EDBT 2026 Demo / reviewers in the wild / expert
Cliff Wang
dblp:81/3700
· DBLP profile ↗
41ranked-venue papers
1as first author
5since 2021 · last 2023
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 28 · 3 since 2021Security and privacy · 10 · 2 since 2021Artificial intelligence and machine learning · 2 · 1 first-authorSystems, architecture and hardware · 2Human-computer interaction and ubiquitous computing · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Remedy or Resource Drain: Modeling and Analysis of Massive Task Offloading Processes in FogabstractTask offloading, which refers to processing (computation-intensive) data at facilitating servers, is an exemplary service that greatly benefits from the fog computing paradigm, which brings computation resources to the edge network for reduced application latency. However, the resource-consuming nature of task execution, as well as the sheer scale of IoT systems, raises an open and challenging question: whether fog is a remedy or a resource drain, considering frequent and massive offloading operations? This question is nontrivial, because participants of offloading processes, i.e., fog nodes, may have diversified technical specifications, while task generators, i.e., task nodes, may employ a variety of criteria to select offloading targets, resulting in an unmanageable space for performance evaluation. To overcome these challenges of heterogeneity, we propose a gravity model that characterizes offloading criteria with various gravity functions, in which individual/system resource consumption can be examined by the device/network effort metrics, respectively. Simulation results show that the proposed gravity model can flexibly describe different offloading schemes in terms of application and node-level behavior. We find that the expected lifetime and device effort of individual tasks decrease as$O({}{1}/{N})$over the network size$N$, while the network effort decreases much slower, even remain$O(1)$when load balancing measures are employed, indicating a possible resource drain in the edge network. Jie Wang 0016, Wenye Wang, Cliff Wang |
IEEE Internet Things J. | 3 |
| 2023 | Toward Fast and Energy-Efficient Access to Cloudlets in Hostile EnvironmentsabstractCloudlets, which refer to the edge computing services deployed at the proximity of end devices, are key providers of connectivity, storage, and computation resources to many applications. While access to cloudlets is pervasive in typical settings, it can be difficult in challenging, even hostile environments, such as military or post-disaster scenarios, featuring multi-hop communication and energy-constrained end devices. In these cases, cloudlets may have become the only equipment powerful enough to execute life-critical applications, such as battle-field situation awareness, tactic cooperation, and search-and-rescue missions. Quality of these services is greatly influenced by the minimum time that a packet can be delivered, i.e., the cloudlet access delay (CAD), whose characteristics remain unknown. To address the open question of fast and efficient cloudlet access, we establish a packet mobility model that allows CAD and energy consumption to be analyzed as a function of the initial device-cloudlet distance. We find that the expected CAD scales either linearly or quadratically under distinct types of packet mobility, and the successful access rate (SAR) can be bounded by functions of the delay constraint. Based on these findings, we develop a packet shedding algorithm that saves 24% transmission power, and reduces the average CAD by 2%, while maintaining a similar SAR in simulated cloudlet access environments. Jie Wang 0016, Sigit Aryo Pambudi, Wenye Wang, Cliff Wang |
IEEE Trans. Wirel. Commun. | 4 |
| 2022 | MTD '22: 9th ACM Workshop on Moving Target DefenseabstractThe ninth ACM Workshop on Moving Target Defense (MTD) Workshop is held on November 7, 2022, in conjunction with the ACM Conference on Computer and Communications Security (CCS). The main objective of the workshop is to discuss novel randomization, diversification, and dynamism techniques for computer systems and network, new metric and analysis frameworks to assess and quantify the effectiveness of MTD, and discuss challenges and opportunities that such defenses provide. This year the workshop has also incorporated a number of invited papers to capture the lessons learned from experts in this field, and highlight some of the unique opportunities for MTD in hardware and challenges of practical deployment of MTD techniques. We have constructed an exciting and diverse program of five refereed papers, two invited papers, and two invited keynote talks that will provide the participant with a vibrant and thought-provoking set of ideas and insights. Hamed Okhravi, Cliff Wang |
CCS | 2 |
| 2022 | Spectrum Activity Surveillance: Modeling and Analysis From Perspectives of Surveillance Coverage and Culprit DetectionabstractSpectrum activity surveillance (SAS) is essential to dynamic spectrum access (DSA)-enabled systems with a two-fold impact: it is a primitive mechanism to collect usage data for spectrum efficiency improvement; it is also a prime widget to collect misuse forensics of unauthorized or malicious users. While realizing SAS for DSA-enabled systems appears to be intuitive and trivial, it is, however, a challenging yet open problem. On one hand, a large-scale SAS function is costly to implement in practice; on the other hand, it is not clear how to characterize the efficacy and performance of monitor deployment strategies. To address such challenges, we introduce a three-factor space, composed ofspectrum,time, andgeographic region, over which the SAS problem is formulated by a two-step solution: 3D-tessellation for sweep (monitoring)coverageand graph walk for detectingspectrum culprits, that is, devices responsible for unauthorized spectrum occupancy. In particular, our system model transforms SAS from a globally collective activity to localized actions, and strategy objectives from qualitative attributes to quantitative measures. With this model, we design low-cost deterministic strategies for dedicated monitors, which outperform strategies found by genetic algorithms, and performance-guaranteed random strategies for crowd-source monitors, which can detect adversarial spectrum culprits in bounded time. Jie Wang 0016, Wenye Wang, Cliff Wang, Min Song 0002 |
IEEE Trans. Mob. Comput. | 3 |
| 2021 | Measurement Integrity Attacks Against Network Tomography: Feasibility and DefenseabstractNetwork tomography is an important tool to estimate link metrics from end-to-end network measurements. An implicit assumption in network tomography is that observed measurements indeed reflect the aggregate of link performance (i.e.,seeing is believing). However, it is not guaranteed today that there exists no anomaly (e.g., malicious autonomous systems and insider threats) in large-scale networks. Malicious nodes can intentionally manipulate link metrics via delaying or dropping packets to affect measurements. Will such an assumption render a vulnerability when facing attackers? The problem is of essential importance in that network tomography is developed towards effective network diagnostics and failure recovery. In this article, we demonstrate that the vulnerability is real and propose a new attack strategy, calledmeasurement integrity attack, in which malicious nodes can substantially damage a network (e.g., delaying packets) and at the same time maliciously manipulate end-to-end measurement results such that a legitimate node is misleadingly identified as the root cause of the damage (thereby becoming a scapegoat) under network tomography. We formulate three basic attack approaches and show under what conditions attacks can be successful. We also reveal conditions to detect and locate such attacks in a network. Our theoretical and experimental results show that simply trusting measurements leads to measurement integrity vulnerabilities. Thus, existing methods should be revisited accordingly for security in various applications. Shangqing Zhao, Cliff Wang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | MTD'20: 7th ACM Workshop on Moving Target DefenseabstractThe seventh ACM Workshop on Moving Target Defense (MTD) Workshop is held virtually on November 9, 2020, in conjunction with the ACM Conference on Computer and Communications Security (CCS). The main objective of the workshop is to discuss novel randomization, diversification, and dynamism techniques for computer systems and network, new metric and analysis frameworks to assess and quantify the effectiveness of MTD, and discuss challenges and opportunities that such defenses provide. New this year the workshop has incorporated a number of invited papers to capture systematization of knowledge (SoK) from experts in this field that investigate the past ten years of MTD and discuss the way forward. We have constructed an exciting and diverse program of three refereed papers, five invited papers, and two invited keynote talks that will provide the participant with a vibrant and thought-provoking set of ideas and insights. Hamed Okhravi, Cliff Wang |
CCS | 2 |
| 2020 | Modeling and Analysis of Conflicting Information Propagation in a Finite Time HorizonabstractEmerging mobile applications enable people to connect with one another more easily than ever, which causes networked systems, e.g., online social networks (OSN) and Internet-of-Things (IoT), to grow rapidly in size, and become more complex in structure. In these systems, different, even conflicting information, e.g., rumor v.s. truth, and malware v.s. security patches, can compete with each other during their propagation over individual connections. For such information pairs, in which a desired information kills its undesired counterpart on contact, an interesting yet challenging question is when and how fast the undesired information dies out. To answer this question, we propose a Susceptible-Infectious-Cured (SIC) propagation model, which captures short-term competitions between the two pieces of information, and define extinction time and half-life time, as two pivots in time, to quantify the dying speed of the undesired information. Our analysis revealed the impact of network topology and initial conditions on the lifetime of the undesired information. In particular, we find that, the Cheeger constant that measures the edge expansion property of a network steers the scaling law of the lifetime with respect to the network size, and the vertex eccentricities that are easier to compute provide accurate estimation of the lifetime. Our analysis also sheds light on where to inject the desired information, such that its undesired counterpart can be eliminated faster. Jie Wang 0016, Wenye Wang, Cliff Wang |
IEEE/ACM Trans. Netw. | 3 |
| 2020 | How Can Randomized Routing Protocols Hide Flow Information in Wireless Networks?abstractPreventing the source-destination network flow information from being disclosed is pivotal for anonymous wireless network applications. However, the advance of network inference, which is able to obtain the flow information without directly measuring it, poses severe challenges towards this goal. Randomized routing is capable of hiding the flow information by injecting substantial errors to the network inference process. In this paper, we systematically study the behavior of randomized routing protocols, and categorize them into three templates, k -random-relay, k -random-neighbor and k -random-path based on their routing behaviors. We propose technical models to characterize these templates in terms of their induced inference errors and their delay costs. We also use simulations to validate the theoretical results. Our work provides the first systematic study on understanding both the benefit and the cost of using randomized routing to hide the flow information in wireless networks. Shangqing Zhao, Cliff Wang |
IEEE Trans. Wirel. Commun. | 3 |
| 2019 | SAS: Modeling and Analysis of Spectrum Activity Surveillance in Wireless Overlay NetworksabstractSpectrum monitoring, run-time usage acquisition, and regulation enforcement, in general can be referred to as spectrum activity surveillance (SAS). It is essential to dynamic spectrum access with a two-fold impact: it is a primitive mechanism to continuously scan spectrum usage for system optimization purposes; it is also a prime widget to obtain spectrum footprints of legitimate users, and record misuse by unauthorized or malicious users. Seemingly trivial, large-scale SAS in wireless overlay networks is actually an open yet challenging problem. This is because on one hand, such a system is time and energy-sensitive and hence unlikely (or not necessary) to implement in practice, due to constraints of radio spectrum license and system deployment. On the other hand, it is not clear how to characterize the efficacy and performance of spectrum monitoring strategies in surveillance over a large geographical region, and detection of spectrum culprits, that is, unauthorized spectrum occupants. To address such a challenge, we consider SAS in a 3-dimensional space that is composed of spectrum, time, and geographical region, and then formulate monitoring strategies as graph walks by accounting for the locality of spectrum activities. In particular, our approach transforms the SAS problem from a globally collective activity to a set of localized, distributed actions, and strategy objectives from qualitative attributes to quantitative measures. We find that randomized strategies with m monitors can achieve a sweep-coverage over a space of n assignment points in Θ(n/m ln n) time, and detect an oblivious or adversarial spectrum culprit in Θ(n/m) time for SAS systems. Jie Wang 0016, Wenye Wang, Cliff Wang |
INFOCOM | 3 |
| 2018 | Fast Rendezvous for Spectrum-Agile IoT Devices with Limited Channel Hopping CapabilityabstractThe explosive number of IoT nodes and adoption of software-defined radio have enabled an efficient method of exploiting idle frequency spectrums called dynamic spectrum access (DSA). The foremost problem in DSA is for a pair of nodes to rendezvous and form a control channel prior to communication. Existing schemes require a channel hopping (CH) pattern with length O(N2), which is overly complex especially when the number of channels N is large. Moreover, the CH patterns are designed assuming DSA nodes have unlimited CH capability, which is hardly satisfied by nodes with long frequency switching time and limited sensing capacity. In this paper, we design a low-complexity rendezvous scheme that account for CH capability limits. The CH capability is captured using spectrum slice graphs that describe the possible channels for the next hop, given the currently-visited channel. By viewing the CH patterns as random walks over the spectrum graphs, we assign the walks with optimal transition probabilities that achieve the smallest rendezvous delay. The resulting symmetric random CH (S-RCH) scheme, which is suitable for IoT nodes without predetermined roles, achieves a lower rendezvous delay than existing Modular Modified Clock (MMC) scheme and offers more than 80 % successful rendezvous in mobile networks. Sigit Aryo Pambudi, Wenye Wang, Cliff Wang |
INFOCOM | 3 |
| 2017 | From Isolation Time to Node Resilience: Impact of Cascades in D2D-Based Social NetworksabstractThe ever-increasing traffic demand from social networking service (SNS) users and recent progress in device-to-device (D2D) technology have empowered a new D2D-based SNS paradigm, which enables multimedia content exchange via short-range wireless networking. In this paradigm, a small node failure may trigger a collection of rapidly-spreading isolation events called cascade-of-failures. Unlike existing works that studied the outcome of cascading failures from the spatial and probabilistic perspectives, this paper sheds light on the temporal properties of the cascade-of-failures. To do this, we introduce a maximum isolation time that quantifies the steps needed until the last node is isolated by the cascades, and then show that it scales non-monotonically to the fraction of initial survivors (non-failure nodes) and increases logarithmically with the network size. Then, we use the result to further analyze a node resilience metric, which is the likelihood that a node does not become isolated before its social networking session is finished. These findings, which are validated using numerical simulations, provide a temporal perspective of network performance that is valuable in the design of D2D-based SNSs yet still missing in the literature. Sigit Aryo Pambudi, Wenye Wang, Cliff Wang |
GLOBECOM | 3 |
| 2017 | Modeling and Strategy Design for Spectrum Monitoring over a Geographical RegionabstractSpectrum monitoring is a prerequisite in dynamic access regulation, policy enforcement, as well as spectrum database establishment. In this paper, we introduce the dimension of geographical space into the spectrum monitoring problem, and studied deployment strategies of multiple monitors, in terms of coverage time and cost. The monitoring problem is modeled as a 3-d continuous sweep coverage problem, whose solution space is then reduced by effectively dividing the spectra-location space, in order to achieve a small coverage time. The cost minimization is then formulated as a Multiple Traveling Salesman problem (MTSP), which is NP-hard. By observing the structure of the strategy space, we propose a solution that attains a reasonable cost, without applying complex optimization algorithms. Jie Wang 0016, Wenye Wang, Cliff Wang |
GLOBECOM | 3 |
| 2017 | On the Root Cause of Dropout-Induced Contraction Process in D2D-Based Mobile Social NetworksabstractDevice-to-device (D2D)-based mobile social networking (MSN) has been touted as a low-power, low-cost alternative to conventional MSN over cellular and WiFi networks. Nevertheless, the open nature of communication channels and the users' social activity that tend to decline over time expose D2D-based MSN to network contractions, which is a consequence of initial dropouts, combined with the jointly unsuccessful information delivery and social contacts. As a result, the network may found some of its users to vanish without knowing the cause of such dropouts. This, however, is a desirable knowledge that can guide towards the design of effective countermeasure schemes. In this paper, we study the problem of deciding whether initial dropouts are social or communication-induced, given the outcome of the network contractions. To do so, we define a minimum utility ratio that quantifies the worst-case impact of network contractions generated by initial dropouts. We derive self-consistent equations for computing the different minimum utility ratios caused by social and communication-based dropouts. We further show that this metric may exhibit different scaling order behaviors, depending on the root cause of initial dropouts. Finally, numerical results show that the proposed self-consistent equations and scaling order analysis can effectively distinguish social and communication-induced network contractions. Sigit Aryo Pambudi, Wenye Wang, Cliff Wang |
ICCCN | 3 |
| 2017 | When Seeing Isn't Believing: On Feasibility and Detectability of Scapegoating in Network TomographyabstractNetwork tomography is a vital tool to estimate link qualities from end-to-end network measurements. An implicit assumption in network tomography is that observed measurements indeed reflect the aggregate of link performance (i.e., seeing is believing). However, it is not guaranteed today that there exists no anomaly (e.g., malicious autonomous systems and insider threats) in large-scale networks. Malicious nodes can intentionally manipulate link metrics via delaying or dropping packets to affect measurements. Will such an assumption render a vulnerability when facing attackers? The problem is of essential importance in that network tomography is developed towards effective network diagnostics and failure recovery. In this paper, we demonstrate that the vulnerability is real and propose a new attack strategy, called scapegoating, in which malicious nodes can substantially damage a network (e.g., delaying packets) and at the same time maliciously manipulate end-to-end measurement results such that a legitimate node is misleadingly identified as the root cause of the damage (thereby becoming a scapegoat) under network tomography. We formulate three basic scapegoating approaches and show under what conditions attacks can be successful. We also reveal conditions to detect such attacks. Our theoretical and experimental results show that simply trusting measurements leads to scapegoating vulnerabilities. Thus, existing methods should be revisited accordingly for security in various applications. Shangqing Zhao, Cliff Wang |
ICDCS | 3 |
| 2017 | Enabling Network Anti-Inference via Proactive Strategies: A Fundamental PerspectiveabstractNetwork inference is an effective mechanism to infer end-to-end flow rates and has enabled a variety of applications (e.g., network surveillance and diagnosis). This paper is focused on the opposite side of network inference, i.e., how to make inference inaccurate, which we call network anti-inference. As most research efforts have been focused on developing efficient inference methods, a design of anti-inference is largely overlooked. Anti-inference scenarios can rise when network inference is not desirable, such as in clandestine communication and military applications. Our objective is to explore network dynamics to provide anti-inference. In particular, we consider two proactive strategies that cause network dynamics: transmitting deception traffic and changing routing to mislead the inference. We build an analytical framework to quantify the induced inference errors of the proactive strategies that maintain limited costs. We find by analysis and simulations that for deception traffic, a simple random transmission strategy can achieve inference errors on the same order of the best coordinated transmission strategy, while changing routing can cause the inference errors of higher order than any deception traffic strategy. Our results not only reveal the fundamental perspective on proactive strategies, but also offer the guidance into the practical design of anti-inference. Cliff Wang |
IEEE/ACM Trans. Netw. | 2 |
| 2016 | MTD 2016: Third ACM Workshop on Moving Target DefenseabstractThe 2016 MTD (Moving Target Defense) workshop seeks to bring together researchers from academia, government, and industry to report on the latest research efforts on moving-target defense, and to have productive discussion and constructive debate on this topic. It is a single day workshop co-located with ACM CCS (Conference on Computer and Communications Security) 2016. Peng Liu 0005, Cliff Wang |
CCS | 2 |
| 2016 | How Robust Is a D2D-Based Messaging Service?abstractMotivated by the massive and increasing number of online messaging service users, the idea of utilizing shortrange device-to-device (D2D) communication has been adapted to the access of instant messaging services on-the-go, introducing a D2D-based messaging service (D2D-Msg) paradigm that promises higher data rate and longer battery life. The quality of message dissemination in such a new paradigm, however, remains largely unknown due to the open nature of the D2D environment. To address this, we define a node survival probability that captures the impact of random and targeted node failures due to the open wireless environment. Further, we define a secondary infection rate R* that measures how fast message propagates initially, and leverage a framework based on probability generating function to analyze R* under random and targeted failures. Numerical results show that the D2D-Msg is more robust against random failure, the targeted node failure favors communication graph with narrow degree distribution, and R* is proportional to the ratio between the number of message-receiving users to all users, which is a good metric for quantifying the D2D-Msg's robustness. Sigit Aryo Pambudi, Wenye Wang, Cliff Wang |
GLOBECOM | 3 |
| 2016 | On the Resilience of D2D-Based Social Networking Service against Random FailuresabstractDevice-to-device (D2D)-based social networking service (SNS) is an emerging information system that enables users with social ties to exchange multimedia contents through multihop short-range wireless links. In the D2D-based SNS, a random initial node failure may lead to a cascade of failures, which is a series of events in which users become isolated from others over subsequent time instances. Different from previous studies that analyze whether network-wide connectivity can be preserved after a cascade of failures, our study sheds light on the D2D-based SNS's resilience from the perspective of end-user connection experience. In this paper, we first introduce a numerical method for calculating the mean fraction of nodes that are not affected by the cascading failures and the amount of time to reach the end of such sequence of failures. Then, we apply a probabilistic approach to derive the lower and upper bounds of a node resilience metric, which is the likelihood that an end-user will not be isolated during an ongoing social networking session. Our analysis and numerical simulations indicate that, compared to exponentially-distributed session times, user session times with Pareto (heavy-tailed) distribution results in poorer node resilience, which quickly deteriorates when the mean session time is high. Sigit Aryo Pambudi, Wenye Wang, Cliff Wang |
GLOBECOM | 3 |
| 2016 | Divide and Conquer: Leveraging Topology in Control of Epidemic Information DynamicsabstractAs online social networks grow in both size and connectivity, epidemic information dynamics in such networks is attracting considerable research interests, due to its impact on both the network and individuals. This paper studies control of malicious information (virus) epidemic with replicable antidote information, taking topological characteristics of the underlying graph into consideration. Specifically, we analytically relate the extinction time of the virus to the diameter and giant component size of the remaining graph after the initial antidote distribution. With this divide and conquer guideline, topology-based antidote distribution approaches are designed, and then examined through simulations in real world network portions. Jie Wang 0016, Wenye Wang, Cliff Wang |
GLOBECOM | 3 |
| 2016 | Modeling and estimating the structure of D2D-based mobile social networksabstractAlong with the explosive growth of mobile social network (MSN) users and the advent of device-to-device (D2D) communications, D2D-based MSN (D2D-MSN) has become a promising alternative for exchanging multimedia contents on-the-go. Although the complete structure of a D2D-MSN plays a key role in understanding its performance, such knowledge is not readily available due to the difficulty of collecting connectivity information from the vast amount of users. To model the structure, we define a D2D-MSN network that jointly captures the social connectivity over the MSN and the opportunistic D2D contacts among users. A random walk with self loop (RWSL) scheme that quickly converges to its stationary distribution is proposed to collect a subset of D2D-MSN nodes. An estimator is then introduced to obtain an unbiased estimate of the D2D-MSN graph's joint degree distribution, pi, j, from the set of visited nodes, leading to an unbiased RWSL scheme. The resulting estimate of pi, j can be used as a statistic for creating synthetic graph and generating functions for analyzing robustness of D2D-MSN. Numerical results show that the proposed unbiased RWSL converges faster to its stationary distribution, achieves higher joint degree distribution accuracy, and visits less number of nodes, compared to existing graph exploration schemes. Sigit Aryo Pambudi, Wenye Wang, Cliff Wang |
ICC | 3 |
| 2016 | How the anti-rumor kills the rumor: Conflicting information propagation in networksabstractOnline Social Networks (OSNs) is taking over television and newspapers, to be the dominant information dissemination option. The growing involvement of individuals create the situation that colliding, even contradicting information coexist and propagate in the same network, which gives rise to an interesting question: how will the conflicting information propagate? To answer this question, the propagation process is described to be an Susceptible-Infected-Cured (SIC) epidemic, and we propose an inference algorithm to study the transient behavior of the competing propagation processes in connected networks. Moreover, we provide an analytic method to derive the conditional infection count distribution for networks with special topologies, as a step further to understand the evolution. A trace collected from the Internet is analyzed to validate our model and methods. Jie Wang 0016, Wenye Wang, Cliff Wang |
ICC | 3 |
| 2016 | On the Evolution and Impact of Mobile Botnets in Wireless NetworksabstractA botnet in mobile networks is a collection of compromised nodes due to mobile malware, which are able to perform coordinated attacks. Different from Internet botnets, mobile botnets do not need to propagate using centralized infrastructures, but can keep compromising vulnerable nodes in close proximity and evolving organically via data forwarding. Such a distributed mechanism relies heavily on node mobility as well as wireless links, therefore it breaks down the underlying premise in existing epidemic modeling for Internet botnets. In this paper, we adopt a stochastic approach to study the evolution and impact of mobile botnets. We find that node mobility can be a trigger to botnet propagation storms: the average size (i.e., number of compromised nodes) of a botnet increases quadratically over time if the mobility range that each node can reach exceeds a threshold; otherwise, the botnet can only contaminate a limited number of nodes with average size always bounded above. This also reveals that mobile botnets can propagate at the fastest rate of quadratic growth in size, which is substantially slower than the exponential growth of Internet botnets. To measure the denial-of-service impact of a mobile botnet, we define a new metric, called last chipper time, which is the last time that service requests, even partially, can still be processed on time as the botnet keeps propagating and launching attacks. The last chipper time is identified to decrease at most on the order of 1=√B, where B is the network bandwidth. This result reveals that although increasing network bandwidth can help mobile services, it can, at the same time, indeed escalate the risk of services being disrupted by mobile botnets. Wenye Wang, Cliff Wang |
IEEE Trans. Mob. Comput. | 3 |
| 2015 | Network anti-inference: A fundamental perspective on proactive strategies to counter flow inferenceabstractNetwork inference is an effective mechanism to infer end-to-end flow rates and has enabled a variety of applications (e.g., network surveillance and diagnosis). The paper is focused on the opposite side of network inference, i.e., how to make inference inaccurate, which we call network anti-inference. As most research efforts have been focused on developing efficient inference methods, design of anti-inference is largely overlooked. Anti-inference scenarios can rise when network inference is not desirable, such as in clandestine communication and military applications. Our objective is to explore network dynamics to provide anti-inference. In particular, we consider two proactive strategies that cause network dynamics: transmitting deception traffic and changing routing to mislead the inference. We build an analytical framework to quantify the induced inference errors of the proactive strategies that maintain limited costs. We find via analysis and simulations that for deception traffic, a simple random transmission strategy can achieve inference errors on the same order of the best coordinated transmission strategy; while changing routing can cause inference errors of higher order than any deception traffic strategy. Our results not only reveal the fundamental perspective on proactive strategies, but also offer the guidance into practical design of anti-inference. Cliff Wang |
INFOCOM | 2 |
| 2015 | Camouflage Traffic: Minimizing Message Delay for Smart Grid Applications under JammingabstractSmart grid is a cyber-physical system that integrates power infrastructures with information technologies. To facilitate efficient information exchange, wireless networks have been proposed to be widely used in the smart grid. However, the jamming attack that constantly broadcasts radio interference is a primary security threat to prevent the deployment of wireless networks in the smart grid. Hence, spread spectrum systems, which provide jamming resilience via multiple frequency and code channels, must be adapted to the smart grid for secure wireless communications, while at the same time providing latency guarantee for control messages. An open question is how to minimize message delay for timely smart grid communication under any potential jamming attack. To address this issue, we provide a paradigm shift from the case-by-case methodology, which is widely used in existing works to investigate well-adopted attack models, to the worst-case methodology, which offers delay performance guarantee for smart grid applications under any attack. We first define a generic jamming process that characterizes a wide range of existing attack models. Then, we show that in all strategies under the generic process, the worst-case message delay is a U-shaped function of network traffic load. This indicates that, interestingly, increasing a fair amount of traffic can in fact improve the worst-case delay performance. As a result, we demonstrate a lightweight yet promising system, transmitting adaptive camouflage traffic (TACT), to combat jamming attacks. TACT minimizes the message delay by generating extra traffic called camouflage to balance the network load at the optimum. Experiments show that TACT can decrease the probability that a message is not delivered on time in order of magnitude. Wenye Wang, Cliff Wang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2014 | How can botnets cause storms? Understanding the evolution and impact of mobile botnetsabstractA botnet in mobile networks is a collection of compromised nodes due to mobile malware, which are able to perform coordinated attacks. Different from Internet botnets, mobile botnets do not need to propagate using centralized infrastructures, but can keep compromising vulnerable nodes in close proximity and evolving organically via data forwarding. Such a distributed mechanism relies heavily on node mobility as well as wireless links, therefore breaks down the underlying premise in existing epidemic modeling for Internet botnets. In this paper, we adopt a stochastic approach to study the evolution and impact of mobile botnets. We find that node mobility can be a trigger to botnet propagation storms: the average size (i.e., number of compromised nodes) of a botnet increases quadratically over time if the mobility range that each node can reach exceeds a threshold; otherwise, the botnet can only contaminate a limited number of nodes with average size always bounded above. This also reveals that mobile botnets can propagate at the fastest rate of quadratic growth in size, which is substantially slower than the exponential growth of Internet botnets. To measure the denial-of-service impact of a mobile botnet, we define a new metric, called last chipper time, which is the last time that service requests, even partially, can still be processed on time as the botnet keeps propagating and launching attacks. The last chipper time is identified to decrease at most on the order of 1/√B, where B is the network bandwidth. This result reveals that although increasing network bandwidth can help with mobile services; at the same time, it can indeed escalate the risk for services being disrupted by mobile botnets. Wenye Wang, Cliff Wang |
INFOCOM | 3 |
| 2014 | Modeling, Evaluation and Detection of Jamming Attacks in Time-Critical Wireless ApplicationsabstractRecently, wireless networking for emerging cyber-physical systems, in particular the smart grid, has been drawing increasing attention in that it has broad applications for time-critical message delivery among electronic devices on physical infrastructures. However, the shared nature of wireless channels unavoidably exposes the messages in transit to jamming attacks, which broadcast radio interference to affect the network availability of electronic equipments. An important, yet open research question is how to model and detect jamming attacks in such wireless networks, where communication traffic is more time-critical than that in conventional data-service networks, such as cellular and WiFi networks. In this paper, we aim at modeling and detecting jamming attacks against time-critical wireless networks with applications to the smart grid. In contrast to communication networks where packets-oriented metrics, such as packet loss and throughput are used to measure the network performance, we introduce a new metric, message invalidation ratio, to quantify the performance of time-critical applications. Our modeling approach is inspired by the similarity between the behavior of a jammer who attempts to disrupt the delivery of a time-critical message and the behavior of a gambler who intends to win a gambling game. Therefore, by gambling-based modeling and real-time experiments, we find that there exists a phase transition phenomenon for successful time-critical message delivery under a variety of jamming attacks. That is, as the probability that a packet is jammed increases from 0 to 1, the message invalidation ratio first increases slightly, then increases dramatically to 1. Based on analytical and experimental results, we design the Jamming Attack Detection based on Estimation (JADE) scheme to achieve robust jamming detection, and implement JADE in a wireless network for power substations in the smart grid. Wenye Wang, Cliff Wang |
IEEE Trans. Mob. Comput. | 3 |
| 2012 | Hiding traffic with camouflage: Minimizing message delay in the smart grid under jammingabstractThe smart grid is an emerging cyber-physical system that integrates power infrastructures with information technologies. In the smart grid, wireless networks have been proposed for efficient communications. However, the jamming attack that broadcasts radio interference is a primary security threat to prevent the deployment of wireless networks. Hence, spread spectrum systems with jamming resilience must be adapted to the smart grid to secure wireless communications. There have been extensive works on designing spread spectrum schemes to achieve feasible communication under jamming attacks. Nevertheless, an open question in the smart grid is how to minimize message delay for timely communication in power applications. In this paper, we address this problem in a wireless network with spread spectrum systems for the smart grid. By defining a generic jamming process that characterizes a wide range of existing jamming models, we show that the worst-case message delay is a U-shaped function of network traffic load. This indicates that, interestingly, increasing a fair amount of redundant traffic, called camouflage, can improve the worst-case delay performance. We demonstrate via experiments that transmitting camouflage traffic can decrease the probability that a message is not delivered on time in order of magnitude for smart grid applications. Wenye Wang, Cliff Wang |
INFOCOM | 3 |
| 2012 | Modeling and Performance Evaluation of Backoff Misbehaving Nodes in CSMA/CA NetworksabstractBackoff misbehavior, in which a wireless node deliberately manipulates its backoff time, can induce significant network problems, such as severe unfairness and denial of service. Although great progress has been made toward the design of countermeasures to backoff misbehavior, little attention has been focused on quantifying the gain of backoff misbehaviors. In this paper, to assess the gain that misbehaving nodes can obtain, we define and study two general classes of backoff misbehavior: continuous misbehavior, which keeps manipulating the backoff time unless it is disabled by countermeasures, and intermittent misbehavior, which tends to evade the detection of countermeasures by performing misbehavior sporadically. Our approach is to introduce a new performance metric, namely order gain, to characterize the performance benefits of misbehaving nodes in comparison to legitimate nodes in CSMA/CA-based wireless networks. We derive the order gains of both continuous and intermittent misbehaviors and further investigate the relation between our metric, order gain, and the throughput gain for a misbehaving node. We show that in IEEE 802.11 networks, the throughput ratio of a backoff misbehaving node to a legitimate node is either bounded above or proportional to the number of legitimate nodes. We use both simulations and experiments to validate our theoretical analysis and to further demonstrate the impact of a wide range of backoff misbehaviors on network performance in CSMA/CA-based wireless networks. Wenye Wang, Cliff Wang |
IEEE Trans. Mob. Comput. | 3 |
| 2011 | From jammer to gambler: Modeling and detection of jamming attacks against time-critical trafficabstractTime-critical wireless applications in emerging network systems, such as e-healthcare and smart grids, have been drawing increasing attention in both industry and academia. The broadcast nature of wireless channels unavoidably exposes such applications to jamming attacks. However, existing methods to characterize and detect jamming attacks cannot be applied directly to time-critical networks, whose communication traffic model differs from conventional models. In this paper, we aim at modeling and detecting jamming attacks against time-critical traffic. We introduce a new metric, message invalidation ratio, to quantify the performance of time-critical applications. A key insight that leads to our modeling is that the behavior of a jammer who attempts to disrupt the delivery of a time-critical message can be exactly mapped to the behavior of a gambler who tends to win a gambling game. We show via the gambling-based modeling and real-time experiments that there in general exists a phase transition phenomenon for a time-critical application under jamming attacks: as the probability that a packet is jammed increases from 0 to 1, the message invalidation ratio first increases slightly (even negligibly), then increases dramatically to 1. Based on analytical and experimental results, we further design and implement the JADE (Jamming Attack Detection based on Estimation) system to achieve efficient and robust jamming detection for time-critical wireless networks. Wenye Wang, Cliff Wang |
INFOCOM | 3 |
| 2010 | Defending DSSS-based broadcast communication against insider jammers via delayed seed-disclosureabstractSpread spectrum techniques such as Direct Sequence Spread Spectrum (DSSS) and Frequency Hopping (FH) have been commonly used for anti-jamming wireless communication. However, traditional spread spectrum techniques require that sender and receivers share a common secret in order to agree upon, for example, a common hopping sequence (in FH) or a common spreading code sequence (in DSSS). Such a requirement prevents these techniques from being effective for anti-jamming broadcast communication, where a jammer may learn the key from a compromised receiver and then disrupt the wireless communication. In this paper, we develop a novel Delayed Seed-Disclosure DSSS (DSD-DSSS) scheme for efficient anti-jamming broadcast communication. DSD-DSSS achieves its anti-jamming capability through randomly generating the spreading code sequence for each message using a random seed and delaying the disclosure of the seed at the end of the message. We also develop an effective protection mechanism for seed disclosure using content-based code subset selection. DSD-DSSS is superior to all previous attempts for anti-jamming spread spectrum broadcast communication without shared keys. In particular, even if a jammer possesses real-time online analysis capability to launch reactive jamming attacks, DSD-DSSS can still defeat the jamming attacks with a very high probability. We evaluate DSD-DSSS through both theoretical analysis and a prototype implementation based on GNU Radio; our evaluation results demonstrate that DSD-DSSS is practical and have superior security properties. An Liu 0001, Peng Ning, Huaiyu Dai, Yao Liu 0007, Cliff Wang |
ACSAC | 5 |
| 2010 | On the Impact of Backoff Misbehaving Nodes in IEEE 802.11 NetworksabstractIn this paper, we address the problem of quantifying the impact of backoff misbehaving nodes in IEEE 802.11 networks. We propose two performance metrics, throughput gain ratio and throughput degradation ratio to quantify the performance gain of misbehaving nodes over legitimate nodes and the performance loss of legitimate nodes due to backoff misbehavior, respectively. We use asymptotic analysis to derive both throughput gain ratio and throughput degradation ratio in an IEEE 802.11 network in the presence of multiple misbehaving nodes. We show that, in general, the throughput gain ratio increases linearly with the number of legitimate nodes, and the throughput degradation ratio increases linearly with the number of misbehaving nodes. Finally, we use ns-2 simulations to validate our analytical results. Cliff Wang, Wenye Wang |
ICC | 2 |
| 2010 | On Order Gain of Backoff Misbehaving Nodes in CSMA/CA-based Wireless NetworksabstractBackoff misbehavior, in which a wireless node deliberately manipulates its backoff time, can induce significant network problems, such as severe unfairness and denial-of-service. Although great progress has been made towards the design of countermeasures to backoff misbehavior, little attention has been focused on quantifying the gain of backoff misbehaviors. In this paper, we define and study two general classes of backoff misbehavior to assess the gain that misbehaving nodes can obtain. The first class, called continuous misbehavior, keeps manipulating the backoff time unless it is disabled by countermeasures. The second class is referred to as intermittent misbehavior, which tends to evade the detection by countermeasures by performing misbehavior sporadically. Our approach is to introduce a new performance metric, namely order gain, which is to characterize the performance benefits of misbehaving nodes in comparison to legitimate nodes. Through analytical studies, simulations, and experiments, we demonstrate the impact of a wide range of backoff misbehaviors on network performance with respect to the number of users in CSMA/CA-based wireless networks. Wenye Wang, Cliff Wang |
INFOCOM | 3 |
| 2008 | Attack-Resistant Location Estimation in Wireless Sensor NetworksabstractMany sensor network applications require sensors' locations to function correctly. Despite the recent advances, location discovery for sensor networks in hostile environments has been mostly overlooked. Most of the existing localization protocols for sensor networks are vulnerable in hostile environments. The security of location discovery can certainly be enhanced by authentication. However, the possible node compromises and the fact that location determination uses certain physical features (e.g., received signal strength) of radio signals make authentication not as effective as in traditional security applications. This article presents two methods to tolerate malicious attacks against range-based location discovery in sensor networks. The first method filters out malicious beacon signals on the basis of the “consistency” among multiple beacon signals, while the second method tolerates malicious beacon signals by adopting an iteratively refined voting scheme. Both methods can survive malicious attacks even if the attacks bypass authentication, provided that the benign beacon signals constitute the majority of the beacon signals. This article also presents the implementation and experimental evaluation (through both field experiments and simulation) of all the secure and resilient location estimation schemes that can be used on the current generation of sensor platforms (e.g., MICA series of motes), including the techniques proposed in this article, in a network of MICAz motes. The experimental results demonstrate the effectiveness of the proposed methods, and also give the secure and resilient location estimation scheme most suitable for the current generation of sensor networks. Donggang Liu, Peng Ning, An Liu 0001, Cliff Wang, Wenliang Du 0001 |
ACM Trans. Inf. Syst. Secur. | 4 |
| 2007 | A New Relaxation Labeling Architecture for Secure Localization in Sensor NetworksabstractA new strategy is proposed to defend against colluding malicious nodes in a sensor network. The new strategy is based on a new relaxation labeling algorithm to classify nodes into benign or malicious ones. Only reports from benign nodes can then be used to perform localization and obtain accurate results. Experimental results based on simulations and field experiments illustrate the performance of the algorithm. Chih-Chieh Geoff Chang, Wesley E. Snyder, Cliff Wang |
ICC | 3 |
| 2007 | Secure Tracking in Sensor NetworksabstractTarget tracking is a canonical issue in sensor networks research. However, tracking security has gained little or no attention. Once a sensor node is compromised, it will be able to inject false location information into the network, and those nodes receiving such information will suffer greatly in terms of tracking precision. This paper, to the best of our knowledge, is the first to explore the topic of security in the context of Bayesian tracking for sensor networks. We propose to activate more than one nodes at each time step, and use a relaxation labeling algorithm to detect malicious nodes whose reports are then removed. Simulations based on both linear and nonlinear motion models demonstrate that out algorithm works better than simply averaging over the results based on the redundant sets of nodes. Chih-Chieh Geoff Chang, Wesley E. Snyder, Cliff Wang |
ICC | 3 |
| 2006 | Secure Distributed Cluster Formation in Wireless Sensor NetworksabstractIn wireless sensor networks, clustering sensor nodes into small groups is an effective technique to achieve scalability, self-organization, power saving, channel access, routing, etc. A number of cluster formation protocols have been proposed recently. However, most existing protocols assume benign environments, and are vulnerable to attacks from malicious nodes. In this paper, we propose a secure distributed cluster formation protocol to organize sensor networks into mutually disjoint cliques. Our protocol has the following properties: (1) normal nodes are divided into mutually disjoint cliques; (2) all the normal nodes in each clique agree on the same clique memberships; (3) while external attackers can be prevented from participating in the cluster formation process, inside attackers that do not follow the protocol semantics can be identified and removed from the network; (4) the communication overhead is moderate; (5) the protocol is fully distributed. Kun Sun 0001, Peng Ning, Cliff Wang |
ACSAC | 4 |
| 2006 | TinySeRSync: secure and resilient time synchronization in wireless sensor networksabstractAccurate and synchronized time is crucial in many sensor network applications due to the need for consistent distributed sensing and coordination. In hostile environments where an adversary may attack the networks and/or the applications through external or compromised nodes, time synchronization becomes an attractive target due to its importance. This paper describes the design, implementation, and evaluation of TinySeRSync, a secure and resilient time synchronization subsystem for wireless sensor networks running TinyOS. This paper makes three contributions: First, it develops a secure single-hop pairwise time synchronization technique using hardware-assisted, authenticated medium access control (MAC) layer timestamping. Unlike the previous attempts, this technique can handle high data rate such as those produced by MICAz motes (in contrast to those by MICA2 motes). Second, this paper develops a secure and resilient global time synchronization protocol based on a novel use of the μTESLA broadcast authentication protocol for local authenticated broadcast, resolving the conflict between the goal of achieving time synchronization with μTESLA-based broadcast authentication and the fact that μTESLA requires loose time synchronization. The resulting protocol is secure against external attacks and resilient against compromised nodes. The third contribution consists of an implementation of the proposed techniques on MICAz motes running TinyOS and a thorough evaluation through field experiments in a network of 60 MICAz motes. Kun Sun 0001, Peng Ning, Cliff Wang |
CCS | 3 |
| 2006 | Secure and resilient clock synchronization in wireless sensor networksabstractWireless sensor networks have received a lot of attention recently due to its wide applications. An accurate and synchronized clock time is crucial in many sensor network applications. Several clock synchronization schemes have been proposed for wireless sensor networks recently to address the resource constraints in such networks. However, most of these techniques assume benign environments, but cannot survive malicious attacks in hostile environments, especially when there are compromised nodes. As an exception, a recent work attempts to detect malicious attacks against clock synchronization, and aborts when an attack is detected. Though this approach can prevent incorrect clock synchronization due to attacks, it will lead to denial of clock synchronization in such situations. This paper adopts a model where all the sensor nodes synchronize their clocks to a common source, which is assumed to be well synchronized to the external clock. This paper seeks techniques to provide redundant ways for each node to synchronize its clock with the common source, so that it can tolerate partially missing or false synchronization information provided by compromised nodes. Two types of techniques are developed using this general method: level-based clock synchronization and diffusion-based clock synchronization. Targeted at static sensor networks, the level-based clock synchronization constructs a level hierarchy initially, and uses (or reuses) this level hierarchy for multiple rounds of clock synchronization. The diffusion-based clock synchronization attempts to synchronize all the clocks without relying on any structure assumptions and, thus, can be used for dynamic sensor networks. This paper further investigates how to use multiple clock sources for both approaches to increase the resilience against compromise of source nodes. The analysis in this paper indicates that both level-based and diffusion-based approaches can tolerate up to s colluding malicious source nodes and t colluding malicious nodes among the neighbors of each normal node, where s and t are two system parameters. This paper also presents the results of simulation studies performed to evaluate the proposed techniques. These results demonstrate that the level-based approach has less overhead and higher precision, but less coverage, than the diffusion-based approach. Kun Sun 0001, Peng Ning, Cliff Wang |
IEEE J. Sel. Areas Commun. | 3 |
| 2005 | Supervised Multispectral Image Segmentation using Active ContoursabstractActive contours have been widely used as image segmentation methods. The use of level set theory has provided more flexibility and convenience for the implementation of active contours. However, traditional active contour models have some limitations on the segmentation of complicated images whose sub-regions consist of multiple components. The segmentation of multispectral images is even a more difficult problem. We propose an advanced active contour model using the statistics of image intensity based on a multivariate mixture density model. The proposed active contour model shows a robust segmentation capability on the images that traditional segmentation methods cannot properly partition. Numerical experiments with synthetic and real images are presented. Cheolha Pedro Lee, Wesley E. Snyder, Cliff Wang |
ICRA | 3 |
| 2005 | Fault-Tolerant Cluster-Wise Clock Synchronization for Wireless Sensor NetworksabstractWireless sensor networks have received a lot of attention recently due to their wide applications, such as target tracking, environment monitoring, and scientific exploration in dangerous environments. It is usually necessary to have a cluster of sensor nodes share a common view of a local clock time, so that all these nodes can coordinate in some important applications, such as time slotted MAC protocols, power-saving protocols with sleep/listen modes, etc. However, all the clock synchronization techniques proposed for sensor networks assume benign environments; they cannot survive malicious attacks in hostile environments. Fault-tolerant clock synchronization techniques are potential candidates to address this problem. However, existing approaches are all resource consuming and suffer from message collisions in most of cases. This paper presents a novel fault-tolerant clock synchronization scheme for clusters of nodes in sensor networks, where the nodes in each cluster can communicate through broadcast. The proposed scheme guarantees an upper bound of clock difference between any nonfaulty nodes in a cluster, provided that the malicious nodes are no more than one third of the cluster. Unlike the traditional fault-tolerant clock synchronization approaches, the proposed technique does not introduce collisions between synchronization messages, nor does it require costly digital signatures. Kun Sun 0001, Peng Ning, Cliff Wang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 1994 | Edge detection in gated cardiac nuclear medicine imagesabstractMean field annealing using a piecewise linear model was applied to gated cardiac nuclear medicine images as a preprocessing tool for image smoothing and noise reduction. A second derivative operator was then used to extract the edges for ventricle boundary estimation. Combined with the user input initial boundary estimate, the extracted edge information was used to find a minimum cost boundary, which was optimum with regards to boundary smoothness and the boundary edge strength.> Cliff Wang, Lori Small, Wesley E. Snyder, Rodney Williams |
CBMS | 1 |