Weiyu Jiang

dblp:88/1904 · DBLP profile ↗
← Back
11ranked-venue papers
3as first author
5since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 3 since 2021Computer networks · 3 · 1 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021
YearPublicationVenuePosition
2025 Pisces: In-Path Distributed Denial-of-Service Defense via Efficient Authentication Code Embedded in IP Address
abstract
High-volume brute-force distributed denial-of-service (DDoS) attack is among the top threats on the Internet. Existing widely deployed methods (e.g., BGP blackhole and scrubbing center) have difficulty achieving legitimate traffic friendliness, low cost, low latency, and high accuracy. We present an in-path DDoS defense mechanism, namelyPisces. Without requiring modifications to existing IP protocols,Piscesembeds authentication information into the IP address. Simultaneously, we design a QUIC-based extension to distribute authentication information.Piscesincorporates a translator module and a filter module, which accurately identifies malicious and legitimate traffic. These multi-dimensional compatibility advantages make it easy to deploy in the real world. We implementPisceson a high-end commercial router with service processing units. Even without hardware acceleration, a single CPU can achieve$ 20\,\text{Gbps}$throughput and the performance can scale linearly with the number of CPUs. The additional latency for the victim-related traffic and other traffic is around$27\,\text{us}$and$0.5\,\text{us}$, respectively, whose cost is far less than the scrubbing center. Remarkably,Pisceswithout false positives can provide high-quality datasets for intelligent approaches and form a prominent complementary effect.
Yi Zhao 0011, Bingyang Liu, Weiyu Jiang, Ke Xu 0002, Qi Li 0002, Chuang Wang 0012, Zongxin Dou
IEEE Trans. Dependable Secur. Comput.3
2023 An optimisation for a two-round good-case latency protocol
abstract
Abstract Byzantine broadcast is a fundamental primitive in distributed computing. A highly efficient Byzantine broadcast protocol, motivated by the real‐world performance of practical state machine replication protocols, is increasingly needed. This article focuses on the state‐of‐the‐art partially synchronous Byzantine broadcast protocol proposed by Abraham et al. (PODC’21), which achieves optimal good‐case latency of two rounds and optimal resilience of n ≥ 5 f − 1 in this setting. Each step of the protocol is analysed, and then improved by cutting down the number of messages required to be collected and transmitted in the heaviest step of the protocol by about half , without adding any extra cost. This benefits from a new property, named “spread”, that we identify and extract from the original protocol. It helps us to eliminate non‐essential work in its view‐change procedure. The authors also show that no further reduction is possible without violating security. A prototype is implemented and the performances of improved and original protocols are evaluated in the same environment. The results show that our improvement can achieve about 50% lower communication cost and 40% shorter latency at a scale of 100 replicas. The latency gap becomes wider as the scale further increases.
Zhenfeng Zhang, Weiyu Jiang, Xiaoman Shawn Li, Jiang Han
IET Inf. Secur.4
2023 An ATC instruction processing-based trajectory prediction algorithm designing
Yi Mao 0003, Qucheng Xu, Weiyu Jiang, Suwan Yin
Neural Comput. Appl.5
2021 TAP: A Traffic-Aware Probabilistic Packet Marking for Collaborative DDoS Mitigation
abstract
In recent years, Distributed Denial-of-Service (DDoS) attacks have become more rampant and continue to be one of the most serious security threats facing network infrastructure. In a classic DDoS attack, the attacker controls numerous bots from many sources to send a significant volume of traffic to flood the victim end or the bottleneck link. In practical networks, it is inefficient and costly to request all partner routers to collaboratively mitigate DDoS attacks. The common feature of DDoS attacks is the abnormal distribution of traffic to the victim. In this paper, we propose TAP, a collaborative DDoS mitigation framework, based on traffic-aware probabilistic packet marking (PPM). TAP enables the victim to select a few hit routers as collaborators to mitigate attack traffic efficiently depending on the traffic distribution. Our evaluation results show that TAP greatly reduces attack traffic within seconds and mitigate the damage caused by DDoS with less overhead, which demonstrates that TAP is an effective, efficient, and rapid-response scheme for collaborative DDoS mitigation.
Mingxing Liu, Ying Liu 0024, Ke Xu 0002, Lin He 0004, Xiaoliang Wang 0004, Yangfei Guo, Weiyu Jiang
MSN7
2021 Security-Oriented Network Architecture
abstract
Internet benefits societies by constantly connecting devices and transmitting data across the world. However, due to the lack of architectural built-in security, the pervasive network attacks faced by the entire information technology are considered to be unending and inevitable. As Internet evolves, security issues are regularly fixed according to a patch-like strategy. Nevertheless, the patch-like strategy generally results in arms races and passive situations, leaving an endless lag in both existing and emerging attacking surface. In this paper, we present NAIS (Network Architecture with Intrinsic Security)—a network architecture towards trustworthiness and security. By solving stubborn security issues like IP spoofing, MITM (man-in-the-middle) attacks, and DDoS (distributed denial of service) attacks at architectural level, NAIS is envisioned to provide the most secure end-to-end communication in the network layer. This paper first presents a comprehensive analysis of network security at Internet range. Then, the system design of NAIS is elaborated with particular design philosophies and four security techniques. Such philosophies and techniques intertwine internally and contribute to a communication environment with authenticity, privacy, accountability, confidentiality, integrity, and availability. Finally, we evaluate the security functionalities on the packet forwarding performance, demonstrating that NAIS can efficiently provide security and trustworthiness in Internet end-to-end communication.
Weiyu Jiang, Bingyang Liu, Chuang Wang 0012
Secur. Commun. Networks1
2020 Poster: Enhancing Remote Healthiness Attestation for Constrained IoT Devices
abstract
The Internet of Things (IoT), which has been rapidly implemented in the smart home, city, and industry, keeps shaping the way we live. However, the constrained resource of IoT leads to a constant vulnerability for its’ resident network and the whole Internet. To mitigate potential threats, a complementary method – Device Identifier Composition Engine (DICE) – is introduced to enable remote healthiness attestation for IoT devices. Although DICE narrows the gap between security necessity and the constrained resource of IoT, a replay attack is still possible to circumvent the method. In this paper, an enhanced DICE+ is proposed to address the weakness. Compared to the original DICE, DICE+ improves DICE with dynamic attestation evidence (other than static evidence in standard DICE), and thus alleviates the replay attack. Based on the evaluation, DICE+ enhances the standard DICE in three aspects simultaneously: (i) Replay attack resilience; (ii) Extreme lightweight overhead; (iii) Fine-grained firmware attestation. According to the chip specification from our product line, a ca. 60% size reduction of the chip security-related area is expectable if such the method applied along with a pure symmetric-cryptography tech-set.
Yihao Jia, Bingyang Liu, Weiyu Jiang, Chuang Wang 0012
ICNP3
2018 CNN-Based Chinese Character Recognition with Skeleton Feature
Yijun Su, Xiang Li 0045, Daren Zha, Weiyu Jiang, Neng Gao, Ji Xiang
ICONIP (5)5
2017 How to Make Information-Flow Analysis Based Defense Ineffective: An ART Behavior-Mask Attack
Xueyi Yang, Lingchen Zhang, Weiyu Jiang, Shiran Pan
ISC4
2015 LightCore: Lightweight Collaborative Editing Cloud Services for Sensitive Data
Weiyu Jiang, Jingqiang Lin 0001, Huorong Li, Lei Wang 0135
ACNS1
2014 Towards Efficient Update of Access Control Policy for Cryptographic Cloud Storage
Weiyu Jiang, Neng Gao
SecureComm (2)1
2005 High accuracy frequency offset correction with adjustable acquisition range in OFDM systems
abstract
A new carrier frequency offset estimation scheme in orthogonal frequency-division multiplexing (OFDM) systems is proposed in this paper. Both the carrier frequency offset acquisition and tracking are based on a fixed-length training-symbol-block, which consists of multiple small identical training symbols. When each training symbol is shortened, the number of training symbols in the training-symbol-block should be increased accordingly to keep the total training-symbol-block length fixed. The proposed scheme extends Moose's estimator, where the estimation error is only dependent on total training symbol energy and cannot be reduced any more, once the total training symbol energy is determined. The proposed scheme can shorten each training symbol in a training-symbol block and select an appropriate estimator simultaneously, which can lead to further reduction of estimation error and increase of acquisition range, even with the total training-symbol-block energy being fixed. Performance analyzes for the proposed scheme in both the additive white Gaussian noise channel (AWGN) and the multipath channel are also presented in this paper. All estimators in the proposed scheme are conditionally unbiased, and simulation results demonstrate that they can work well both in the multipath channel and in the AWGN channel.
Zhongshan Zhang, Weiyu Jiang, Jinchun Gao
IEEE Trans. Wirel. Commun.2