EDBT 2026 Demo / reviewers in the wild / expert
Edmond W. W. Chan
dblp:73/5303
· DBLP profile ↗
24ranked-venue papers
4as first author
0since 2021 · last 2018
0000-0002-8304-8928ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 11 · 3 first-authorSecurity and privacy · 8 · 1 first-authorSystems, architecture and hardware · 5Graphics, computer vision, multimedia, augmented reality and games · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer networks
7 papers |
Network measurement and analytics · 69% Transport protocols and congestion control · 15% Content delivery and video streaming · 11% | |
| Network and information security
3 papers |
Network security · 74% Privacy and data protection · 17% Web and mobile security · 9% |
Topics — the 19 heaviest of 23, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Network measurement and analytics › network performance measurement
network path measurement |
0.4 | 2 | 2018 | LinkScope: Toward Detecting Target Link Flooding Attacks · IEEE Trans. Inf. Forensics Secur. 2018 Measurement of loss pairs in network paths · Internet Measurement Conference 2010 |
Network security › attack strategy
denial-of-service attack |
0.3 | 1 | 2018 | LinkScope: Toward Detecting Target Link Flooding Attacks · IEEE Trans. Inf. Forensics Secur. 2018 |
Network security › attack strategy › denial-of-service attack
link flooding attack |
0.3 | 1 | 2018 | LinkScope: Toward Detecting Target Link Flooding Attacks · IEEE Trans. Inf. Forensics Secur. 2018 |
Network measurement and analytics › bandwidth estimation
network path capacity measurement |
0.2 | 2 | 2011 | TRIO: measuring asymmetric capacity with three minimum round-trip times · CoNEXT 2011 A minimum-delay-difference method for mitigating cross-traffic impact on capacity measurement · CoNEXT 2009 |
Content delivery and video streaming
quality of experience |
0.2 | 1 | 2014 | On Measuring One-Way Path Metrics from a Web Server · ICNP 2014 |
Transport protocols and congestion control
transport protocols |
0.1 | 1 | 2012 | Robust Network Covert Communications Based on TCP and Enumerative Combinatorics · IEEE Trans. Dependable Secur. Comput. 2012 |
Network security
anonymity networks |
0.1 | 1 | 2012 | Robust Network Covert Communications Based on TCP and Enumerative Combinatorics · IEEE Trans. Dependable Secur. Comput. 2012 |
Network security
covert channel |
0.1 | 1 | 2012 | Robust Network Covert Communications Based on TCP and Enumerative Combinatorics · IEEE Trans. Dependable Secur. Comput. 2012 |
Privacy and data protection › information leakage
information leakage prevention |
0.1 | 1 | 2011 | HTTPOS: Sealing Information Leaks with Browser-side Obfuscation of Encrypted Flows · NDSS 2011 |
Network security
traffic analysis |
0.1 | 1 | 2011 | HTTPOS: Sealing Information Leaks with Browser-side Obfuscation of Encrypted Flows · NDSS 2011 |
Network measurement and analytics
network tomography |
0.1 | 1 | 2010 | Measurement of loss pairs in network paths · Internet Measurement Conference 2010 |
Network measurement and analytics › network performance measurement
packet loss estimation |
0.1 | 1 | 2010 | Measurement of loss pairs in network paths · Internet Measurement Conference 2010 |
Network management and operations › fault management › fault diagnosis
network fault diagnosis |
0.1 | 1 | 2018 | LinkScope: Toward Detecting Target Link Flooding Attacks · IEEE Trans. Inf. Forensics Secur. 2018 |
Network measurement and analytics › internet measurement
internet path measurement |
0.1 | 1 | 2009 | Design and Implementation of TCP Data Probes for Reliable and Metric-Rich Network Path Monitoring · USENIX ATC 2009 |
Information theory
channel capacity |
0.0 | 1 | 2012 | Robust Network Covert Communications Based on TCP and Enumerative Combinatorics · IEEE Trans. Dependable Secur. Comput. 2012 |
Information theory › information-theoretic security › covert communication
covert capacity |
0.0 | 1 | 2012 | Robust Network Covert Communications Based on TCP and Enumerative Combinatorics · IEEE Trans. Dependable Secur. Comput. 2012 |
Network measurement and analytics › latency measurement
round-trip time measurement |
0.0 | 1 | 2011 | TRIO: measuring asymmetric capacity with three minimum round-trip times · CoNEXT 2011 |
Network measurement and analytics › bandwidth estimation
packet-pair dispersion |
0.0 | 1 | 2009 | A minimum-delay-difference method for mitigating cross-traffic impact on capacity measurement · CoNEXT 2009 |
Transport protocols and congestion control
TCP |
0.0 | 1 | 2009 | Design and Implementation of TCP Data Probes for Reliable and Metric-Rich Network Path Monitoring · USENIX ATC 2009 |
Methods — techniques the papers use, named apart from their topics
path performance profiling · 0.7non-cooperative measurement · 0.7timing channel encoding · 0.4enumerative combinatorics · 0.4TCP analysis · 0.2HTTP · 0.2HTML5 timing API · 0.2round-trip time probing · 0.1packet dispersion · 0.1packet-pair probing · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2018 | LinkScope: Toward Detecting Target Link Flooding AttacksabstractA new class of target link flooding attacks (LFAs) can cut off the Internet connections of a target area without being detected, because they employ legitimate flows to congest selected links. Although new mechanisms for defending against LFA have been proposed, the deployment issues limit their usage, since they require either additional modules to enhance routers or using the software-defined network to replace the traditional routers. In this paper, we propose a novel framework that employs both the end-to-end and hop-by-hop network measurement techniques to capture the abnormal path performance degradation for detecting LFA and then locate the target links or areas whenever possible, and develop a prototype of the framework named LinkScope. Although using network measurement to capture network anomaly is not new, we tackle a number of challenging issues, such as conducting large-scale Internet path monitoring via non-cooperative measurement so that users do not need to install LinkScope on every host, profiling the performance of asymmetric Internet paths and detecting LFA. The extensive evaluation in a testbed and the Internet shows that with limited bandwidth and computational overhead, LinkScope can achieve timely detection and diagnosis of LFA with high detection rate and low false positive rate. Lei Xue 0001, Xiaobo Ma 0001, Xiapu Luo, Edmond W. W. Chan, TungNgai Miu, Guofei Gu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2014 | On Measuring One-Way Path Metrics from a Web ServerabstractMeasuring one-way path metrics can facilitate adaptive online services (e.g., Video streaming and CDN) tuning to improve quality of experience (QoE) of their clients. However, existing server-side measurement systems suffer from (i) measuring only few one-way path metrics, (ii) limited client-side support, and (iii) heavy overheads. In this paper, we propose and implement OWPScope, a novel system that can be deployed to any web server to measure four important one-way path metrics-packet loss, packet reordering, jitter, and capacity-without requiring software or plug in installation at their web clients. Moreover, OWPScope performs representative measurement by correlating only information gleaned from standard features in HTML5 (e.g., Navigation timing, resource timing), HTTP, and TCP. Our extensive evaluations in both a test bed and the Internet show that OWPScope can effectively measure one-way path metrics with low overhead. Xiapu Luo, Lei Xue 0001, Yuru Shao, Chenxiong Qian, Edmond W. W. Chan |
ICNP | 6 |
| 2014 | Towards Detecting Target Link Flooding Attack
Lei Xue 0001, Xiapu Luo, Edmond W. W. Chan, Xian Zhan |
LISA | 3 |
| 2013 | An efficient approach to multi-level route analytics
Ang Chen 0001, Edmond W. W. Chan, Xiapu Luo, Waiting W. T. Fok, Rocky K. C. Chang |
IM | 2 |
| 2013 | MonoScope: Automating network faults diagnosis based on active measurements
Waiting W. T. Fok, Xiapu Luo, Ricky K. P. Mok, Weichao Li 0001, Edmond W. W. Chan, Rocky K. C. Chang |
IM | 6 |
| 2012 | QDASH: a QoE-aware DASH systemabstractDynamic Adaptation Streaming over HTTP (DASH) enhances the Quality of Experience (QoE) for users by automatically switching quality levels according to network conditions. Various adaptation schemes have been proposed to select the most suitable quality level during video playback. Adaptation schemes are currently based on the measured TCP throughput received by the video player. Although video buffer can mitigate throughput fluctuations, it does not take into account the effect of the transition of quality levels on the QoE. Ricky K. P. Mok, Xiapu Luo, Edmond W. W. Chan, Rocky K. C. Chang |
MMSys | 3 |
| 2012 | Characterization of 3G control-plane signaling overhead from a data-plane perspectiveabstractIn 3G networks, when user applications of mobile subscribers send or receive data-plane traffic, control-plane signaling messages will be triggered to initiate or release radio resources for the data transfer. Such signaling messages can increase the processing and transmission overheads of the 3G cellular network infrastructure, and this in turns degrades the performance experience of mobile subscribers. Thus, understanding the signaling overhead of a 3G network becomes critical. In this paper, we conduct the first comprehensive measurement study of the signaling overhead of a city-wide 3G operational network in China. Our main contributions are two-fold. First, based on real cellular traces collected from both data and control planes, we validate that by simply monitoring data-plane packets, we can accurately profile the control-plane signaling overhead due to the initiations of radio resources for data transfer. Second, using data-plane signaling profiling, we characterize the signaling overhead due to common transport protocols and network applications. Our measurement methodology and results presented in this paper would be useful for network operators to better understand how data-plane traffic patterns influence the control-plane signaling overhead of a 3G network. Edmond W. W. Chan, Patrick P. C. Lee |
MSWiM | 2 |
| 2012 | Robust Network Covert Communications Based on TCP and Enumerative CombinatoricsabstractThe problem of communicating covertly over the Internet has recently received considerable attention from both industry and academic communities. However, the previously proposed network covert channels are plagued by their unreliability and very low data rate. In this paper, we show through a new class of timing channels coined as Cloak that it is possible to devise a 100 percent reliable covert channel and yet offer a much higher data rate (up to an order of magnitude) than the existing timing channels. Cloak is novel in several aspects. First, Cloak uses the different combinations of N packets sent over X flows in each round to represent a message. The combinatorial nature of the encoding methods increases the channel capacity largely with (N,X). Second, based on the well-known 12-fold Way, Cloak offers 10 different encoding and decoding methods, each of which has a unique tradeoff among several important considerations, such as channel capacity and camouflage capability. Third, the packet transmissions modulated by Cloak can be carefully crafted to mimic normal TCP flows for evading detection. We have implemented Cloak and evaluated it in the PlanetLab and a controlled testbed. The results show that it is not uncommon for Cloak to have an order of channel goodput improvement over the IP Timing channel and JitterBug. Moreover, Cloak does not suffer from any message loss under various loss and reordering scenarios. Xiapu Luo, Edmond W. W. Chan, Peng Zhou 0002, Rocky K. C. Chang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2011 | TRIO: measuring asymmetric capacity with three minimum round-trip timesabstractMeasuring network path capacity is an important capability to many Internet applications. But despite over ten years of effort, the capacity measurement problem is far from being completely solved. This paper addresses the problem of measuring network paths of asymmetric capacity without requiring the remote node's control or overwhelming the bottleneck link. We first show through analysis and measurement that the current packet-dispersion methods, due to the packet size limitations, can only measure up to a certain degree of capacity asymmetry. Second, we propose TRIO that removes the limitation by using round-trip times (RTTs). TRIO cleverly exploits two types of probes to obtain three minimum RTTs to compute bothforward and reverse capacities, and another minimum RTT for measurement validation. We validate TRIO's accuracy and versatility on a testbed and the Internet, and develop a system to measure path capacity from the server or user side. Edmond W. W. Chan, Ang Chen 0001, Xiapu Luo, Ricky K. P. Mok, Weichao Li 0001, Rocky K. C. Chang |
CoNEXT | 1 |
| 2011 | A combinatorial approach to network covert communications with applications in Web LeaksabstractVarious effective network covert channels have recently demonstrated the feasibility of encoding messages into the timing or content of individual network objects, such as data packets and request messages. However, we show in this paper that more robust and stealthy network covert channels can be devised by exploiting the relationship of the network objects. In particular, we propose a combinatorial approach for devising a wide spectrum of covert channels which can meet different objectives based on the channel capacity and channel undetectability. To illustrate the approach, we design WebLeaks and ACKLeaks, two novel covert channels which can leak information through the data and acknowledgment traffic in a web session. We implement both channels and deploy them on the PlanetLab nodes for evaluation. Besides the channel capacity, we apply the state-of-the-art detection schemes to evaluate their camouflage capability. The experiment results show that their capacity can be boosted up by our combinatorial approach, and at the same time they can effectively evade the detection. Xiapu Luo, Peng Zhou 0002, Edmond W. W. Chan, Rocky K. C. Chang, Wenke Lee |
DSN | 3 |
| 2011 | Planetopus: A system for facilitating collaborative network monitoringabstractMany new methods and tools have been developed to measure the quality of network paths for the last ten years. However, there are relatively few works that consider deploying these methods for collaborative network measurement: a number of measuring points belonging to different autonomous systems collaborate on monitoring and diagnosing their network performance. In this paper, we present Planetopus, a distributed system for facilitating collaborative network monitoring. Planetopus provides a single platform for configuring and scheduling measurement tasks performed on a set of distributed measuring points. Planetopus currently performs measurement mainly using OneProbe and tcptraceroute. Moreover, we introduce two useful facilities for analyzing the measurement data: a new metric for quantifying route changes and a heatmap-based visualization method for discovering patterns and anomalies from a set of path measurements. We demonstrate the utility of Planetopus through several case studies in which poor routes are identified and corrected, different ISPs' network services are compared, and network performance problems are diagnosed. Weichao Li 0001, Waiting W. T. Fok, Edmond W. W. Chan, Xiapu Luo, Rocky K. C. Chang |
Integrated Network Management | 3 |
| 2011 | Measuring the quality of experience of HTTP video streamingabstractHTTP video streaming, such as Flash video, is widely deployed to deliver stored media. Owing to TCP's reliable service, the picture and sound quality would not be degraded by network impairments, such as high delay and packet loss. However, the network impairments can cause rebuffering events which would result in jerky playback and deform the video's temporal structure. These quality degradations could adversely affect users' quality of experience (QoE). In this paper, we investigate the relationship among three levels of quality of service (QoS) of HTTP video streaming: network QoS, application QoS, and user QoS (i.e., QoE). Our ultimate goal is to understand how the network QoS affects the QoE of HTTP video streaming. Our approach is to first characterize the correlation between the application and network QoS using analytical models and empirical evaluation. The second step is to perform subjective experiments to evaluate the relationship between application QoS and QoE. Our analysis reveals that the frequency of rebuffering is the main factor responsible for the variations in the QoE. Ricky K. P. Mok, Edmond W. W. Chan, Rocky K. C. Chang |
Integrated Network Management | 2 |
| 2011 | HTTPOS: Sealing Information Leaks with Browser-side Obfuscation of Encrypted Flows
Xiapu Luo, Peng Zhou 0002, Edmond W. W. Chan, Wenke Lee, Rocky K. C. Chang, Roberto Perdisci |
NDSS | 3 |
| 2011 | Non-cooperative Diagnosis of Submarine Cable Faults
Edmond W. W. Chan, Xiapu Luo, Waiting W. T. Fok, Weichao Li 0001, Rocky K. C. Chang |
PAM | 1 |
| 2010 | Neighbor-Cooperative Measurement of Network Path QualityabstractIn the current Internet landscape, a stub autonomous system (AS) could choose from a number of providers and peers to advertise its routes. However, the route selection may not always result in a best choice in terms of end-to-end path performance. Instead of having an AS to monitor all possible paths, we argue that it is much more effective and beneficial for a number of neighboring ASes to cooperate in the path measurement. In this paper, we present a neighbor-cooperative measurement system in which each participating AS conducts measurement using their current routes for the same set of remote endpoints. A collation of the measurement results can help identify and correct poor routes, compare different providers' network services, and diagnose network performance problems. We report measurement results from an actual deployment involving eight neighboring universities for over a year. Rocky K. C. Chang, Waiting W. T. Fok, Weichao Li 0001, Edmond W. W. Chan, Xiapu Luo |
GLOBECOM | 4 |
| 2010 | Measurement of loss pairs in network pathsabstractLoss-pair measurement was proposed a decade ago for discovering network path properties, such as a router's buffer size. A packet pair is regarded as a loss pair if exactly one packet is lost. Therefore, the residual packet's delay can be used to infer the lost packet's delay. Despite this unique advantage shared by no other methods, no loss-pair measurement in actual networks has ever been reported. In this paper, we further develop the loss-pair measurement and make the following contributions. First, we characterize the residual packet's delay by including other important factors (such as the impact of the first packet in the pair) which were ignored before. Second, we employ a novel TCP-based probing method to measure from a single endpoint all four possible loss pairs for a round-trip network path. Third, we conducted loss-pair measurement for 88 round-trip paths continuously for almost three weeks. Being the first set of loss-pair measurement, we obtained a number of original results, such as prevalence of loss pairs, distribution of different types of loss pairs, and effect of route change on the paths' congestion state. Edmond W. W. Chan, Xiapu Luo, Weichao Li 0001, Waiting W. T. Fok, Rocky K. C. Chang |
Internet Measurement Conference | 1 |
| 2009 | A minimum-delay-difference method for mitigating cross-traffic impact on capacity measurementabstractThe accuracy and speed of path capacity measurement could be seriously affected by the presence of cross traffic on the path. In this paper, we propose a new cross-traffic filtering method called minimum delay difference (MDDIF). Unlike the classic packet-pair dispersion techniques, the MDDIF method can obtain accurate capacity estimate from the minimal possible delay of packets from different packet pairs. We have proved that the MDDIF method is correct and that it takes less time to obtain accurate samples than the minimum delay sum (MDSUM) method. We also present analytical and measurement results to evaluate the MDDIF method and to compare its performance with the MDSUM method. Edmond W. W. Chan, Xiapu Luo, Rocky K. C. Chang |
CoNEXT | 1 |
| 2009 | CLACK: A Network Covert Channel Based on Partial Acknowledgment EncodingabstractThe ability of setting up a covert channel, which allows any two nodes with Internet connections to engage in secretive communication, clearly causes a very serious security concern. A number of recent studies have indeed shown that setting up such covert channels is possible by exploiting the protocol fields in the IP, TCP, or application layer. However, the quality of these covert channels is susceptible to unpredictable network condition and active wardens. In this paper, we propose CLACK, a new covert channel which encodes covert messages into the TCP acknowledgments (ACKs). Since the message encoding is performed in a TCP data channel, CLACK is reliable and resilience to adverse network conditions. Moreover, CLACK is very difficult to detect in practice, because the TCK ACKs encoded by CLACK cannot be easily distinguished from the normal ACKs. We have implemented and tested CLACK in a test-bed to validate its correctness. Xiapu Luo, Edmond W. W. Chan, Rocky K. C. Chang |
ICC | 2 |
| 2009 | Design and Implementation of TCP Data Probes for Reliable and Metric-Rich Network Path Monitoring
Xiapu Luo, Edmond W. W. Chan, Rocky K. C. Chang |
USENIX ATC | 2 |
| 2008 | TCP covert timing channels: Design and detectionabstractExploiting packets’ timing information for covert communication in the Internet has been explored by several network timing channels and watermarking schemes. Several of them embed covert information in the inter-packet delay. These channels, however, can be detected based on the perturbed traffic pattern, and their decoding accuracy could be degraded by jitter, packet loss and packet reordering events. In this paper, we propose a novel TCP-based timing channel, named TCPScript to address these shortcomings. TCPScript embeds messages in “normal” TCP data bursts and exploits TCP’s feedback and reliability service to increase the decoding accuracy. Our theoretical capacity analysis and extensive experiments have shown that TCPScript offers much higher channel capacity and decoding accuracy than an IP timing channel and JitterBug. On the countermeasure, we have proposed three new metrics to detect aggressive TCPScript channels. Xiapu Luo, Edmond W. W. Chan, Rocky K. C. Chang |
DSN | 2 |
| 2007 | Cloak: A Ten-Fold Way for Reliable Covert Communications
Xiapu Luo, Edmond W. W. Chan, Rocky K. C. Chang |
ESORICS | 2 |
| 2007 | Crafting Web Counters into Covert Channels
Xiapu Luo, Edmond W. W. Chan, Rocky K. C. Chang |
SEC | 2 |
| 2006 | Vanguard: A New Detection Scheme for a Class of TCP-targeted Denial-of-Service AttacksabstractA few low-rate, TCP-targeted Denial-of-Service (DoS) attacks have been recently proposed, including the Shrew attack, Reduction of Quality (RoQ) attack, and Pulsing DoS (PDoS) attack. All of them use periodic attack pulses to throttle TCP flows. These attacks could potentially become major threats to the Internet's stabiliity and therefore they have motivated the development of a number of detection mechanisms for such attacks. However, those detection mechanisms are designed for specific attacks. Moreover, they assume that the period of the attack pulses is a nonzero constant. Unfortunately, these assumptions can be easily thwarted by more sophisticated attack strategies. In this paper, we propose a new detection system called Vanguard to identify a wide range of the aforementioned low-rate, DoS attacks, including the traditional flooding-based attacks as a special case. Vanguard can also detect attacks with randomized attack periods. We have validated Vanguard's efficacy based on extensive test-bed experiments. We have also compared Vanguard with other recently proposed detection systems. Xiapu Luo, Edmond W. W. Chan, Rocky K. C. Chang |
NOMS | 2 |
| 2005 | Performance Analysis of TCP/AQM Under Denial-of-Service AttacksabstractThe interaction between TCP and various active queue management (AQM) algorithms has been extensively analyzed for the last few years. However, the analysis usually assumed that routers and TCP flows are not under any network attacks. In this paper, we investigate how the performance of TCP flows is affected by denial-of-service (DoS) attacks under the drop tail and various AQM schemes. In particular, we consider two types of DoS attacks-the traditional flooding-based DoS (FDDoS) attacks and the recently proposed pulsing DoS (PDoS) attacks. Both analytical and simulation results support that the PDoS attacks are more effective than the FDDoS attacks under the same average attack rate. Moreover, the drop tail surprisingly outperforms the RED-like AQMs when the router is under a PDoS attack, whereas the RED-like AQMs perform better under a severe FDDoS attack. On the other hand, the Adaptive Virtual Queue algorithm can retain a higher TCP throughput during PDoS attacks as compared with the RED-like AQMs. Xiapu Luo, Rocky K. C. Chang, Edmond W. W. Chan |
MASCOTS | 3 |