Xin Zhang 0003

dblp:76/1584-3 · DBLP profile ↗
← Back
19ranked-venue papers
9as first author
0since 2021 · last 2015
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 9 · 5 first-authorSecurity and privacy · 7 · 3 first-authorSystems, architecture and hardware · 3 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer networks
9 papers
Network management and operations · 47% Routing and switching · 17% Internet architecture and protocols · 14%
Network and information security
7 papers
Network security · 96% Systems and software security · 4%
Computer architecture, parallel and distributed computing, and storage systems
3 papers
Hardware accelerators and domain-specific architectures · 74% Memory systems · 13% Reconfigurable computing and FPGAs · 13%

Topics — the 24 heaviest of 26, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Network management and operations › fault management › fault diagnosis
fault localization
0.322014
DFL: Secure and Practical Fault Localization for Datacenter Networks · IEEE/ACM Trans. Netw. 2014
Network fault localization with small TCB · ICNP 2011
Network management and operations › fault management › fault diagnosis › fault localization
secure fault localization
0.322014
DFL: Secure and Practical Fault Localization for Datacenter Networks · IEEE/ACM Trans. Netw. 2014
Network fault localization with small TCB · ICNP 2011
Network management and operations › fault management
fault diagnosis
0.332012
Secure and Scalable Fault Localization under Dynamic Traffic Patterns · IEEE Symposium on Security and Privacy 2012
ShortMAC: Efficient Data-Plane Fault Localization · NDSS 2012
Packet-dropping adversary identification for data plane security · CoNEXT 2008
Network management and operations › fault management › fault diagnosis
data-plane fault localization
0.322012
Secure and Scalable Fault Localization under Dynamic Traffic Patterns · IEEE Symposium on Security and Privacy 2012
ShortMAC: Efficient Data-Plane Fault Localization · NDSS 2012
Network security › intrusion detection and prevention
intrusion detection
0.222010
Scalable NIDS via Negative Pattern Matching and Exclusive Pattern Matching · INFOCOM 2010
A Memory-Efficient Parallel String Matching Architecture for High-Speed Intrusion Detection · IEEE J. Sel. Areas Commun. 2006
Routing and switching
ad hoc network routing
0.112012
Jamming-Resilient Multipath Routing · IEEE Trans. Dependable Secur. Comput. 2012
Wireless networking › anti-jamming
jamming-resilient routing
0.112012
Jamming-Resilient Multipath Routing · IEEE Trans. Dependable Secur. Comput. 2012
Routing and switching
multipath routing
0.112012
Jamming-Resilient Multipath Routing · IEEE Trans. Dependable Secur. Comput. 2012
Routing and switching
routing protocol
0.112012
Jamming-Resilient Multipath Routing · IEEE Trans. Dependable Secur. Comput. 2012
Wireless networking
wireless network protocols
0.112012
Jamming-Resilient Multipath Routing · IEEE Trans. Dependable Secur. Comput. 2012
Internet architecture and protocols › packet processing
packet classification
0.122006
DPPC-RE: TCAM-Based Distributed Parallel Packet Classification with Range Encoding · IEEE Trans. Computers 2006
IPv6-Oriented 4*OC768 Packet Classification with Deriving-Merging Partition and Field-Variable Encoding Algorithm · INFOCOM 2006
Software-defined and programmable networks
path control
0.112011
SCION: Scalability, Control, and Isolation on Next-Generation Networks · IEEE Symposium on Security and Privacy 2011
Internet architecture and protocols › packet processing › packet classification
TCAM-based packet classification
0.122006
DPPC-RE: TCAM-Based Distributed Parallel Packet Classification with Range Encoding · IEEE Trans. Computers 2006
IPv6-Oriented 4*OC768 Packet Classification with Deriving-Merging Partition and Field-Variable Encoding Algorithm · INFOCOM 2006
Network security › intrusion detection and prevention › intrusion detection
network intrusion detection
0.112010
Scalable NIDS via Negative Pattern Matching and Exclusive Pattern Matching · INFOCOM 2010
Hardware accelerators and domain-specific architectures
pattern matching accelerator
0.112010
Scalable NIDS via Negative Pattern Matching and Exclusive Pattern Matching · INFOCOM 2010
Internet architecture and protocols › packet processing › packet classification › range matching
range encoding
0.112006
DPPC-RE: TCAM-Based Distributed Parallel Packet Classification with Range Encoding · IEEE Trans. Computers 2006
Internet architecture and protocols › packet processing › packet classification
range matching
0.112006
DPPC-RE: TCAM-Based Distributed Parallel Packet Classification with Range Encoding · IEEE Trans. Computers 2006
Network security › intrusion detection and prevention › intrusion detection
pattern matching
0.112006
A Memory-Efficient Parallel String Matching Architecture for High-Speed Intrusion Detection · IEEE J. Sel. Areas Commun. 2006
Datacenter networks
load balancing
0.012012
Secure and Scalable Fault Localization under Dynamic Traffic Patterns · IEEE Symposium on Security and Privacy 2012
Software-defined and programmable networks
programmable data plane
0.012012
ShortMAC: Efficient Data-Plane Fault Localization · NDSS 2012
Systems and software security › trusted computing
trusted computing base
0.012011
Network fault localization with small TCB · ICNP 2011
Routing and switching › packet forwarding
high-speed packet forwarding
0.012006
IPv6-Oriented 4*OC768 Packet Classification with Deriving-Merging Partition and Field-Variable Encoding Algorithm · INFOCOM 2006
Reconfigurable computing and FPGAs
FPGA accelerator
0.012006
A Memory-Efficient Parallel String Matching Architecture for High-Speed Intrusion Detection · IEEE J. Sel. Areas Commun. 2006
Memory systems › content-addressable memory
TCAM
0.012006
DPPC-RE: TCAM-Based Distributed Parallel Packet Classification with Range Encoding · IEEE Trans. Computers 2006

Methods — techniques the papers use, named apart from their topics

delayed function disclosure · 0.4delayed key disclosure · 0.3trusted computing · 0.2security analysis · 0.2parallel pattern matching · 0.2load balancing · 0.2distributed routing protocol · 0.1availability history vectors · 0.1worst-case analysis · 0.1parallel architecture · 0.1distributed parallel processing · 0.1deterministic finite automata · 0.1parallel encoding · 0.1deriving-merging partition · 0.1
YearPublicationVenuePosition
2015 Algorithms to speedup pattern matching for network intrusion detection systems
Kai Zheng 0003, Zhiping Cai, Xin Zhang 0003, Zhijun Wang 0001, Baohua Yang
Comput. Commun.3
2014 DFL: Secure and Practical Fault Localization for Datacenter Networks
abstract
Datacenter networking has gained increasing popularity in the past few years. While researchers paid considerable efforts to enhance the performance and scalability of datacenter networks, achieving reliable data delivery in these emerging networks with misbehaving routers and switches received far less attention. Unfortunately, documented incidents of router compromise underscore that the capability to identify adversarial routers and switches is an imperative and practical need rather than merely a theoretical exercise. To this end, data-plane fault localization (FL) aims to identify faulty links and is an effective means of achieving high network availability. However, existing secure FL protocols assume that the source node knows the entire outgoing path that delivers the source node's packets and that the path is static and long-lived. These assumptions are invalidated by the dynamic traffic patterns and agile load balancing commonly seen in modern datacenter networks. We propose the first secure FL protocol, DFL, with no requirements on path durability or the source node knowing the outgoing paths. Through a core technique we named delayed function disclosure, DFL incurs little communication overhead and a small, constant router state independent of the network size or the number of flows traversing a router.
Xin Zhang 0003, Fanfu Zhou, Haiyang Sun 0003, Adrian Perrig, Athanasios V. Vasilakos, Haibing Guan
IEEE/ACM Trans. Netw.1
2013 STRIDE: sanctuary trail - refuge from internet DDoS entrapment
abstract
We propose STRIDE, a new DDoS-resilient Internet architecture that isolates attack traffic through viable bandwidth allocation, preventing a botnet from crowding out legitimate flows. This new architecture presents several novel concepts including tree-based bandwidth allocation and long-term static paths with guaranteed bandwidth. In concert, these mechanisms provide domain-based bandwidth guarantees within a trust domain - administrative domains grouped within a legal jurisdiction with enforceable accountability; each administrative domain in the trust domain can then internally split such guarantees among its endhosts to provide (1) connection establishment with high probability, and (2) precise bandwidth guarantees for established flows, regardless of the size or distribution of the botnet outside the source and the destination domains. Moreover, STRIDE maintains no per-flow state on backbone routers and requires no key establishment across administrative domains. We demonstrate that STRIDE achieves these DDoS defense properties through formal analysis and simulation. We also show that STRIDE mitigates emerging DDoS threats such as Denial-of-Capability (DoC) [6] and N2 attacks [22] based on these properties that none of the existing DDoS defense mechanisms can achieve.
Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim, Sangjae Yoo, Xin Zhang 0003, Soo Bum Lee, Virgil D. Gligor, Adrian Perrig
AsiaCCS4
2012 ShortMAC: Efficient Data-Plane Fault Localization
Xin Zhang 0003, Zongwei Zhou, Hsu-Chun Hsiao, Tiffany Hyun-Jin Kim, Adrian Perrig, Patrick Tague
NDSS1
2012 Secure and Scalable Fault Localization under Dynamic Traffic Patterns
abstract
Compromised and misconfigured routers are a well-known problem in ISP and enterprise networks. Data-plane fault localization (FL) aims to identify faulty links of compromised and misconfigured routers during packet forwarding, and is recognized as an effective means of achieving high network availability. Existing secure FL protocols are path-based, which assume that the source node knows the entire outgoing path that delivers the source node's packets and that the path is static and long-lived. However, these assumptions are incompatible with the dynamic traffic patterns and agile load balancing commonly seen in modern networks. To cope with real-world routing dynamics, we propose the first secure neighborhood-based FL protocol, DynaFL, with no requirements on path durability or the source node knowing the outgoing paths. Through a core technique we named delayed key disclosure, DynaFL incurs little communication overhead and a small, constant router state independent of the network size or the number of flows traversing a router. In addition, each DynaFL router maintains only a single secret key, which based on our measurement results represents 2 - 4 orders of magnitude reduction over previous path-based FL protocols.
Xin Zhang 0003, Chang Lan, Adrian Perrig
IEEE Symposium on Security and Privacy1
2012 Mobile encryption for laptop data protection (MELP)
abstract
Based on the advances in laptop technologies and the mobility characteristics, laptops have become a vital device used at various places. Usually, numerous sensitive files such as credit card numbers and Web cookies are stored on laptops for convenient usage. However, if a laptop is stolen, the data stored on it is easily leaked; which may cause serious consequences. Encrypting files by encryption keys is a general solution; however, if the decryption keys are also stored on laptops, the files can also be decrypted by adversaries easily. To solve this problem, this paper proposes the Mobile Encryption for Laptop data Protection (MELP) system. MELP includes the design of an online server and mobile phone, and encrypts each sensitive file by a file system encryption key, which is further sequentially encrypted twice by the phone's and server's encryption keys. The reason of adopting a mobile phone is that at least one simple confirmation of execution must be performed by a user, and the reason of adopting an online server is that if both user's laptop and mobile phone are stolen, users can still disable the online decryption process on the server.
Yung-Wei Kao, Xin Zhang 0003, Ahren Studer, Adrian Perrig
IET Inf. Secur.2
2012 Jamming-Resilient Multipath Routing
abstract
Jamming attacks are especially harmful to the reliability of wireless communication, as they can effectively disrupt communication between any node pairs. Existing jamming defenses primarily focus on repairing connectivity between adjacent nodes. In this paper, we address jamming at the network level and focus on restoring the end-to-end data delivery through multipath routing. As long as all paths do not fail concurrently, the end-to-end path availability is maintained. Prior work in multipath selection improves routing availability by choosing node-disjoint paths or link-disjoint paths. However, through our experiments on jamming effects using MicaZ nodes, we show that disjointness is insufficient for selecting fault-independent paths. Thus, we address multipath selection based on the knowledge of a path's availability history. Using Availability History Vectors (AHVs) of paths, we present a centralized AHV-based algorithm to select fault-independent paths, and a distributed AHV-based routing protocol built on top of a classic routing algorithm in ad hoc networks. Our extensive simulation results validate that both AHV-based algorithms are effective in overcoming the jamming impact by maximizing the end-to-end availability of the selected paths.
Hossen Asiful Mustafa, Xin Zhang 0003, Zhenhua Liu 0005, Wenyuan Xu 0001, Adrian Perrig
IEEE Trans. Dependable Secur. Comput.2
2011 Network fault localization with small TCB
abstract
Clear evidence indicates the existence of compromised routers in ISP and enterprise networks. Fault localization (FL) protocols enable a network to localize specific links of compromised routers sabotaging network data delivery and are recognized as an essential means to enhancing network availability in the face of targeted attacks. However, theoretically proven lower bounds have shown that secure FL protocols in the current network infrastructure inevitably incur prohibitive overhead. We observe the current limits are due to a lack of trust relationships among network nodes. We demonstrate that we can achieve much higher FL efficiency by leveraging trusted computing technology to design a trusted network-layer architecture, Tru eN et, with a small Trusted Computing Base (TCB). We intend Tru e N e t to serve as a case study that demonstrates trusted computing's ability in yielding tangible and measurable benefits for secure network protocol designs.
Xin Zhang 0003, Zongwei Zhou, Geoffrey Hasker, Adrian Perrig, Virgil D. Gligor
ICNP1
2011 SCION: Scalability, Control, and Isolation on Next-Generation Networks
abstract
We present the first Internet architecture designed to provide route control, failure isolation, and explicit trust information for end-to-end communications. SCION separates ASes into groups of independent routing sub-planes, called trust domains, which then interconnect to form complete routes. Trust domains provide natural isolation of routing failures and human misconfiguration, give endpoints strong control for both inbound and outbound traffic, provide meaningful and enforceable trust, and enable scalable routing updates with high path freshness. As a result, our architecture provides strong resilience and security properties as an intrinsic consequence of good design principles, avoiding piecemeal add-on protocols as security patches. Meanwhile, SCION only assumes that a few top-tier ISPs in the trust domain are trusted for providing reliable end-to-end communications, thus achieving a small Trusted Computing Base. Both our security analysis and evaluation results show that SCION naturally prevents numerous attacks and provides a high level of resilience, scalability, control, and isolation.
Xin Zhang 0003, Hsu-Chun Hsiao, Geoffrey Hasker, Haowen Chan, Adrian Perrig, David G. Andersen
IEEE Symposium on Security and Privacy1
2011 Short paper: Jamming-resilient multipath routing leveraging availability-based correlation
abstract
Jamming attacks are especially harmful to the reliability of wireless communication, as they can effectively disrupt communication. Existing jamming defenses primarily focus on repairing connectivity between adjacent nodes. In this paper, we address jamming at the network level and focus on restoring the end-to-end data delivery through multipath routing. As long as all paths do not fail concurrently, the end-to-end path availability is maintained. Prior work in multipath selection improves routing by choosing node-disjoint paths or link-disjoint paths. However, through our experiments on jamming effects using MicaZ nodes, we show that topological disjointness is insufficient for selecting fault-independent paths. Thus, we address multipath selection based on the knowledge of a path's availability history. Using Availability History Vectors (AHVs) of paths, we present an AHV-based Link-State (ALS) algorithm to select fault-independent paths. Our extensive simulation results validate that the ALS algorithm is effective in overcoming the jamming impact by maximizing the end-to-end availability of the selected paths.
Hossen Asiful Mustafa, Xin Zhang 0003, Zhenhua Liu 0005, Wenyuan Xu 0005, Adrian Perrig
WISEC2
2010 Correlation-Resilient Path Selection in Multi-Path Routing
abstract
Multi-path routing is effective to enhance network availability, by selecting multiple failure-independent paths for reaching one destination in the hope to survive individual path failures. Researchers suggest to select IP-layer topologically disjoint paths, assuming that they are failure-independent and can hardly fail simultaneously. Unfortunately, failure correlations lurking behind the IP-layer topology can surreptitiously squash availability gained through multi-path routing because selected paths can fail simultaneously. Spurred by this observation, we propose a new path metric and selection scheme resilient to failure correlations between topologically disjoint paths, by utilizing path availability history to reveal failure correlations. This paper presents a first stride towards the new direction of availability-oriented multi-path selection, with formal and systematic problem definition, modeling, and algorithms.
Xin Zhang 0003, Adrian Perrig
GLOBECOM1
2010 Scalable NIDS via Negative Pattern Matching and Exclusive Pattern Matching
abstract
In this paper, we identify the unique challenges in deploying parallelism on TCAM-based pattern matching for Network Intrusion Detection Systems (NIDSes). We resolve two critical issues when designing scalable parallelism specifically for pattern matching modules: 1) how to enable fine-grained parallelism in pursuit of effective load balancing and desirable speedup simultaneously; and 2) how to reconcile the tension between parallel processing speedup and prohibitive TCAM power consumption. To this end, we first propose the novel concept of Negative Pattern Matching to partition flows, by which the number of TCAM lookups can be significantly reduced, and the resulting (fine-grained) flow segments can be inspected in parallel without incurring false negatives. Then we propose the notion of Exclusive Pattern Matching to divide the entire pattern set into multiple subsets which can later be matched against selectively and independently without affecting the correctness. We show that Exclusive Pattern Matching enables the adoption of smaller and faster TCAM blocks and improves both the pattern matching speed and scalability. Finally, our theoretical and experimental results validate that the above two concepts are inherently complementary, enabling our integrated scheme to provide performance gain in any scenario (with either clean or dirty traffic).
Kai Zheng 0003, Xin Zhang 0003, Zhiping Cai, Zhijun Wang 0001, Baohua Yang
INFOCOM2
2009 Centaur: A Hybrid Approach for Reliable Policy-Based Routing
abstract
In this paper, we consider the design of a policy-based routing system and the role that link state might play. Looking at the problem from a link-state perspective, we propose Centaur, a hybrid routing protocol combining the benefits of both link state and path vector. Through analytical and experimental studies, we demonstrate Centaur's potential in achieving rich policy expressiveness and high network availability. Our work shows that it is possible to combine link-state and path-vector approaches into a practical and efficient algorithm for policy-based routing.
Xin Zhang 0003, Adrian Perrig, Hui Zhang 0001
ICDCS1
2008 Packet-dropping adversary identification for data plane security
abstract
Until recently, the design of packet dropping adversary identification protocols that are robust to both benign packet loss and malicious behavior has proven to be surprisingly elusive. In this paper, we propose a secure and practical packet-dropping adversary localization scheme that is robust and achieves a high detection rate and low communication and storage overhead -- the three key performance metrics for such protocols in realistic settings. Other recent work just optimizes either the detection rate or the communication overhead.
Xin Zhang 0003, Abhishek Jain 0002, Adrian Perrig
CoNEXT1
2007 Clustered K-Center: Effective Replica Placement in Peer-to-Peer Systems
abstract
Peer-to-Peer (P2P) systems provide decentralization, self-organization, scalability and failure-resilience, but suffer from high worst-case latencies. Researchers have proposed various replication algorithms to place multiple copies of objects across the network in pursuit of better performance for P2P computing; nevertheless, they neither presented clear analysis nor derived worst-case bound for their algorithms. In this paper, we model the replica placement problem arising in real-world P2P networks as a Clustered K-Center problem which we prove to be NP-complete. Then we propose an efficient approximation algorithm to this problem with a provable upper bound. Extensive experiments have been conducted to demonstrate the effectiveness and efficiency of our algorithm. The experimental results show that our approach can run several orders of magnitude faster than the optimal solution while being able to minimizing the query latency.
Xin Zhang 0003, Laxmi N. Bhuyan, Bin Liu 0001
GLOBECOM2
2007 Route Table Partitioning and Load Balancing for Parallel Searching with TCAMs
abstract
With the continuous advances in optical communications technology, the link transmission speed of Internet backbone has been increasing rapidly. This in turn demands more powerful IP address lookup engine. In this paper, we propose a power-efficient parallel TCAM-based lookup engine with a distributed logical caching scheme for dynamic load-balancing. In order to distribute the lookup requests among multiple TCAM chips, a smart partitioning approach called pre-order splitting divides the route table into multiple sub-tables for parallel processing. Meanwhile, by virtual of the cache-based load balancing scheme with slow-update mechanism, a speedup factor ofN-1 can be guaranteed for a system with N (N>2) TCAM chips, even with unbalanced bursty lookup requests.
Dong Lin, Yue Zhang 0006, Chengchen Hu, Bin Liu 0001, Xin Zhang 0003, Derek Chi-Wai Pao
IPDPS5
2006 IPv6-Oriented 4*OC768 Packet Classification with Deriving-Merging Partition and Field-Variable Encoding Algorithm
abstract
Packet Classification serves as a plinth for many newly emerging network applications. Most of the previous packet classification schemes are IPv4-oriented, and some of them have achieved high throughput with chip-level parallelism of Ternary Content Addressable Memories (TCAM). However, due to their inefficient utilization of TCAM resources, further upgrade incurs prohibitive hardware costs. As IPv6 will dominate the Next Generation Internet, IPv6-oriented packet classification is of increasing importance. In this paper, we propose a packet classification scheme geared towards IPv6. This scheme incorporates efficient and flexible algorithms for parallelism and distributed storing, which provides an unprecedentedly high throughput with relatively low storage costs. Our scheme also integrates delicate parallel encoding algorithms to maximize the TCAM utilization and increase its throughput. Using commercially available TCAM, the scheme is able to classify 266 million IPv6 packets per second (Mpps), matching 4×OC-768 (160 Gbps) line rate. Key words—Packet Classification, Encoding, IPv6, TCAM
Xin Zhang 0003, Bin Liu 0001, Wei Li 0051, Ying Xi, David Bermingham, Xiaojun Wang 0001
INFOCOM1
2006 A Memory-Efficient Parallel String Matching Architecture for High-Speed Intrusion Detection
abstract
The ability to inspect both packet headers and payloads to identify attack signatures makes network intrusion detection system (NIDS) a promising approach to protect Internet systems. Since most of the known attacks can be represented with strings or combinations of multiple substrings, string matching is a key component, as well as the bottleneck in NIDS to address the requirement of constantly increasing capacity. We propose a memory-efficient multiple-character-approaching architecture consisting of multiple parallel deterministic finite automata (DFAs), called TDP-DFA. By employing efficient representations for the transition rules in each DFA, TDP-DFA significantly reduces the complexity. We also present a novel scheme to share the storage of transition rules among multiple DFAs, substantially decreasing the total storage cost, and avoiding the cost increase being proportional to the number of DFAs. We evaluate this design through theoretical analysis and comprehensive experiments. Results show that TDP-DFA is able to meet the critical requirement of OC-768 wirespeed processing, as well as constituting a promising way for scaling up to cope with throughput over 100 Gb/s in the future.
Hongbin Lu, Kai Zheng 0003, Bin Liu 0001, Xin Zhang 0003
IEEE J. Sel. Areas Commun.4
2006 DPPC-RE: TCAM-Based Distributed Parallel Packet Classification with Range Encoding
abstract
Packet classification has been a critical data path function for many emerging networking applications. An interesting approach is the use of ternary content addressable memory (TCAM) to achieve deterministic, high-speed packet classification performance. However, apart from high cost and power consumption, due to slow growing clock rate for memory technology, in general, the traditional single TCAM-based solution has difficulty to keep up with fast growing line rates. Moreover, the TCAM storage efficiency is largely affected by the need to support rules with ranges or range matching. In this paper, a distributed TCAM scheme that exploits chip-level-parallelism is proposed to greatly improve the throughput performance. This scheme seamlessly integrates with a range encoding scheme which not only solves the range matching problem, but also ensures a balanced high throughput performance. A thorough theoretical worst-case analysis of throughput, processing delay, and power consumption, as well as the experimental results show that the proposed solution can achieve scalable throughput performance matching up to OC768 line rate or higher. The added TCAM storage overhead is found to be reasonably small for the five real-world classifiers studied.
Kai Zheng 0003, Hao Che, Zhijun Wang 0001, Bin Liu 0001, Xin Zhang 0003
IEEE Trans. Computers5