EDBT 2026 Demo / reviewers in the wild / expert
Sammy Chan
dblp:68/4423
· DBLP profile ↗
123ranked-venue papers
4as first author
53since 2021 · last 2026
0000-0002-8524-229XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 80 · 4 first-author · 34 since 2021Security and privacy · 15 · 10 since 2021Artificial intelligence and machine learning · 9 · 8 since 2021Applied, interdisciplinary, general and emerging computing · 7Systems, architecture and hardware · 5Graphics, computer vision, multimedia, augmented reality and games · 4Databases, data management, data science and information retrieval · 2 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CMSM: Cross-modal semantic matching for lightweight IDS in the IoV
Zhendong Wang 0002, Xiping Zhou, Huamao Xie, Dahai Li, Daojing He, Sammy Chan |
Comput. Networks | 6 |
| 2026 | Federated learning based on two-stage knowledge distillation for intrusion detection in industrial IoT
Renqiang Zhou, Zhendong Wang 0002, Shuxin Yang, Daojing He, Sammy Chan |
Expert Syst. Appl. | 5 |
| 2026 | ACRM: An Adaptive Cluster Radius Multihop Routing Protocol With Direction Awareness for Large-Scale WSNsabstractAs the scale of wireless sensor networks (WSNs) continues to expand, challenges such as excessive network energy consumption and load imbalance have become increasingly severe. Existing non-uniform clustering protocols rely on fixed parameters and local information, lack the ability to dynamically perceive global energy differences, and are thus difficult to adapt to the dynamic changes of large-scale networks for balancing energy consumption and load. To address this issue, this paper proposes an adaptive cluster radius multi-hop routing protocol (ACRM) suitable for large-scale WSNs. The protocol provides a decision-making basis for the adjustment of nodes’ personalized competition radii and auction-based cluster head selection through an energy disparity factor quantified based on the Gini coefficient. On this basis, cluster head selection is modeled as a static game with incomplete information. Through an auction mechanism, cluster head seats are allocated according to the principle of maximizing bid prices, and a price decay strategy is introduced to prevent overloading of low-energy nodes. In the routing phase, intra-cluster routing employs hierarchical decision-making to select a subset of nodes for multi-hop communication to reduce energy consumption; while inter-cluster routing establishes multi-hop paths based on a direction-aware scoring mechanism that integrates node direction and energy, effectively avoiding path detours and reverse transmissions. Additionally, unlike existing non-uniform clustering protocols, ACRM effectively addresses the issues of cluster head overload near the base station and excessive energy consumption from frequent clustering through directly connected node offloading and adaptive periodic reconfiguration. Simulation results show that in a 500m×500m network scenario, the network stability period of ACRM reaches 636 rounds, which is over 100% higher than that of protocols such as LEACH, LEACH-OR, EEUC, and DEBUC, approximately 61.8% higher than PUAG, and 18.4% higher than UCRTD; significant improvements are also observed in the overall network lifetime and the number of data packets received by the base station. Zhendong Wang 0002, Silong Cao, Shuxin Yang, Daojing He, Sammy Chan |
IEEE Internet Things J. | 5 |
| 2026 | PPTD: A Path Profiling-Based Threat Detection Method Toward Deployed Smart ContractsabstractSmart contracts have been the target of attackers (e.g., identifying and exploiting vulnerabilities). Existing countermeasures for detecting threats in smart contracts include symbolic execution, formal verification, and fuzzing, most of which only target specific known threats. However, such approaches may not be effective in detecting unknown/unseen threats (e.g., those without predefined vulnerability patterns). Building on the principles of smart contract threats and the immutability property, we propose a path profiling-based threat detection (PPTD) approach. To achieve accurate tracking of cyclic and acyclic paths, PPTD combines the profiling all paths (PAP) algorithm with the efficient path profiling (EPP) algorithm to record contract execution paths. This incurs lower gas overhead while effectively detecting and preventing threats. PPTD obtains legal paths and achieves data flow level detection through fuzzer, and automatically protects vulnerable smart contracts from threats, avoiding manual modification of vulnerable codes. Specifically, our approach is also designed to detect threats and prevent attacks after the contract is deployed, as demonstrated in our evaluations. Daojing He, Sammy Chan, Kim-Kwang Raymond Choo |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Exploiting Semantics of Special Characters to Strengthen Passwords
Daojing He, Zhiyong Liu 0003, Sammy Chan, Kim-Kwang Raymond Choo |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | The Impact of Digit Semantic Patterns on Password SecurityabstractContinuously preventing weak password attacks is one of the most important initiatives to secure IoT systems. Password strength meters can guide users to create secure passwords, but in our investigation, we found that current password strength meters in mainstream IoT systems overestimate the strength of passwords with digit segments, leading users to choose passwords they thought were secure but are actually not. Therefore, we conduct a more in-depth and comprehensive study on the semantic characteristics of digit segments in passwords than ever before. We obtained unpublished high-frequency digit semantic patterns through semantic extraction methods and improved the PCFG attack by utilizing these newly discovered semantic pattern characteristics. The experimental results show that the semantic characteristics of digit segments have an important impact on the strength of user passwords. Finally, we propose a feasible scheme to improve the password strength meter for IoT systems based on the high-frequency semantic characteristics of digit segments. Daojing He, Zhiyong Liu 0003, Beibei Zhou, Sammy Chan, Kim-Kwang Raymond Choo |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | NiIas: Non-Interactive Instant Authentication and Secure Data Delivery Protocol for Multi-Access Edge ComputingabstractThe inherent heterogeneity and mobility of Multi access Edge Computing (MEC) necessitate security protocols that ensure instant connectivity while maintaining resilience against resource exhaustion. This paper presents NiIas, a non-interactive instant authentication and secure data delivery proto col. Unlike conventional protocols that require prior handshakes, NiIas enables immediate payload transmission without session resumption delays. The protocol leverages a multi-authorization identity-based cryptosystem to decentralize trust and eliminate certificate management overhead. Furthermore, NiIas employs an authenticate-before-decryption mechanism as a lightweight admission control. This design filters unauthorized traffic prior to decryption and effectively protects edge verifiers from denial of-service attacks. Rigorous security analysis formally establishes the protocol's cryptographic guarantees. Moreover, numerical simulations on resource-constrained devices and M/D/1 queuing theoretic analysis demonstrate that NiIas achieves superior availability and stability compared to state-of-the-art protocols. Xuru Li, Daojing He, Lifei Wei, Sammy Chan, Kim-Kwang Raymond Choo, Dezhi Han |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Energy efficient clustering and routing for wireless sensor networks by applying a spider wasp optimizer
Zhendong Wang 0002, Yaozhong Yang, Daojing He, Sammy Chan |
Ad Hoc Networks | 5 |
| 2025 | DTKD-IDS: A dual-teacher knowledge distillation intrusion detection model for the industrial internet of things
Biao Xie, Zhendong Wang 0002, Daojing He, Sammy Chan |
Ad Hoc Networks | 5 |
| 2025 | ICMH-CHR: An intra-cluster multi-hop based cluster head rotation protocol for wireless sensor networks
Weibing Zeng, Zhendong Wang 0002, Shuxin Yang, Daojing He, Sammy Chan |
Ad Hoc Networks | 5 |
| 2025 | Blockchain-based efficient and secure cloud cross-domain data sharing with dynamic revocation by multiple authorities
Guangfu Wu, Daojing He, Sammy Chan |
Comput. Networks | 4 |
| 2025 | Comparison on resilience and energy efficiency of authentication schemes in IoT networksabstractAbstract Network security is one of the primary concerns when deploying IoT applications. A proper authentication scheme can strengthen network security and resilience against malicious attacks. The quantitative comparison among authentication schemes is rarely found. Thus, it is difficult to choose the appropriate authentication scheme objectively. This paper presents a quantitative comparison of three authentication schemes, including blockchain‐based authentication, a widely discussed new approach for IoT security. This paper focuses on network‐level simulation instead of the protocol, providing a different angle when evaluating an authentication scheme. The simulations include five common topologies in IoT networks under five different attack strategies. The results show that the blockchain‐based scheme has the most substantial resilience compared to PKI‐based and PSK methods, while the computational cost is 1% less than the PKI‐based method. In addition, the PSK method is most energy efficient as its computational cost is only around 1% of PKI‐based and blockchain‐based methods. Chi Ho Lau, Sammy Chan |
Expert Syst. J. Knowl. Eng. | 2 |
| 2025 | Multi-population dynamic grey wolf optimizer based on dimension learning and Laplace Mutation for global optimization
Zhendong Wang 0002, Lei Shu 0001, Shuxin Yang, Daojing He, Sammy Chan |
Expert Syst. Appl. | 6 |
| 2025 | A Vulnerability Detection Method for Smart Contracts Based on Dynamic Meta OptimizerabstractWith the increasingly complex blockchain technology environment and emerging security threats, the detection and prevention of vulnerabilities in blockchain smart contracts have become crucial for ensuring the healthy development of blockchain technology and avoiding substantial economic losses. Recently developed vulnerability detection methods for smart contracts suffer from the drawbacks of insufficient feature extraction and inadequate multitask detection. This paper proposes a multifaceted learning model, DLR, based on a dual-loop architecture of meta learning to address these issues by adopting model-agnostic meta-learning techniques. This model employs a syntax analyzer for targeted feature extraction, with graph information used as a supporting tool during the initial stage of feature engineering. Combined with an improved optimizer algorithm in the inner loop, the model can effectively learn and adjust based on the specific requirements of each task. In the outer loop, the model achieves efficient learning rate adjustment for multi-task learning by integrating the adaptive learning rate of the Adam optimizer with a global adjustment using simulated annealing strategy, thereby enhancing performance across diverse tasks. Experimental results demonstrate significant improvements in detection accuracy over state-of-the-art methods for three types of vulnerabilities, with our method achieving detection accuracies of 94.40%, 93.36%, and 94.33% for reentrancy, timestamp dependence, and integer overflow vulnerabilities, respectively. Daojing He, Sammy Chan |
IEEE Internet Things J. | 3 |
| 2025 | HASHL: Dynamic Hash Verification for Detecting and Preventing Eclipse AttacksabstractWith the rapid development of blockchain technology, P2P networks are facing increasing security threats, among which Eclipse attacks, as a type of network isolation attack, have seriously affected the normal operation of the network and the integrity of data. To address this challenge, this study implements node authentication and dynamic reputation evaluation by leveraging a dynamic hash computation mechanism that integrates challenge strings, node identifiers, and the latest active time, ensuring the uniqueness of node identities and the authenticity of operations. Based on a dynamic hash chain behavior evaluation mechanism, node behaviors are quantified across three dimensions: integrity, consistency, and temporal consistency, enabling precise identification of anomalous nodes. Furthermore, a network prevention repository framework is proposed, which dynamically adjusts the trust index of nodes by combining historical behavior with real-time data, effectively detecting and defending against stealthy Eclipse attacks. In addition, extensive testing on both Bitcoin and Ethereum platforms has shown that the method proposed in this study not only can effectively coexist on these two platforms, but also significantly improves the security and stability of the network, effectively reducing the occurrence of Eclipse attacks. Daojing He, Chen Tu, Sammy Chan |
IEEE Internet Things J. | 4 |
| 2025 | A Secure and Efficient Software Random Number Generator Applicable to Internet of ThingsabstractThe application of random numbers is essential in the Internet of Things (IoT), ranging from traditional data encryption functions to secure and trustworthy technologies for intelligent IoT devices. Due to their unique advantages of flexibility and convenience, software random number generators (SRNGs) are widely used in various computational applications within IoT. The research focus is on the quality, efficiency, and structural security of the output random sequences. However, there is no completely unified structural standard for SRNGs. For instance, even widely used generators, such as the Linux generator have certain deficiencies in the quality or security of their random sequence outputs. This article proposes a more secure and efficient software random number generator, namely SESRNG. First, a dual entropy pool system is constructed using a circular shift register connected to a ring aggregation pool. This system collects multiple system entropy sources in two rounds, with Shannon entropy estimation applied for online entropy estimation of the source data. Next, we utilize dual chaotic systems as extension functions to iteratively compute the entropy source data. In the designed deterministic random number generator structure, the SHA256 algorithm is used as a post-processing function to hash the key parameters of the internal state, resulting in the final random sequence. We used three well-known test suites—ENT, NIST, and the “Information Security Technology Randomness Test Methods for Binary Sequences”—to evaluate the performance of the SRNG. The results show that SESRNG can provide high-quality random numbers that meet the needs of various IoT applications. Daojing He, Weiwen Huang, Sammy Chan |
IEEE Internet Things J. | 4 |
| 2025 | RDLSH: Adaptive Entity Recognition and Relation Extraction for IoT Knowledge GraphabstractWith the rapid development of the Internet of Things (IoT), security issues are becoming increasingly severe. Malicious attackers use IoT devices to carry out network attacks, resulting in data leakage. The use of knowledge graphs effectively prevents and resists attacks through deep mining and association analysis in security situation awareness and threat prediction. Entity recognition and relationship extraction are the core steps in the construction of knowledge graphs. They are used to automatically extract meaningful entities and relationships from massive data and perform reasoning, but they still face challenges in accuracy and computational cost in extracting long texts and complex relationships. To address these issues, this paper proposes the RDLSH model for processing of local context, low-frequency entity recognition, and global semantic associations. Based on the Reformer architecture, it dynamically adjusts the local sensitive hashing parameters, and combines the multi-head attention mechanism to achieve good performance in capturing cross-paragraph and long-distance dependencies, and efficiently handles entity recognition and relationship extraction tasks. In addition, the RDLSH model introduces reversible residual networks and bidirectional transfer mechanisms to optimize the memory usage of large-scale data processing and improve computational efficiency. Experimental results show that the RDLSH model not only improves the accuracy of entity and relationship extraction, but also enhances the cross-sentence dependency processing capability and computational efficiency. Daojing He, Chen Tu, Sammy Chan |
IEEE Internet Things J. | 3 |
| 2025 | A Novel Lightweight IoT Intrusion Detection Model Based on Self-Knowledge DistillationabstractThe Internet of Things (IoT) environment contains many different types of devices, each with different functionalities, communication protocols, and security capabilities, which makes the IoT a complex challenge for security protection. Therefore, network intrusion detection (NID) is needed to detect intrusions in the network to secure the IoT. In recent years, deep learning (DL)-based intrusion detection systems have achieved excellent results, but they tend to require high-computational resources and storage space, which is not feasible for most IoT devices. In this article, we propose a lightweight intrusion detection model based on self-knowledge distillation (SKD), namely, tied block convolution lightweight deep neural network (TBCLNN), which improves the detection accuracy while also reducing the number of model parameters and computational cost. Specifically, we use the binary Harris Hawk optimization algorithm (bHHO) for dimensionality reduction of traffic features. We use lightweight convolution, such as tied block convolution (TBC), to design lightweight neural network (LNN) models with residual and inverse residual structures. Moreover, we propose an improved SKD loss function to solve the sample imbalance problem and compensate for the performance degradation caused by lightweight neural networks. The multiclassification accuracy of our proposed method exceeds 99% on all three publicly available IoT datasets. The experimental results show that our method has a small model size and requires only low-computational resources, making it suitable for resource-constrained IoT intrusion detection. Zhendong Wang 0002, Renqiang Zhou, Shuxin Yang, Daojing He, Sammy Chan |
IEEE Internet Things J. | 5 |
| 2025 | Enhancing Android malware detection via knowledge distillation on homogenized function call graphs
Zhendong Wang 0002, Shuxin Yang, Daojing He, Sammy Chan |
Knowl. Based Syst. | 5 |
| 2025 | Lightweight model-contrastive federated learning with multi-center clustering for IoT intrusion detection
Renqiang Zhou, Zhendong Wang 0002, Shuxin Yang, Daojing He, Sammy Chan |
Knowl. Based Syst. | 5 |
| 2025 | Blockchain Assisted Trust Management for Data-Parallel Distributed LearningabstractMachine learning models can support decision-making in mobile terminals (MTs) deployments, but their training generally requires massive datasets and abundant computation resources. This is challenging in practice due to the resource constraints of many MTs. To address this issue, data-parallel distributed learning can be conducted by offloading computation tasks from MTs to the edge-layer nodes. To facilitate the establishment of trust, one can leverage trust management, say to use trust values derived from local model quality and evaluations by other nodes as access criteria. Nonetheless, security and performance considerations remain unsolved. In this paper, we propose a blockchain-assisted dynamic trust management scheme for distributed learning, which comprises nodes attributes registration, trust calculation, information saving, and block writing. The proof of stake (PoS) consensus mechanism is leveraged to enable efficient consensus among the nodes using trust values as stakes. The incentive mechanism and corresponding dynamic optimization are then proposed to further improve system performance and security. The reinforcement-learning approach is leveraged to provide the optimal strategy for nodes’ local iterations and selection. Simulations and security analysis demonstrate that our proposed scheme can achieve an optimal trade-off between efficiency and quality of distributed learning while maintaining system security. Yuxiao Song, Daojing He, Minghui Dai, Sammy Chan, Kim-Kwang Raymond Choo, Mohsen Guizani |
IEEE Trans. Mob. Comput. | 4 |
| 2024 | PPTFI: Patch Presence Test for Function-Irrelevant PatchesabstractIn the past decades, downstream manufacturers often failed to timely adopt the security patches, resulting in some discovered vulnerabilities still posing serious risks. In the currently popular field of blockchain smart contracts, this is also a thorny issue. Although some new methods have been proposed to update and patch smart contracts deployed in blockchain networks, the binary codes of most vulnerable smart contracts are still being executed without patching. To detect the unpatched binaries as soon as possible, signature based patch presence tests and software similarity based patch presence tests have been proposed to check whether a certain patch is applied to the released software binaries. However, a large number of bug-fix patches are irrelevant to functions. They are small in size and only modify program entities other than functions. Existing signature-based patch detection methods and software similarity-based tools have limitations in detecting such patches. In this paper, we propose PPTFI, a patch presence test for function-irrelevant patches. PPTFI understands these patches and extracts code and data information as patch signatures for scanning target binaries. Being evaluated on 62 different versions of 31 real-world function-irrelevant patches and 512 binaries across 16 various compilation environments, PPTFI achieves an accuracy of 77.54%, significantly outperforming existing techniques. Daojing He, Juzheng Zhang, Sencun Zhu, Sammy Chan |
MSN | 5 |
| 2024 | Multi-strategy enhanced grey wolf algorithm for obstacle-aware WSNs coverage optimization
Zhendong Wang 0002, Lili Huang 0001, Shuxin Yang, Daojing He, Sammy Chan |
Ad Hoc Networks | 6 |
| 2024 | Virtual-Mobile-Agent-Assisted Boundary Tracking for Continuous Objects in Underwater Acoustic Sensor NetworksabstractAquatic environments confront mounting threats from diverse sources, among which the persistent migration of continuous objects (e.g., chemical contaminants) is a primary concern. While advances have been made in tracking these entities using underwater acoustic sensor networks (UASNs), full-scale monitoring is challenged by unpredictable sensor deployments. Though Autonomous underwater vehicles show promise, their prohibitive costs and operational complexities limit their broad adoption. To tackle these issues, this article introduces a novel search strategy named virtual mobile agent-assisted continuous object tracking (VMA-COT). Drawing inspiration from binary tree structures, VMA-COT refines the search from the entire network to targeted hierarchical boundary mapping cells. Each cell encompasses a Section of the object’s boundary. A designated node within each cell evaluates information entropy at specified locations using a meticulously designed search sequence. By utilizing a feedback mechanism, grounded in the information entropy and the search sequence, VMA-COT progressively pinpoints the boundary. This methodology can be likened to a central node dispatching mobile agents in each cell. These agents, limited by a specific step range, adjust their trajectories for precise boundary delineation. Empirical tests and simulations demonstrate the effectiveness of VMA-COT, highlighting its efficiency, accuracy, and boundary node utilization. Li Liu 0022, Shengchao Zhu, Sammy Chan, Changmao Wu |
IEEE Internet Things J. | 4 |
| 2024 | GSASG: Global Sparsification With Adaptive Aggregated Stochastic Gradients for Communication-Efficient Federated LearningabstractThis article addresses the challenge of communication efficiency in federated learning by the proposed algorithm called global sparsification with adaptive aggregated stochastic gradients (GSASGs). GSASG leverages the advantages of local sparse communication, global sparsification communication, and adaptive aggregated gradients. More specifically, we devise an efficient global top-$k^{\prime }$sparsification operator. By applying this operator to the aggregated gradients obtained from the top-k sparsification, the global model parameter is rarefied to reduce the download transmitted bits from$O(dMT)$to$O(k^{\prime }MT)$, where d is the dimension of the gradient, M is the number of workers, T is the total number of epochs, and$k^{\prime } \leq k\lt d$. Meanwhile, the adaptive aggregated gradient method is adopted to skip meaningless communication and reduce communication rounds. The deep neural network training experiment demonstrates that, compared to the previous algorithms GSASG significantly reduces communication cost without sacrificing the model performance. For instance, when considering the MNIST data set with$k=1\% d$and$k^{\prime }=0.5\% d$, in terms of communication rounds, GSASG outperforms sparse communication by 91%, adaptive aggregated gradients by 90%, and the combination of sparse communication with adaptive aggregated gradients by 56%. In terms of communication bits, GSASG yields 1% of the communication bits needed with previous algorithms. Runmeng Du, Daojing He, Zikang Ding, Sammy Chan, Xuru Li |
IEEE Internet Things J. | 5 |
| 2024 | Unknown Threats Detection Methods of Smart ContractsabstractWith the explosive growth of blockchain platforms and applications, security threats of blockchain also occur frequently. As a decentralized application deployed on the blockchain, smart contracts help the blockchain realize safe and efficient information storage, asset management, and value transfer. Therefore, smart contracts play a vital role in the security of the blockchain. In recent years, security threats against smart contracts have increased, not only causing huge economic losses but also impacting the credit system of the blockchain. Therefore, many researchers have carried out corresponding research on the security threats of smart contracts. Common threat detection methods include formal verification, symbolic execution, fuzzing, etc. Most of these methods are only for known threats, while there is not much work on detecting unknown threats. In order to better deal with unknown threats, we present a review of the typical smart contract security events in recent years, analyze the security threats from contract coding, Ethereum virtual machine, and blockchain characteristics. Further, we compare and summarize the latest unknown threat detection methods. Then, to address the problem that very few unknown threat samples are available, a detection method based on a few-shot learning is proposed. Daojing He, Sammy Chan, Mohsen Guizani |
IEEE Internet Things J. | 3 |
| 2024 | A Comprehensive Detection Method for the Lateral Movement Stage of APT AttacksabstractDue to the outbreak of the new crown epidemic, more companies prefer to use telecommuting for work, which also provides more attack surfaces for APT attacks. After initially gaining access to the intranet, attackers will use server message block (SMB), RDP, and other remote sharing or connection protocols to move horizontally to achieve the purpose of privilege escalation. In this work, we design a multidimensional detection framework to detect lateral movement behavior based on the SMB protocol in the intranet environment. This framework combines active trapping and passive scanning, and uses neural networks to determine the attack samples used by the adversary when moving laterally. We test the effectiveness of the active trapping technology in a simulation environment, and verify through real malware samples that the accuracy of neural network detection can reach about 90%. The experimental results show that our work can effectively detect the lateral movement behavior using the SMB protocol in the intranet environment. Daojing He, Hongjie Gu, Sammy Chan, Mohsen Guizani |
IEEE Internet Things J. | 4 |
| 2024 | On Phishing URL Detection Using Feature ExtensionabstractPhishing is a common cybercrime event with great harm. Various phishing attacks have occurred repeatedly and have caused huge economic losses. With the booming development of blockchain and cryptocurrency, the huge amount of money in the field and the immature ecosystem have induced phishing attacks to flood the field in large quantities. Unfortunately, phishing has become the main means of attack in the field, posing a huge security threat to users’ digital assets. The existing methods for detecting phishing websites rely on the quality of uniform resource locator (URL) feature extraction, and the extraction angle is becoming increasingly rigid. Therefore, this article proposes a phishing URL detection model that utilizes feature extension. This method uses the TextRank algorithm to generate a feature extension library and embeds the extracted features into the URL to be detected. After the URL is vectorized, it is input into the two-layer classification network proposed in this article to classify the website. This classifier consists of an upstream task Bert layer and a downstream task convolutional neural network layer. It is possible to simultaneously learn the comprehensive representation information and local feature information of URLs, effectively avoiding overfitting problems and improving the ability to identify phishing websites. Comparative experiments are conducted using a data set of real phishing websites. The experimental results show that this model has higher accuracy and stability compared to other phishing website detection models. Daojing He, Sammy Chan, Mohsen Guizani |
IEEE Internet Things J. | 4 |
| 2024 | A Method for Detecting Phishing Websites Based on Tiny-Bert StackingabstractThe Internet is an indispensable part of our lives. Therefore, it is very important to ensure network security and maintain a safe network environment. Phishing, as a low-cost and imperceptible network attack, is rampant in the world’s information networks. To address this issue, this paper proposes a phishing website detection model based on tiny-Bert stacking. The core concept of the proposed model is to use tiny-Bert to extract features from website URL strings, and learn the semantic features and long-range dependent features in URLs. Then we build a Stacking algorithm-based classifier which includes four basic learners among which, CatBoost, XGBoost and LightGBM are the first-level learners, and GBDT is the second-level learner. This detection model can identify phishing websites without manual feature extraction, and the basic learners of Stacking can compensate each other for errors in the classification process, improve generalization, and achieve higher accuracy. The proposed model is evaluated using a dataset based on real phishing websites. Compared to the state of the art, the results show that the proposed model has an accuracy rate of up to 99.14%, a recall rate of up to 99.13%, and is more stable. Daojing He, Sammy Chan, Kim-Kwang Raymond Choo |
IEEE Internet Things J. | 4 |
| 2024 | Special Characters Usage and Its Effect on Password SecurityabstractContinuously preventing weak password attacks is one of the most important initiatives to secure IoT and smart contract platforms. Despite their significance as crucial components of passwords, special character segments have been overlooked. This study systematically studies the basic characteristics and semantic patterns of special character segments. We assess the efficacy of special character segment characteristics in cracking trials through assimilation into the latest Probabilistic Context-Free Grammar (PCFGv4) method for password cracking by updating the pre-terminal structure or performing special character segment transformation. Experimental findings demonstrate that a mere 6% transformation rate improves the cracking rate by 3.72% under the optimal assimilation combination. Our investigation reveals that the current password creation policies of mainstream IoT platforms and smart contract wallets overestimate the strength of passwords with special characters. To enhance their passwords, users can employ low-frequency special character semantic strings. For IoT platforms or smart contract wallets, the use of blacklist constructed from special character segment characteristics can effectively mitigate the risk of overestimating the strength of passwords with special characters. Daojing He, Zhiyong Liu 0003, Sammy Chan, Mohsen Guizani |
IEEE Internet Things J. | 4 |
| 2024 | UCRTD: An Unequally Clustered Routing Protocol Based on Multihop Threshold Distance for Wireless Sensor NetworksabstractCluster head (CH) nodes near the base station (BS) die prematurely due to the need to perform more communication tasks, which can lead to disruption of network connectivity and makes it difficult to achieve the goal of load balancing in Wireless Sensor Networks (WSNs), this problem is known as hot spot problem. To solve this problem, non-uniform clustering strategies have been proposed. However, all the current related non-uniform clustering protocols have some drawbacks, such as the lack of a theoretical basis for the value of the multi-hop threshold distance between clusters, the limited attention to the data transmission process, and the insufficient load balancing of the protocols in the face of complex and variable networks. Based on the above problems, we propose an unequally clustered routing protocol based on multi-hop threshold distance (UCRTD) for WSNs. First, this paper analyzes the energy-saving threshold distance for multi-hop communication in conjunction with the energy consumption model of WSNs, and based on the multi-hop energy-saving threshold distance, a strategy for selecting the best energy-saving relay node is proposed. In intra-cluster communication, considering that medium-sized networks form larger clusters, cluster members (CMs) within the cluster that are farther away from the CH take multi-hop communication. For inter-cluster communication, to maximize the network lifetime, the most energy-efficient CH node with the highest residual energy is selected in the routing phase for alternate multi-hop transmission, and this strategy effectively prolongs the network lifetime and also ensures the load balance of the network. Simulation results show that the proposed UCRTD effectively prolongs the network lifetime and maintains good load balancing under multiple network environments when compared with four existing EEUC, EBUC, EADUC, and EAUCA unequal clustering protocols as well as LEACH protocol. Zhendong Wang 0002, Weibing Zeng, Shuxin Yang, Daojing He, Sammy Chan |
IEEE Internet Things J. | 5 |
| 2024 | A comprehensive survey of smart contract security: State of the art and research directions
Guangfu Wu, Daojing He, Sammy Chan |
J. Netw. Comput. Appl. | 6 |
| 2024 | A hierarchical hybrid intrusion detection model for industrial internet of things
Zhendong Wang 0002, Daojing He, Sammy Chan |
Peer Peer Netw. Appl. | 5 |
| 2024 | Improving byzantine fault tolerance based on stake evaluation and consistent hashing
Guangfu Wu, Daojing He, Sammy Chan, Xiaoyan Fu |
Peer Peer Netw. Appl. | 4 |
| 2024 | A Lightweight and Secure Communication Protocol for the IoT EnvironmentabstractEnsuring secure communications for the Internet of Things (IoT) systems remains a challenge. Due to exacting resource limitations of computing, memory, and communication in IoT environments, communication schemes based on asymmetric cryptographic systems can be challenging to deploy. An alternative is to deploy symmetric encryption schemes based on pre-shared keys. However, there are also challenges in designing such schemes and examples include how to achieve an optimal trade-off between security and performance levels while meeting resource consumption requirements. Hence, this paper presents a lightweight key synchronization update algorithm, which is then used as a building block in our proposed lightweight secure communication protocol. The security of the protocol is analyzed to show that it can resist common attacks, such as replay attacks, and man-in-the-middle attacks. We then use Tamarin, a widely accepted security protocol verification tool, for formal verification. In addition, we evaluate the randomness and computational performance of the lightweight key synchronization update algorithm and demonstrate that it outperforms other schemes. We also evaluate the performance of the protocol, in terms of computational and communication costs, to demonstrate utility. Zikang Ding, Daojing He, Qi Qiao, Xuru Li, Sammy Chan, Kim-Kwang Raymond Choo |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2024 | You Can Glimpse but You Cannot Identify: Protect IoT Devices From Being FingerprintedabstractWith pervasive IoT networking, traffic-analysis-based IoT fingerprinting techniques have been well researched. For example, by integrating blockchain technology and device fingerprinting, authentication of devices connected to a network can be achieved. Though the primary motivations are identifying vulnerabilities and implementing access control, the techniques could be exploited to trace IoT users’ privacy. We propose a traffic morphing scheme to protect IoT devices from being identified by fingerprinting models. The scheme mainly consists of a morphing policy learning algorithm, a rewarding model, and a time-series-based feature estimation algorithm. Backed by the timely rewarding model, a learning agent produces an optimal policy that perturbs the target fingerprinting model while preserving the original traffic function. The estimation algorithm predicts the feature vectors of unfinished flows to enable live traffic morphing. The scheme's advantage is that it requires minimal knowledge of the fingerprinting model and supports live morphing. Experimental results show that over 81% of the IoT devices become unidentifiable, and the scheme degrades the average F1 score of mainstream fingerprinting models from 0.996 to 0.526. For certain devices and target models, the scheme even reaches 100% effectiveness. Shuaishuai Tan, Shui Yu 0001, Wenyin Liu, Daojing He, Sammy Chan |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Double-Layer Detection of Internal Threat in Enterprise Systems Based on Deep LearningabstractIn recent years, phishing mail-mediated attacks are proliferating. When victims are enterprise employees, internal security of the enterprise systems will also be threatened. Facing the advanced phishing email attacks and complex insider threat attacks, enterprise systems equipped with traditional machine learning models cannot detect such attacks effectively. Therefore, we propose a double-layer detection framework in this paper. Firstly, from the perspective of individual security, Long Short-Term Memory (LSTM) and extreme gradient boosting tree (XGBoost) are used to build a phishing email detection model. The model generalization ability and precision rate are improved by adding a custom loss function in the training process. Then, from the perspective of group security, Bidirectional LSTM and Attention mechanism are used to build an insider threat detection model. Our model has better results for multi-domain time series and anomaly detection in comparison to different models and existing insider threat detection models. We test the effectiveness of the proposed framework through real phishing email cases and insider threat attack events on our simulation verification platform. The experimental results demonstrate that our proposed framework can protect enterprise systems from phishing attacks and insider threats. Daojing He, Xueqian Xu, Sammy Chan, Kim-Kwang Raymond Choo |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Continuous Object Tracking via Joint Global-Local Binary Tree Topological Transformation in Underwater Acoustic Sensor NetworksabstractFrequent activities in marine energy exploration and transportation have led to the ongoing presence of continuous objects, such as oil spills and radioactive waste, in the ocean. This article focuses on enhancing the understanding of these objects’ boundaries for accurate assessment of their shape, coverage, and evolution. We introduce a continuous object tracking algorithm named JGL-COT, based on joint global-local binary tree topological transformations and specifically designed for underwater acoustic sensor networks. The contribution of JGL-COT lies in its ability to leverage the correlation between the morphologies of a continuous object's boundaries over time, alternating between global and local binary tree topological transformations. When the present boundary features a strong resemblance to its previous form, JGL-COT switches to a local transformation by establishing a semi-infinite region. Otherwise, it transitions to a global transformation. Following this, JGL-COT chooses a group of binary tree-structured cells for boundary mapping, creating virtual boundary nodes as sampling points for boundary fitting. Building upon graph theory, we derive the lower bound on the effectiveness and time complexity of the proposed joint global and local binary tree topological transformations when applied to object boundary tracking. Experiments in both realistic and simulated settings confirm that JGL-COT provides highly accurate tracking and significantly reduces network energy consumption. Li Liu 0022, Tengfei Zhao, Sammy Chan, Changmao Wu |
IEEE Trans. Mob. Comput. | 3 |
| 2023 | Effectiveness of Authentication Schemes in the Internet of Things Networks with Different Structural TopologiesabstractThis paper reports an empirical study of the effectiveness of three different authentication methods for Internet of Things (IoT) networks. They are simulated under three attack strategies with three different structural topologies. The survival size and survival link ratio (SLR) are examined to provide some references and insight for designing IoT networks under various conditions and applications. Chi Ho Lau, Fan Yan, Sammy Chan |
IWCMC | 3 |
| 2023 | Password Cracking by Exploiting User Group Information
Beibei Zhou, Daojing He, Sencun Zhu, Sammy Chan |
SecureComm (1) | 5 |
| 2023 | Application of Deep Neural Network with Frequency Domain Filtering in the Field of Intrusion DetectionabstractIn the field of intrusion detection, existing deep learning algorithms have limited capability to effectively represent network data features, making it challenging to model the complex mapping relationship between network data and attack behavior. This limitation, in turn, impacts the detection accuracy of intrusion detection systems. To address this issue and further enhance detection accuracy, this paper proposes an algorithm called the Fourier Neural Network (FNN). The core of FNN consists of a Deep Fourier Neural Network Block (DFNNB), which is composed of a Hadamard Neural Network (HNN) and a Fourier Neural Network Layer (FNNL). In a DFNNB, the HNN is responsible for sampling the network intrusion data samples in different time domain spaces. The FNNL, on the other hand, performs a Fourier transform on the samples outputted by the HNN and maps them to the frequency domain space, followed by a filtering process. Finally, the data processed by filtering are transformed back to the time domain space for subsequent feature extraction work by the DFNNB. Additionally, to enhance the algorithm’s detection accuracy and filter out noise signals, this paper also introduces a High‐energy Filtering Process (HFP), which eliminates noise signals from the data signal and reduces interference on the final detection result. Due to the ability of FNN to process network data in both the time domain space and the frequency domain space, it possesses a stronger capability in expressing data features. Finally, this paper conducts performance evaluations on the KDD Cup99, NSL‐KDD, UNSW‐NB15, and CICIDS2017 datasets. The results demonstrate that the proposed FNN‐based IDS model achieves higher detection rates, lower false alarm rates, and better detection performance than classical deep learning and machine learning methods. Zhendong Wang 0002, Jingfei Li, Zhenyu Xu 0010, Shuxin Yang, Daojing He, Sammy Chan |
Int. J. Intell. Syst. | 6 |
| 2023 | Detection of Vulnerabilities of Blockchain Smart ContractsabstractWith the wide application of Internet of Things and blockchain, research on smart contracts has received increased attention, and security threat detection for smart contracts is one of the main focuses. This article first introduces the common security vulnerabilities in blockchain smart contracts, and then classifies the vulnerabilities detection tools for smart contracts into six categories according to the different detection methods: 1) formal verification method; 2) symbol execution method; 3) fuzzy testing method; 4) intermediate representation method; 5) stain analysis method; and 6) deep learning method. We test 27 detection tools and analyze them from several perspectives, including the capability of detecting a smart contract version. Finally, it is concluded that most of the current vulnerability detection tools can only detect vulnerabilities in a single and old version of smart contracts. Although the deep learning method detects fewer types of smart contract vulnerabilities, it has higher detection accuracy and efficiency. Therefore, the combination of static detection methods, such as deep learning method and dynamic detection methods, including the fuzzy testing method to detect more types of vulnerabilities in multi-version smart contracts to achieve higher accuracy is a direction worthy of research in the future. Daojing He, Rui Wu 0015, Xinji Li, Sammy Chan, Mohsen Guizani |
IEEE Internet Things J. | 4 |
| 2023 | A Novel Authentication Protocol for IoT-Enabled DevicesabstractThe Internet of Things (IoT) is composed of a large number of miniaturized devices interconnected through the Internet. These devices, equipped with sensing, computing, and communication capabilities, can be used to remotely control the environment or the monitored infrastructure. However, IoT devices usually only have limited resources, and thus designing a lightweight security authentication protocol for them is a challenge. This article proposes an identity authentication protocol between embedded devices and server. The protocol uses the elliptic curve encryption algorithm and realizes the anonymity of the device by hashing their IDs and prevents the server from replay attacks by adding security attributes timestamp. We prove the security of the protocol and its resistance to security attacks and also formally verify it using the AVISPA tool. In addition, through experimental comparison with existing protocols, we demonstrate the performance superiority of the proposed protocol. Daojing He, Ziming Zhao 0009, Sammy Chan, Mohsen Guizani |
IEEE Internet Things J. | 3 |
| 2023 | Hitting Moving Targets: Intelligent Prevention of IoT Intrusions on the FlyabstractMassive Internet of Things (IoT) devices have been playing a critical role in both the cyber and physical worlds. Various cyber attacks pose significant risks to IoT. Machine learning-based intrusion detection system (IDS) has earned much research attention. However, the intrusion prevention system (IPS) is rarely explored. Realtime intrusion prevention is quite challenging because the decision has to be made during a flow rather than after it finishes. Restricted by aligning with the shortest flows, existing IPSs generally inspect only the very first packets, leading to information loss for accurate detection. In this article, we first measure the information loss quantitatively. Then we devise Sniper, an IoT IPS scheme consisting of a flow length predictor, a novel feature space, and an enhanced ensemble learning algorithm. The flow length predictor guides a proper prevention time point to preserve as much information as possible. The proposed Markov matrix-based feature encoding method further saves more information than existing ones. The enhanced learning algorithm ensures a low-false positive rate (FPR), which is critical for IPSs. We benchmark Sniper with one closed-world and three open-world data sets. The results show that Sniper achieves a 99.89% prevention rate and 0.03% FPR, which is superior to the five state-of-the-art baseline models. Shuaishuai Tan, Wenyin Liu, Qingkuan Dong, Sammy Chan, Shui Yu 0001, Xiaoxiong Zhong, Daojing He |
IEEE Internet Things J. | 4 |
| 2023 | LIGHT: Lightweight Authentication for Intra Embedded Integrated Electronic SystemsabstractAs embedded integrated electronic systems (EIESs) become more pervasive (including in mission-critical applications), the need to ensure the security of data exchange in such a system against various malicious activities becomes more pronounced. However, designing secure and efficient solutions, such as authentication protocols, for the many different embedded systems with varying internal communication modes remains challenging. Therefore, in this paper, we propose a lightweight authenticated key-exchange (AKE) protocol for EIESs based on half-duplex and “command/response” bus. Specifically, the proposed protocol is designed to operate on resource-constrained devices, as well as having minimal number of interactions. We then prove the security of the proposed protocol and present the security parameter selection strategy for protocol implementation based on the empirical evaluations. Moreover, efficiency analysis also shows that the protocol can be effectively deployed in the EIESs environment. Xuru Li, Daojing He, Ximeng Liu, Sammy Chan, Manghan Pan, Kim-Kwang Raymond Choo |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | A Lightweight Authentication and Key Exchange Protocol With Anonymity for IoTabstractThe number of IoT devices is growing rapidly, and the interaction between devices and servers is also more frequent. However, IoT devices are often at the edge of the network, which leads their communications with the server to be completely exposed, making it more vulnerable to attacks. Moreover, IoT devices have limited energy and computational resources. Therefore, we propose in this paper a lightweight authentication and key exchange protocol with anonymity for IoT devices. The proposed scheme supports mutual authentication between IoT devices and the server. We verify the security of the protocol through formal and informal analyses. Finally, we compare security and performance with other protocols, which shows that our protocol has the advantages of being lightweight and secure. Daojing He, Yanchang Cai, Ziming Zhao 0009, Sammy Chan, Mohsen Guizani |
IEEE Trans. Wirel. Commun. | 5 |
| 2022 | A lightweight approach for network intrusion detection in industrial cyber-physical systems based on knowledge distillation and deep metric learning
Zhendong Wang 0002, Daojing He, Sammy Chan |
Expert Syst. Appl. | 4 |
| 2022 | Design and Formal Analysis of a Lightweight MIPv6 Authentication SchemeabstractThe emergence of mobile IPv6 (MIPv6) significantly affected how we live and work, while it still faces more security threats than traditional wireless networks. On the other hand, most mobile devices have constrained computing and storage resources. The network environment is complex, and the network topology also changes very frequently. Although various security protocols have been proposed for authentication in MIPv6, there are still some challenges. First, most of the subsisting authentication schemes cannot work in resource-constrained environments. Second, each of these authentication protocols has some defects, which may lead to serious consequences. So it is valuable and crucial to conduct security analysis at the design stage of protocols. Currently, most researchers attempt adopting informal methods, which are not as effective and suitable as formal methods. Some researchers have been conscious of the advantages of using formal methods to verify protocols. However, the approaches are too complex to understand for those who are not familiar with formal methods. In light of these challenges, we propose a lightweight MIPv6 authentication scheme for environments with low resources. We conduct a security analysis and performance comparison of the proposed authentication scheme. In particular, we use the SVO logic to formally analyze its security. We also explain how to use this formal method, which can be regarded as an example to better illustrate the application of formal analysis in MIPv6 authentication schemes. Daojing He, Xuru Li, Sammy Chan, Mohsen Guizani |
IEEE Internet Things J. | 4 |
| 2022 | Firmware Vulnerabilities Homology Detection Based on Clonal Selection Algorithm for IoT DevicesabstractWith the wide application of Internet of Things (IoT) devices, security attacks against their firmware often occur, which has attracted more attention from the research community. Firmware is an important part of IoT devices, and attacks against them is one of the main means to destroy them. Therefore, firmware security is considered a core of the overall devices’ security. At present, most of the firmware vulnerabilities have a small number of related samples, so it is difficult to use machine learning methods to generate detectors for some of them. Therefore, based on the collected data of related firmware vulnerabilities, this article proposes a firmware vulnerability homology detection method based on the clonal selection algorithm. We design the numerical and structural characteristics of vulnerability functions, train a detector for each function separately, and improve the recall rate of vulnerability detection. Compared with existing machine learning methods, this method only depends on the affinity between the objective function and the detector, which avoids the requirement of a large number of sample data sets. Finally, relevant experiments are carried out to verify the effectiveness of the method. Daojing He, Xiaohu You 0001, Tinghui Li 0003, Sammy Chan, Mohsen Guizani |
IEEE Internet Things J. | 4 |
| 2021 | A Lightweight Certificateless Non-interactive Authentication and Key Exchange Protocol for IoT EnvironmentsabstractIn order to protect user privacy and provide better access control in Internet of Things (IoT) environments, designing an appropriate two-party authentication and key exchange protocol is a prominent challenge. In this paper, we propose a lightweight certificateless non-interactive authentication and key exchange (CNAKE) protocol for mutual authentication between remote users and smart devices. Based on elliptic curves, our lightweight protocol provides high security performance, realizes non-interactive authentication between the two entities, and effectively reduces communication overhead. Under the random oracle model, the proposed protocol is provably secure based on the Computational Diffie-Hellman and Bilinear Diffie-Hellman hardness assumption. Finally, through a series of experiments and comprehensive performance analysis, we demonstrate that our scheme is fast and secure. Menghan Pan, Daojing He, Xuru Li, Sammy Chan, Emmanouil A. Panaousis |
ISCC | 4 |
| 2021 | Intrusion detection methods based on integrated deep learning model
Zhendong Wang 0002, Yaodi Liu, Daojing He, Sammy Chan |
Comput. Secur. | 4 |
| 2021 | Offloading Time Optimization via Markov Decision Process in Mobile-Edge ComputingabstractComputation offloading from a mobile device to the edge server is an emerging paradigm to reduce completion latency of intensive computations in mobile-edge computing (MEC). In order to satisfy the delay-sensitive computing tasks, offloading time, including task uploading time, task execution time, and results downloading time is adopted as the computational performance metrics for offloading nodes that perform offloaded computing tasks for mobile devices. Therefore, how to minimize the offloading time by selecting an optimal offloading node in MEC is of research importance. This work first investigates a MEC system consisting of mobile devices and heterogeneous edge severs that support various radio access technologies. Then, based on the available bandwidth of heterogeneous edge severs and the location of mobile devices, an optimal offloading node selection strategy is formulated as a Markov decision process (MDP), and solved by employing the value iteration algorithm (VIA). Finally, extensive numerical results demonstrate the effectiveness of the proposed strategy over classic strategies in terms of offloading time. Guisong Yang, Ling Hou, Daojing He, Sammy Chan, Mohsen Guizani |
IEEE Internet Things J. | 5 |
| 2021 | Deep logarithmic neural network for Internet intrusion detection
Zhendong Wang 0002, Zhenyu Xu 0010, Daojing He, Sammy Chan |
Soft Comput. | 4 |
| 2020 | Hybrid Intrusion Detection Mechanisms for Integrated Electronic SystemsabstractWhile integrated electronic systems (IESs) are widely used in military and civilian applications, their security issues are barely studied. By analyzing the architecture of the system and the characteristics of bus communication, this paper proposes an intrusion detection method based on the message sequence and behavioral rules of subsystems. According to the bus protocol, messages are divided into periodic and aperiodic messages. For the previous, we adopt sequence analysis and propose an algorithm that extract the sequence intelligently to determine if there are anomalies. For aperiodic messages, we detect the anomalies by modeling the system behaviors as decision trees. Through implementing experiments on our simulation system, we demonstrate that the proposed detection is more accurate than the existing schemes while incurring both lower false negative rate and lower false positive rate. Qi Qiao, Daojing He, Sencun Zhu, Jiahao Gao, Sammy Chan |
SECON | 6 |
| 2020 | TLP-IDS: A Two-layer Intrusion Detection System for Integrated Electronic SystemsabstractWith the increasing applications of integrated electronic systems (IESs), especially in security critical application scenarios like satellites and aircraft, new vulnerabilities and attacks have emerged recently. To detect the attacks, we propose TLP-IDS, a real-time intrusion detection system (IDS). TLP-IDS includes two layers of detection modules, one based on time and sequence logic and the other based on historical data. For the modules in the first layer, periodic and aperiodic messages are distinguished based on variations of message intervals, and we learnd from the idea of Markov decision process (MDP) in reinforcement learning (RL) to automatically learn the logical relationship between sequences. In the second layer, an online sequence extreme learning machine (OS-ELM) method is deployed to fit the data and further combined with the Weibull distribution function for prediction and detection. To evaluate our system, we implement several attack scenarios on a test bed, and measure the detection performance. Experimental results show that our system can quickly and effectively detect various attacks. Daojing He, Sencun Zhu, Sammy Chan |
SRDS | 5 |
| 2020 | TCSLP: A trace cost based source location privacy protection scheme in WSNs for smart cities
Hao Wang 0047, Guangjie Han, Chunsheng Zhu, Sammy Chan, Wenbo Zhang 0001 |
Future Gener. Comput. Syst. | 4 |
| 2020 | Computation offloading time optimisation via Q-learning in opportunistic edge computingabstractThe emergence of computation offloading can meet the real‐time requirements of computing tasks with intensive computing demands. In this study, the authors use opportunistic communication to construct a network framework for opportunistic edge computing (OEC) to perform computation offloading. Specifically, OEC forms a computing resource pool near the edge servers in the edge layer by gathering idle computing resources. Firstly, the state of the system is defined by the attributes of the computing task, the execution location of the computing task and the location of the terminal device in OEC. Then the computation offloading time is calculated and learned by selecting different offloading nodes. Finally, an optimal offloading node selection strategy based on the Q‐learning algorithm is obtained. Extensive simulations show that the proposed strategy consumes the minimum computation offloading time compared with benchmark algorithms in aspects of the amount of uploaded data, the total number of CPU cycles of the task and the number of computing tasks. Guisong Yang, Ling Hou, Daojing He, Sammy Chan |
IET Commun. | 6 |
| 2020 | CTRA: A complex terrain region-avoidance charging algorithm in Smart World
Guangjie Han, Haofei Guan, Zeren Zhou, Zhifan Li, Sammy Chan, Wenbo Zhang 0001 |
J. Netw. Comput. Appl. | 5 |
| 2019 | A Maximum Cache Value Policy in Hybrid Memory-Based Edge Computing for Mobile DevicesabstractEdge computing is proposed to bridge mobile devices with cloud computing data centers in the era of mobile big data, as an intermediate level of computing power. One important issue in edge computing is how to improve performance for mobile devices. Current systems utilize cache in multicore systems to reduce memory access cost with an acceptable hardware cost. However, existing cache management policies are unable to maximize cache value in the newly developed hybrid memory platform that combines phase-change memory and dynamic random-access memory. In this paper, we propose maximizes cache value (MCV), an efficient cache management policy, which MCV to minimize memory access cost in a hybrid main memory platform for edge computing. Extensive simulation studies indicate that this strategy can improve performance in hybrid main memory-based edge computing for mobile devices. Gangyong Jia, Guangjie Han, Sammy Chan |
IEEE Internet Things J. | 4 |
| 2019 | Performance Modeling of Representative Load Sharing Schemes for Clustered Servers in Multiaccess Edge ComputingabstractDue to their limited functionality, ubiquitous connected devices in the Internet of Things rely heavily on the computational and storage resources of the cloud. However, mainstream cloud systems always require high network bandwidth and cannot satisfy the delay requirement of real-time applications. Therefore, a new paradigm called multiaccess edge computing has emerged to offload the computation and storage needs of end user devices to the edge cloud servers located in the radio access networks of 5G mobile networks. In this paper, we study and compare three load sharing schemes, namely, no sharing, random sharing, and least loaded sharing, which exploit the collaboration between clustered servers in different degrees. We develop computationally efficient analytical models to evaluate the performance of these schemes. These models are validated by simulation, and then used to compare the performances of the three load sharing schemes under various system parameters. Comparison results show that the least loaded sharing scheme is most suitable to fully exploit the collaboration between the servers and achieve load balance among them. It contributes to reducing the blocking probability and waiting time experienced by users. Li Liu 0022, Sammy Chan, Guangjie Han, Mohsen Guizani, Masaki Bandai |
IEEE Internet Things J. | 2 |
| 2018 | A source location protection protocol based on dynamic routing in WSNs for the Social Internet of Things
Guangjie Han, Lina Zhou, Hao Wang 0047, Wenbo Zhang 0001, Sammy Chan |
Future Gener. Comput. Syst. | 5 |
| 2018 | Privacy-friendly and efficient secure communication framework for V2G networksabstractThe vehicle‐to‐grid (V2G) technology enables electric vehicles to deliver electricity into power systems, providing them supplementary capacity. On the other hand, a new set of security threats are brought to smart grid participants by V2G networks. However, security and privacy in V2G networks have so far received little attention, despite a rich literature on the design of conceptual structures or the impact of V2G networks on the current grid. In this study, the authors explore the features of V2G communication networks and identify their security challenges for communication functions. The authors then establish a novel and secure communication framework for V2G networks to achieve a balance among security, privacy preservation, efficiency and accountability without relying on any trusted third party. The feasibility of the framework is demonstrated by experimental results. Daojing He, Sammy Chan, Mohsen Guizani |
IET Commun. | 2 |
| 2018 | Dynamic cloud resource management for efficient media applications in mobile computing environments
Gangyong Jia, Guangjie Han, Jinfang Jiang, Sammy Chan |
Pers. Ubiquitous Comput. | 4 |
| 2017 | Software-Defined-Networking-Enabled Traffic Anomaly Detection and MitigationabstractTraffic anomaly detection has been a principal direction in the network security field, which aims to identify attacks based on significant deviations from the established normal usage profiles. Recently, a new networking paradigm, software defined networking (SDN), has emerged to facilitate effective network control and management. In this paper, we present the advantages of leveraging SDN to detect traffic anomaly, and review recent progresses in this direction. Despite their effectiveness for traditional traffic, SDN-based traffic anomaly detection methods have to face the challenge of continuously increasing network traffic. To this end, we propose two refined algorithms to be used in an anomaly detection framework which can handle voluminous data, and report some experimental results to demonstrate their performance. Daojing He, Sammy Chan, Xiejun Ni, Mohsen Guizani |
IEEE Internet Things J. | 2 |
| 2017 | A Trust Model Based on Cloud Theory in Underwater Acoustic Sensor NetworksabstractUnderwater acoustic sensor networks (UASNs) are susceptible to a large number of security threats, e.g., jamming attacks at the physical layer, collision attacks at the data link layer, and DoS attacks at the network layer. Because of the communication, computation, and storage constraints of underwater sensor nodes, traditional security mechanisms, e.g., encryption algorithms, are not suitable for UASNs. A trust model has been recently suggested as an effective security mechanism for open environments such as terrestrial wireless sensor networks (TWSNs), and considerable research has been done on modeling and managing trust relationships among sensor nodes. However, the trust models proposed for TWSNs cannot be directly used in a UASN due to its unique characteristics such as unreliable acoustic channel, dynamic network structure, and weak link connectivity. In this paper, we propose a novel trust model based on cloud theory (TMC) for UASNs. The objective of TMC is to solve uncertainty and fuzziness of trust based on cloud theory, which ultimately improves trust evaluation accuracy. Moreover, simulation results demonstrate that our algorithm outperforms other related works in terms of detection ratio of malicious nodes, successful packet delivery ratio, and network lifetime. Jinfang Jiang, Guangjie Han, Lei Shu 0001, Sammy Chan, Kun Wang 0005 |
IEEE Trans. Ind. Informatics | 4 |
| 2016 | Network Anomaly Detection Using Unsupervised Feature Selection and Density Peak Clustering
Xiejun Ni, Daojing He, Sammy Chan, Farooq Ahmad |
ACNS | 3 |
| 2016 | Security and privacy in Internet of things: methods, architectures, and solutionsabstractInternet of Things (IoT) is a fast-growing research area which spans various technological fields, including computer science, electronic engineering, mobile and wireless communications, embedded systems, etc. Many technologies serve as the building blocks of this new paradigm, such as wireless sensor networks, RFID, cloud services, machine-to-machine interfaces, and so on. IoT will allow billions of objects in the physical world as well as virtual environments to exchange data with each other in an autonomous way so as to create smart environments such as automotive, healthcare, logistics, environmental monitoring, and many others. However, IoT introduces new challenges for the security of systems and processes and the privacy of individuals. Protecting the information in IoT is a complex and difficult task. IoT requires global connectivity and accessibility, which means that anyone can access in anytime and anyway, and that the number of attack vectors available to malicious attackers might become staggering. Furthermore, the inherent complexity of the IoT, where multiple heterogeneous entities located in different contexts can exchange information with each other, further complicates the design and deployment of efficient, interoperable, and scalable security mechanisms. Ubiquitous and cloud computing also increase the urgency of the privacy leakage problem. As a result, there is an increasing demand for development of new security and privacy approaches to guarantee the security, privacy, integrity, and availability of resources in IoTs. Traditional security countermeasures cannot be directly used in IoTs because of the different standards and communication stacks involved. Moreover, the large number of interconnected devices in IoTs introduces scalability issues. Therefore, new and novel security and privacy methods, architectures, and solutions are needed to deal with security threats in IoTs. In this special issue, we are delighted to present a selection of nine papers, which, in our opinion, will contribute to the enhancement of knowledge in security and privacy research for IoTs. The collection of high-quality research papers provides a view on the latest research advances on security and privacy methods, architectures, and solutions in IoTs. The contributions of these papers are outlined in the succeeding text. In the first paper, A new authentication protocol for healthcare applications using wireless medical sensor networks with user anonymity, Xiong Li, Jianwei Niu, Saru Kumari, Junguo Liao, Wei Liang, and Muhammad Khurram Khan adopt the biometrics as the third authentication factor and propose a new authentication protocol to guarantee secure communication and protect the user privacy for healthcare application using WMSNs with user anonymity. In the proposed protocol, a wrong password detection mechanism is designed to reduce unnecessary computation and communication costs. In the second paper, Fusion: coalesced confidential storage and communication framework for the IoT, instead of developing independent security solutions, Ibrahim Ethem Bagci, Shahid Raza, Utz Roedig, and Thiemo Voigt present Fusion to address both the communication and storage security. The paper demonstrates that compared with performing traditional cryptographic operations separately, using the combined solution is much safer and more energy efficient. In the third paper, A changeable personal identification number-based keystroke dynamics authentication system on smart phones, Ting-Yi Chang, Cheng-Jung Tsai, Wang-Jui Tsai, Chun-Cheng Peng, and Han-Sing Wu propose a novel keystroke dynamics-based authentication (KDA) system to protect security of smart phones. Compared with the traditional KDA system, in the proposed new KDA system, the personal identification number codes of the subscribers can be well protected, and the users can change their personal identification number codes and passwords anytime without extra retraining. With the wide use of smart mobile devices, task collaborations among mobile devices are becoming ubiquitous and important. The security issues can be well guaranteed if the tasks can be effectively balanced. Therefore, in the fourth paper, SAFE-CROWD: secure task allocation for collaborative mobile social network, Xiaochen Fan, Panlong Yang, Qingyu Li, Dawei Liu, Chaocan Xiang, and Yonggang Zhao propose “SAFE-CROWD”, which is a secure task-allocation scheme. Using SAFE-CROWD, the tasks can be securely and collaboratively completed among mobile devices. In the fifth paper, ShoVAT: Shodan-based vulnerability assessment tool for Internet-facing services, Béla Genge and Cǎlin Enǎchescu propose a novel tool called Shodan-based vulnerability assessment tool (ShoVAT) to guarantee the automated vulnerability assessment of Internet-facing services. Based on the indexing capabilities of Shodan search engine, ShoVAT first finds services and then reconstructs key vulnerability identifiers. Finally, the vulnerabilities are obtained using National Vulnerability Database. The experiment results show that 3922 vulnerabilities are found on 1501 services in 12 different institutions. In the sixth paper, Distributed flood attack detection mechanism using artificial neural network in wireless mesh networks, Muhammad Altaf Khan, Shafiullah Khan, Bilal Shams, and Jaime Lloret propose an artificial neural network-based technique to detect distributed flooding attacks in multi-hop wireless mesh networks. The proposed scheme is named as the distributed flood attack detector. The distributed flood attack detector is designed to be implemented at mesh gateway in wireless mesh network. By using artificial neural networks, the network traffic can be divided into different categories, and thus, the flood attacks can be detected. In the seventh paper, Toward a flexible and fine-grained access control framework for infrastructure as a service clouds, Bo Li, Jianxin Li, Lu Liu, and Chao Zhou propose a flexible and fine-grained access control framework, named IaaS-oriented Hybrid Access Control (iHAC), to ensure that the resources cannot be illegally accessed or used. iHAC consists of three main parts: an IaaS-oriented Hybrid Access Control model, a VM-centric access control approach, and a VMM-enabled network access control mechanism. The simulation results show that iHAC can efficiently make correct access control decisions with acceptable performance overhead. In the eighth paper, An intrusion detection method for wireless sensor network based on mathematical morphology, Yanwen Wang, Xiaoling Wu, and Hainan Chen propose an innovative intrusion detection method called granulometric size distribution (GSD) method based on mathematical morphology to detect malicious attack in IoTs. If the number of active nodes in a wireless sensor network is fixed, the GSD curves are similar. Therefore, malicious nodes can be efficiently detected based on the abnormal GSD. In the last of the presented papers, A secure energy-efficient access control scheme for wireless sensor networks based on elliptic curve cryptography, Yuanyuan Zhang, Neeraj Kumar, Jianhua Chen, and Joel J. P. C. Rodrigues propose a secure energy-efficient access-control scheme for wireless sensor networks based on elliptic curve cryptography. The algorithm is explained in detail, and a variety of malicious attacks are simulated to evaluate the performance of the proposed algorithm. To summarize, we believe that this special issue will contribute to enhancing knowledge in security and privacy research in IoT in particular. In addition, we also hope that the presented results will stimulate further research in the important areas of information and network security. We also want to thank the editor-in-chief of the Security and Communication Networks journal, the leading researchers contributing to the special issue, and excellent reviewers for their great help and support that made this special issue possible. Guangjie Han, Lei Shu 0001, Sammy Chan, Jiankun Hu |
Secur. Commun. Networks | 3 |
| 2016 | The Application of DOA Estimation Approach in Patient Tracking Systems with High Patient DensityabstractIn this paper, an improved localization method named three-uniform-linear-array localization is proposed for patient track systems. Three receivers adopting a smart antenna technique cooperate with each other to locate the patients using the angulation positioning method. In order to be able to track patients in environment with high patient density, a high-resolution direction-of-arrival (DOA) estimation algorithm for the coexistence of noncircular and circular signals is proposed. First, the maximal and common noncircularity rated signals are preliminarily estimated. Second, based on the noise space block matrix, the DOAs of these signals are re-estimated with high accuracy. Then, the covariance matrix of the maximal and common noncircularity rated signals is reconstructed. The contributions of these signals are eliminated after performing a subtraction operation on the covariance matrix of the received data and only those of circular signals remain. Finally, the DOAs of circular signals are obtained. Results of simulations and real tests demonstrate the effectiveness and performance of the proposed algorithm. Liangtian Wan, Guangjie Han, Lei Shu 0001, Sammy Chan |
IEEE Trans. Ind. Informatics | 4 |
| 2015 | Security-Enhanced Reprogramming with XORs Coding in Wireless Sensor Networks
Daojing He, Sammy Chan |
ICICS | 3 |
| 2015 | Secure and Distributed Data Discovery and Dissemination in Wireless Sensor NetworksabstractA data discovery and dissemination protocol for wireless sensor networks (WSNs) is responsible for updating configuration parameters of, and distributing management commands to, the sensor nodes. All existing data discovery and dissemination protocols suffer from two drawbacks. First, they are based on the centralized approach; only the base station can distribute data items. Such an approach is not suitable for emergent multi-owner-multi-user WSNs. Second, those protocols were not designed with security in mind and hence adversaries can easily launch attacks to harm the network. This paper proposes the first secure and distributed data discovery and dissemination protocol named DiDrip. It allows the network owners to authorize multiple network users with different privileges to simultaneously and directly disseminate data items to the sensor nodes. Moreover, as demonstrated by our theoretical analysis, it addresses a number of possible security vulnerabilities that we have identified. Extensive security analysis show DiDrip is provably secure. We also implement DiDrip in an experimental network of resource-limited sensor nodes to show its high efficiency in practice. Daojing He, Sammy Chan, Mohsen Guizani, Haomiao Yang |
IEEE Trans. Parallel Distributed Syst. | 2 |
| 2015 | Accountable and Privacy-Enhanced Access Control in Wireless Sensor NetworksabstractIn general, owners and users of wireless sensor networks (WSNs) are different entities. A user may want to hide his/her data access privacy from anyone else including the network owner and, at the same time, users who misbehave need to be identified. Such requirements necessitate privacy-preserving and accountable access control. In this paper, we develop a novel protocol, named APAC, to satisfy this need. First, APAC can enforce strict access control so that the sensed data is only accessible by the authorized users. Second, APAC offers sophisticated user privacy protection. Third, misbehaving users or owners can be audited and pinpointed. Last but not least, it does not rely on the existence of a trusted third party, and thus is more feasible in practice. The feasibility of the APAC is demonstrated by experiments on resource-limited mobile devices and sensor platforms. Daojing He, Sammy Chan, Mohsen Guizani |
IEEE Trans. Wirel. Commun. | 2 |
| 2014 | Performance Analysis of Contention Based Services with Bulk Transmission in IEEE 802.16 OFDMA NetworksabstractWith the development of wireless broadband access, OFDMA technology is widely used for the next generation telecommunication systems. In this paper, we focus on analyzing the performance of contention-based services in IEEE 802.16 OFDMA networks with bulk services. We derive various performance measures such as queue utilization in an subscriber station, probability of unsuccessful bandwidth request, and the mean service time of a packet. The accuracy of the proposed analytical model is validated by extensive simulations. Jianqing Liu, Sammy Chan, Xueyuan Su, Hai Le Vu 0001 |
VTC Spring | 2 |
| 2014 | A comparative simulation study of TCP/AQM systems for evaluating the potential of neuron-based AQM schemes
Fan Li 0008, Jinsheng Sun, Moshe Zukerman, Zhengfei Liu, Sammy Chan, Guanrong Chen, King-Tim Ko |
J. Netw. Comput. Appl. | 6 |
| 2014 | A Novel and Lightweight System to Secure Wireless Medical Sensor NetworksabstractWireless medical sensor networks (MSNs) are a key enabling technology in e-healthcare that allows the data of a patient's vital body parameters to be collected by the wearable or implantable biosensors. However, the security and privacy protection of the collected data is a major unsolved issue, with challenges coming from the stringent resource constraints of MSN devices, and the high demand for both security/privacy and practicality. In this paper, we propose a lightweight and secure system for MSNs. The system employs hash-chain based key updating mechanism and proxy-protected signature technique to achieve efficient secure transmission and fine-grained data access control. Furthermore, we extend the system to provide backward secrecy and privacy preservation. Our system only requires symmetric-key encryption/decryption and hash operations and is thus suitable for the low-power sensor nodes. This paper also reports the experimental results of the proposed system in a network of resource-limited motes and laptop PCs, which show its efficiency in practice. To the best of our knowledge, this is the first secure data transmission and access control system for MSNs until now. Daojing He, Sammy Chan, Shaohua Tang |
IEEE J. Biomed. Health Informatics | 2 |
| 2014 | Lightweight and Confidential Data Discovery and Dissemination for Wireless Body Area NetworksabstractAs a special sensor network, a wireless body area network (WBAN) provides an economical solution to real-time monitoring and reporting of patients' physiological data. After a WBAN is deployed, it is sometimes necessary to disseminate data into the network through wireless links to adjust configuration parameters of body sensors or distribute management commands and queries to sensors. A number of such protocols have been proposed recently, but they all focus on how to ensure reliability and overlook security vulnerabilities. Taking into account the unique features and application requirements of a WBAN, this paper presents the design, implementation, and evaluation of a secure, lightweight, confidential, and denial-of-service-resistant data discovery and dissemination protocol for WBANs to ensure the data items disseminated are not altered or tampered. Based on multiple one-way key hash chains, our protocol provides instantaneous authentication and can tolerate node compromise. Besides the theoretical analysis that demonstrates the security and performance of the proposed protocol, this paper also reports the experimental evaluation of our protocol in a network of resource-limited sensor nodes, which shows its efficiency in practice. In particular, extensive security analysis shows that our protocol is provably secure. Daojing He, Sammy Chan, Yan Zhang 0002, Haomiao Yang |
IEEE J. Biomed. Health Informatics | 2 |
| 2014 | Multi-Path Routing and Forwarding in Non-Cooperative Wireless NetworksabstractMulti-path routing and forwarding in non-cooperative networks is extremely challenging due to the co-existence of both rational and Byzantine nodes. They both might deviate from the protocol; however, their intentions and behaviors are totally different. Rational nodes aim to maximize their utilities, while Byzantine nodes purposefully deviate from the protocol to disrupt the normal operation of a network. Most work in the literature treat both kinds of misbehavior without distinction and thus lead to ineffective solutions. This paper presents a hybrid design that seamlessly integrates mechanisms for different misbehavior in a unified framework. The GSP auction provides incentives for rational nodes to cooperate and results in truth-telling Nash equilibria. With the possible inclusion of Byzantine nodes in the least cost paths selected by GSP, the FORBID mechanism builds a decentralized reputation system such that malicious behavior is effectively detected. This in turn triggers the GSP auction to update the least cost paths so as to exclude the malicious nodes from being selected for communication. It is proved that the unified protocol is cooperation-optimal. Experiments have been conducted to further investigate the performance of the proposed protocol and the impact of various parameters. Xueyuan Su, Gang Peng 0001, Sammy Chan |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 2014 | Performance analysis and optimization of best-effort service in IEEE 802.16 networksabstractThe IEEE 802.16-based WiMAX technology has great potential for the fourth-generation mobile networks. Some of its service classes use the contention-based broadcast polling mechanism to request resources. In this paper, we investigate the performance experienced by these services when the network is unsaturated. In particular, we model each subscriber station as an M/G/1 queue where the service time is determined by the parameters of the network configuration and the binary exponential backoff contention resolution algorithm. We develop a fixed-point analysis to derive analytical expressions for network throughput and packet access delay. The accuracy of the analytical model is validated by comparing it with simulation over a wide range of operating conditions. The implications of various different parameter configurations on the performance are investigated using the analytical model. Moreover, we show that the model can be degenerated to the saturated condition. The utility of both the unsaturated and saturated models is further demonstrated by finding the optimal set of parameter values that maximize the network throughput. Sammy Chan, Hai Le Vu 0001, Jianqing Liu |
Wirel. Commun. Mob. Comput. | 1 |
| 2013 | Decentralized Power Control for Random Access with Successive Interference CancellationabstractThis paper is concerned with the decentralized power allocation problem in random access systems. We propose a scheme that is especially suitable for systems requiring high throughput but with difficulty in establishing centralized control, such as cognitive radio environments. Specifically, we assume successive interference cancellation (SIC) at the receiver for multi-packet reception (MPR). We consider a decentralized random power transmission strategy where each user selects its transmitted power level randomly according to a power distribution conditioned on its own channel state. Our focus is on the design of this distribution such that the system packet throughput is maximized under rate and power constraints. We start from a two-user system. A main finding of this paper is that the supports of the optimal power distributions are of discrete nature. This finding greatly simplifies the distribution optimization problem. We also discuss a sub-optimal solution to systems with more than two users. Numerical results demonstrate that the proposed scheme can achieve noticeable performance improvement compared with conventional single-user detection (SUD) based ones and offer a flexible tradeoff between the system throughput and power consumption. Chongbin Xu, Li Ping 0001, Peng Wang 0008, Sammy Chan, Xiaokang Lin |
IEEE J. Sel. Areas Commun. | 4 |
| 2013 | Handauth: Efficient Handover Authentication with Conditional Privacy for Wireless NetworksabstractExisting mechanisms for handover authentication mainly focus on designing a secure authentication module, little attention has been paid to protect users' privacy when they are authenticated by the access points for data access. Further, most existing approaches do not support user revocation. In this paper, we present a secure and efficient authentication protocol named Handauth. Similar to the mechanisms of this field, Handauth provides user authentication and session key establishment. However, compared to other well-known approaches, Handauth not only enjoys both computation and communication efficiency, but also achieves strong user anonymity and untraceablility, forward secure user revocation, conditional privacy-preservation, AAA server anonymity, access service expiration management, access point authentication, easily scheduled revocation, dynamic user revocation and attack resistance. Experimental results show that the proposed approach is feasible for real applications. Daojing He, Jiajun Bu, Sammy Chan, Chun Chen 0001 |
IEEE Trans. Computers | 3 |
| 2013 | Secure and Lightweight Network Admission and Transmission Protocol for Body Sensor NetworksabstractA body sensor network (BSN) is a wireless network of biosensors and a local processing unit, which is commonly referred to as the personal wireless hub (PWH). Personal health information (PHI) is collected by biosensors and delivered to the PWH before it is forwarded to the remote healthcare center for further processing. In a BSN, it is critical to only admit eligible biosensors and PWH into the network. Also, securing the transmission from each biosensor to PWH is essential not only for ensuring safety of PHI delivery, but also for preserving the privacy of PHI. In this paper, we present the design, implementation, and evaluation of a secure network admission and transmission subsystem based on a polynomial-based authentication scheme. The procedures in this subsystem to establish keys for each biosensor are communication efficient and energy efficient. Moreover, based on the observation that an adversary eavesdropping in a BSN faces inevitable channel errors, we propose to exploit the adversary's uncertainty regarding the PHI transmission to update the individual key dynamically and improve key secrecy. In addition to the theoretical analysis that demonstrates the security properties of our system, this paper also reports the experimental results of the proposed protocol on resource-limited sensor platforms, which show the efficiency of our system in practice. Daojing He, Chun Chen 0001, Sammy Chan, Jiajun Bu, Pingxin Zhang |
IEEE J. Biomed. Health Informatics | 3 |
| 2013 | Secure Data Discovery and Dissemination based on Hash Tree for Wireless Sensor NetworksabstractWireless sensor networks (WSNs) are widely applicable in monitoring and control of environment parameters. It is sometimes necessary to disseminate data through wireless links after they are deployed in order to adjust configuration parameters of sensors or distribute management commands and queries to sensors. Several approaches have been proposed recently for data discovery and dissemination in WSNs. However, they all focus on how to ensure reliability and usually overlook security vulnerabilities. This paper identifies the security vulnerabilities in data discovery and dissemination when used in WSNs. Such vulnerabilities allow an adversary to update a network with undesirable values, erase critical variables, or launch denial-of-service (DoS) attacks. To address these vulnerabilities, this paper presents the design, implementation, and evaluation of a secure, lightweight, and DoS-resistant data discovery and dissemination protocol named SeDrip for WSNs. Our protocol takes into consideration the limited resources of sensor nodes, packet loss and out-of-sequence packet delivery. Also, it can provide instantaneous authentication without packet buffering delay, and tolerate node compromise. Besides the theoretical analysis that demonstrates the security and performance of SeDrip, this paper also reports the experimental evaluation of SeDrip in a network of resource-limited sensor nodes, which shows its efficiency in practice. Daojing He, Sammy Chan, Shaohua Tang, Mohsen Guizani |
IEEE Trans. Wirel. Commun. | 2 |
| 2012 | IAPI: An intelligent adaptive PI active queue management scheme
Jinsheng Sun, Sammy Chan, Moshe Zukerman |
Comput. Commun. | 2 |
| 2012 | Secure and efficient dynamic program update in wireless sensor networksabstractABSTRACT Dynamic program update protocols provide a convenient way to reprogram sensor nodes after deployment. However, designing a secure program update protocol for wireless sensor networks is a difficult task because wireless networks are susceptible to attacks and nodes have limited resources. Recently, two secure program update protocols using orthogonality principle have been found to be vulnerable to two impersonation attacks, although these attacks are rather restrictive. This paper reports one new attack that is more general and makes the program update protocols even more vulnerable. With this attack, an attacker can easily impersonate the base station to install his/her preferred program on sensor nodes and then obtain control over the network. As a remedy, two simple countermeasures are suggested to defend against all these attacks. Finally, the security properties of the two proposed solutions are formally validated by a model checking tool. Copyright © 2011 John Wiley & Sons, Ltd. Daojing He, Sammy Chan, Chun Chen 0001, Jiajun Bu |
Secur. Commun. Networks | 2 |
| 2012 | ReTrust: Attack-Resistant and Lightweight Trust Management for Medical Sensor NetworksabstractWireless medical sensor networks (MSNs) enable ubiquitous health monitoring of users during their everyday lives, at health sites, without restricting their freedom. Establishing trust among distributed network entities has been recognized as a powerful tool to improve the security and performance of distributed networks such as mobile ad hoc networks and sensor networks. However, most existing trust systems are not well suited for MSNs due to the unique operational and security requirements of MSNs. Moreover, similar to most security schemes, trust management methods themselves can be vulnerable to attacks. Unfortunately, this issue is often ignored in existing trust systems. In this paper, we identify the security and performance challenges facing a sensor network for wireless medical monitoring and suggest it should follow a two-tier architecture. Based on such an architecture, we develop an attack-resistant and lightweight trust management scheme named ReTrust. This paper also reports the experimental results of the Collection Tree Protocol using our proposed system in a network of TelosB motes, which show that ReTrust not only can efficiently detect malicious/faulty behaviors, but can also significantly improve the network performance in practice. Daojing He, Chun Chen 0001, Sammy Chan, Jiajun Bu, Athanasios V. Vasilakos |
IEEE Trans. Inf. Technol. Biomed. | 3 |
| 2012 | A Distributed Trust Evaluation Model and Its Application Scenarios for Medical Sensor NetworksabstractThe development of medical sensor networks (MSNs) is imperative for e-healthcare, but security remains a formidable challenge yet to be resolved. Traditional cryptographic mechanisms do not suffice given the unique characteristics of MSNs, and the fact that MSNs are susceptible to a variety of node misbehaviors. In such situations, the security and performance of MSNs depend on the cooperative and trust nature of the distributed nodes, and it is important for each node to evaluate the trustworthiness of other nodes. In this paper, we identify the unique features of MSNs and introduce relevant node behaviors, such as transmission rate and leaving time, into trust evaluation to detect malicious nodes. We then propose an applicationindependent and distributed trust evaluation model for MSNs. The trust management is carried out through the use of simple cryptographic techniques. Simulation results demonstrate that the proposed model can be used to effectively identify malicious behaviors and thereby exclude malicious nodes. This paper also reports the experimental results of the Collection Tree Protocol with the addition of our proposed model in a network of TelosB motes, which show that the network performance can be significantly improved in practice. Further, some suggestions are given on how to employ such a trust evaluation model in some application scenarios. Daojing He, Chun Chen 0001, Sammy Chan, Jiajun Bu, Athanasios V. Vasilakos |
IEEE Trans. Inf. Technol. Biomed. | 3 |
| 2012 | Secure and Efficient Handover Authentication Based on Bilinear Pairing FunctionsabstractSeamless handover over multiple access points is highly desirable to mobile nodes, but ensuring security and efficiency of this process is challenging. This paper shows that prior handover authentication schemes incur high communication and computation costs, and are subject to a few security attacks. Further, a novel handover authentication protocol named PairHand is proposed. PairHand uses pairing-based cryptography to secure handover process and to achieve high efficiency. Also, an efficient batch signature verification scheme is incorporated into PairHand. Experiments using our implementation on laptop PCs show that PairHand is feasible in real applications. Daojing He, Chun Chen 0001, Sammy Chan, Jiajun Bu |
IEEE Trans. Wirel. Commun. | 3 |
| 2012 | DiCode: DoS-Resistant and Distributed Code Dissemination in Wireless Sensor NetworksabstractCode dissemination in a wireless sensor network (WSN) is the process of propagating a new program image or relevant commands to sensor nodes. As a WSN is usually deployed in hostile environments, secure code dissemination is and will continue to be a major concern. Most code dissemination protocols are based on the centralized approach in which only the base station has the authority to initiate code dissemination. However, it is desirable and sometimes necessary to disseminate code images in a distributed manner which allows multiple authorized network users to simultaneously and directly update code images on different nodes without involving the base station. Motivated by this consideration, we develop a secure and distributed code dissemination protocol named DiCode. A salient feature of DiCode is its ability to resist denial-of-service attacks which have severe consequences on network availability. Further, the security properties of our protocol are demonstrated by theoretical analysis. To verify the efficiency of the proposed approach in practice, we also implement the proposed mechanism in a network of resource-constrained sensor nodes. Daojing He, Chun Chen 0001, Sammy Chan, Jiajun Bu |
IEEE Trans. Wirel. Commun. | 3 |
| 2012 | Performance Modeling of Broadcast Polling in IEEE 802.16 Networks with Finite-Buffered Subscriber StationsabstractIn this paper, an approximated model is proposed to analyze the performance of the contention based services via broadcast polling in unsaturated IEEE 802.16 networks with channel errors. The main idea is that each subscriber station with buffer capacity K can be treated as a M/G/1/K queue with service time determined by the backoff process of broadcast polling. Using this model, the normalized network throughput and the distribution of the packet delay are derived. This proposed analytical model is useful for performance evaluation and optimization of best effort or contention-based non-real time polling services. Our simulator written in C++ verifies the accuracy of the proposed analytical model. Furthermore, we show that the model gives good approximations for network performance with a more realistic bursty arrival process at light load, while providing conservative performance measures at medium and high loads. Jianqing Liu, Sammy Chan, Hai Le Vu 0001 |
IEEE Trans. Wirel. Commun. | 2 |
| 2011 | FORBID: Cope with Byzantine Behaviors in Wireless Multi-Path Routing and ForwardingabstractConsider multi-path routing and forwarding scenarios in wireless ad hoc networks. Rational and Byzantine nodes both might deviate from the protocol. However, their intentions and behaviors are different. To extend our previous work on generalized second price (GSP) auction for stimulating rational nodes for cooperation, we propose FORBID mechanism in this work to cope with Byzantine behaviors. The core of the FORBID mechanism is a decentralized reputation system. Based on available evidence, each node relies on Bayesian inference to internally update its reputation beliefs that how reliable each other node is. Different from the passive overhearing techniques such as ``watchdog'', each source node under FORBID actively triggers detection process to collect evidence towards Byzantine behaviors. In addition, FORBID includes a flocking algorithm to allow careful dissemination of reputation information and thus shortens the misbehavior detection time. Xueyuan Su, Gang Peng 0001, Sammy Chan |
GLOBECOM | 3 |
| 2011 | High-Throughput Routing with Superposition Coding and Successive Interference CancellationabstractNetwork coding aware routing protocols have been an interesting research topic in recent years. In this paper, we explore similar routing gains with physical layer coding techniques. A source routing protocol S3 is proposed to be implemented with a routing metric called iETT. By extending the traditional ETT measurement, iETT provides a simple way to make the routing protocol interference-aware. To further enable superposition coding and successive interference cancellation, S3 uses iETT to explore physical layer coding opportunities and measure potential gains in network throughput. Experimental evaluations confirm the effectiveness of iETT and S3. Significant improvements in network throughput are observed in both single-path and multi-path routing scenarios. Xueyuan Su, Sammy Chan |
ICC | 2 |
| 2011 | Distributed privacy-preserving access control in a single-owner multi-user sensor networkabstractA distributed access control module in wireless sensor networks (WSNs) allows the network to authorize and grant user access privileges for in-network data access. Prior research mainly focuses on designing such access control modules for WSNs, but little attention has been paid to protect user's identity privacy when a user is verified by the network for data accesses. Often, a user does not want the WSN to associate his identity to the data he requests, particularly in a single-owner multi-user WSN. In this paper, we present the design, implementation, and evaluation of a novel approach, Priccess, to ensure privacy-preserving access control. In addition to the theoretical analysis that demonstrates the security properties of Priccess, this paper also reports the experimental results of Priccess in a network of Imote2 motes, which show the efficiency of Priccess in practice. Daojing He, Jiajun Bu, Sencun Zhu, Mingjian Yin, Yi Gao 0001, Sammy Chan, Chun Chen 0001 |
INFOCOM | 7 |
| 2011 | Performance modelling of broadcast polling protocol in unsaturated IEEE 802.16 networksabstractIn this paper, we propose a general model for the broadcast polling protocol of unsaturated IEEE 802.16 networks in which each subscriber station has a finite buffer. A subscriber station can be modelled as a M/G/1/K queue with its service time determined by the broadcast polling protocol. The buffer overflow probability, network throughput and packet delay performances are analyzed. The proposed model is validated by simulation confirming its accuracy for various scenarios studied. Jianqing Liu, Sammy Chan, Hai Le Vu 0001 |
LCN | 2 |
| 2011 | Optimal throughput for 802.11 DCF with multiple packet receptionabstractIn this paper, we propose an analytical model for evaluating the MAC throughput in an unsaturated IEEE 802.11 wireless local area network (WLAN) where multiple packets reception (MPR) is possible using multiuser detection techniques. In particular, a recently proposed successive interference cancellation (SIC) scheme for MPR is considered where users can randomly choose the transmission power from a set of discrete power levels. We derive an explicit expression for throughput of the WLAN based on such an SIC scheme and validate the accuracy of the model via ns-2 simulation results. We show that the throughput is significantly improved compared to the conventional 802.11 MAC protocol just by resolving collisions between two packets with different transmission power levels. In addition, we provide the optimal power distribution to maximize the throughput achievable in an SIC-enabled WLAN. Mingrui Zou, Sammy Chan, Hai Le Vu 0001, Chongbin Xu, Li Ping 0001 |
LCN | 2 |
| 2011 | Performance effects of two-way FAST TCP
Fei Ge, Sammy Chan, Lachlan L. H. Andrew, Fan Li 0008, Liansheng Tan, Moshe Zukerman |
Comput. Networks | 2 |
| 2011 | Privacy-Preserving Universal Authentication Protocol for Wireless CommunicationsabstractSeamless roaming over wireless networks is highly desirable to mobile users, and security such as authentication of mobile users is challenging. In this paper, we propose a privacy-preserving universal authentication protocol, called Priauth, which provides strong user anonymity against both eavesdroppers and foreign servers, session key establishment, and achieves efficiency. Most importantly, Priauth provides an efficient approach to tackle the problem of user revocation while supporting strong user untraceability. Daojing He, Jiajun Bu, Sammy Chan, Chun Chen 0001, Mingjian Yin |
IEEE Trans. Wirel. Commun. | 3 |
| 2011 | Distributed Access Control with Privacy Support in Wireless Sensor NetworksabstractA distributed access control module in wireless sensor networks (WSNs) allows the network to authorize and grant user access privileges for in-network data access. Prior research mainly focuses on designing such access control modules for WSNs, but little attention has been paid to protect user's identity privacy when a user is verified by the network for data accesses. Often, a user does not want the WSN to associate his identity to the data he requests. In this paper, we present the design, implementation, and evaluation of a novel approach, Priccess, to ensure distributed privacy-preserving access control. In Priccess, users who have similar access privileges are organized into the same group by the network owner. A network user signs a query command on behalf of his group and then sends the signed query to the sensor nodes of his interest. The signature can be verified by its recipient as coming from someone authorized without exposing the actual signer. In addition to the theoretical analysis that demonstrates the security properties of Priccess, this paper also reports the experimental results of Priccess in a network of Imote2 motes, which show the efficiency of Priccess in practice. Daojing He, Jiajun Bu, Sencun Zhu, Sammy Chan, Chun Chen 0001 |
IEEE Trans. Wirel. Commun. | 4 |
| 2010 | A priority-based processor sharing model for TDM passive optical networksabstractThe use of passive optical networks (PONs) enables access rates of multi-Gbit/sec bandwidth and provision of quality of service for high definition multimedia services. In this paper, we consider and analyse a generic multi-priority dynamic bandwidth allocation (DBA) algorithm for TDM PONs serving multimedia traffic in an upstream link. PON traffic is served strictly according to its priority. We consider this DBA algorithm using two approaches: (i) the algorithm assigns a fixed service quantum to each priority service and (ii) different service quanta are assigned to different priority services. The mean message delay is evaluated using a multiqueue processor sharing (MPS) model and an MPS with Heterogeneous Traffic (MPS-HT)model for the two approaches respectively. The MPS model is a classical processor sharing model limited by the critical assumption that there is egalitarian service sharing among all users, which is inefficient for multimedia applications in PONs. We extend the MPS model to a general MPS-HT model that enables the analysis of message delay performance in the case where the service quanta may be different for different services. Moshe Zukerman, Ron Addie, Sammy Chan, Richard J. Harris 0001 |
IEEE J. Sel. Areas Commun. | 4 |
| 2009 | Generalized Second Price Auction in Multi-Path Routing with Selfish NodesabstractWe model the multi-path routing with selfish nodes as an auction and provide a novel solution from the game-theoretical perspective. By adapting the idea of generalized second price (GSP) payment originating from Internet advertising business and developing pertinent policies for multi-hop networks, we design a mechanism that results in Nash equilibria rather than the traditional strategyproofness, which alleviates the over-payment problem of the widely used Vickrey-Clark-Groves (VCG) payment mechanism. We first provide rigorous theoretical analysis of the proposed mechanism, showing the equilibrium behavior and bounds of the over-payment alleviation, and then evaluate the effectiveness of this protocol through extensive simulations. Xueyuan Su, Sammy Chan, Gang Peng 0001 |
GLOBECOM | 2 |
| 2008 | Priority-Based fair Scheduling for Multimedia WiMAX Uplink TrafficabstractWorldwide interoperability for microwave access (WiMAX) is based on the IEEE 802.16 Standard with mobility support from the 802.16e amendment and it enables convergence of mobile and fixed broadband wireless networks covering metropolitan and rural areas. WiMAX traffic management aims at providing efficient delivery of multimedia applications with a range of QoS requirements. Focussing on the point-to-multipoint mode, we propose a priority-based fair scheduling algorithm for subscriber stations to serve a mixture of uplink traffic from different scheduling services and provide an analytical model for evaluating user-perceived delay performance under this scheduling scheme. The model is supported and validated by a simulation study. We present numerical results to illustrate the effect of traffic load and other design parameters on WiMAX message delay. Sammy Chan, Moshe Zukerman, Richard J. Harris 0001 |
ICC | 2 |
| 2008 | Combination Load Balancing for Video-on-Demand SystemsabstractWe observe that an effect of ldquodisk resource sharingrdquo of multi-copy movie traffic has great impact on the blocking performance of a video-on-demand system. This observation leads us to establish a conjecture on how to balance the movie traffic load among ldquocombinationrdquo groups of disks to maximize the level of disk resource sharing. For a given file replication instance, the conjecture predicts in general an effective lower bound on the blocking performance of the system. It motivates the design of a numerical index that measures quantitatively the goodness of disk resource sharing on allocation of multi-copy movie files. It also motivates the design of a greedy file allocation method that decides a good quality heuristic solution for each feasible file replication instance. We further develop analytical formulas to obtain approximate results for the bound fast and accurately. These techniques can be utilized by an optimization program to find near-optimal file assignment solutions for the system computationally efficiently. Jun Guo 0001, Eric Wing Ming Wong, Sammy Chan, Peter G. Taylor, Moshe Zukerman, Wallace Kit-Sang Tang |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2008 | Evolutionary Optimization of File Assignment for a Large-Scale Video-on-Demand SystemabstractWe present a genetic algorithm for tackling a file assignment problem for a large-scale video-on-demand system. The file assignment problem is to find the optimal replication and allocation of movie files to disks so that the request blocking probability is minimized subject to capacity constraints. We adopt a divide-and-conquer strategy, where the entire solution space of file assignments is divided into subspaces. Each subspace is an exclusive set of solutions sharing a common file replication instance. This allows us to utilize a greedy file allocation method for finding a good-quality heuristic solution within each subspace. We further design two performance indices to measure the quality of the heuristic solution on 1.) its assignment of multicopy movies and 2.) its assignment of single-copy movies. We demonstrate that these techniques, together with ad hoc population handling methods, enable genetic algorithms to operate in a significantly reduced search space and achieve good-quality file assignments in a computationally efficient way. Jun Guo 0001, Yi Wang 0017, Wallace Kit-Sang Tang, Sammy Chan, Eric Wing Ming Wong, Peter G. Taylor, Moshe Zukerman |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2008 | Performance Analysis of Resource Selection Schemes for a Large Scale Video-on-Demand SystemabstractThe designers of a large scale video-on-demand system face an optimization problem of deciding how to assign movies to multiple disks (servers) such that the request blocking probability is minimized subject to capacity constraints. To solve this problem, it is essential to develop scalable and accurate analytical means to evaluate the blocking performance of the system for a given file assignment. The performance analysis is made more complicated by the fact that the request blocking probability depends also on how disks are selected to serve user requests for multicopy movies. In this paper, we analyze several efficient resource selection schemes. Numerical results demonstrate that our analysis is scalable and sufficiently accurate to support the task of file assignment optimization in such a system. Jun Guo 0001, Eric Wing Ming Wong, Sammy Chan, Peter G. Taylor, Moshe Zukerman, Wallace Kit-Sang Tang |
IEEE Trans. Multim. | 3 |
| 2007 | A QoS Architecture for IDMA-Based Multi-Service Wireless NetworksabstractThe recent investigations on interleave-division multiple-access (IDMA) have demonstrated its advantage in supporting high-data-rate and multi-rate services over wireless fading channels. This paper focuses on quality of service (QoS) guarantee in IDMA-based multi-service wireless networks. We propose a QoS architecture which addresses the key issues of QoS guarantee for multi-service in IDMA, including medium access control (MAC), admission control, power control, and rate allocation. The proposed IDMA QoS architecture avoids complex packet scheduling at the MAC layer which is however required in other existing multiple access systems. Data packets can be transmitted in IDMA without scheduling delay. Additionally, to improve the efficiency of random access, an interleave- division slotted-ALOHA (IDSA) access method is proposed for the IDMA MAC protocol. We derive the relationship between the arrival rate of access requests and the number of access interleavers allocated to an IDMA system for a given access success probability. Based on this relationship, we can adaptively adjust the number of access interleavers according to the traffic load of access requests, so as to ensure a satisfactory probability of successful access as well as low complexity of request detection at the receiver. Qian Huang 0003, Sammy Chan, King-Tim Ko, Li Ping 0001, Peng Wang 0008 |
ICC | 2 |
| 2007 | RLAR: Robust Link Availability Routing Protocol for Mobile Ad Hoc NetworksabstractMany previously proposed routing metrics and algorithms for ad hoc networks work well in static networks, however, when nodes are moving and wireless links may fail from time to time, these routing metrics and algorithms are prone to poor performance. A cross-layer based routing protocol for mobile ad hoc networks, called Robust Link Availability Routing (RLAR) protocol, is proposed in this paper. RLAR consists of two modules, which estimates the link reliability using physical layer information and deals with robust optimal routing, respectively. Based on the optimal tree backbone, a mesh structure is formed for reliability enhancement. Through simulations, RLAR is proved to be able to increase the packet delivery ratio and reduce the frequency of re routings for dynamic network topologies. Xueyuan Su, Sammy Chan, King Sun Chan |
ICC | 2 |
| 2007 | An Error-aware and Energy Efficient Routing Protocol in MANETsabstractThe network lifetime is a key design factor of mobile ad-hoc networks (MANETs). To prolong the lifetime of MANETs, one is forced to attain the tradeoff of minimizing the energy consumption and load balancing. In MANETs, energy waste resulting from retransmission due to high frame error rate (FER) of wireless channel is significant. In this paper, we propose a novel protocol termed error-aware candidate set routing protocol (ECSRP). ECSRP chooses a route in a candidate subset in the route cache in which all the nodes have enough residual battery power. This approach avoids overusing certain routes. If multiple routes exist in the candidate set, ECSRP employs a metric achieving the tradeoff between energy-efficiency and load balancing to select the optimal route. It also takes channel condition into consideration by incorporating packet loss probability in the computation of energy consumption. This helps to reduce the number of retransmissions and save energy. We evaluate the performance of ECSRP under the Gilbert error model. Simulation results demonstrate that ECSRP outperforms the representative protocol conditional min-max battery cost routing (CMMBCR) protocol in terms of total energy consumption and load balancing. Liansheng Tan, Sammy Chan |
ICCCN | 3 |
| 2007 | Instability effects of two-way traffic in a TCP/AQM system
Jinsheng Sun, Sammy Chan, King-Tim Ko, Guanrong Chen, Moshe Zukerman |
Comput. Commun. | 2 |
| 2007 | Improving Wireless TCP Throughput by a Novel TCM-Based Hybrid ARQabstractA novel hybrid ARQ (HARQ) scheme using a concatenated two-state trellis-coded modulation (CT-TCM) code is proposed for improving wireless TCP throughput. A distinguished feature of the proposed scheme is that the heavily punctured TCM codes are used for retransmissions of the corrupted data block, which are combined at the receiver with the previously received sequences of the same data block for decoding. By this method, significantly improved coding gain and efficient spectrum utilization can be achieved with very low complexity. A Markov model is developed to evaluate TCP throughput over the proposed HARQ in wireless link. By both analysis and simulation, we demonstrate that compared with other existing TCM-based ARQ schemes, significant improvement of TCP throughput over wireless links is achieved by the proposed CT-TCM HARQ while smaller buffer size is required at the access point. Qian Huang 0003, Sammy Chan, Li Ping 0001, Moshe Zukerman |
IEEE Trans. Wirel. Commun. | 2 |
| 2006 | Max-min Fair Rate Allocation in Multi-hop Wireless Ad Hoc NetworksabstractIn this paper, a price-based rate allocation scheme for multi-hop wireless ad hoc networks is proposed. To accurately reflect the clique constraint of wireless ad hoc networks, the clique-based price is proposed to act as the congestion signal, which controls the end-to-end rates of multi-hop flows. Through simulation, the proposed scheme is shown to be able to effectively distribute the bandwidth, according to max-min fair criterion, to multi-hop flows from the end-to-end perspective Xueyuan Su, Sammy Chan |
MASS | 2 |
| 2005 | A novel method for modeling and analysis of distributed video on demand systemsabstractWe consider a simple model for distributed video on demand (VoD) systems. The model is analyzed by the Erlang fixed point (EFP) approximation and by a new method referred to as overflow priority classification (OPC). The OPC method imposes a preemptive priority regime in a non-priority system to capture the traffic load dependence among VoD servers. Comparison between OPC and EFP reveals that OPC is more accurate. The comparison is made with respect to two quality of service (QoS) measures, the loss probability and the probability that a video request is not served by the preferred VoD server given that it is not lost. Eric Wing Ming Wong, Michael Y. M. Chiu, Moshe Zukerman, Zvi Rosberg, Sammy Chan, Andrew Zalesky |
ICC | 5 |
| 2004 | Designing a stable and effective PD-control AQMabstractFrom the control theory point of view, it is reasonable to regard the TCP congestion control mechanism as a feedback control system. The TCP congestion control is complemented by the active queue management (AQM) scheme implemented in the routers, which could improve the effectiveness. Recently, an effective proportional-differential (PD) control algorithm has been proposed as a new AQM scheme for TCP congestion control. But it is still difficult to assign the parameter values of the PD-controller. This paper proposes a method for the design of an effective and stable PD-control AQM for routers in the Internet. For this purpose, a first-order plus time-delay TCP model is constructed, and a relay feedback method is employed to determine a set of stable parameter values of the model. From this set of values, and the requirements of the gain and phase margin, the specified parameter values of the PD-controller can be easily obtained by scanning the stable parameter set. King-Tim Ko, Guanrong Chen, Jinsheng Sun, Sammy Chan |
ICARCV | 5 |
| 2004 | Performance benchmarks for an interactive video-on-demand systemabstractLittle and Venkatesh conjectured that, for an interactive VoD system with a single random trial resource selection scheme, the blocking probability of a user's request is minimized when the overall movie traffic load is spread uniformly on each disk in the system. In this paper, we generalize this conjecture to the situation where there can be repeated random trials or where a least busy fit resource selection scheme is used. We support our conjecture with a simulation of a realistic system, and propose a metric following the idea of our conjecture to assess the goodness of movie assignment in the system. Jun Guo 0001, Peter G. Taylor, Eric Wing Ming Wong, Sammy Chan, Moshe Zukerman, Wallace Kit-Sang Tang |
ICC | 4 |
| 2004 | Effect of Large Buffers on TCP Queueing BehaviorabstractUsing a simple model of saturated, synchronized and homogeneous sources of TCP Reno with drop-tail queue management and a discrete-time framework, we derive formulae for stationary as well as transient queueing behavior that shed light on the relationship between large buffers and work conservation (queue never empties). Using simulations, the relevance of the results for the case of non-synchronized sources is demonstrated. In particular, we demonstrate that a certain simple lower bound for the stationary queue length applies also to the case where the sources are non-stationary. Jinsheng Sun, Moshe Zukerman, King-Tim Ko, Guanrong Chen, Sammy Chan |
INFOCOM | 5 |
| 2003 | PD-controller: a new active queue management schemeabstractThis paper describes a proportional-differential (PD) control algorithm as a new active queue management (AQM) scheme for TCP/IP congestion control. From the viewpoint of the control theory, TCP congestion control system can be regarded as a feedback regulating system. In this paper, a robust AQM called PD-controller is proposed. The design principles of PD-controller are presented in details. Its performance is extensively evaluated by simulations. The results demonstrate that the PD-controller AQM is stable and robust against traffic load fluctuations, UDP and HTTP disturbances. Its superiority over other AQMs is also demonstrated. Jinsheng Sun, Guanrong Chen, King-Tim Ko, Sammy Chan, Moshe Zukerman |
GLOBECOM | 4 |
| 2003 | On the efficient use of video-on-demand storage facilityabstractWe consider a video-on-demand system in which multiple copies of each movie file are kept in separate disks. Various schemes for file allocation and retrieval are considered and compared. We have introduced a certain easy-to-implement scheme that requires 15% more storage than another certain harder-to-implement scheme. Jun Guo 0001, Peter G. Taylor, Moshe Zukerman, Sammy Chan, Wallace Kit-Sang Tang, Eric Wing Ming Wong |
ICME | 4 |
| 2002 | Call Admission Control for 3G CDMA Networks with Differentiated QoS
Qian Huang 0003, Hui-Min Chen, King-Tim Ko, Sammy Chan, King Sun Chan |
NETWORKING | 4 |
| 2000 | A New Max-Min Fairness Definition to Neutralize Malicious UsersabstractEnforcement of max-min fairness encourages end users to implement adaptive end-to-end flow control. This pushes back the responsibility of controlling congestion to users and guarantees reliable and efficient network operation. Unfortunately, there could be malicious users who are indifferent to congestion and intentionally cause performance degradation to other users. The commonly used max-min fairness definition might allocate more resources to malicious users than they deserve and hence cause network inefficiency. This paper proposes a modified max-min definition according to which strict priority is given to cooperative users over malicious ones. We demonstrate that implementation of such two-priority fairness in local network bottlenecks will achieve controlled congestion as well as global fairness, even in the presence of malicious users. This paper motivates the need for traffic measurements to identify malicious users. Sammy Chan, Moshe Zukerman |
ICC (3) | 1 |
| 1998 | Achieving fair and high packet-level throughput in ABR serviceabstractFair packet discarding (FPD) is a mechanism which provides incentives to users for participation in congestion control, such that ATM networks can operate in a more efficient manner. In this paper, we propose a simple congestion control framework consisting of FPD and ATM Forum's explicit-rate flow control scheme. By simulations, we show that this framework enables the packet-level throughput of each connection converging to the max-min fair apportionment in a distributed manner. With the built-in policing capability of FPD, this framework also eliminates the need of usage parameter control for ABR service. Sammy Chan, Moshe Zukerman, Eric Wing Ming Wong, King-Tim Ko, Edmund Yeung |
ICC | 1 |
| 1998 | Iterative decoding of concatenated Hadamard codesabstractWe investigate the decoding technique and performance of concatenated Hadamard codes. Efficient soft-in-soft-out decoding algorithms based on the fast Hadamard transform are developed. The performance required by CDMA mobile or PCS speech services, e.g., BER=10/sup -3/, can be achieved at E/sub b//N/sub 0/=0.5 dB using short interleaver length of 198 bits. Li Ping 0001, Sammy Chan |
ICC | 2 |
| 1998 | Iterative decoding of multi-dimensional concatenated single parity check codesabstractThis paper is concerned with the decoding technique and performance of multi-dimensional concatenated single-parity-check (SPC) code. A very efficient sub-optimal soft-in-soft-out decoding rule is presented for the SPC code, costing only 3 addition-equivalent-operations per information bit. Multi-dimensional concatenated coding and decoding principles are investigated. Simulation results of rate 5/6 and 4/5 3-dimensional concatenated SPC codes are provided. Performance of BER=10/sup -4/-10/sup -5/ can be achieved by the MAP and max-log-MAP decoders, respectively, with E/sub b//N/sub 0/ only 1 and 1.5 dB away from the theoretical limits. Li Ping 0001, Sammy Chan, Kwan Lawrence Yeung |
ICC | 2 |
| 1997 | Max-Log-MAP Filtering Algorithm for Decoding Product F24 CodeabstractThis paper presents a symbol-by-symbol decoding method for the F/sub 24/ code. It forms the core part of an iterative Max-Log-MAP filtering algorithm for the product F/sub 24/ code and noticeable coding gain is observed by simulation The complexity of the proposed algorithm is very modest. The relatively short frame length of the product F/sub 24/ code can be an advantage for its applications in some communication systems. Li Ping 0001, Sammy Chan, Kwan Lawrence Yeung |
ICC (3) | 2 |
| 1997 | Fair packet discarding for controlling ABR traffic in ATM networksabstractThe asynchronous transfer mode (ATM) Forum has chosen rate-based control as the flow control scheme for the available bit-rate (ABR) service. However, rate-based schemes can achieve congestion control only if all users act in a cooperative manner. Even a limited number of uncooperative users can cause congestion collapse. We propose a mechanism called fair packet discarding to provide incentives to users to participate in network congestion control so that the network can operate in a more efficient manner. Sammy Chan, Eric Wing Ming Wong, King-Tim Ko |
IEEE Trans. Commun. | 1 |
| 1993 | Fairness in ATM Networks
Moshe Zukerman, Sammy Chan |
Comput. Networks ISDN Syst. | 2 |
| 1992 | Fairness in Broadband ISDNabstractThe authors propose a fairness criterion for sharing spare (unallocated) capacity among different nonguaranteed bursty data sources with different relative usage values. Based on this criterion, the throughput of some sources may be controlled in the case where the total average offered traffic within a certain small time interval is greater than the total available spare capacity. It is proposed that all controlled sources will enjoy a share of capacity which is proportional to their relative usage values, and that no uncontrolled source will enjoy higher relative throughput than a controlled source. This criterion uniquely defines a set of throughputs for all sources. A method to compute these throughput values which has been demonstrated by several examples has been presented.> Moshe Zukerman, Sammy Chan |
INFOCOM | 2 |