabilistic models (DDPMs).
DiMa models the process of generating hard instances as denoising steps, and optimizes them by a novel reinforcement learning algorithm, named \emph{shortcut policy gradient} (SPG).
We first examine DiMa on the classic OBM problem by reproducing its known hardest input instance in literature.
Further, we apply DiMa to two well-known variants of OBM, for which the exact hardness remains an open problem, and we successfully improve their theoretical state-of-the-art upper bounds. Aocheng Shen, Qiankun Zhang 0001, Bin Yuan 0002, Jing Wang 0036, Shenghao Liu, Xianjun Deng |
ICML | 5 |
| 2025 | SoK: Automated Vulnerability Repair: Methods, Tools, and Assessments
Zhen Li 0027, Kedie Shu, Shenghua Guan, Deqing Zou, Shouhuai Xu, Bin Yuan 0002, Hai Jin 0001 |
USENIX Security Symposium | 7 |
| 2024 | Membership Inference Attacks against Vision Transformers: Mosaic MixUp Training to the DefenseabstractVision transformers (ViTs) have demonstrated great success in various fundamental CV tasks, mainly benefiting from their self-attention-based transformer architectures, and the paradigm of pre-training followed by fine-tuning. However, such advantages may lead to significant data privacy risks, such as membership inference attacks (MIAs), which remain unclear. This paper presents the first comprehensive study on MIAs and corresponding defenses against ViTs. Our first contribution is a rollout-attention-based MIA method (RAMIA), based on an experimental observation that the attention, more precisely the rollout attention, behaves disproportionately for members and non-members. We evaluate RAMIA on the standard ViT architecture proposed by Google (ICLR 2021), achieving high accuracy, precision, and recall performance. Further, inspired by another experimental observation on a strong connection between positional embeddings (PEs) and attentions, we propose a novel framework for training ViTs, named Mosaic MixUp Training (MMUT), as a defense against RAMIA. Intuitively, MMUT mixes up private images and public ones at a patch level, and mosaics the corresponding PEs with a global learnable mosaic embedding. Our empirical results show MMUT achieves a much better accuracy-privacy trade-off than some common defense mechanisms. Extensive experiments are conducted to rigorously evaluate both RAMIA and MMUT. Qiankun Zhang 0001, Bin Yuan 0002, Bingqian Du |
CCS | 4 |
| 2024 | MQTTactic: Security Analysis and Verification for Logic Flaws in MQTT ImplementationsabstractIoT messaging protocols are critical to connecting users and IoT devices. Among all the protocols, the Message Queuing and Telemetry Transport (MQTT) is arguably the most widely used. Mainstream IoT platforms leverage MQTT brokers, server side implementation of MQTT, to enable and mediate user-device communication (e.g., the transmission of control commands). There are over 70 open-source MQTT brokers, which have been widely adopted in production. Any security defects in those open-source MQTT brokers easily get into many vendors’ IoT deployments with amplified impacts, inevitably endangering the security of IoT applications and millions of users. We report the first systematic security analysis of open-source MQTT brokers in the wild. To enable the analysis, we designed and developed MQTTactic, a semi-automatic tool that can formally verify MQTT broker implementations based on generated security properties. MQTTactic is based on static code analysis, formal modeling, and automated model checking (with off-the-shelf model checker Spin). In designing MQTTactic, we characterize and address key technical challenges. MQTTactic currently focuses on authorization-related properties, and discovered 7 novel, zero-day flaws practically enabling serious, unauthorized access. We reported all flaws to related parties, who acknowledged the issues and have been taking actions to fix them. Our thorough evaluation shows that MQTTactic is effective and practical. Bin Yuan 0002, Zhanxiang Song, Yan Jia 0009, Deqing Zou, Hai Jin 0001, Luyi Xing |
SP | 1 |
| 2024 | Leakage of Authorization-Data in IoT Device Sharing: New Attacks and CountermeasureabstractDevice sharing among users is a common functionality in today's IoT clouds. Supporting device sharing are the delegation methods proposed by different IoT clouds, which we find are heterogeneous and ad-hoc IoT clouds use various data (e.g., device ID, product ID, and access token) as authorization certificates. In this paper, we report the first systematic study on how the authorization-data are managed in IoT device sharing. Our study brought to light the security risks in today's IoT authorization-data management, identifying 6 authorization-data leakage flaws. To mitigate such flaws, we propose an approach to hide the authorization-data from the delegatee (a.k.a., the user authorized to access the devices) without disrupting the device sharing services. We propose SecHARE, an automated tool to patch the vulnerable IoT clouds. We applied SecHARE to 3 popular open-source IoT clouds. Results have shown the compatibility, effectiveness, and efficiency of SecHARE. We have made SecHARE publicly available Bin Yuan 0002, Maogen Yang, Qunjinming Chen, Zhanxiang Song, Zhen Li 0027, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Toward Automated Attack Discovery in SDN Controllers Through Formal VerificationabstractSoftware-defined Network (SDN), presented to be a novel architecture of network because of its separation of data plane and control plane, brings centralization and extensibility to network management as well as new attacks that exploit the flexibility of SDN. OpenFlow, which is the protocol that is applied by the majority of SDN, leads to the widely used definition of the communication between the controller and the switch resulting in similar implementations regardless of different vendors. In this paper, we focus on the mechanisms of packet processing and topology discovery and their fundamental weaknesses caused by general implementations or device limitations. Despite the common vulnerabilities, the universal standard mechanisms of basic function in SDN also enlighten us to present an automated attack discovery method based on the formal verification with a generic model of SDN system. We describe the abstraction of the SDN components, their key functions, and communications along with the malicious operations that could be executed by malicious hosts and malicious switches and translate them into a formal model of the SDN system. The formal verification carried on with the assertion representing the security properties derived from the common vulnerabilities of the SDN system reports the potential attack paths each of which shows an attack process. Our evaluation shows that our method can discover feasible attack paths efficiently and effectively, with 23 attacks being identified, among which 2 are new. We further demonstrate the practicality of the 2 new attacks. Bin Yuan 0002, Chi Zhang 0117, Jiajun Ren, Qunjinming Chen, Biang Xu, Qiankun Zhang 0001, Zhen Li 0027, Deqing Zou, Fan Zhang 0024, Hai Jin 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | Lost along the Way: Understanding and Mitigating Path-Misresolution Threats to Container IsolationabstractFilesystem isolation enforced by today's container technology has been found to be less effective in the presence of host-container interactions increasingly utilized by container tools. This weakened isolation has led to a type of path misresolution (Pamir) vulnerabilities, which have been considered to be highly risky and continuously reported over the years. In this paper, we present the first systematic study on the Pamir risk and the existing fixes to related vulnerabilities. Our research reveals that in spite of significant efforts being made to patch vulnerable container tools and address the risk, the Pamir vulnerabilities continue to be discovered, including a new vulnerability (CVE-2023-0778) we rediscovered from patched software. A key insight of our study is that the Pamir risk is inherently hard to prevent at the level of container tools, due to their heavy reliance on third-party components. While security inspections should be applied to all components to mediate host-container interactions, third-party component developers tend to believe that container tools should perform security checks before invoking their components, and are therefore reluctant to patch their code with the container-specific protection. Moreover, due to the large number of components today's container tools depend on, re-implementing all of them is impractical. Zhi Li 0048, Weijie Liu 0004, XiaoFeng Wang 0001, Bin Yuan 0002, Hongliang Tian, Hai Jin 0001, Shoumeng Yan |
CCS | 4 |
| 2023 | IoT Anomaly Detection Via Device Interaction GraphabstractWith diverse functionalities and advanced platform applications, Internet of Things (IoT) devices extensively interact with each other, and these interactions govern the legitimate device state transitions. At the same time, attackers can easily manipulate these devices, and it is difficult to detect covert device control. In this work, we propose the device interaction graph, which uses device interactions to profile normal device behavior. We also formalize two types of device anomalies, and present an anomaly detection system CausalIoT. It can automatically construct the graph and validate runtime device events. For any violation of interaction executions, CausalIoT further checks whether it can trigger unexpected interaction executions and tracks the affected devices.1 Compared with existing methods, CausalIoT achieves the highest detection accuracy for abnormal device state transitions (95.2% precision and 96.8% recall). Moreover, we are the first to detect unexpected interaction executions, and CausalIoT successfully reports 91.9% anomaly chains on real-world testbeds. Zhuohua Li 0001, Mingshen Sun, Bin Yuan 0002, John C. S. Lui |
DSN | 4 |
| 2023 | Enhancing Deep Learning-based Vulnerability Detection by Building Behavior Graph ModelabstractSoftware vulnerabilities have posed huge threats to the cyberspace security, and there is an increasing demand for automated vulnerability detection (VD). In recent years, deep learning-based (DL-based) vulnerability detection systems have been proposed for the purpose of automatic feature extraction from source code. Although these methods can achieve ideal performance on synthetic datasets, the accuracy drops a lot when detecting real-world vulnerability datasets. Moreover, these approaches limit their scopes within a single function, being not able to leverage the information between functions. In this paper, we attempt to extract the function's abstract behaviors, figure out the relationships between functions, and use this global information to assist DL-based VD to achieve higher performance. To this end, we build a Behavior Graph Model and use it to design a novel framework, namely VulBG. To examine the ability of our constructed Behavior Graph Model, we choose several existing DL-based VD models (e.g., TextCNN, ASTGRU, CodeBERT, Devign, and VulCNN) as our baseline models and conduct evaluations on two real-world datasets: the balanced$\text{FFMpeg}+\text{Qemu}$dataset and the unbalanced$\text{Chrome} +\text{Debian}$dataset. Experimental results indicate that VulBG enables all baseline models to detect more real vulnerabilities, thus improving the overall detection performance. Bin Yuan 0002, Yilin Fang, Yueming Wu 0001, Deqing Zou, Zhen Li 0027, Zhi Li 0048, Hai Jin 0001 |
ICSE | 1 |
| 2023 | Fine-Grained Code Clone Detection with Block-Based Splitting of Abstract Syntax TreeabstractCode clone detection aims to find similar code fragments and gains increasing importance in the field of software engineering. There are several types of techniques for detecting code clones. Text-based or token-based code clone detectors are scalable and efficient but lack consideration of syntax, thus resulting in poor performance in detecting syntactic code clones. Although some tree-based methods have been proposed to detect syntactic or semantic code clones with decent performance, they are mostly time-consuming and lack scalability. In addition, these detection methods can not realize fine-grained code clone detection. They are unable to distinguish the concrete code blocks that are cloned. In this paper, we design Tamer, a scalable and fine-grained tree-based syntactic code clone detector. Specifically, we propose a novel method to transform the complex abstract syntax tree into simple subtrees. It can accelerate the process of detection and implement the fine-grained analysis of clone pairs to locate the concrete clone parts of the code. To examine the detection performance and scalability of Tamer, we evaluate it on a widely used dataset BigCloneBench. Experimental results show that Tamer outperforms ten state-of-the-art code clone detection tools (i.e., CCAligner, SourcererCC, Siamese, NIL, NiCad, LVMapper, Deckard, Yang2018, CCFinder, and CloneWorks). Tiancheng Hu, Zijing Xu, Yilin Fang, Yueming Wu 0001, Bin Yuan 0002, Deqing Zou, Hai Jin 0001 |
ISSTA | 5 |
| 2023 | On the Security of Smart Home Systems: A Survey
Bin Yuan 0002, Jun Wan 0006, Deqing Zou, Hai Jin 0001 |
J. Comput. Sci. Technol. | 1 |
| 2023 | SmartPatch: Verifying the Authenticity of the Trigger-Event in the IoT PlatformabstractEmerging IoT clouds are playing a more important role in modern lives, enabling users/developers to program applications to make better use of smart devices. However, preliminary research has shown IoT cloud vulnerabilities could expose IoT users to security risks. To better understand the problem, we studied the SmartThings cloud, one of the most popular IoT cloud platforms that support user-defined device automation (SmartApps). Specifically, we found new vulnerabilities in SmartThings that allow attackers to fake events to trigger the SmartApps to operate devices (e.g., open a lock). Exploiting such vulnerabilities, we successfully faked 7 different types of events, which impact 138 (out of 187) SmartThings’ official open-sourced SmartApps. To defeat such attacks, we propose an authenticity-verification-based scheme to deny fake events. Moreover, we designed a tool,SmartPatch, to help users secure their SmartThings systems. In specific,SmartPatchautomatically patches the vulnerable SmartApps and Device Handlers (input) and outputs the flawless programs, which are ready for users to deploy in their SmartThings systems. We have madeSmartPatchpublicly available. With the help ofSmartPatch, we patched all the vulnerable SmartThings’ official open-sourced programs (146 SmartApps and 321 Device Handlers). Experiments have shown the compatibility, effectiveness, and efficiency of our proposed approach. Bin Yuan 0002, Maogen Yang, Luyi Xing, Xuchang Wang, Deqing Zou, Hai Jin 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | StateDiver: Testing Deep Packet Inspection Systems with State-Discrepancy GuidanceabstractDeep Packet Inspection (DPI) systems are essential for securing modern networks (e.g., blocking or logging abnormal network connections). However, DPI systems are known to be vulnerable in their implementations, which could be exploited for evasion attacks. Due to the critical role DPI systems play, many efforts have been made to detect vulnerabilities in the DPI systems through manual inspection, symbolic execution, and fuzzing, which suffer from either poor scalability, path explosion, or inappropriate feedback. In this paper, based on our observation that a DPI system usually reaches an abnormal internal state before a forbidden packet passes through it, we propose a fuzzing framework that prioritizes inputs/mutations which could trigger the DPI system’s abnormal internal states. Further, to avoid deep understanding of the DPI systems under inspection (e.g., to identify the abnormal states), we feed one pair of inputs to multiple DPI systems and check whether the state changes of these DPI systems are consistent — an inconsistent internal state change/transference in one of the DPI systems indicates a new abnormal state is reached in the corresponding DPI system. Naturally, inputs that trigger new abnormal states are preferentially selected for mutations to generate new inputs. Following this idea, we develop StateDiver, the first fuzzing framework that uses the state discrepancy between different DPI systems as feedback to find more bypassing strategies. We make StateDiver publicly available online. With the help of StateDiver, we tested 3 famous open-source DPI systems (Snort, Snort++, and Suricata) and discovered 16 bypass strategies (8 new and 8 previously known). We have reported all the vulnerabilities to the vendors and received one CVE by the time of paper writing. We also compared StateDiver with Geneva, the state-of-the-art fuzzing tool for detecting DPI bugs. Results showed that StateDiver outperformed Geneva at the number and speed of finding vulnerabilities, indicating the ability of StateDiver to detect strategies bypassing DPI systems effectively. Zhechang Zhang, Bin Yuan 0002, Kehan Yang, Deqing Zou, Hai Jin 0001 |
ACSAC | 2 |
| 2022 | P-Verifier: Understanding and Mitigating Security Risks in Cloud-based IoT Access PoliciesabstractModern IoT device manufacturers are taking advantage of the managed Platform-as-a-Service (PaaS) and Infrastructure-as-a-Service (IaaS) IoT clouds (e.g., AWS IoT, Azure IoT) for secure and convenient IoT development/deployment. The IoT access control is achieved by manufacturer-specified, cloud-enforced IoT access policies (cloud-standard JSON documents, called IoT Policies) stating which users can access which IoT devices/resources under what constraints. In this paper, we performed a systematic study on the security of cloud-based IoT access policies on modern PaaS/IaaS IoT clouds. Our research shows that the complexity in the IoT semantics and enforcement logic of the policies leaves tremendous space for device manufacturers to program a flawed IoT access policy, introducing convoluted logic flaws which are non-trivial to reason about. In addition to challenges/mistakes in the design space, it is astonishing to find that mainstream device manufacturers also generally make critical mistakes in deploying IoT Policies thanks to the flexibility offered by PaaS/IaaS clouds and the lack of standard practices for doing so. Our assessment of 36 device manufacturers and 310 open-source IoT projects highlights the pervasiveness and seriousness of the problems, which once exploited, can have serious impacts on IoT users' security, safety, and privacy. To help manufacturers identify and easily fix IoT Policy flaws, we introduce P-Verifier, a formal verification tool that can automatically verify cloud-based IoT Policies. With evaluated high effectiveness and low performance overhead, P-Verifier will contribute to elevating security assurance in modern IoT deployments and access control. We responsibly reported all findings to affected vendors and fixes were deployed or on the way. Ze Jin, Luyi Xing, Yiwei Fang, Yan Jia 0009, Bin Yuan 0002, Qixu Liu |
CCS | 5 |
| 2022 | SAND: semi-automated adaptive network defense via programmable rule generation and deployment
Haoyu Chen 0004, Deqing Zou, Hai Jin 0001, Shouhuai Xu, Bin Yuan 0002 |
Sci. China Inf. Sci. | 5 |
| 2022 | Effective network intrusion detection via representation learning: A Denoising AutoEncoder approach
Ivandro Ortet Lopes, Deqing Zou, Ihsan H. Abdulqadder, Francis A. Ruambo, Bin Yuan 0002, Hai Jin 0001 |
Comput. Commun. | 5 |
| 2021 | Who's In Control? On Security Risks of Disjointed IoT Device Management ChannelsabstractAn IoT device today can be managed through different channels, e.g., by its device manufacturer's app, or third-party channels such as Apple's Home app, or a smart speaker. Supporting each channel is a management framework integrated in the device and provided by different parties. For example, a device that integrates Apple HomeKit framework can be managed by Apple Home app. We call the management framework of this kind, including all its device- and cloud-side components, a device management channel (DMC). 4 third-party DMCs are widely integrated in today's IoT devices along with the device manufacturer's own DMC: HomeKit, Zigbee/Z-Wave compatible DMC, and smart-speaker Seamless DMC. Each of these DMCs is a standalone system that has full mandate on the device; however, if their security policies and control are not aligned, consequences can be serious, allowing a malicious user to utilize one DMC to bypass the security control imposed by the device owner on another DMC. We call such a problem Chaotic Device Management (Codema). Yan Jia 0009, Bin Yuan 0002, Luyi Xing, Dongfang Zhao 0010, Yifan Zhang 0010, XiaoFeng Wang 0001, Yijing Liu 0007, Kaimin Zheng, Peyton Crnjak, Yuqing Zhang 0001, Deqing Zou, Hai Jin 0001 |
CCS | 2 |
| 2021 | Automatically derived stateful network functions including non-field attributesabstractThe modern network consists of thousands of network devices from different suppliers that perform distinct code-pendent functions, such as routing, switching, modifying header fields, and access control across physical and virtual networks. Because of the network complexity, the network is prone to a wide range of errors, such as false-positive configuration, software errors, or unexpected interactions across protocols. These errors can lead to loops, sub-optimal routing, path leaks, black holes, and access control violations that make services unavailable, vulnerable to exploitation, or prone to attacks (e.g., DDoS attacks). To mitigate these problems, network operators deploy many different stateful network functions, like firewalls, NATs, load balancers, and intrusion-prevention boxes. They have become an important part of networks today, so it is critical to verify that these network functions are the same as expected deployments. All static network verification tools are meant to rigorously check network software or configuration for bugs before deployment. They usually use handwritten models or limited derivation models that are error-prone and ignore the fact that even the same type of network functions (from different vendors) still have different implementation details. In this paper, we propose a tool that can automatically synthesize more realistic and high-fidelity models that include stateful network functions with non-field attributes. We design an inferring algorithm, implement the transformation between data packages and symbolic packages, and obtain a finite state machine that can accurately express the actions of black-box network functions for a given configuration. Bin Yuan 0002, Shengyao Sun, Xianjun Deng, Deqing Zou, Haoyu Chen 0004, Shenghui Li, Hai Jin 0001 |
TrustCom | 1 |
| 2021 | DSEOM: A Framework for Dynamic Security Evaluation and Optimization of MTD in Container-Based CloudabstractDue to the lightweight features, the combination of container technology and microservice architecture makes container-based cloud environment more efficient and agile than VM-based cloud environment. However, it also greatly amplifies the dynamism and complexity of the cloud environment and increases the uncertainty of security issues in the system concurrently. In this case, the effectiveness of defense mechanisms with fixed strategies would fluctuate as the updates occur in cloud environment. We refer this problem as effectiveness drift problem of defense mechanisms, which is particularly acute in the proactive defense mechanisms, such as moving target defense (MTD). To tackle this problem, we present DSEOM, a framework that can automatically perceive updates of container-based cloud environment, rapidly evaluate the effectiveness change of MTD and dynamically optimize MTD strategies. Specifically, we establish a multi-dimensional attack graphs model to formalize various complex attack scenarios. Combining with this model, we introduce the concept of betweenness centrality to effectively evaluate and optimize the implementation strategies of MTD. In addition, we present a series of security and performance metrics to quantify the effectiveness of MTD strategies in DSEOM. And we conduct extensive experiments to illustrate the existence of the effectiveness drift problem and demonstrate the usability and scalability of DSEOM. Hai Jin 0001, Zhi Li 0048, Deqing Zou, Bin Yuan 0002 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | Detecting Malicious Switches for a Secure Software-defined Tactile InternetabstractThe rapid development of the Internet of Things has led to demand for high-speed data transformation. Serving this purpose is the Tactile Internet, which facilitates data transfer in extra-low latency. In particular, a Tactile Internet based on software-defined networking (SDN) has been broadly deployed because of the proven benefits of SDN in flexible and programmable network management. However, the vulnerabilities of SDN also threaten the security of the Tactile Internet. Specifically, an SDN controller relies on the network status (provided by the underlying switches) to make network decisions, e.g., calculating a routing path to deliver data in the Tactile Internet. Hence, the attackers can compromise the switches to jeopardize the SDN and further attack Tactile Internet systems. For example, an attacker can compromise switches to launch distributed denial-of-service attacks to overwhelm the SDN controller, which will disrupt all the applications in the Tactile Internet. In pursuit of a more secure Tactile Internet, the problem of abnormal SDN switches in the Tactile Internet is analyzed in this article, including the cause of abnormal switches and their influences on different network layers. Then we propose an approach that leverages the messages sent by all switches to identify abnormal switches, which adopts a linear structure to store historical messages at a relatively low cost. By mapping each flow message to the flow establishment model, our method can effectively identify malicious SDN switches in the Tactile Internet and thus enhance its security. Bin Yuan 0002, Chen Lin 0006, Deqing Zou, Laurence T. Yang, Hai Jin 0001 |
ACM Trans. Internet Techn. | 1 |
| 2020 | Shattered Chain of Trust: Understanding Security Risks in Cross-Cloud IoT Access Delegation
Bin Yuan 0002, Yan Jia 0009, Luyi Xing, Dongfang Zhao 0010, XiaoFeng Wang 0001, Deqing Zou, Hai Jin 0001, Yuqing Zhang 0001 |
USENIX Security Symposium | 1 |
| 2020 | HostWatcher: Protecting hosts in cloud data centers through software-defined networking
Bin Yuan 0002, Deqing Zou, Hai Jin 0001, Shui Yu 0001, Laurence T. Yang |
Future Gener. Comput. Syst. | 1 |
| 2020 | Secure Data Transportation With Software-Defined Networking and k-n Secret Sharing for High-Confidence IoT ServicesabstractInternet of Things (IoT) has become a critical infrastructure in smart city services. Unlike traditional network nodes, most of the current IoT devices are constrained with limited capabilities. Moreover, frequent changes in the network status (e.g., nodes turns into the sleep mode to save battery) make it even more difficult to set up a stable, secure transmission among smart city IoT devices. On the one hand, these weaknesses make the IoT more vulnerable to attacks, such as data eavesdropping, which can monitor, tamper, and obtain the transporting data. On the other hand, the high-confidence smart city service strongly relies on the security of data transporting among the IoT devices, e.g., data being tempered would reduce the reliability of smart city services and data being monitored or stolen would infringe the privacy of smart city services. Toward high-confidence smart city IoT services, we proposed an approach to secure the data transportation among the smart city IoT devices, which combines a k-n secret-sharing mechanism and software-defined networking (SDN) technique to securely transport IoT data. Specifically, the data are transported by multiple routes calculated by the SDN controller adaptively. Data safety is guaranteed by the all-or-nothing feature of the k-n secret-sharing mechanism. Two SDN-based transmission strategies, which leverage the SDN's advantages on network management, and scheduling, are applied to overcome the challenges of the unstable network state in IoT. Extensive experiments conducted from many aspects show that the proposed approach can remarkably reduce the attack success rate with reasonable and acceptable overhead. Bin Yuan 0002, Chen Lin 0006, Deqing Zou, Laurence T. Yang, Hai Jin 0001, Chunming Rong |
IEEE Internet Things J. | 1 |
| 2020 | Exploring New Opportunities to Defeat Low-Rate DDoS Attack in Container-Based Cloud EnvironmentabstractDDoS attacks are rampant in cloud environments and continually evolve into more sophisticated and intelligent modalities, such as low-rate DDoS attacks. But meanwhile, the cloud environment is also developing in constant. Now container technology and microservice architecture are widely applied in cloud environment and compose container-based cloud environment. Comparing with traditional cloud environments, the container-based cloud environment is more lightweight in virtualization and more flexible in scaling service. Naturally, a question that arises is whether these new features of container-based cloud environment will bring new possibilities to defeat DDoS attacks. In this paper, we establish a mathematical model based on queueing theory to analyze the strengths and weaknesses of the container-based cloud environment in defeating low-rate DDoS attack. Based on this, we propose a dynamic DDoS mitigation strategy, which can dynamically regulate the number of container instances serving for different users and coordinate the resource allocation for these instances to maximize the quality of service. And extensive simulations and testbed-based experiments demonstrate our strategy can make the limited system resources be utilized sufficiently to maintain the quality of service acceptable and defeat DDoS attack effectively in the container-based cloud environment. Zhi Li 0048, Hai Jin 0001, Deqing Zou, Bin Yuan 0002 |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2019 | A domain-divided configurable security model for cloud computing-based telecommunication services
Jinan Shen, Deqing Zou, Hai Jin 0001, Bin Yuan 0002, Weiqi Dai |
J. Supercomput. | 4 |
| 2019 | Defending Against Flow Table Overloading Attack in Software-Defined NetworksabstractThe Software-Defined Network (SDN) is a new and promising network architecture. At the same time, SDN will surely become a new target of cyber attackers. In this paper, we point out one critical vulnerability in SDNs, the size of flow table, which is most likely to be attacked. Due to the expensive and power-hungry features of Ternary Content Addressable Memory (TCAM), a flow table usually has a limited size, which can be easily disabled by a flow table overloading attack (a transformed DDoS attack). To provide a security service in SDN, we proposed a QoS-aware mitigation strategy, namely, peer support strategy, which integrates the available idle flow table resource of the whole SDN system to mitigate such an attack on a single switch of the system. We established a practical mathematical model to represent the studied system, and conducted a thorough analysis for the system in various circumstances. Based on our analysis, we found that the proposed strategy can effectively defeat the flow table overloading attacks. Extensive simulations and testbed-based experiments solidly support our claims. Moreover, our work also shed light on the implementation of SDN networks against possible brute-force attacks. Bin Yuan 0002, Deqing Zou, Shui Yu 0001, Hai Jin 0001, Weizhong Qiang, Jinan Shen |
IEEE Trans. Serv. Comput. | 1 |
| 2018 | Enhanced Attack Aware Security Provisioning Scheme in SDN/NFV Enabled over 5G NetworkabstractSoftware Defined Network (SDN) and Network Function Virtualization (NFV) are essential technologies that support next generation 5G networks. Security provisioning in 5G network is major issue due to involvement of numerous users. To provide security against major attacks in SDN and NFV enabled 5G network, in this paper an enhanced attack aware security provisioning scheme is proposed. In this work, security is provided by following process: (i) Initial Authentication process, (ii) Classification of packets, and (iii) Switch migration process. Initial authentication is performed at Access Point (AP) for each user by Secure ID based Authentication (SIA) scheme. The suspected packets are detected in controller and classified at Virtual Network Function (VNF). For packet classification, the optimal packet features are selected using Genetic Algorithm with Correlation (GAC) based feature selection algorithm. We have proposed a Radial Basis Function with Extreme Learning Machine (RBF-ELM) classifier. Then, the malicious packets are dropped at VNF and normal packets are redirected to destination address through controller. To mitigate flow table overloading attack, we have presented an Enhanced Artificial Bee Colony (EABC) algorithm in controller. Experimental result shows that our proposed security provisioning scheme shows better performance in terms of delay, amount of redirected packets, detection accuracy, packet transmission rate and packet loss ratio. Ihsan H. Abdulqadder, Deqing Zou, Israa T. Aziz, Bin Yuan 0002 |
ICCCN | 4 |
| 2018 | Validating User Flows to Protect Software Defined Network EnvironmentsabstractSoftware Defined Network is a promising network paradigm which has led to several security threats in SDN applications that involve user flows, switches, and controllers in the network. Threats as spoofing, tampering, information disclosure, Denial of Service, flow table overloading, and so on have been addressed by many researchers. In this paper, we present novel SDN design to solve three security threats: flow table overloading is solved by constructing a star topology-based architecture, unsupervised hashing method mitigates link spoofing attack, and fuzzy classifier combined with L1-ELM running on a neural network for isolating anomaly packets from normal packets. For effective flow migration Discrete-Time Finite-State Markov Chain model is applied. Extensive simulations using OMNeT++ demonstrate the performance of our proposed approach, which is better at preserving holding time than are other state-of-the-art works from the literature. Ihsan H. Abdulqadder, Deqing Zou, Israa T. Aziz, Bin Yuan 0002 |
Secur. Commun. Networks | 4 |
| 2018 | A Practical Byzantine-Based Approach for Faulty Switch Tolerance in Software-Defined NetworksabstractOver the past few years, software-defined networking (SDN) has stimulated worldwide interests in both academia and industry for its proven benefits. However, the reliability of SDN has become a significant barrier in adopting it. Many efforts have been made to enhance the reliability of SDNs. However, the research all assume a benign data plane, and overlook the fundamental question: what if the switches provide tainted network state information (controller's inputs) to the controller? To obtain a global view and produce networking decisions, SDN controllers must collect detailed and up-to-date network state information from the switches. Therefore, tainted inputs can easily disrupt the correctness of controller and reduce the reliability of SDN. In this paper, we argue that faulty switches can easily taint the controller's inputs in SDN, which would further mislead the controller. We investigate possible consequences of the existence of faulty switches with thorough analyses and practical examples. Aiming at enhancing the reliability of SDNs, we design and implement a prototype system that leverages Byzantine model to automatically tolerate faulty switches. Extensive experiments show that the proposed system can guarantee the correctness of the controller's inputs (specifically, flow statistics information) even when faulty switches exist with trivial overheads. Bin Yuan 0002, Hai Jin 0001, Deqing Zou, Laurence T. Yang, Shui Yu 0001 |
IEEE Trans. Netw. Serv. Manag. | 1 |