EDBT 2026 Demo / reviewers in the wild / expert
Zhen Ling 0001
dblp:79/7563-1
· DBLP profile ↗
109ranked-venue papers
24as first author
63since 2021 · last 2026
0000-0001-9691-8702ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 56 · 19 first-author · 31 since 2021Security and privacy · 31 · 2 first-author · 22 since 2021Systems, architecture and hardware · 11 · 3 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 6 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 4 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Authority Backdoor: A Certifiable Backdoor Mechanism for Authoring DNNsabstractDeep Neural Networks (DNNs), as valuable intellectual property, face unauthorized use. Existing protections, such as digital watermarking, are largely passive; they provide only post-hoc ownership verification and cannot actively prevent the illicit use of a stolen model. This work proposes a proactive protection scheme, dubbed ``Authority Backdoor," which embeds access constraints directly into the model. In particular, the scheme utilizes a backdoor learning framework to intrinsically lock a model's utility, such that it performs normally only in the presence of a specific trigger (e.g., a hardware fingerprint). But in its absence, the DNN's performance degrades to be useless. To further enhance the security of the proposed authority scheme, the certifiable robustness is integrated to prevent an adaptive attacker from removing the implanted backdoor. The resulting framework establishes a secure authority mechanism for DNNs, combining access control with certifiable robustness against adversarial attacks. Extensive experiments on diverse architectures and datasets validate the effectiveness and certifiable robustness of the proposed framework. Shaofeng Li 0001, Tian Dong 0003, Xiangyu Xu 0001, Guangchi Liu, Zhen Ling 0001 |
AAAI | 6 |
| 2026 | A Needle in a Haystack: Defending Federated Learning Backdoor Attacks via Orthogonal Subnetwork Pruning
Zihan Ma 0008, Guangchi Liu, Xiangyu Xu 0001, Shaofeng Li 0001, Zhen Ling 0001, Junzhou Luo |
INFOCOM | 5 |
| 2026 | Your Outer Appearance Mirrors Your Inner Self: Exploiting Unobservable Node Internals to Deanonymize Uploaders in Freenet
Yonghuan Xu, Ming Yang 0001, Shan Wang 0008, Xiaodan Gu, Zixia Liu, Zhen Ling 0001 |
INFOCOM | 6 |
| 2026 | Detecting Rule Anomalies and Interference for Home Automation
Kai Dong 0001, Jianjie Zhou, Zhen Ling 0001, Ming Yang 0001, Xinwen Fu |
INFOCOM | 5 |
| 2026 | Cease at the Ultimate Goodness: Towards Efficient Website Fingerprinting Defense via Iterative Mutual Information Minimization
Zhen Ling 0001, Guangchi Liu, Shaofeng Li 0001, Junzhou Luo, Xinwen Fu |
NDSS | 2 |
| 2026 | Time will Tell: Large-scale De-anonymization of Hidden I2P Services via Live Behavior Alignment
Hongze Wang, Zhen Ling 0001, Xiangyu Xu 0001, Yumingzhi Pan, Guangchi Liu, Junzhou Luo, Xinwen Fu |
NDSS | 2 |
| 2026 | UIEE: Secure and Efficient User-space Isolated Execution Environment for Embedded TEE Systems
Huaiyu Yan, Zhen Ling 0001, Xuandong Chen, Xinhui Shao, Yier Jin, Ming Yang 0001, Junzhou Luo |
NDSS | 2 |
| 2026 | BACnet or "BADnet"? On the (In)Security of Implicitly Reserved Fields in BACnet
Qiguang Zhang, Junzhou Luo, Zhen Ling 0001, Yue Zhang 0025, Chongqing Lei, Christopher Morales, Xinwen Fu |
NDSS | 3 |
| 2026 | Descriptors of Exposure: Undermining Tor Anonymity Through Exploiting Descriptor Flood
Chunmian Wang, Junzhou Luo, Zhen Ling 0001, Yue Zhang 0025, Shan Wang 0008, Ming Yang 0001, Guangchi Liu, Xinwen Fu |
SP | 3 |
| 2026 | A Tor-Based Anonymous Network Covert ChannelabstractNetwork Covert Channels (NCC) enhance covertness by concealing the existence of information transmission. However, traditional NCCs remain vulnerable to traffic analysis. Once NCC is detected, adversaries can breach anonymity by uncovering users' network identities and even communication relationships. While certain indirect NCCs offer limited anonymity to protect the identity of at most one party and the relationship, this level proves insufficient. This paper proposes ANCC, an innovative Anonymous Network Covert Channel that is the first to achieve comprehensive anonymity for the sender, the receiver and the communication relationship. By leveraging the Tor network's Hidden Service Directories (HSDirs) as intermediate nodes, Tor-based ANCC modulates covert information through the publication and retrieval statuses of hidden services distributed on multiple HSDirs. This mechanism allows ANCC traffic to blend seamlessly into legitimate Tor traffic, ensuring both robust covertness and high-level anonymity. Theoretical analysis demonstrates that even against a powerful adversary compromising fifty intermediate nodes, the detection probability remains below 0.25%, with the risk of identity or relationship exposure staying negligible (under 0.0021% and 0.00002% respectively). Additionally, the multiple HSDirs supporting parallel transmission enhance the channel capacity and error correction encoding strengthens the robustness. Extensive evaluation within the real-world Tor network demonstrates a transmission accuracy exceeding 99.6% and a channel capacity of around 3 Kbps, proving its effectiveness for practical applications. Ming Yang 0001, Zhen Ling 0001, Zixia Liu, Changwei Cao, Shan Wang 0008, Xinwen Fu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Toward Secure and Efficient Driver Support for Embedded TEE SystemsabstractTrusted execution environments (TEEs), like TrustZone, are pervasively employed to protect security sensitive programs and data from various attacks issued by untrusted rich execution environments (REEs) while they execute compact TEE operating systems which implement minimum security-critical operations but have poor device driver support. In this paper, we propose a twin driver approach where a pair of TEE and REE drivers is generated and cooperate to enable secure and efficient TEE driver support. To begin with, we propose a driver data flow analysis framework named driver analyzer (DrvAna) to automatically analyze the shared states between the TEE and REE driver where a novel data structure named value-type tree is investigated to facilitate field-sensitive data flow analysis upon the driver state. Furthermore, in order to maintain a minimal trusted computing base, we propose a Linux driver runtime (LDR) inside the TEE, a sandbox environment that confines the TEE driver based on the ARM domain access control features and mediates the driver's interaction with the TEE. We implement a DrvAna prototype based on LLVM as well as an LDR prototype on an NXP IMX6Q SABRE-SD evaluation board, adapt 6 existing Linux drivers into LDR, and evaluate their performance. The experimental results show that the LDR drivers can achieve comparable performance with their Linux counterparts with negligible overheads. Huaiyu Yan, Zhen Ling 0001, Xinhui Shao, Ming Yang 0001, Junzhou Luo, Xinwen Fu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | PR-RFFI: Practical RF Fingerprint Injection Based Wi-Fi Device IdentificationabstractRecently, there has been an emerging radio frequency fingerprint identification (RFFI) technology that enhances fingerprint distinguishability by deliberately injecting an RF fingerprint into the device's Wi-Fi baseband signal. The current RF fingerprint injection methods are impractical, degrading the communication quality between Wi-Fi devices while offering limited improvements in distinguishability among a set of devices. To address these issues, we propose injecting I/Q imbalance into a short training field (STF) instead of the entire baseband signal. Our findings indicate that this method can effectively preserve the quality of the original wireless communication. Besides, a temperature-independent RF feature differential carrier frequency offset (DCFO) is proposed as an extended feature for the enhancement of fingerprint distinguishability. Building upon these, we introduce a fingerprinting scheme called PR-RFFI that generates distinguishable fingerprints for a set of devices by injecting appropriate I/Q imbalance and DCFO into the STF. Leveraging the short-term invariance of the channel, we design a practical I/Q imbalance extraction method based on the communication-quality preserving injection. Moreover, we design an optimal assignment method for I/Q imbalance and DCFO to maximize the distinguishability of RF fingerprints for all devices. Finally, we implement the PR-RFFI solution and conduct experiments in real-world and simulation scenarios. The experimental results demonstrate that PR-RFFI consistently maintains good communication quality, and achieves over 98% precision, recall, and F1-score. Xiaolin Gu, Wenjia Wu, Ming Yang 0001, Linqing Gui, Zhen Ling 0001, Fu Xiao 0001, Junzhou Luo |
IEEE Trans. Mob. Comput. | 5 |
| 2026 | Toward Practical Headphones Eavesdropping Leveraging COTS mmWave RadarabstractHeadphones have become ubiquitous in daily work and communication, leading users to assume a sense of privacy and security during confidential conversations while overlooking the potential risk of eavesdropping. In this paper, we present mmEar, an end-to-end eavesdropping system that demonstrates the feasibility of compromising headphones using a commercial off-the-shelf (COTS) mmWave radar. Unlike previous approaches that rely on relatively strong vibrations, mmEar targets extremely faint, low-SNR speech-induced vibrations on headphone surfaces. To address this challenge, we introduce a Faint Vibration Emphasis (FVE) technique that amplifies phase variations on the IQ plane, followed by a deep denoising network for enhanced signal quality. Furthermore, we design a diffusion-based generative model within a pretrain–finetune framework, leveraging large-scale synthetic data to significantly improve generalization and robustness across diverse scenarios. Extensive experiments on multiple headphone and earphone models validate the practicality and effectiveness of the proposed attack, revealing that most tested devices can be compromised to recover intelligible speech. Xiangyu Xu 0001, Hao Kong 0004, Zhen Ling 0001, Jiadi Yu, Junzhou Luo, Xinwen Fu |
IEEE Trans. Mob. Comput. | 5 |
| 2025 | Revolutionizing Encrypted Traffic Classification with MH-Net: A Multi-View Heterogeneous Graph ModelabstractWith the growing significance of network security, the classification of encrypted traffic has emerged as an urgent challenge. Traditional byte-based traffic analysis methods are constrained by the rigid granularity of information and fail to fully exploit the diverse correlations between bytes. To address these limitations, this paper introduces MH-Net, a novel approach for classifying network traffic that leverages multi-view heterogeneous traffic graphs to model the intricate relationships between traffic bytes. The essence of MH-Net lies in aggregating varying numbers of traffic bits into multiple types of traffic units, thereby constructing multi-view traffic graphs with diverse information granularities. By accounting for different types of byte correlations, such as header-payload relationships, MH-Net further endows the traffic graph with heterogeneity, significantly enhancing model performance. Notably, we employ contrastive learning in a multi-task manner to strengthen the robustness of the learned traffic unit representations. Experiments conducted on the ISCX and CIC-IoT datasets for both the packet-level and flow-level traffic classification tasks demonstrate that MH-Net achieves the best overall performance compared to dozens of SOTA methods. Haozhen Zhang, Haodong Yue, Xi Xiao 0001, Le Yu 0002, Qing Li 0006, Zhen Ling 0001 |
AAAI | 6 |
| 2025 | Time Tells All: Deanonymization of Blockchain RPC Users with Zero Transaction FeeabstractRemote Procedure Call (RPC) services have become a primary gateway for users to access public blockchains. While they offer significant convenience, RPC services also introduce critical privacy challenges that remain insufficiently examined. Existing deanonymization attacks either do not apply to blockchain RPC users or incur costs like transaction fees assuming an active network eavesdropper. In this paper, we propose a novel deanonymization attack that can link an IP address of a RPC user to this user's blockchain pseudonym. Our analysis reveals a temporal correlation between the timestamps of transaction confirmations recorded on the public ledger and those of TCP packets sent by the victim when querying transaction status. We assume a strong passive adversary with access to network infrastructure, capable of monitoring traffic at network border routers or Internet exchange points. By monitoring network traffic and analyzing public ledgers, the attacker can link the IP address of the TCP packet to the pseudonym of the transaction initiator by exploiting the temporal correlation. This deanonymization attack incurs zero transaction fee. We mathematically model and analyze the attack method, perform large-scale measurements of blockchain ledgers, and conduct real-world attacks to validate the attack. Our attack achieves a high success rate of over 95% against normal RPC users on various blockchain networks, including Ethereum, Bitcoin and Solana. Shan Wang 0008, Ming Yang 0001, Yu Liu 0168, Yue Zhang 0025, Shuaiqing Zhang, Zhen Ling 0001, Jiannong Cao 0001, Xinwen Fu |
CCS | 6 |
| 2025 | FlexEmu: Towards Flexible MCU Peripheral EmulationabstractMicrocontroller units (MCUs) are widely used in embedded devices due to their low power consumption and cost-effectiveness. MCU firmware controls these devices and is vital to the security of embedded systems. However, performing dynamic security analyses for MCU firmware has remained challenging due to the lack of usable execution environments -- existing dynamic analyses cannot run on physical devices (e.g., insufficient computational resources), while building emulators is costly due to the massive amount of heterogeneous hardware, especially peripherals. Recent advances in automated peripheral emulation have made MCU emulation more scalable. However, these efforts only support limited peripherals and are hard to extend because they require ad-hoc adaptations. Chongqing Lei, Zhen Ling 0001, Xiangyu Xu 0001, Shaofeng Li 0001, Guangchi Liu, Kai Dong 0001, Junzhou Luo |
CCS | 2 |
| 2025 | Poster: KeyRadar: Contactless Touchscreen Keystroke Inference via mmWave Sensing and Language ModelsabstractWe present KeyRadar, a contactless keystroke inference system that leverages mmWave radar to capture fine-grained 2D motion signals from virtual keypresses on touchscreen devices. Unlike existing visual or acoustic side-channel methods, KeyRadar uses a MIMO radar array to sense subtle back-surface vibrations and employs a hybrid CNN-Transformer model for accurate single-key recognition. To reconstruct full text input, it combines a Tire-based decoding algorithm with a large language model for semantic correction. Evaluated on a nine-key touchscreen in various user conditions, KeyRadar achieves more than 77% single-key precision and 0.8 + semantic similarity, demonstrating a practical and stealthy threat to input privacy. Haixin Zhang, Xiangyu Xu 0001, Zhen Ling 0001 |
MobiCom | 3 |
| 2025 | Poster: Object-Aware Vibration Fusion: Leveraging Frequency Response Diversity for Through-Wall EavesdroppingabstractTraditional mmWave-based acoustic eavesdropping systems primarily focus on sensing techniques, overlooking the physical characteristics of the objects being sensed. In this work, we propose Object-Aware Vibration Fusion, a through-wall eavesdropping system that leverages the frequency response diversity of everyday objects to enhance speech reconstruction. Instead of treating environmental surfaces as generic reflectors, we model and exploit their distinct resonance patterns, which respond selectively to different frequency bands of speech. By capturing and fusing vibrations from multiple objects through a frequency-aware fusion framework, our system constructs a richer and more intelligible representation of the original audio. Experimental results show that this object-centric approach significantly improves speech intelligibility and quality across varying conditions, highlighting the power of frequency response diversity in passive acoustic sensing. Xiangyu Xu 0001, Zhen Ling 0001 |
MobiCom | 3 |
| 2025 | Distributed Private Aggregation in Graph Neural Networks
Huanhuan Jia, Yuanbo Zhao, Kai Dong 0001, Zhen Ling 0001, Ming Yang 0001, Junzhou Luo, Xinwen Fu |
USENIX Security Symposium | 4 |
| 2025 | TORCHLIGHT: Shedding LIGHT on Real-World Attacks on Cloudless IoT Devices Concealed within the Tor Network
Yumingzhi Pan, Zhen Ling 0001, Yue Zhang 0025, Hongze Wang, Guangchi Liu, Junzhou Luo, Xinwen Fu |
USENIX Security Symposium | 2 |
| 2025 | The Cost of Performance: Breaking ThreadX with Kernel Object Masquerading Attacks
Xinhui Shao, Zhen Ling 0001, Yue Zhang 0025, Huaiyu Yan, Yumeng Wei, Zixia Liu, Junzhou Luo, Xinwen Fu |
USENIX Security Symposium | 2 |
| 2025 | DTPN: A Diffusion-based Traffic Purification Network for Tor Website FingerprintingabstractWebsite Fingerprinting attack is a type of method used to classify network traffic generated by users on the Tor (The Onion Router) based on the websites they visit, leading to the leakage of individuals' privacy . For Website Fingerprinting attack, network traffic defense methods involve adding noise to the original network traffic to render the attacker's methods ineffective. Previous attack methods primarily focused on improving classification accuracy by enhancing the attack model, with adversarial training being the most common approach. However, adversarial training requires frequent updates and exhibits poor generalization when dealing with previously unseen network traffic protection methods. In order to address the limitations of adversarial training, a novel method is proposed leveraging a diffusion model for network traffic purification. This paper is the first to use a diffusion model to resist network traffic defense based on adversarial perturbations. The diffusion models are theoretically suited for data purification in the training mode, i.e., removing noises generated by adversarial perturbations from the data. Our method enables existing network traffic classification methods to maintain effective classification of network traffic after protection without requiring retraining, while also achieving good generalization performance with previously unseen network traffic defense methods. The purified network traffic data can effectively improve the robustness of existing website fingerprinting methods. Experiments conducted under various network traffic defense strategies demonstrate that the proposed method increases accuracy by up to 60.8% on DF dataset and 50.3% on CW100 dataset, respectively, compared to adversarial training. Xi Xiao 0001, Guangwu Hu, Zhen Ling 0001, Hao Li 0027, Bin Zhang 0048 |
WSDM | 4 |
| 2025 | Pivot: Panoramic-Image-Based VR User Authentication against Side-Channel AttacksabstractWith metaverse attracting increasing attention from both academic and industry, the application of virtual reality (VR) has extended beyond 3D immersive viewing/gaming to a broader range of areas, such as banking, shopping, tourism, education, and so on, which involves a growing amount of sensitive and private user data into VR systems. However, with current password-based user authentication schemes in mainstream VR devices, studies demonstrate that side-channel attacks can pose a severe threat to VR user privacy. To mitigate the threat, we propose a novel panoramic-image-based VR user authentication system, i.e., Pivot , to defend against such attacks, yet maintain high usability. Specifically, in Pivot , we design an image-random-pivoting-based user interaction mechanism to assist users in quickly and securely selecting memorable points of interest in a panoramic image. Then an image region segmentation algorithm is designed to automatically scatter the points to regions to form the customized graphic password for the user, which could ensure a sufficiently large password space and also reduce the near-region point misclicks. Afterward, the region indexes are used to generate the hashed password for authentication. Both theoretical security analysis and extensive user studies demonstrate that Pivot is secure and user-friendly in practice. Gui Xiao, Zhen Ling 0001, Qunqun Fan, Xiangyu Xu 0001, Wenjia Wu, Ding Ding 0002, Chen Chen 0147, Xinwen Fu |
ACM Trans. Multim. Comput. Commun. Appl. | 2 |
| 2025 | Toward Cross-Environment Continuous Gesture User Authentication With Commercial Wi-FiabstractBehavior biometrics-based user authentication with Wi-Fi gains significant attention due to its ubiquitous and contact-free manners. An individual’s identity can be verified by analyzing activities induced signal variances, excellently balancing the security demands and user experience. However, the inherent complexity of Wi-Fi signals presents significant challenges for behavior biometrics-based user authentication. The susceptibility of Wi-Fi signals results in a poor cross-environment generalization capability, which is overlooked by the existing research. In addition, most existing works of behavior-based user authentication are based on one-off activity. This makes them vulnerable to zero-effort attacks and imitation attacks. To address these issues, we propose a cross-environment continuous gesture-based user authentication framework with Wi-Fi, dubbed Wi-CGAuth. Specifically, the cross-environment generalization capability is enhanced by the cross-layer joint optimization approach. At the lowest signal layer, the signals’ time, spatial, and frequency diversity are extended maximally, by a novel, subcarrier-level, cost-effective signal optimization strategy. At the middle layer, the multi-view fusion method, i.e., multi-transfer component analysis (TCA), is applied to refine the signals from transceiver pairs after signal preprocessing. The continuous gesture segmentation problem is modeled as the classification problem, which is solved by CNN. At the upper layer, a Convolutional Neural Network-Transformer (CNN-Transformer) model is employed to achieve the dual task of effective user authentication and accurate gesture recognition. After extensive experiments in three typical indoor scenarios, Wi-CGAuth can achieve an average authentication accuracy of 92.7%, demonstrating its robustness and effectiveness. Lei Zhang 0024, Yazhou Ma, Mingzi Zuo, Zhen Ling 0001, Changyu Dong, Guangquan Xu, Xiaochen Fan, Qian Zhang 0001 |
IEEE Trans. Netw. | 4 |
| 2024 | Collapse Like A House of Cards: Hacking Building Automation System Through FuzzingabstractBuilding Automation Systems (BAS) play a pivotal role in modern smart buildings, integrating sensors, controllers, and software to manage crucial functions such as HVAC, lighting, and more. The global smart building market is on the rise, underscoring the importance of securing BAS networks. This paper introduces the Building Automation System Evaluator (BASE), a specialized fuzzer designed to assess the security of BAS networks. BAS networks typically involve a BAS client communicating with a BAS server through BAS protocols (e.g., BACnet, KNX), each presenting unique challenges in BAS network fuzzing. These challenges encompass complex packet structures and sequencing in BAS protocols, closed-source clients with indeterminable code coverage, and unobservable server status with limited throughput. BASE automatically identifies protocol structures, dynamically instruments clients for code coverage analysis, and monitors responses for new coverage areas. Collected timestamps are used to estimate the input scan intervals of servers, optimizing throughput. We evaluated BASE on various BAS servers and clients, uncovering 13 new vulnerabilities. Furthermore, we present three attack case studies, highlighting the real-world security implications of these vulnerabilities in BAS systems, such as delayed fire detection, loss of climate control, and security breaches. We reported our findings to the respective vendors, who acknowledged the implications, and some have subsequently patched their systems based on our reports. Yue Zhang 0025, Zhen Ling 0001, Michael Cash, Qiguang Zhang, Christopher Morales, Qun Zhou 0002, Xinwen Fu |
CCS | 2 |
| 2024 | RIoTFuzzer: Companion App Assisted Remote Fuzzing for Detecting Vulnerabilities in IoT DevicesabstractDue to the diversity of architectures and peripherals of Internet of Things (IoT) systems, blackbox fuzzing stands out as a prime option for discovering vulnerabilities of IoT devices. Existing blackbox fuzzing tools often rely on companion apps to generate valid fuzzing packets. However, existing methods encounter the challenges of bypassing the cloud server side validation when it comes to fuzz devices that rely on cloud-based communication. Moreover, they tend to concentrate their efforts on Java components within Android companion apps, limiting their effectiveness in assessing non-Java components such as JavaScript-based mini-apps. In this paper, we introduce a novel blackbox fuzzing method, named RIoTFuzzer, designed to remotely uncover vulnerabilities of IoT devices with the assistance of companion apps, particularly those powered by All-in-one Apps with the JavaScript-based mini-apps feature enabled. Our approach utilizes document-based control command extraction, hybrid analysis for mutation point identification and side-channel-guided fuzzing to effectively address the challenges of fuzzing IoT devices remotely. We apply RIoTFuzzer to 27 IoT devices on prominent platforms and discovered 11 vulnerabilities. All of them have been acknowledged by the corresponding vendors. 8 have been confirmed by the vendors and have been assigned 4 CVE IDs. Our experiment results also demonstrate that side-channel-guided fuzzing can significantly enhance the efficiency of fuzzing packets sent to IoT devices, with an average increase of 76.62% and a maximum increase of 362.62%. Kaizheng Liu, Ming Yang 0001, Zhen Ling 0001, Yue Zhang 0025, Chongqing Lei, Junzhou Luo, Xinwen Fu |
CCS | 3 |
| 2024 | CORE: Transaction Commit-Controlled Release of Private Data Over BlockchainsabstractIn blockchain applications such as digital goods exchange, private data may be transmitted from a data owner to a recipient through a transfer transaction. However, these blockchain applications often assume the underlying blockchain system is secure and reliable, and thus do not consider transaction failures. We find that a failed transfer transaction may disclose the private data to the recipient, but the data owner may not receive tokens as payments or the ledger may not correctly record the data trail. To handle transaction failures and protect private data, we propose a novel transaction commit-controlled release (CORE) protocol. With CORE, the private data can only be obtained by an intended recipient after the transfer transaction is committed, the data owner receives tokens, and the ledger correctly records the data trail. We perform security analysis of CORE, implement CORE and evaluate its performance over representative public and permissioned blockchains. The results of our extensive experiments show CORE introduces minor overhead in terms of transaction latency and transaction fees. We are the first to identify and address the generic private data disclosure issues in both public and permissioned blockchains. Shan Wang 0008, Ming Yang 0001, Jiannong Cao 0001, Zhen Ling 0001, Qiang Tang 0005, Xinwen Fu |
ICDCS | 4 |
| 2024 | WFGuard: an Effective Fuzzing-testing-based Traffic Morphing Defense against Website FingerprintingabstractWebsite fingerprinting (WF) attack is a type of traffic analysis attack. It enables a local and passive eavesdropper situated between the Tor client and the Tor entry node to deduce which websites the client is visiting. Currently, deep learning (DL) based WF attacks have overcome a number of proposed WF defenses, demonstrating superior performance compared to traditional machine learning (ML) based WF attacks. To mitigate this threat, we present WFGuard, a fuzzing-testing-based traffic morphing WF defense technique. WFGuard employs fine-grained neuron information within WF classifiers to design a joint optimization function and then applies gradient ascent to maximize both neurons value and misclassification possibility in DL-based WF classifiers. During each traffic mutation cycle, we propose a gradient based dummy traffic injection pattern generation approach, continuously mutating the traffic until a pattern emerges that can successfully deceive the classifier. Finally, the pattern present in successful variant traces are extracted and applied as defense strategies to Tor traffic. Extensive evaluations reveal that WFGuard can effectively decrease the accuracy of DL-based WF classifiers (e.g., DF and Var-CNN) to a mere 4.43%, while only incurring an 11.04% bandwidth overhead. This highlights the potential efficacy of our approach in mitigating WF attacks. Zhen Ling 0001, Gui Xiao, Xiangyu Xu 0001, Guangchi Liu |
INFOCOM | 1 |
| 2024 | Samba: Detecting SSL/TLS API Misuses in IoT Binary ApplicationsabstractIoT devices are increasingly adopting Secure Socket Layer (SSL) and Transport Layer Security (TLS) protocols. However, the misuse of SSL/TLS libraries still threatens the communication. Existing tools for detecting SSL/TLS API misuses primarily rely on source code analysis while IoT applications are usually released as binaries with no source code. This paper presents Samba, a novel tool to automatically detect SSL/TLS API misuses in IoT binaries through static analysis. To overcome the path explosion problem and deal with various SSL/TLS implementations, we introduce a three-level reduction method to construct the SSL/TLS API-centric graph (SAG), which has a much smaller size compared with the conventional inter-procedural control flow graph. We propose a formal expression of API misuse signatures, which is capable of capturing different types of misuse, particularly those in the SSL/TLS connection establishment process. We successfully analyze 115 IoT binaries and find that 94 of them have the vulnerability of insecure certificate verification and 112 support deprecated SSL/TLS protocols. Samba is the first IoT binary analysis system for detecting SSL/TLS API misuses. Kaizheng Liu, Ming Yang 0001, Zhen Ling 0001, Yuan Zhang 0009, Chongqing Lei, Xinwen Fu |
INFOCOM | 3 |
| 2024 | A De-anonymization Attack against Downloaders in FreenetabstractFreenet is a well-known anonymous communication system that enables file sharing among users. It employs a probabilistic hops-to-live (HTL) decrement approach to hide the originator among nodes in a multi-hop path. Therefore, all nodes shall exhibit identical behaviors to preserve anonymity. However, we discover that the path folding mechanism in Freenet violates this principle due to behavior discrepancy between downloaders and intermediate nodes. The path folding mechanism is designed to optimize the network topology of Freenet. A delayed path folding message by a successor node may incur a timeout event at its predecessor, and an intermediate node reacts differently to such timeout with a downloader. Therefore, malicious nodes can deliberately trigger the timeout event to identify downloaders. The complex implementation of the path folding timeout detection mechanism in Freenet complicates our de-anonymization attack. We thoroughly analyze the underlying cause and develop three strategies to manipulate three types of messages respectively at the malicious node, minimizing the false positive rate. We conduct extensive real-world experiments to verify the feasibility and effectiveness of our attack. They show that our attack achieves a true positive rate of 100% and false positive rate of near 0% under two different Freenet download modes. Yonghuan Xu, Ming Yang 0001, Zhen Ling 0001, Zixia Liu, Xiaodan Gu |
INFOCOM | 3 |
| 2024 | mmEar: Push the Limit of COTS mmWave Eavesdropping on HeadphonesabstractRecent years have witnessed a surge of headphones (including in-ear headphones) usage in works and communications. Because of the privacy-preserve property, people feel comfortable having confidential communication wearing headphones and pay little attention to speech leakage. In this paper, we present an end-to-end eavesdropping system, mmEar, which shows the feasibility of launching an eavesdropping attack on headphones leveraging a commercial mmWave radar. Different from previous works that realize eavesdropping by sensing speech-induced vibrations with reasonable amplitude, mmEar focuses on capturing the extremely faint vibrations with a low signal-to-noise ratio (SNR) on the surface of headphones. Toward this end, we propose a faint vibration emphasis (FVE) method that models and amplifies the mmWave responses to speech-induced vibrations on the In-phase and Quadrature (IQ) plane, followed by a deep denoising network to further improve the SNR. To achieve practical eavesdropping on various headphones and setups, we propose a cGAN model with a pretrain-finetune scheme, boosting the generalization ability and robustness of the attack by generating high-quality synthesis data. We evaluate mmEar with extensive experiments on different headphones and earphones and find that most of them can be compromised by the proposed attack for speech recovery. Xiangyu Xu 0001, Zhen Ling 0001, Li Lu 0008, Junzhou Luo, Xinwen Fu |
INFOCOM | 3 |
| 2024 | CQP-RFFI: Injecting a Communication-Quality Preserving RF Fingerprint for Wi-Fi Device IdentificationabstractRecently, there has been an emerging radio frequency fingerprint identification (RFFI) technology that enhances fingerprint distinguishability by deliberately injecting I/Q imbalance into the device’s Wi-Fi baseband signal. Due to the additional injection of I/Q imbalance, this approach inevitably impacts the communication quality between devices, as it reduces the accuracy of channel estimation. To address this issue, we propose injecting the I/Q imbalance into a short training field (STF) instead of the entire baseband signal. Our findings indicate that this method can effectively preserve the quality of the original wireless communication. Building upon this, we introduce a fingerprinting scheme called CQP-RFFI that generates distinguishable fingerprints for a set of devices by injecting appropriate I/Q imbalance into the STF. Leveraging the short-term invariance of the channel, we design a practical I/Q imbalance extraction method based on the communication-quality preserving injection. Moreover, we design an optimal assignment method for I/Q imbalance to maximize the distinguishability of RF fingerprints for all devices. Finally, we implement the CQP-RFFI solution and conduct experiments in real-world scenarios. The experimental results demonstrate that CQP-RFFI achieves 96% precision, recall, and F1-score, and can consistently maintain good communication quality. Xiaolin Gu, Wenjia Wu, Yusen Zhou, Aibo Song, Ming Yang 0001, Zhen Ling 0001, Junzhou Luo |
IWQoS | 6 |
| 2024 | LDR: Secure and Efficient Linux Driver Runtime for Embedded TEE Systems
Huaiyu Yan, Zhen Ling 0001, Xinhui Shao, Kai Dong 0001, Ming Yang 0001, Junzhou Luo, Xinwen Fu |
NDSS | 2 |
| 2024 | Relation Mining Under Local Differential Privacy
Kai Dong 0001, Chuang Jia, Zhen Ling 0001, Ming Yang 0001, Junzhou Luo, Xinwen Fu |
USENIX Security Symposium | 4 |
| 2024 | A Friend's Eye is A Good Mirror: Synthesizing MCU Peripheral Models from Peripheral Drivers
Chongqing Lei, Zhen Ling 0001, Yue Zhang 0025, Junzhou Luo, Xinwen Fu |
USENIX Security Symposium | 2 |
| 2024 | TEA-RFFI: Temperature adjusted radio frequency fingerprint-based smartphone identification
Xiaolin Gu, Wenjia Wu, Yusen Zhou, Aibo Song, Ming Yang 0001, Zhen Ling 0001, Junzhou Luo |
Comput. Networks | 6 |
| 2024 | On building automation system securityabstractBuilding Automation Systems (BASs) are seeing increased usage in modern society due to the plethora of benefits they provide such as automation for climate control, HVAC systems, entry systems, and lighting controls. Many BASs in use are outdated and suffer from numerous vulnerabilities that stem from the design of the underlying BAS protocol. In this paper, we provide a comprehensive, up-to-date survey on BASs and attacks against seven BAS protocols including BACnet, EnOcean, KNX, LonWorks, Modbus, ZigBee, and Z-Wave. Holistic studies of secure BAS protocols are also presented, covering BACnet Secure Connect, KNX Data Secure, KNX/IP Secure, ModBus/TCP Security, EnOcean High Security and Z-Wave Plus. LonWorks and ZigBee do not have security extensions. We point out how these security protocols improve the security of the BAS and what issues remain. A case study is provided which describes a real-world BAS and showcases its vulnerabilities as well as recommendations for improving the security of it. We seek to raise awareness to those in academia and industry as well as highlight open problems within BAS security. Christopher Morales, Matthew Harper, Michael Cash, Zhen Ling 0001, Qun Zhou 0002, Xinwen Fu |
High Confid. Comput. | 5 |
| 2024 | Optimal Harvest-Then-Transmit Scheduling for Throughput Maximization in Time-Varying RF Powered SystemsabstractEnergy harvesting is a promising technique to address the energy hunger problem for thousands of wireless devices. In Radio Frequency (RF) energy harvesting systems, a wireless device first harvests energy and then transmits data with this energy, hence the ‘harvest-then-transmit’ (HTT) principle is widely adopted. We must carefully design the HTT schedule, i.e., schedule the timing between harvesting and transmission, and decide the data transmission power such that the throughput can be maximized with the limited harvested energy. Distinct from existing work, we assume energy harvested from RF sources is time-varying, which is more practical but more difficult to handle. We first discover a surprising result that the optimal transmission power is independent of the transmission time, but solely depends on the RF harvesting power, for a simple case when the energy harvesting is stable. We then obtain an optimal offline HTT-scheduling for the general case that allows the RF harvesting power to vary with time. To the best of our knowledge, it is the first optimal HTT-scheduling algorithm that achieves maximum data throughput for time-varying RF powered systems. Finally, an efficient online heuristic algorithm is designed based on the offline optimality properties. Simulations show that the proposed online algorithm has superior performance, which achieves more than 90% of the offline maximum throughput in most cases. Feng Shan, Junzhou Luo, Qiao Jin 0003, Liwen Cao, Weiwei Wu 0001, Zhen Ling 0001, Fang Dong 0001 |
IEEE J. Sel. Areas Commun. | 6 |
| 2024 | IdeNet: Making Neural Network Identify Camouflaged Objects Like CreaturesabstractCamouflaged objects often blend in with their surroundings, making the perception of a camouflaged object a more complex procedure. However, most neural-network-based methods that simulate the visual information processing pathway of creatures only roughly define the general process, which deficiently reproduces the process of identifying camouflaged objects. How to make modeled neural networks perceive camouflaged objects as effectively as creatures is a significant topic that deserves further consideration. After meticulous analysis of biological visual information processing, we propose an end-to-end prudent and comprehensive neural network, termed IdeNet, to model the critical information processing. Specifically, IdeNet divides the entire perception process into five stages: information collection, information augmentation, information filtering, information localization, and information correction and object identification. In addition, we design tailored visual information processing mechanisms for each stage, including the information augmentation module (IAM), the information filtering module (IFM), the information localization module (ILM), and the information correction module (ICM), to model the critical visual information processing and establish the inextricable association of biological behavior and visual information processing. The extensive experiments show that IdeNet outperforms state-of-the-art methods in all benchmarks, demonstrating the effectiveness of the five-stage partitioning of visual information processing pathway and the tailored visual information processing mechanisms for camouflaged object detection. Our code is publicly available at: https://github.com/whyandbecause/IdeNet. Juwei Guan, Xiaolin Fang 0001, Tongxin Zhu, Zhipeng Cai 0001, Zhen Ling 0001, Ming Yang 0001, Junzhou Luo |
IEEE Trans. Image Process. | 5 |
| 2024 | RF-TESI: Radio Frequency Fingerprint-based Smartphone Identification under Temperature VariationabstractRadio frequency fingerprint identification (RFFI) is a promising technique for smartphone identification. However, we find that the temperature of the RF front end in smartphones can significantly impact the RF features, including the carrier frequency offset (CFO) and statistical RF features. The unstable RF features caused by temperature changes can negatively affect the performance of state-of-the-art RFFI approaches. To this end, we propose the RF-TESI solution for smartphone identification under temperature variation. First, we construct a dataset by extracting temperature and RF features. In the dataset, the extracted temperature values constitute a set of temperature values and each registered temperature value corresponds to a group of RF features. Next, we evaluate the distinctiveness of RF features across smartphones to select the most suitable RF fingerprint. Then, we train multiple random forest models, each tagged with a registered temperature. In addition, because there are still many temperatures out of the temperature set, we design an RF fingerprint estimation method to estimate RF fingerprints at unregistered temperatures. Finally, the experiments show RF-TESI demonstrates satisfactory performance under different scenarios, taking into account variations in temperature, time and position. Besides, our proposed approach is better than all state-of-the-art approaches in smartphone identification. Xiaolin Gu, Wenjia Wu, Aibo Song, Ming Yang 0001, Zhen Ling 0001, Junzhou Luo |
ACM Trans. Sens. Networks | 5 |
| 2023 | Lightweight Gesture Based Trigger-Action Programming for Home Internet-of-ThingsabstractIFTTT is one of the most popular Trigger-Action Programming platforms. The rules generated in IFTTT are named IoT Applets. Despite the powerful programming interface provided by IFTTT, establishing an Applet requires technical skills and is not convenient enough for most users. To address this problem, we propose a gesture based programming method to help end users establish and manage IoT Applets in a convenient way. It requires employment of an RGB-D camera, and recognizes users’ pointing rays and hand actions. The obtained information is interpreted to certain devices and device events for Applet management. An experiment involving 20 participants validates the performance of our proposed method. Kai Dong 0001, Xiaodan Gu, Zhen Ling 0001, Ming Yang 0001 |
CSCWD | 4 |
| 2023 | TorDNS: A Novel Correlated Onion Address Generation Approach and ApplicationabstractThe onion service is the most important mechanism of the Tor network which enables service providers to publish anonymously various TCP services, such as web services. To access the target onion services, clients first know the 56-byte onion addresses. However, randomly generated onion addresses are difficult to memorize and can be easily used by attackers to generate phishing sites with similar onion addresses. In this paper, we propose a correlated onion address generation approach which is capable of generating a unique onion address via a customized string and a root onion address. This approach enables the generated onion addresses to be computed by clients using a human-memorable string, resulting in easier access to onion services. Based on this approach, we design and implement a Tor Domain Name System (TorDNS) that allows different service providers to register anonymously and clients to access anonymous services quickly through human-memorable pseudo-onion addresses. TorDNS is compatible with existing onion service mechanism and does not introduce additional privacy and security issues. In addition, similarity detection of pseudo-onion addresses can effectively reduce the risk of phishing sites on the Tor network. Chunmian Wang, Junzhou Luo, Zhen Ling 0001, Ming Yang 0001, Xiaodan Gu, Yu Yao 0008 |
CSCWD | 3 |
| 2023 | A Comprehensive and Long-term Evaluation of Tor V3 Onion Services
Chunmian Wang, Junzhou Luo, Zhen Ling 0001, Xinwen Fu |
INFOCOM | 3 |
| 2023 | Do Not Give a Dog Bread Every Time He Wags His Tail: Stealing Passwords through Content Queries (CONQUER) Attacks
Chongqing Lei, Zhen Ling 0001, Yue Zhang 0025, Kai Dong 0001, Kaizheng Liu, Junzhou Luo, Xinwen Fu |
NDSS | 2 |
| 2023 | Sensor-based implicit authentication through learning user physiological and behavioral characteristics
Jinghui Zhang 0001, Hancheng Zhang, Zhen Ling 0001, Ming Yang 0001 |
Comput. Commun. | 5 |
| 2023 | Wi-Fi device identification based on multi-domain physical layer fingerprint
Jinghui Zhang 0001, Zhengjia Xu, Junhe Li, Qiangsheng Dai, Zhen Ling 0001, Ming Yang 0001 |
Comput. Commun. | 5 |
| 2023 | A practical multi-tab website fingerprinting attack
Xiaodan Gu, Ming Yang 0001, Bingchen Song, Zhen Ling 0001 |
J. Inf. Secur. Appl. | 5 |
| 2023 | Mobile applications identification using autoencoder based electromagnetic side channel analysis
Jinghui Zhang 0001, Boxi Liang, Hancheng Zhang, Zhen Ling 0001, Ming Yang 0001 |
J. Inf. Secur. Appl. | 5 |
| 2023 | Flow Topology-Based Graph Convolutional Network for Intrusion Detection in Label-Limited IoT NetworksabstractGiven the distributed nature of the massively connected “Things” in IoT, IoT networks have been a primary target for cyberattacks. Although machine learning based network intrusion detection systems (NIDS) can effectively detect abnormal network traffic behaviors, most existing approaches are based on a large amount of labeled traffic flow data, which hinders their implementation in the highly dynamic IoT networks with limited labeling. In this paper, we develop a novel Flow Topology based Graph Convolutional Network (FT-GCN) approach for label-limited IoT network intrusion detection. Our main idea is to leverage the underlying traffic flow patterns,$i.e.$, the flow topological structure, to unlock the full potential of the traffic flow data with limited labeling, where the FT-GCN will be deployed at the edge servers in IoT networks to detect intrusions via software defined network technologies. Specifically, FT-GCN first takes the time correlation of traffic flows into account to construct an interval-constrained traffic graph (ICTG). Besides, a Node-Level Spatial (NLS) attention mechanism is designed to further enhance the key statistical features of traffic flows in ICTG. Finally, the combined representation of statistical flow features and flow topological structure are learned by the cost-effective Topology Adaptive Graph Convolutional Networks (TAGCN) for intrusion identification in IoT networks. Extensive experiments are conducted on three real-world datasets, which demonstrate the effectiveness of the proposed FT-GCN compared to state-of-the-art approaches. Xiaoheng Deng, Jincai Zhu, Xin-jun Pei, Lan Zhang 0005, Zhen Ling 0001, Kaiping Xue |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2022 | fASLR: Function-Based ASLR for Resource-Constrained IoT Systems
Xinhui Shao, Zhen Ling 0001, Huaiyu Yan, Yumeng Wei, Xinwen Fu |
ESORICS (2) | 3 |
| 2022 | Implication of Animation on Android SecurityabstractWe find that seemingly innocuous animations widely used in Android can pose great threats to user security and privacy. Both entrance and exit animations can be exploited. In our draw-and-destroy overlay attack, a malicious app periodically draws and destroys transparent UI-intercepting overlays, which can be put over victim apps to intercept user inputs stealthily. Although Android is patched to show alerts if there is an overlay over an app, quickly drawing and destroying malicious overlays can exploit the slow-in animation of the notification alert view and suppress the alert. In our draw-and-destroy toast attack, a malicious app periodically creates a new customized toast over a victim app before the previously customized toast disappears. This attack exploits the fade-out animation of the toast so that transition between two successive toasts cannot be observed. The two draw-and-destroy attacks can be building blocks of other attacks. We particularly study the password-stealing attack given its severe consequence, in which the draw-and-destroy toast attack displays a fake keyboard over the original keyboard and the draw-and-destroy overlay attack places transparent overlays over the fake keyboard to intercept user inputs. Extensive real-world experiments are conducted to validate the feasibility and effectiveness of the attacks. We also discuss defense measures mitigating the attacks. We are the first to discover the security implications of animation on Android security. Shan Wang 0008, Zhen Ling 0001, Yue Zhang 0025, Ruizhao Liu, Joshua Kraunelis, Kang Jia, Bryan Pearson, Xinwen Fu |
ICDCS | 2 |
| 2022 | Real-Time Execution of Trigger-Action Connection for Home Internet-of-ThingsabstractIFTTT is a programming framework for Applets (i.e., user customized policies with a "trigger-action" syntax), and is the most popular Home Internet-of-Things (H-IoT) platform. The execution of an Applet prompted by a device operation suffers from a long delay, since IFTTT has to periodically reads the states of the device to determine whether the trigger is satisfied, with an interval of up to 5min for professionals and 60min for normal users. Although IFTTT sets up a flexible polling interval based on the past several times an Applet has run, the delay is still around 2min even for frequently executed Applets. This paper proposes a novel trigger notification mechanism "RTX-IFTTT" to implement real-time execution of Applets. The mechanism does not require any changes to the current IFTTT framework or the H-IoT devices, but only requires an H-IoT edge node (e.g., router) to identify the device events (e.g., turning on/off) and notify IFTTT to perform the action of an Applet when an identified event is the trigger of that Applet. The experimental results show that the averaged Applet execution delay for RTX-IFTTT is only about 2sec. Kai Dong 0001, Daoming Li, Zhen Ling 0001, Wenjia Wu |
INFOCOM | 5 |
| 2022 | Towards an Efficient Defense against Deep Learning based Website FingerprintingabstractWebsite fingerprinting (WF) attacks allow an attacker to eavesdrop on the encrypted network traffic between a victim and an anonymous communication system so as to infer the real destination websites visited by a victim. Recently, the deep learning (DL) based WF attacks are proposed to extract high level features by DL algorithms to achieve better performance than that of the traditional WF attacks and defeat the existing defense techniques. To mitigate this issue, we propose a-genetic-programming-based variant cover traffic search technique to generate defense strategies for effectively injecting dummy Tor cells into the raw Tor traffic. We randomly perform mutation operations on labeled original traffic traces by injecting dummy Tor cells into the traces to derive variant cover traffic. A high level feature distance based fitness function is designed to improve the mutation rate to discover successful variant traffic traces that can fool the DL-based WF classifiers. Then the dummy Tor cell injection patterns in the successful variant traces are extracted as defense strategies that can be applied to the Tor traffic. Extensive experiments demonstrate that we can introduce 8.1% of bandwidth overhead to significantly decrease the accuracy rate below 0.4% in the realistic open-world setting. Zhen Ling 0001, Gui Xiao, Wenjia Wu, Xiaodan Gu, Ming Yang 0001, Xinwen Fu |
INFOCOM | 1 |
| 2022 | Large-scale Evaluation of Malicious Tor Hidden Service Directory DiscoveryabstractTor is the largest anonymous communication system, providing anonymous communication services to approximately 2.8 million users and 170,000 hidden services per day. The Tor hidden service mechanism can protect a server from exposing its real identity during the communication. However, due to a design flaw of the Tor hidden service mechanism, adversaries can deploy malicious Tor hidden service directories (HSDirs) to covertly collect all onion addresses of hidden services and further probe the hidden services. To mitigate this issue, we design customized honeypot hidden services based on one-to-one and many-to-one HSDir monitoring approaches to luring and identifying the malicious HSDirs conducting the rapid and delayed probing attacks, respectively. By analyzing the probing behaviors and payloads, we investigate a novel semantic-based probing pattern clustering approach to classify the adversaries so as to shed light on the purposes of the malicious HSDirs. Moreover, we perform theoretical analysis of the capability and accuracy of our approaches. Large-scale experiments are conducted in the real-world Tor network by deploying hundreds of thousands of honeypots during a monitoring period of more than three months. Finally, we identify 8 groups of 32 malicious HSDirs, discover 25 probing pattern clusters and reveal 3 major probing purposes. Chunmian Wang, Zhen Ling 0001, Wenjia Wu, Ming Yang 0001, Xinwen Fu |
INFOCOM | 2 |
| 2022 | TeRFF: Temperature-aware Radio Frequency Fingerprinting for SmartphonesabstractIn recent years, radio frequency (RF) fingerprinting has attracted more and more attention. Many different types of RF fingerprints have been proposed, such as carrier frequency offset (CFO), sampling frequency offset and error vector magnitude. Among them, the CFO fingerprint is recognized as a promising RF fingerprint. However, for commonly used smartphones, we find that its CFO fingerprint is unstable, because the temperature of crystal oscillator varies greatly and large fluctuations of temperature significantly affect its CFO fingerprint. Therefore, the solutions of CFO-based fingerprinting will no longer be effective for smartphones if the temperature of crystal oscillator is not involved. To this end, we propose a more reliable and applicable CFO-based fingerprinting approach called temperature-aware radio frequency fingerprinting (TeRFF). First, we construct a dataset by extracting crystal oscillator's temperature and the corresponding CFO value on multiple smartphones over a period. In the dataset, the extracted temperature values constitute a set of temperature values, and each registered temperature value corresponds to a group of CFO samples. On this basis, we train multiple Naive Bayes models, each tagged with a registered temperature value. Moreover, since there are many temperature values which are not in the temperature set, we design a CFO estimation method to estimate the CFO fingerprint at the unregistered temperature. Finally, the experimental results demonstrate that our proposed solution TeRFF makes the CFO fingerprinting still effective for smartphone identification, and its performance is better than other existing RF fingerprinting schemes. Xiaolin Gu, Wenjia Wu, Naixuan Guo, Aibo Song, Ming Yang 0001, Zhen Ling 0001, Junzhou Luo |
SECON | 7 |
| 2022 | Learning-aided client association control for high-density WLANs
Wenjia Wu, Jiazhi Yao, Xiaolin Fang 0001, Feng Shan, Ming Yang 0001, Zhen Ling 0001, Junzhou Luo |
Comput. Networks | 7 |
| 2022 | fASLR: Function-Based ASLR via TrustZone-M and MPU for Resource-Constrained IoT SystemsabstractThe address space layout randomization (ASLR) has been widely deployed on modern operating systems against code reuse attacks (CRAs), such as return-oriented programming (ROP) and jump-oriented programming (JOP). However, porting ASLR to resource-constrained IoT devices is a great challenge due to the limited memory space for randomization. We propose a function-based ASLR scheme (fASLR) for IoT runtime security utilizing the ARM TrustZone-M technology and the memory protection unit (MPU) supported by ARM Cortex-M processors. fASLR loads a function from the flash and randomizes its base address in a randomization region in RAM when the function is being called. We design novel mechanisms on cleaning up finished functions from the RAM and memory addressing to tackle the complexity of function relocation and randomization. Optimizations are applied to effectively reduce overhead introduced by runtime memory management. We also formally prove that user applications will run correctly with fASLR enabled. Compared with the related work, a prominent advantage of fASLR is that fASLR can run an application even if the application code cannot be completely loaded into RAM for execution. We test fASLR with 21 applications. The experimental results show that fASLR achieves a high randomization entropy and incurs a runtime overhead of less than 10%. Xinhui Shao, Zhen Ling 0001, Huaiyu Yan, Yumeng Wei, Xinwen Fu |
IEEE Internet Things J. | 3 |
| 2022 | On Security of TrustZone-M-Based IoT SystemsabstractInternet of Things (IoT) devices have been increasingly integrated into our daily life. However, such smart devices suffer a broad attack surface. Particularly, attacks targeting the device software at runtime are challenging to defend against if IoT devices use resource-constrained microcontrollers (MCUs). TrustZone-M, a TrustZone extension designed specifically for MCUs, is an emerging hardware security technique fortifying software security of MCU-based IoT devices. This article introduces a comprehensive security framework for IoT devices using TrustZone-M-enabled MCUs, in which device security is protected in five dimensions, i.e., hardware, boot-time software, runtime software, network, and over-the-air (OTA) update. Along developing the framework, we also present the first security analysis of potential runtime software security issues in TrustZone-M-enabled MCUs. In particular, we explore the feasibility of launching stack-based buffer overflow (BOF) attack for code injection, return-oriented programming (ROP) attack, heap-based BOF attack, format string attack, and attacks against nonsecure callable (NSC) functions in the context of TrustZone-M. We validate these attacks using SAM L11, a microchip MCU with TrustZone-M and provide defense mechanisms in the runtime software dimension of the proposed framework. The security framework is implemented with a full-fledged secure and trustworthy air quality monitoring device using SAM L11 as its MCU. Yue Zhang 0025, Clayton White, Brandon Keating, Bryan Pearson, Xinhui Shao, Zhen Ling 0001, Haofei Yu, Cliff C. Zou, Xinwen Fu |
IEEE Internet Things J. | 7 |
| 2021 | 802.11ac Device Identification based on MAC Frame AnalysisabstractIn Wi-Fi networks, devices can be identified by physical features or MAC layer features, and the solutions of device identification can be used to enhance device authentication. Since 802.11ac Standard has been widely applied in Wi-Fi devices in recent years, the traditional identification methods designed for 802.11b/g/n devices will be no longer applicable. Therefore, it is necessary to design the corresponding 802.11ac device identification method. Compared with the physical feature-based method, the MAC layer-based method has advantages of low cost and easy deployment, so it has attracted more and more researchers' attention. In this paper, we use the fields from 802.11ac MAC frame as fingerprints. Through the analysis of 802.11ac MAC frame, a preprocessing method of the frame is proposed to mask strong and easy-to-modified identifiers. Then to overcome the difficulties caused by random changes in field values, we propose a device identification method based on the deep learning to select features automatically. Compared with the previous one using the transmitting rate as a feature, our method does not spend much time capturing packets in the device identification stage and has better performance whose average precision and recall exceed 99%. Xiaolin Gu, Wenjia Wu, Zhouguo Chen, Aibo Song, Zhen Ling 0001, Ming Yang 0001 |
CSCWD | 5 |
| 2021 | Prison Break of Android Reflection Restriction and DefenseabstractJava reflection technique is pervasively used in the Android system. To reduce the risk of reflection abuse, Android restricts the use of reflection at the Android Runtime (ART) to hide potentially dangerous methods/fields. We perform the first comprehensive study of the reflection restrictions and have discovered three novel approaches to bypass the reflection restrictions. Novel reflection-based attacks are also presented, including the password stealing attack. To mitigate the threats, we analyze these restriction bypassing approaches and find three techniques crucial to these approaches, i.e., double reflection, memory manipulation, and inline hook. We propose a defense mechanism that consists of classloader double checker, ART variable protector, and ART method protector, to prohibit the reflection restriction bypassing. Finally, we design and implement an automatic reflection detection framework and have discovered 5,531 reflection powered apps out of 100,000 downloaded apps, which are installed on our defense enabled Android system of a Google Pixel 2 to evaluate the effectiveness and efficiency of our defense mechanism. Extensive empirical experiment results demonstrate that our defense enabled system can accurately obstruct the malicious reflection attempts. Zhen Ling 0001, Ruizhao Liu, Yue Zhang 0025, Kang Jia, Bryan Pearson, Xinwen Fu, Junzhou Luo |
INFOCOM | 1 |
| 2021 | Resource Demand Prediction of Cloud Workloads Using an Attention-based GRU ModelabstractResources of cloud workloads can be automatically allocated according to the requirements of the application. In the long-term running process, resource requirements change dynamically. Insufficient allocation may lead to the decline of service quality, and excessive allocation will lead to the waste of resources. Therefore, it is crucial to accurately predict resource demand. This paper aims to improve resource utilization in the data center by predicting the resources required for each application. Resource demand forecasting understands and manages future resource needs by mining current and past resource usage patterns. Because we need to analyze time series data with long-term dependence and noise, it is challenging to predict future resource utilization.We designed and implemented an attention-based GRU model. The attention mechanism was added to the GRU model to quickly filter out valuable information from large amounts of data. We used the Azure and Alibaba cluster trace to train our neural network, and used three evaluation indicators RMSE, MAPE and R2 to evaluate our proposed method. The experimental results show that our prediction method has 4.5% improvements in RMSE evaluation criteria and 9.5% improvements in MAPE evaluation criteria compared with single GRU model (without attention mechanism) used. That is, the prediction model with the attention mechanism can improve the accuracy of resource prediction. At the same time, we also studied the influence of the window size on the experimental results, finding that the prediction results are more accurate as the window size increases. Wenjuan Shu, Fanping Zeng, Zhen Ling 0001, Guozhu Chen |
MSN | 3 |
| 2021 | On Manually Reverse Engineering Communication Protocols of Linux-Based IoT SystemsabstractIoT security and privacy has raised grave concerns. Efforts have been made to design tools to identify and understand vulnerabilities of IoT systems. Most of the existing protocol security analysis techniques rely on a well understanding of the underlying communication protocols. In this article, we systematically present the first manual reverse engineering framework for discovering communication protocols of embedded Linux-based IoT systems. We have successfully applied our framework to reverse engineer a number of IoT systems. As an example, we present a detailed use of the framework reverse engineering the WeMo smart plug communication protocol by extracting the firmware from the flash, performing static and dynamic analysis of the firmware, and analyzing network traffic. The discovered protocol exposes severe design flaws that allow attackers to control or deny the service of victim plugs. Our manual reverse engineering framework is generic and can be applied to both read-only and writable embedded Linux filesystems. Kaizheng Liu, Ming Yang 0001, Zhen Ling 0001, Huaiyu Yan, Yue Zhang 0025, Xinwen Fu, Wei Zhao 0001 |
IEEE Internet Things J. | 3 |
| 2021 | Secure boot, trusted boot and remote attestation for ARM TrustZone-based IoT Nodes
Zhen Ling 0001, Huaiyu Yan, Xinhui Shao, Junzhou Luo, Yiling Xu, Bryan Pearson, Xinwen Fu |
J. Syst. Archit. | 1 |
| 2020 | On Runtime Software Security of TrustZone-M Based IoT DevicesabstractInternet of Things (IoT) devices have been increasingly integrated into our daily life. However, such smart devices suffer a broad attack surface. Particularly, attacks targeting the device software at runtime are challenging to defend against if IoT devices use resource-constrained microcontrollers (MCUs). TrustZone-M, a TrustZone extension for MCUs, is an emerging security technique fortifying MCU based IoT devices. This paper presents the first security analysis of potential software security issues in TrustZone-M enabled MCUs. We explore the stack-based buffer overflow (BOF) attack for code injection, return-oriented programming (ROP) attack, heap-based BOF attack, format string attack, and attacks against Non-secure Callable (NSC) functions in the context of TrustZone-M. We validate these attacks using the Microchip SAM L11 MCU, which uses the ARM Cortex-M23 processor with the TrustZone-M technology. Strategies to mitigate these software attacks are also discussed. Yue Zhang 0025, Cliff C. Zou, Xinhui Shao, Zhen Ling 0001, Xinwen Fu |
GLOBECOM | 5 |
| 2020 | SIC2: Securing Microcontroller Based IoT Devices with Low-cost Crypto CoprocessorsabstractIn this paper, we explore the use of microcontrollers (MCUs) and crypto coprocessors to secure IoT applications, and show how developers may implement a low-cost platform that provides protects private keys against software attacks. We first demonstrate the plausibility of format string attacks on the ESP32, a popular MCU from Espressif that uses the Harvard architecture. The format string attacks can be used to remotely steal private keys hard-coded in the firmware. We then present a framework termed SIC2(Securing IoT with Crypto Coprocessors), for secure key provisioning that protects end users' private keys from both software attacks and untrustworthy manufacturers. As a proof of concept, we pair the ESP32 with the low-cost ATECC608A cryptographic coprocessor by Microchip and connect to Amazon Web Services (AWS) and Amazon Elastic Container Service (EC2) using a hardware-protected private key, which provides the security features of TLS communication including authentication, encryption and integrity. We have developed a prototype and performed extensive experiments to show that the ATECC608A crypto chip may significantly reduce the TLS handshake time by as much as 82% with the remote server, and it may lower the total energy consumption of the system by up to 70%. Our results indicate that securing IoT with crypto coprocessors is a practicable solution for low-cost MCU based IoT devices. Bryan Pearson, Cliff C. Zou, Yue Zhang 0025, Zhen Ling 0001, Xinwen Fu |
ICPADS | 4 |
| 2020 | BLESS: A BLE Application Security Scanning FrameworkabstractBluetooth Low Energy (BLE) is a widely adopted wireless communication technology in the Internet of Things (IoT). BLE offers secure communication through a set of pairing strategies. However, these pairing strategies are obsolete in the context of IoT. The security of BLE based devices relies on physical security, but a BLE enabled IoT device may be deployed in a public environment without physical security. Attackers who can physically access a BLE-based device will be able to pair with it and may control it thereafter. Therefore, manufacturers may implement extra authentication mechanisms at the application layer to address this issue. In this paper, we design and implement a BLE Security Scan (BLESS) framework to identify those BLE apps that do not implement encryption or authentication at the application layer. Taint analysis is used to track if BLE apps use nonces and cryptographic keys, which are critical to cryptographic protocols. We scan 1073 BLE apps and find that 93% of them are not secure. To mitigate this problem, we propose and implement an application-level defense with a low-cost $0.55 crypto co-processor using public key cryptography. Yue Zhang 0025, Jian Weng 0001, Zhen Ling 0001, Bryan Pearson, Xinwen Fu |
INFOCOM | 3 |
| 2020 | FingerAuth: 3D magnetic finger motion pattern based implicit authentication for mobile devices
Ming Yang 0001, Zhen Ling 0001, Yaowen Liu, Wenjia Wu |
Future Gener. Comput. Syst. | 3 |
| 2020 | STIR: A Smart and Trustworthy IoT System Interconnecting Legacy IR DevicesabstractLegacy-infrared (IR) devices are pervasively used. They are often controlled by IR remotes and cannot be controlled over the Internet. A trustworthy and cost-effective smart IR system that is able to change an IR controllable device into a smart Internet of Things (IoT) device and interconnect them for smart city/home applications is offered in this article. First, a printed circuit board (PCB) consisting of an IR receiver and multiple IR transmitters side by side which are capable of transmitting about 20 m indoors is designed and implemented. This IR transceiver board is the first of its kind. Second, the IR transceiver can be linked up with a Raspberry Pi, for which we develop two software tools, recording and replaying any IR signals so as to put the corresponding IR device in control. Third, a smartphone can be connected to the Pi by means of a message queuing telemetry transport (MQTT) cloud server so that the commands can be sent by the smartphone to the legacy IR device over the Internet. We have also identified the deficiency of TLS mutual authentication implemented by the popular MQTT open-source package Mosquitto for a trustworthy IoT system and patched the system. We analyze the factors that affect the IR signal transmission distance, discuss the security concerns of our IR transceiver, and illustrate the scenarios for attacks. For instance, TV can be turned off remotely by a drone equipped with the transceiver. Zhen Ling 0001, Chuta Sano, Chukpozohn Toe, Zupei Li, Xinwen Fu |
IEEE Internet Things J. | 1 |
| 2020 | A Novel IM Sync Message-Based Cross-Device TrackingabstractCybercrime is significantly growing as the development of internet technology. To mitigate this issue, the law enforcement adopts network surveillance technology to track a suspect and derive the online profile. However, the traditional network surveillance using the single-device tracking method can only acquire part of a suspect’s online activities. With the emergence of different types of devices (e.g., personal computers, mobile phones, and smart wearable devices) in the mobile edge computing (MEC) environment, one suspect can employ multiple devices to launch a cybercrime. In this paper, we investigate a novel cross-device tracking approach which is able to correlate one suspect’s different devices so as to help the law enforcement monitor a suspect’s online activities more comprehensively. Our approach is based on the network traffic analysis of instant messaging (IM) applications, which are typical commercial service providers (CSPs) in the MEC environment. We notice a new habit of using IM applications, that is, one individual logs in the same account on multiple devices. This habit brings about devices’ receiving sync messages, which can be utilized to correlate devices. We choose five popular apps (i.e., WhatsApp, Facebook Messenger, WeChat, QQ, and Skype) to prove our approach’s effectiveness. The experimental results show that our approach can identify IM messages with high F1 -scores (e.g., QQ’s PC message is 0.966, and QQ’s phone message is 0.924) and achieve an average correlating accuracy of 89.58% of five apps in an 8-people experiment, with the fastest correlation speed achieved in 100 s. Naixuan Guo, Junzhou Luo, Zhen Ling 0001, Ming Yang 0001, Wenjia Wu, Xiaodan Gu |
Secur. Commun. Networks | 3 |
| 2019 | On Misconception of Hardware and Cost in IoT Security and PrivacyabstractThe popularity of IoT has raised grave security and privacy concerns. There is a misconception that security and privacy issues of IoT systems are caused by the hardware and its cost. In this paper, we will explore the use of microcontrollers (MCUs) and crypto modules in IoT applications and demonstrate that hardware and cost may not be the bottleneck of IoT security and privacy in various application domains. We discuss how to implement hardware security, system/firmware security, network security, and data security with the low-cost Espressif's ESP32, TI's CC3220 and Microchip's cryptographic co-processor ATECC608A. We perform extensive experiments to validate the performance of cryptographic and networking operations of IoT devices based on those and other MCUs and crypto modules. We are the first to perform a comprehensive measurement and comparison of cryptographic and networking performance of these modern IoT MCUs and modules. Bryan Pearson, Yue Zhang 0025, Rajib Dey, Zhen Ling 0001, Mostafa A. Bassiouni, Xinwen Fu |
ICC | 5 |
| 2019 | Novel and Practical SDN-based Traceback Technique for Malicious Traffic over Anonymous NetworksabstractDiverse anonymous communication systems are widely deployed as they can provide the online privacy protection and Internet anti-censorship service. However, these systems are severely abused and a large amount of anonymous traffic is malicious. To mitigate this issue, we propose a novel and practical traceback technique to confirm the communication relationship between the suspicious server and the user. We leverage the software-defined network (SDN) switch at a destination server side to intercept target traffic towards the server and alter the advertised TCP window sizes so as to stealthily vary the traffic rate at the server. By carefully varying the traffic rate, we can successfully modulate a secret signal into the traffic. The traffic carrying the signal passes through the anonymous communication system and reaches the SDN switch at the user side. Then we can detect the modulated signal from the traffic so as to confirm the communication relationship between the server and the user. To validate the feasibility and effectiveness of our technique, extensive real-world experiments are performed using three popular anonymous communication systems, i.e., SSH tunnel, OpenVPN tunnel, and Tor. The results demonstrate that the detection rates approach 100% for SSH and Open VPN and 95% for Tor while the false positive rates are significantly low, approaching 0% for these three systems. Zhen Ling 0001, Junzhou Luo, Danni Xu, Ming Yang 0001, Xinwen Fu |
INFOCOM | 1 |
| 2019 | Your clicks reveal your secrets: a novel user-device linking method through network and visual data
Naixuan Guo, Junzhou Luo, Zhen Ling 0001, Ming Yang 0001, Wenjia Wu, Xinwen Fu |
Multim. Tools Appl. | 3 |
| 2018 | SecTap: Secure Back of Device Input System for Mobile DevicesabstractSmart mobile devices have become an integral part of people's life and users often input sensitive information on these devices. However, various side channel attacks against mobile devices pose a plethora of serious threats against user security and privacy. To mitigate these attacks, we present a novel secure Back-of-Device (BoD) input system, SecTap, for mobile devices. To use SecTap, a user tilts her mobile device to move a cursor on the keyboard and tap the back of the device to secretly input data. We design a tap detection method by processing the stream of accelerometer readings to identify the user's taps in real time. The orientation sensor of the mobile device is used to control the direction and the speed of cursor movement. We also propose an obfuscation technique to randomly and effectively accelerate the cursor movement. This technique not only preserves the input performance but also keeps the adversary from inferring the tapped keys. Extensive empirical experiments were conducted on different smart phones to demonstrate the usability and security on both Android and iOS platforms. Zhen Ling 0001, Junzhou Luo, Yaowen Liu, Ming Yang 0001, Kui Wu 0001, Xinwen Fu |
INFOCOM | 1 |
| 2018 | SecT: A Lightweight Secure Thing-Centered IoT Communication SystemabstractIn this paper, we propose a secure lightweight and thing-centered IoT communication system based on MQTT, SecT, in which a device/thing authenticates users. Compared with a server-centered IoT system in which a cloud server authenticates users, a thing-centered system preserves user privacy since the cloud server is primarily a relay between things and users and does not store or see user data in plaintext. The contributions of this work are three-fold. First, we explicitly identify critical functionalities in bootstrapping a thing and design secure pairing and binding strategies. Second, we design a strategy of end-to-end encrypted communication between users and things for the sake of user privacy and even the server cannot see the communication content in plaintext. Third, we design a strong authentication system that can defeat known device scanning attack, brute force attack and device spoofing attack against IoT. We implemented a prototype of SecT on a $10 Raspberry Pi Zero W and performed extensive experiments to validate its performance. The experiment results show that SecT is both cost-effective and practical. Although we design SecT for the smart home application, it can be easily extended to other IoT application domains. Zhen Ling 0001, Biao Chen 0002, Xinwen Fu, Wei Zhao 0001 |
MASS | 2 |
| 2018 | Turning Legacy IR Devices into Smart IoT Devices
Chuta Sano, Zupei Li, Zhen Ling 0001, Xinwen Fu |
WASA | 4 |
| 2018 | On the limitations of existing notions of location privacy
Kai Dong 0001, Taolin Guo, Haibo Ye, Xuansong Li, Zhen Ling 0001 |
Future Gener. Comput. Syst. | 5 |
| 2018 | Fingerprinting Network Entities Based on Traffic Analysis in High-Speed Network EnvironmentabstractFor intrusion detection, it is increasingly important to detect the suspicious entities and potential threats. In this paper, we introduce the identification technologies of network entities to detect the potential intruders. However, traditional entities identification technologies based on the MAC address, IP address, or other explicit identifiers can be deactivated if the identifier is hidden or tampered. Meanwhile, the existing fingerprinting technology is also restricted by its limited performance and excessive time lapse. In order to realize entities identification in high-speed network environment, PFQ kernel module and Storm are used for high-speed packet capture and online traffic analysis, respectively. On this basis, a novel device fingerprinting technology based on runtime environment analysis is proposed, which employs logistic regression to implement online identification with a sliding window mechanism, reaching a recognition accuracy of 77.03% over a 60-minute period. In order to realize cross-device user identification, Web access records, domain names in DNS responses, and HTTP User-Agent information are extracted to constitute user behavioral fingerprints for online identification with Multinomial Naive Bayes model. When the minimum effective feature dimension is set to 9, it takes only 5 minutes to reach an accuracy of 79.51%. Performance test results show that the proposed methods can support over 10Gbps traffic capture and online analysis, and the system architecture is justified in practice because of its practicability and extensibility. Xiaodan Gu, Ming Yang 0001, Peilong Pan, Zhen Ling 0001 |
Secur. Commun. Networks | 5 |
| 2018 | Energy-Efficient User Association with Congestion Avoidance and Migration Constraint in Green WLANsabstractGreen wireless local area networks (WLANs) have captured the interests of academia and industry recently, because they save energy by scheduling an access point (AP) on/off according to traffic demands. However, it is very challenging to determine user association in a green WLAN while simultaneously considering several other factors, such as avoiding AP congestion and user migration constraints. Here, we study the energy‐efficient user association with congestion avoidance and migration constraint (EACM). First, we formulate the EACM problem as an integer linear programming (ILP) model, to minimize APs’ overall energy consumption within a time interval while satisfying the following constraints: traffic demand, AP utilization threshold, and maximum number of demand node (DN) migrations allowed. Then, we propose an efficient migration‐constrained user reassociation algorithm, consisting of two steps. The first step removeskAP‐DN associations to eliminate AP congestion and turn off as many idle APs as possible. The second step reassociates thesekDNs according to an energy efficiency strategy. Finally, we perform simulation experiments that validate our algorithm’s effectiveness and efficiency. Wenjia Wu, Junzhou Luo, Kai Dong 0001, Ming Yang 0001, Zhen Ling 0001 |
Wirel. Commun. Mob. Comput. | 5 |
| 2017 | Implicit authentication for mobile device based on 3D magnetic finger motion patternabstractTouch pattern based implicit authentication has been proposed to defend against diverse attacks against mobile devices that aim to obtain credentials, e.g., passwords, in the process of user authentication. However, this defense technique cannot obtain a complete user operation pattern by merely deriving user operation data via a touch-enabled screen, since user operations, including on-screen and in-air finger movements, are performed in a three-dimensional space. In this paper, we propose a novel three-dimensional magnetic finger motion pattern based implicit authentication technique, referred to as FingerAuth. To use FingerAuth, a user first wears a magnetic ring on her finger and uses this finger to operate her mobile device, e.g., typing messages and surfing websites. By using a built-in three-axis magnetometer on the mobile device, we can derive the three-dimension (3D) magnetic finger motion pattern that is used as a human behavioral feature to implicitly authenticate the user. We construct robust 3D magnetic finger motion pattern detection model using machine learning techniques. Real-world experiments were conducted to demonstrate that our approach achieves high accuracy of 96.38% as well as low false acceptance rate of 4.06% and low false rejection rate of 3.18%. Yaowen Liu, Ming Yang 0001, Zhen Ling 0001, Junzhou Luo |
CSCWD | 3 |
| 2017 | An End-to-End View of IoT Security and PrivacyabstractIn this paper, we present an end-to-end view of IoT security and privacy and a case study. Our contribution is twofold. First, we present our end-to-end view of an IoT system and this view can guide risk assessment and design of an IoT system. We identify 10 basic IoT functionalities that are related to security and privacy. Based on this view, we systematically present security and privacy requirements in terms of IoT system, software, networking and big data analytics in the cloud. Second, using the end-to-end view of IoT security and privacy, we present a vulnerability analysis of the Edimax IP camera system. We are the first to exploit this system and have identified various attacks that can fully control all the cameras from the manufacturer. Our real- world experiments demonstrate the effectiveness of the discovered attacks and raise the alarms again for the IoT manufacturers. Zhen Ling 0001, Kaizheng Liu, Yiling Xu, Yier Jin, Xinwen Fu |
GLOBECOM | 1 |
| 2017 | A Case Study of Usable Security: Usability Testing of Android Privacy Enhancing Keyboard
Zhen Ling 0001, Melanie Borgeest, Chuta Sano, Sirong Lin, Mogahid Fadl, Wei Yu 0002, Xinwen Fu, Wei Zhao 0001 |
WASA | 1 |
| 2017 | Occupancy-aided energy disaggregation
Guoming Tang, Zhen Ling 0001, Fengyong Li, Daquan Tang, Jiuyang Tang |
Comput. Networks | 2 |
| 2017 | A novel attack to track users based on the behavior patternsabstractSummary Currently, people around the world daily use the Internet to access various services, such as e‐mail and online shopping. However, the behavior‐based tracking attacks have posed a considerable threat to users' privacy. Relying on characteristic patterns within the Internet activities, this attack can link a user's multiple sessions. In this paper, we investigate the behavior‐based tracking attack and propose some countermeasures to mitigate the threat. We preprocess the raw traffic data and then extract features ranging from lower layer network packets to high‐level application‐related traffic. Specifically, we focus on four types of application‐level traffic to infer users' habits, including HTTP, IM, e‐mail, and P2P. In addition, we extract the web queries entered into shopping websites and classify them to infer users' preferences. Then, we construct the preference models and propose an improved method. For evaluation, we collect traffic in the real‐world environment to construct a large‐scale dataset. Five hundred and nine users are selected in terms of the user's active degree. When the term frequency–inverse document frequency transformation is used, the improved method can identify an average of 93.79% instances correctly. Our extensive empirical experiments demonstrate the effectiveness and efficiency of our approaches. Finally, we discuss and evaluate several countermeasures. Copyright © 2016 John Wiley & Sons, Ltd. Xiaodan Gu, Ming Yang 0001, Congcong Shi, Zhen Ling 0001, Junzhou Luo |
Concurr. Comput. Pract. Exp. | 4 |
| 2017 | Detection of malicious behavior in android apps through API calls and permission uses analysisabstractSummary In recent years, with the prevalence of smartphones, the number of Android malware shows explosive growth. As malicious apps may steal users' sensitive data and even money from mobile and bank accounts, it is important to detect potential malicious behaviors so as to block them. To achieve this goal, we propose a dynamic behavior inspection and analysis framework for malicious behavior detection. A customized Android system is built to record apps' API calls, permission uses, and some other runtime features. We also develop an automated app behavior inspection platform to install and inspect massive samples so as to collect apps' dynamic behavior records. Then these records are exploited to train a string subsequence kernel–based Support Vector Machine (SVM) model, which can be used to classify benign and malicious behaviors offline. To realize online detection, we further extract apps' runtime features including sensitive permission combination uses, sensitive behavior sequences, and user interactions for behavior classification. The classification results can reach an accuracy of 84.9% in offline phase and 99.0% in online phase. Besides, we verify our scheme for identifying malicious apps, and the results show that 71.8% instances of malware samples are identified by running each app for only 18 minutes. Ming Yang 0001, Shan Wang 0008, Zhen Ling 0001, Yaowen Liu, Zhenyu Ni |
Concurr. Comput. Pract. Exp. | 3 |
| 2017 | Security Vulnerabilities of Internet of Things: A Case Study of the Smart Plug SystemabstractWith the rapid development of the Internet of Things, more and more small devices are connected into the Internet for monitoring and control purposes. One such type of devices, smart plugs, have been extensively deployed worldwide in millions of homes for home automation. These smart plugs, however, would pose serious security problems if their vulnerabilities were not carefully investigated. Indeed, we discovered that some popular smart home plugs have severe security vulnerabilities which could be fixed but unfortunately are left open. In this paper, we case study a smart plug system of a known brand by exploiting its communication protocols and successfully launching four attacks: 1) device scanning attack; 2) brute force attack; 3) spoofing attack; and 4) firmware attack. Our real-world experimental results show that we can obtain the authentication credentials from the users by performing these attacks. We also present guidelines for securing smart plugs. Zhen Ling 0001, Junzhou Luo, Yiling Xu, Kui Wu 0001, Xinwen Fu |
IEEE Internet Things J. | 1 |
| 2017 | Dealing with Insufficient Location Fingerprints in Wi-Fi Based Indoor Location FingerprintingabstractThe development of the Internet of Things has accelerated research in the indoor location fingerprinting technique, which provides value-added localization services for existing WLAN infrastructures without the need for any specialized hardware. The deployment of a fingerprinting based localization system requires an extremely large amount of measurements on received signal strength information to generate a location fingerprint database. Nonetheless, this requirement can rarely be satisfied in most indoor environments. In this paper, we target one but common situation when the collected measurements on received signal strength information are insufficient, and show limitations of existing location fingerprinting methods in dealing with inadequate location fingerprints. We also introduce a novel method to reduce noise in measuring the received signal strength based on the maximum likelihood estimation, and compute locations from inadequate location fingerprints by using the stochastic gradient descent algorithm. Our experiment results show that our proposed method can achieve better localization performance even when only a small quantity of RSS measurements is available. Especially when the number of observations at each location is small, our proposed method has evident superiority in localization accuracy. Kai Dong 0001, Zhen Ling 0001, Xiangyu Xia, Haibo Ye, Wenjia Wu, Ming Yang 0001 |
Wirel. Commun. Mob. Comput. | 2 |
| 2017 | Privacy Enhancing Keyboard: Design, Implementation, and Usability TestingabstractTo protect users from numerous password inference attacks, we invent a novel context aware privacy enhancing keyboard (PEK) for Android touch-based devices. Usually PEK would show a QWERTY keyboard when users input text like an email or a message. Nevertheless, whenever users enter a password in the input box on his or her touch-enabled device, a keyboard will be shown to them with the positions of the characters shuffled at random. PEK has been released on the Google Play since 2014. However, the number of installations has not lived up to our expectation. For the purpose of usable security and privacy, we designed a two-stage usability test and performed two rounds of iterative usability testing in 2016 and 2017 summer with continuous improvements of PEK. The observations from the usability testing are educational: (1) convenience plays a critical role when users select an input method; (2) people think those attacks that PEK prevents are remote from them. Zhen Ling 0001, Melanie Borgeest, Chuta Sano, Jazmyn Fuller, Anthony Cuomo, Sirong Lin, Wei Yu 0002, Xinwen Fu, Wei Zhao 0001 |
Wirel. Commun. Mob. Comput. | 1 |
| 2016 | Secure fingertip mouse for mobile devicesabstractVarious attacks may disclose sensitive information such as passwords of mobile devices. Residue-based attacks exploit oily or heat residues on the touch screen, computer vision based attacks analyze the hand movement on a keyboard, and sensor based attacks measure a device's motion difference via motion sensors as different keys are tapped. A randomized soft keyboard may defeat these attacks. However, a randomized key layout is counter-intuitive and users may be reluctant to adopt it. In this paper, we introduce a novel and intuitive input system, secure finger mouse, which uses a mobile device's camera sensing the fingertip movement, moves an on-screen cursor and performs clicks by sensing click gestures. We design a randomized mouse acceleration algorithm so that the adversary cannot infer keys clicked on the soft keyboard by observing the finger movement. The secure finger mouse can defeat attacks including residue, computer vision and motion based attacks too. We perform both theoretical analysis and real-world experiments to demonstrate the security and usability of the secure fingertip mouse. Zhen Ling 0001, Junzhou Luo, Qinggang Yue, Ming Yang 0001, Wei Yu 0002, Xinwen Fu |
INFOCOM | 1 |
| 2016 | Password Extraction via Reconstructed Wireless Mouse TrajectoryabstractLogitech made the following statement in 2009: “Since the displacements of a mouse would not give any useful information to a hacker, the mouse reports are not encrypted.” In this paper, we prove the exact opposite is true-i.e., it is indeed possible to leak sensitive information such as passwords through the displacements of a Bluetooth mouse. Our results can be easily extended to other wireless mice using different radio links. We begin by presenting multiple ways to sniff unencrypted Bluetooth packets containing raw mouse movement data. We then show that such data may reveal text-based passwords entered by clicking on software keyboards. We propose two attacks, the prediction attack and replay attack, which can reconstruct the on-screen cursor trajectories from sniffed mouse movement data. Two inference strategies are used to discover passwords from cursor trajectories. We conducted a holistic study over all popular operating systems and analyzed how mouse acceleration algorithms and packet losses may affect the reconstruction results. Our real-world experiments demonstrate the severity of privacy leakage from unencrypted Bluetooth mice. We also discuss countermeasures to prevent privacy leakage from wireless mice. To the best of our knowledge, our work is the first to demonstrate privacy leakage from raw mouse data. Xian Pan, Zhen Ling 0001, Aniket Pingley, Wei Yu 0002, Nan Zhang 0004, Kui Ren 0001, Xinwen Fu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2015 | TorWard: Discovery, Blocking, and Traceback of Malicious Traffic Over TorabstractTor is a popular low-latency anonymous communication system. It is, however, currently abused in various ways. Tor exit routers are frequently troubled by administrative and legal complaints. To gain an insight into such abuse, we designed and implemented a novel system, TorWard, for the discovery and the systematic study of malicious traffic over Tor. The system can avoid legal and administrative complaints, and allows the investigation to be performed in a sensitive environment such as a university campus. An intrusion detection system (IDS) is used to discover and classify malicious traffic. We performed comprehensive analysis and extensive real-world experiments to validate the feasibility and the effectiveness of TorWard. Our results show that around 10% Tor traffic can trigger IDS alerts. Malicious traffic includes P2P traffic, malware traffic (e.g., botnet traffic), denial-of-service attack traffic, spam, and others. Around 200 known malwares have been identified. To mitigate the abuse of Tor, we implemented a defense system, which processes IDS alerts, tears down, and blocks suspect connections. To facilitate forensic traceback of malicious traffic, we implemented a dual-tone multi-frequency signaling-based approach to correlate botnet traffic at Tor entry routers and that at exit routers. We carried out theoretical analysis and extensive real-world experiments to validate the feasibility and the effectiveness of TorWard for discovery, blocking, and traceback of malicious traffic. Zhen Ling 0001, Junzhou Luo, Kui Wu 0001, Wei Yu 0002, Xinwen Fu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2015 | Tor Bridge Discovery: Extensive Analysis and Large-scale Empirical EvaluationabstractTor is a well-known low-latency anonymous communication system that is able to bypass the Internet censorship. However, publicly announced Tor routers are being blocked by various parties. To counter the censorship blocking, Tor introduced non-public bridges as the first-hop relay into its core network. In this paper, we investigated the effectiveness of two categories of bridge-discovery approaches: 1) enumerating bridges from bridge HTTPS and email servers, and 2) inferring bridges by malicious Tor middle routers. Large-scale real-world experiments were conducted and validated our theoretic findings. We discovered 2365 Tor bridges through the two enumeration approaches and 2369 bridges by only one Tor middle router in 14 days. Our study shows that the bridge discovery based on malicious middle routers is simple, efficient, and effective to discover bridges with little overhead. We also discussed issues related to bridge discovery and mechanisms to counter the malicious bridge discovery. Zhen Ling 0001, Junzhou Luo, Wei Yu 0002, Ming Yang 0001, Xinwen Fu |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2014 | Blind Recognition of Touched Keys on Mobile DevicesabstractIn this paper, we introduce a novel computer vision based attack that automatically discloses inputs on a touch-enabled device while the attacker cannot see any text or popup in a video of the victim tapping on the touch screen. We carefully analyze the shadow formation around the fingertip, apply the optical flow, deformable part-based model (DPM), k-means clustering and other computer vision techniques to automatically locate the touched points. Planar homography is then applied to map the estimated touched points to a reference image of software keyboard keys. Recognition of passwords is extremely challenging given that no language model can be applied to correct estimated touched keys. Our threat model is that a webcam, smartphone or Google Glass is used for stealthy attack in scenarios such as conferences and similar gathering places. We address both cases of tapping with one finger and tapping with multiple fingers and two hands. Extensive experiments were performed to demonstrate the impact of this attack. The per-character (or per-digit) success rate is over 97% while the success rate of recognizing 4-character passcodes is more than 90%. Our work is the first to automatically and blindly recognize random passwords (or passcodes) typed on the touch screen of mobile devices with a very high success rate. Qinggang Yue, Zhen Ling 0001, Xinwen Fu, Benyuan Liu, Kui Ren 0001, Wei Zhao 0001 |
CCS | 2 |
| 2014 | TorWard: Discovery of malicious traffic over TorabstractTor is a popular low-latency anonymous communication system. However, it is currently abused in various ways. Tor exit routers are frequently troubled by administrative and legal complaints. To gain an insight into such abuse, we design and implement a novel system, TorWard, for the discovery and systematic study of malicious traffic over Tor. The system can avoid legal and administrative complaints and allows the investigation to be performed in a sensitive environment such as a university campus. An IDS (Intrusion Detection System) is used to discover and classify malicious traffic. We performed comprehensive analysis and extensive real-world experiments to validate the feasibility and effectiveness of TorWard. Our data shows that around 10% Tor traffic can trigger IDS alerts. Malicious traffic includes P2P traffic, malware traffic (e.g., botnet traffic), DoS (Denial-of-Service) attack traffic, spam, and others. Around 200 known malware have been identified. To the best of our knowledge, we are the first to perform malicious traffic categorization over Tor. Zhen Ling 0001, Junzhou Luo, Kui Wu 0001, Wei Yu 0002, Xinwen Fu |
INFOCOM | 1 |
| 2013 | Protocol-level hidden server discoveryabstractTor hidden services are commonly used to provide a TCP based service to users without exposing the hidden server's IP address in order to achieve anonymity and anti-censorship. However, hidden services are currently abused in various ways. Illegal content such as child pornography has been discovered on various Tor hidden servers. In this paper, we propose a protocollevel hidden server discovery approach to locate the Tor hidden server that hosts the illegal website. We investigate the Tor hidden server protocol and develop a hidden server discovery system, which consists of a Tor client, a Tor rendezvous point, and several Tor entry onion routers. We manipulate Tor cells, the basic transmission unit over Tor, at the Tor rendezvous point to generate a protocol-level feature at the entry onion routers. Once our controlled entry onion routers detect such a feature, we can confirm the IP address of the hidden server. We conduct extensive analysis and experiments to demonstrate the feasibility and effectiveness of our approach. Zhen Ling 0001, Junzhou Luo, Kui Wu 0001, Xinwen Fu |
INFOCOM | 1 |
| 2013 | On Malware Leveraging the Android Accessibility Framework
Joshua Kraunelis, Yinjie Chen, Zhen Ling 0001, Xinwen Fu, Wei Zhao 0001 |
MobiQuitous | 3 |
| 2013 | How Privacy Leaks From Bluetooth Mouse?
Xian Pan, Zhen Ling 0001, Aniket Pingley, Wei Yu 0002, Kui Ren 0001, Nan Zhang 0004, Xinwen Fu |
NDSS | 2 |
| 2013 | Protocol-level attacks against Tor
Zhen Ling 0001, Junzhou Luo, Wei Yu 0002, Xinwen Fu, Weijia Jia 0001, Wei Zhao 0001 |
Comput. Networks | 1 |
| 2013 | Blind detection of spread spectrum flow watermarksabstractABSTRACT Recently, the direct sequence spread spectrum (DSSS)‐based technique has been proposed to trace anonymous network flows. In this technique, homogeneous pseudo‐noise (PN) codes are used to modulate multiple bit signals that are embedded into the target flow as watermarks. This technique could be maliciously used to degrade an anonymous communication network. In this paper, we propose an effective single flow‐based scheme to detect the existence of these watermarks. Our investigation shows that, even if we have no knowledge of the applied PN code, we are still able to detect malicious DSSS watermarks via mean‐square autocorrelation (MSAC) of a single modulated flow's traffic rate time series. MSAC shows periodic peaks because of self‐similarity in the modulated traffic caused by homogeneous PN codes that are used in modulating multiple bit signals. Our scheme has low complexity and does not require any PN code synchronization. We evaluate this detection scheme's effectiveness via simulations. Our results demonstrate a high detection rate with a low false positive rate. Real‐world experiments on Tor also validate the feasibility of the detection scheme. Our scheme is more flexible and accurate than the existing multiflow‐based approach in DSSS watermark detection. We also present a theory for reconstructing the DSSS code once the DSSS code length is known and simulations validate the feasibility. Copyright © 2012 John Wiley & Sons, Ltd. Weijia Jia 0001, Fung Po Tso 0001, Zhen Ling 0001, Xinwen Fu, Dong Xuan, Wei Yu 0002 |
Secur. Commun. Networks | 3 |
| 2013 | Novel Packet Size-Based Covert Channel Attacks against AnonymizerabstractIn this paper, we present a study on the anonymity of Anonymizer, a well-known commercial anonymous communication system. We discovered the architecture of Anonymizer and found that the size of web packets in the Anonymizer network can be very dynamic at the client. Motivated by this finding, we investigated a class of novel packet size-based covert channel attacks against Anonymizer. The attacker between a website and the Anonymizer server can manipulate the web packet size and embed secret signal symbols into the target traffic. An accomplice at the user side can sniff the traffic and recognize the secret signal. In this way, the anonymity provided by Anonymizer is compromised. We developed intelligent and robust algorithms to cope with the packet size distortion incurred by Anonymizer and Internet. We developed techniques to make the attack harder to detect: 1) We pick up right packets of web objects to manipulate to preserve the regularity of the TCP packet size dynamics, which can be measured by the Hurst parameter; 2) We adopt the Monte Carlo sampling technique to preserve the distribution of the web packet size despite manipulation. We have implemented the attack over Anonymizer and conducted extensive analytical and experimental evaluations. It is observed that the attack is highly efficient and requires only tens of packets to compromise the anonymous web surfing via Anonymizer. The experimental results are consistent with our theoretical analysis. Zhen Ling 0001, Xinwen Fu, Weijia Jia 0001, Wei Yu 0002, Dong Xuan, Junzhou Luo |
IEEE Trans. Computers | 1 |
| 2012 | How privacy leaks from bluetooth mouse?abstractRaw mouse movement data can be sniffed via off-the-shelf tools. In this demo, we show that such data, while seemingly harmless, may reveal extremely sensitive information such as passwords. Nonetheless, such a Bluetooth-mouse-sniffing attack can be challenging to perform mainly because of two reasons: (i) packet loss is common for Bluetooth traffic, and (ii) modern operating systems use complex mouse acceleration strategies, which make it extremely difficult, if not impossible, to reconstruct the precise on-screen cursor coordinates from raw mouse movements. To address those challenges, we have conducted an extensive and careful study, over multiple operating systems, on the reconstruction of mouse cursor trajectory from raw mouse data and the inference of privacy-sensitive information - e.g., user password - from the reconstructed trajectory. Our experimental data demonstrate the severity of privacy leaking from un-encrypted Bluetooth mouse. To the best of our knowledge, our work is the first to retrieve sensitive information from sniffed mouse raw data. Video links of successful replay attack for different target OS are given in Section 3.2. Xian Pan, Zhen Ling 0001, Aniket Pingley, Wei Yu 0002, Nan Zhang 0004, Xinwen Fu |
CCS | 2 |
| 2012 | Extensive analysis and large-scale empirical evaluation of tor bridge discoveryabstractTor is a well-known low-latency anonymous communication system that is able to bypass Internet censorship. However, publicly announced Tor routers are being blocked by various parties. To counter the censorship blocking, Tor introduced nonpublic bridges as the first-hop relay into its core network. In this paper, we analyzed the effectiveness of two categories of bridge-discovery approaches: (i) enumerating bridges from bridge https and email servers, and (ii) inferring bridges by malicious Tor middle routers. Large-scale experiments were conducted and validated our theoretic findings. We discovered 2365 Tor bridges through the two enumeration approaches and 2369 bridges by only one Tor middle router in 14 days. Our study shows that the bridge discovery based on malicious middle routers is simple, efficient and effective to discover bridges with little overhead. We also discussed the mechanisms to counter the malicious bridge discovery. Zhen Ling 0001, Junzhou Luo, Wei Yu 0002, Ming Yang 0001, Xinwen Fu |
INFOCOM | 1 |
| 2012 | A novel network delay based side-channel attack: Modeling and defenseabstractInformation leakage via side channels has become a primary security threat to encrypted web traffic. Existing side channel attacks and corresponding countermeasures focus primarily on packet length, packet timing, web object size and web flow size. However, we found that encrypted web traffic can also leak information via network delay between a user and the web sites that she visits. Motivated by this observation, we investigate a novel network-delay based side-channel attack to infer web sites visited by a user. The adversary can utilize pattern recognition techniques to differentiate web sites by measuring sample mean and sample variance of the round-trip time (RTT) between a victim user and web sites. We theoretically analyzed the damage caused by such an adversary and derived closed-form formulae for detection rate, the probability that the adversary correctly recognizes a web site. To defeat this side-channel attack, we proposed several countermeasures. The basic idea is to shape traffic from different web sites so that they have similar RTT statistics. We proposed the strategies based on the k-means clustering and K-Anonymity to ensure that traffic shaping will not cause excessive delay while providing a predictable degree of anonymity. We conducted extensive experiments and our empirical results match our theory very well. Zhen Ling 0001, Junzhou Luo, Yang Zhang 0072, Ming Yang 0001, Xinwen Fu, Wei Yu 0002 |
INFOCOM | 1 |
| 2012 | A New Cell-Counting-Based Attack Against TorabstractVarious low-latency anonymous communication systems such as Tor and Anonymizer have been designed to provide anonymity service for users. In order to hide the communication of users, most of the anonymity systems pack the application data into equal-sized cells (e.g., 512 B for Tor, a known real-world, circuit-based, low-latency anonymous communication network). Via extensive experiments on Tor, we found that the size of IP packets in the Tor network can be very dynamic because a cell is an application concept and the IP layer may repack cells. Based on this finding, we investigate a new cell-counting-based attack against Tor, which allows the attacker to confirm anonymous communication relationship among users very quickly. In this attack, by marginally varying the number of cells in the target traffic at the malicious exit onion router, the attacker can embed a secret signal into the variation of cell counter of the target traffic. The embedded signal will be carried along with the target traffic and arrive at the malicious entry onion router. Then, an accomplice of the attacker at the malicious entry onion router will detect the embedded signal based on the received cells and confirm the communication relationship among users. We have implemented this attack against Tor, and our experimental data validate its feasibility and effectiveness. There are several unique features of this attack. First, this attack is highly efficient and can confirm very short communication sessions with only tens of cells. Second, this attack is effective, and its detection rate approaches 100% with a very low false positive rate. Third, it is possible to implement the attack in a way that appears to be very difficult for honest participants to detect (e.g., using our hopping-based signal embedding). Zhen Ling 0001, Junzhou Luo, Wei Yu 0002, Xinwen Fu, Dong Xuan, Weijia Jia 0001 |
IEEE/ACM Trans. Netw. | 1 |
| 2011 | Equal-Sized Cells Mean Equal-Sized Packets in Tor?abstractTor is a well-known low-latency anonymous communication system. To prevent the traffic analysis attack, Tor packs application data into equal-sized cells. However, we found that equal-sized cells at the application layer do not necessarily produce equal-sized packets at the network layer. Therefore, we introduced a packet size based attack that compromises Tor's communication anonymity with no need of controlling Tor routers. An attacker can manipulate size of packets between a web site and an exit onion router and embeds a signal into the target traffic. An accomplice at the user side can sniff the traffic and recognize this signal. To cope with the signal distortion incurred by Tor and Internet, we developed an effective signal recovery mechanism. Our real-world experiments validate the effectiveness of our attack against Tor. Our work demonstrates the need for re-considering the issue of padding anonymous communication data into equal size. Zhen Ling 0001, Junzhou Luo, Wei Yu 0002, Xinwen Fu |
ICC | 1 |
| 2011 | A novel packet size based covert channel attack against anonymizerabstractAnonymizer is a proprietary anonymous communication system. We discovered its architecture and found that the size of web packets through Anonymizer are very dynamic at the client. Motivated by this finding, we investigated a novel packet size based covert channel attack, against the anonymity service. In the attack, one attacker manipulates the web packet size between the web server and Anonymizer and embed signal symbols into the target traffic. An accomplice at the user side can sniff the traffic and recognize the secret signal. We developed intelligent and robust algorithms to cope with the packet size distortion incurred by Anonymizer and Internet. We developed several techniques to make the attack harder to detect: (i) We pick up right packets of web objects to manipulate in order to preserve the regularity of the TCP packet size dynamics; (ii) We adopt the Monte Carlo sampling technique to preserve the distribution of the web packet size despite manipulation. We have implemented the attack over Anonymizer and conducted extensive analysis and experimental evaluations. It is observed that the attack is highly efficient and requires only tens of packets to compromise the anonymous web surfing. The experimental results are consistent with our theoretical analysis. Zhen Ling 0001, Xinwen Fu, Weijia Jia 0001, Wei Yu 0002, Dong Xuan |
INFOCOM | 1 |
| 2011 | A potential HTTP-based application-level attack against Tor
Xiaogang Wang 0012, Junzhou Luo, Ming Yang 0001, Zhen Ling 0001 |
Future Gener. Comput. Syst. | 4 |
| 2009 | A new cell counter based attack against torabstractVarious low-latency anonymous communication systems such as Tor and Anoymizer have been designed to provide anonymity service for users. In order to hide the communication of users, many anonymity systems pack the application data into equal-sized cells (e.g., 512 bytes for Tor, a known real-world, circuit-based low-latency anonymous communication network). In this paper, we investigate a new cell counter based attack against Tor, which allows the attacker to confirm anonymous communication relationship among users very quickly. In this attack, by marginally varying the counter of cells in the target traffic at the malicious exit onion router, the attacker can embed a secret signal into the variation of cell counter of the target traffic. The embedded signal will be carried along with the target traffic and arrive at the malicious entry onion router. Then an accomplice of the attacker at the malicious entry onion router will detect the embedded signal based on the received cells and confirm the communication relationship among users. We have implemented this attack against Tor and our experimental data validate its feasibility and effectiveness. There are several unique features of this attack. First, this attack is highly efficient and can confirm very short communication sessions with only tens of cells. Second, this attack is effective and its detection rate approaches 100% with a very low false positive rate. Third, it is possible to implement the attack in a way that appears to be very difficult for honest participants to detect (e.g. using our hopping-based signal embedding). Zhen Ling 0001, Junzhou Luo, Wei Yu 0002, Xinwen Fu, Dong Xuan, Weijia Jia 0001 |
CCS | 1 |
| 2009 | A novel flow multiplication attack against TorabstractTor has become one of the most popular overlay networks for anonymizing TCP traffic. A novel and effective flow multiplication attack against Tor is proposed in this paper, which exploits the fundamental vulnerability of anonymous web browsing by using a man-in-the-middle attack on client's HTTP flow. In the flow multiplication attack, whenever a malicious exit onion router detects a web request to a target server, it responds with a malicious page embedded with specified number of image tags, which will cause the browser to initiate deterministic number of web connections on the same circuit to fetch those images. The entry onion router on the circuit can then find such traffic pattern and the communication relationship between the client and the web server will be discovered. Even if all active content systems such as JavaScript in the browser are disabled, our attack can still compromise the anonymity of Tor while achieving invisibility by keeping client's communication running continuously. The experiment results on Tor validate the feasibility and effectiveness of our attack. Xiaogang Wang 0012, Junzhou Luo, Ming Yang 0001, Zhen Ling 0001 |
CSCWD | 4 |
| 2009 | Blind Detection of Spread Spectrum Flow WatermarksabstractRecently, the direct sequence spread-spectrum (DSSS)-based technique has been proposed to trace anonymous network flows. In this technique, homogeneous pseudo-noise (PN) codes are used to modulate multiple-bit signals that are embedded into the target flow as watermarks. This technique could be maliciously used to degrade an anonymous communication network. In this paper, we propose a simple single flow-based scheme to detect the existence of these watermarks. Our investigation shows that even if we have no knowledge of the applied PN code, we are still able to detect malicious DSSS watermarks via mean-square autocorrelation (MSAC) of a single modulated flow's traffic rate time series. MSAC shows periodic peaks due to self-similarity in the modulated traffic caused by homogeneous PN codes that are used in modulating multiple-bit signals. Our scheme has low complexity and does not require any PN-code synchronization. We evaluate this detection scheme's effectiveness via simulations and real-world experiments on Tor. Our results demonstrate a high detection rate with a low false positive rate. Our scheme is more flexible and accurate than an existing multi-flow-based approach in DSSS watermark detection. Weijia Jia 0001, Fung Po Tso 0001, Zhen Ling 0001, Xinwen Fu, Dong Xuan, Wei Yu 0002 |
INFOCOM | 3 |