EDBT 2026 Demo / reviewers in the wild / expert
Z. Morley Mao
dblp:91/584 · also Morley Mao, Zhuoqing Mao 0001, Zhuoqing Morley Mao
· DBLP profile ↗
178ranked-venue papers
8as first author
43since 2021 · last 2026
0000-0002-9844-2055ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 81 · 5 first-author · 9 since 2021Security and privacy · 49 · 8 since 2021Artificial intelligence and machine learning · 18 · 17 since 2021Systems, architecture and hardware · 18 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 10 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 10 · 10 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Automatic Teller Machines for Offline E-cash
Anrin Chakraborti, Qingzhao Zhang 0001, Jingjia Peng, Z. Morley Mao, Michael K. Reiter |
ACNS (2) | 4 |
| 2026 | RLBoost: Harvesting Preemptible Cloud Resources for Cost-Efficient Reinforcement Learning on LLMs
Xueshen Liu, Haizhong Zheng, Juncheng Gu, Beidi Chen, Z. Morley Mao, Arvind Krishnamurthy, Ion Stoica |
NSDI | 6 |
| 2026 | Banshee: Target Switch Attacks on Gimbal-Stabilized Visual Tracking Systems via Acoustic InjectionabstractGimbal-stabilized visual tracking is critical for modern autonomous systems such as Unmanned Aerial Vehicles (UAVs). While prior work shows acoustic signals can disturb gimbal internals, the impact of such attacks on real-world applications like UAV tracking and following remains underexplored. Existing demonstrations largely overlook practical challenges for real-world attacks, such as object-motion uncertainty and runtime latency. To bridge this gap, we present Banshee, the first physically realizable attack that induces target switching in UAV visual tracking systems by exploiting acoustic vulnerabilities in gimbal-camera systems. Banshee generates carefully crafted acoustic waveforms that induce optimized adversarial gimbal oscillations, causing directionally biased camera-view drifts that break inter-frame target associations. Consequently, the onboard tracker is driven to switch from the original target to an attacker-selected object with high probability, with occasional target loss. Banshee achieves a 93.6% success rate in simulation across two commercial gimbal systems and five trackers. Real-world benchtop and in-flight black-box attacks against a commercial drone across varied scenarios show an overall 95.5% attack success rate. Our results reveal a practical cross-domain vulnerability between acoustics and vision, highlighting the need for robust designs of gimbal systems and applications. Our code is available at: https://github.com/U1ltra/Banshee. Joseph Brewington, Qingzhao Zhang 0001, Z. Morley Mao |
SP | 4 |
| 2025 | Cocoon: Robust Multi-Modal Perception with Uncertainty-Aware Sensor FusionabstractAn important paradigm in 3D object detection is the use of multiple modalities to enhance accuracy in both normal and challenging conditions, particularly for long-tail scenarios. To address this, recent studies have explored two directions of adaptive approaches: MoE-based adaptive fusion, which struggles with uncertainties arising from distinct object configurations, and late fusion for output-level adaptive fusion, which relies on separate detection pipelines and limits comprehensive understanding. In this work, we introduce Cocoon, an object- and feature-level uncertainty-aware fusion framework. The key innovation lies in uncertainty quantification for heterogeneous representations, enabling fair comparison across modalities through the introduction of a feature aligner and a learnable surrogate ground truth, termed feature impression. We also define a training objective to ensure that their relationship provides a valid metric for uncertainty quantification. Cocoon consistently outperforms existing static and adaptive methods in both normal and challenging conditions, including those with natural and artificial corruptions. Furthermore, we show the validity and efficacy of our uncertainty metric across diverse datasets. Minkyoung Cho, Qingzhao Zhang 0001, Marco Pavone 0001, Jeong Joon Park, Z. Morley Mao |
ICLR | 8 |
| 2025 | AutoDAN-Turbo: A Lifelong Agent for Strategy Self-Exploration to Jailbreak LLMsabstractJailbreak attacks serve as essential red-teaming tools, proactively assessing whether LLMs can behave responsibly and safely in adversarial environments. Despite diverse strategies (e.g., cipher, low-resource language, persuasions, and so on) that have been proposed and shown success, these strategies are still manually designed, limiting their scope and effectiveness as a red-teaming tool. In this paper, we propose AutoDAN-Turbo, a black-box jailbreak method that can automatically discover as many jailbreak strategies as possible from scratch, without any human intervention or predefined scopes (e.g., specified candidate strategies), and use them for red-teaming. As a result, AutoDAN-Turbo can significantly outperform baseline methods, achieving a 74.3% higher average attack success rate on public benchmarks. Notably, AutoDAN-Turbo achieves an 88.5 attack success rate on GPT-4-1106-turbo. In addition, AutoDAN-Turbo is a unified framework that can incorporate existing human-designed jailbreak strategies in a plug-and-play manner. By integrating human-designed strategies, AutoDAN-Turbo can even achieve a higher attack success rate of 93.4 on GPT-4-1106-turbo. Xiaogeng Liu, G. Edward Suh, Yevgeniy Vorobeychik, Z. Morley Mao, Somesh Jha, Patrick McDaniel, Huan Sun 0001, Bo Li 0026, Chaowei Xiao |
ICLR | 5 |
| 2025 | Compute or Load KV Cache? Why Not Both?abstractLarge Language Models (LLMs) are increasingly deployed in large-scale online services, enabling sophisticated applications. However, the computational overhead of generating key-value (KV) caches in the prefill stage presents a major bottleneck, particularly for long-context inputs. Prefix caching mitigates this issue by storing KV caches for reuse, reducing redundant computation. Despite its advantages, prefix caching suffers from high latency due to the limited I/O bandwidth of storage devices, constraining inference efficiency. To address this challenge, we introduce Cake, a novel KV cache loading system that optimally utilizes both computational and I/O resources in parallel. Cake employs a bidirectional scheduling strategy that dynamically balances KV cache computation and loading, ensuring efficient resource utilization. Additionally, Cake incorporates an adaptive scheduling mechanism that seamlessly integrates with non-prefix caching requests, improving system throughput and adapting to fluctuating resource availabilty. Through extensive evaluations across various hardware configurations, datasets, and storage conditions, Cake achieves on average 2.6× reduction in Time to First Token (TTFT) compared to compute-only and I/O-only methods. Our findings highlight Cake as an effective and practical solution for optimizing long-context LLM inference, bridging the gap between computation and I/O efficiency in large-scale AI deployments. Shuowei Jin, Xueshen Liu, Qingzhao Zhang 0001, Z. Morley Mao |
ICML | 4 |
| 2025 | SCORPION: Robust Spatial-Temporal Collaborative Perception Model on Lossy Wireless NetworkabstractCollaborative Perception enables multiple agents, such as autonomous vehicles and infrastructure, to share sensor data via vehicular networks so that each agent gains an extended sensing range and better perception quality. Despite its promising benefits, realizing the full potential of such systems faces significant challenges due to inherent imperfections in underlying system layers, consisting of network layer imperfections and hardware-level noises. Such imperfections and noises include packet loss in vehicular networks, localization errors from GPS measurements, and synchronization errors caused by clock deviation and network latency. To address these challenges, we propose a novel end-to-end collaborative perception framework, SCORPION, that harnesses the AI co-design of the application layer and system layer to tackle the aforementioned imperfections. SCORPION consists of three main components: lost bird’s eye view feature reconstruction (L-BEV-R) recovers lost spatial features during lossy V2X communication, while deformable spatial cross attention (DSCA) and temporal alignment (TA) compensate for localization and synchronization errors in feature fusion. Experimental results on both synthetic and real-world collaborative 3D object detection datasets demonstrate that SCORPION advances the state-of-the-art collaborative perception methods by 5.9 - 13.2 absolute AP on both standard and noisy scenarios. Ruiyang Zhu, Minkyoung Cho, Shuqing Zeng, Fan Bai 0002, Z. Morley Mao |
IROS | 5 |
| 2025 | Learnings from Deploying Network QoS Alignment to Application Priorities for Storage Services
Matthew Buckley, Parsa Pazhooheshy, Z. Morley Mao, Nandita Dukkipati, Hamid Hajabdolali Bazzaz, Priyaranjan Jha, Yingjie Bi, Steve Middlekauff, Yashar Ganjali |
NSDI | 3 |
| 2025 | Roaming Free in the VR World with MP2
Xumiao Zhang, Yuning Chen, Xuan Zeng 0002, Zhilong Zheng, Xianshang Lin, Yanmei Liu, Songwu Lu, Z. Morley Mao, Wan Du, Dennis Cai, Ennan Zhai |
USENIX ATC | 10 |
| 2024 | Leveraging Hierarchical Feature Sharing for Efficient Dataset Condensation
Haizhong Zheng, Shutong Wu, Bhavya Kailkhura, Z. Morley Mao, Chaowei Xiao, Atul Prakash 0001 |
ECCV (24) | 5 |
| 2024 | CALICO: Self-Supervised Camera-LiDAR Contrastive Pre-training for BEV PerceptionabstractPerception is crucial in the realm of autonomous driving systems, where bird's eye view (BEV)-based architectures have recently reached state-of-the-art performance. The desirability of self-supervised representation learning stems from the expensive and laborious process of annotating 2D and 3D data. Although previous research has investigated pretraining methods for both LiDAR and camera-based 3D object detection, a unified pretraining framework for multimodal BEV perception is missing. In this study, we introduce CALICO, a novel framework that applies contrastive objectives to both LiDAR and camera backbones. Specifically, CALICO incorporates two stages: point-region contrast (PRC) and region-aware distillation (RAD). PRC better balances the region- and scene-level representation learning on the LiDAR modality and offers significant performance improvement compared to existing methods. RAD effectively achieves contrastive distillation on our self-trained teacher model. CALICO's efficacy is substantiated by extensive evaluations on 3D object detection and BEV map segmentation tasks, where it delivers significant performance improvements. Notably, CALICO outperforms the baseline method by 10.5\% and 8.6\% on NDS and mAP. Moreover, CALICO boosts the robustness of multimodal 3D object detection against adversarial attacks and corruption. Additionally, our framework can be tailored to different backbones and heads, positioning it as a promising approach for multimodal BEV perception. Haizhong Zheng, Qingzhao Zhang 0001, Atul Prakash 0001, Z. Morley Mao, Chaowei Xiao |
ICLR | 5 |
| 2024 | OASIS: Collaborative Neural-Enhanced Mobile Video StreamingabstractNeural-enhanced video streaming (e.g., super-resolution) is an ongoing revolution which can provide extremely high-quality video streaming services breaking the restriction of bandwidth. However, such enhancements require intense computation power that is not affordable for a single mobile device, which hinders their real-world deployment. To address the limitation, we propose OASIS, the first system that facilitates multiple users in close proximity to execute intense neural-enhanced video streaming in realtime. To this end, OASIS intelligently distributes computation tasks among multiple mobile devices, selects appropriate video bitrates and super-resolution models, and optimizes video chunk delivery. As a result, the expensive neural-enhanced streaming is done through distributed collaboration, achieving optimal quality of experience (QoE). We implement and evaluate OASIS on commodity smartphones from different vendors, under various network and computation conditions. Extensive experiments demonstrate the high efficiency of OASIS: it improves the video streaming QoE by 40%-200% and reduces each participant's energy consumption by 60% when the system scales up from a single device to six devices. Shuowei Jin, Ruiyang Zhu, Ahmad Hassan 0004, Xiao Zhu 0001, Xumiao Zhang, Z. Morley Mao, Feng Qian 0001, Zhi-Li Zhang |
MMSys | 6 |
| 2024 | Learn To be Efficient: Build Structured Sparsity in Large Language ModelsabstractLarge Language Models (LLMs) have achieved remarkable success with their billion-level parameters, yet they incur high inference overheads. The emergence of activation sparsity in LLMs provides a natural approach to reduce this cost by involving only parts of the parameters for inference. However, existing methods only focus on utilizing this naturally formed activation sparsity in a post-training setting, overlooking the potential for further amplifying this inherent sparsity. In this paper, we hypothesize that LLMs can learn to be efficient by achieving more structured activation sparsity. To achieve this, we introduce a novel training algorithm, Learn-To-be-Efficient (LTE), designed to train efficiency-aware LLMs to learn to activate fewer neurons and achieve a better trade-off between sparsity and performance. Furthermore, unlike SOTA MoEfication methods, which mainly focus on ReLU-based models, LTE can also be applied to LLMs like LLaMA using non-ReLU activations. Extensive evaluation on language understanding, language generation, and instruction tuning tasks show that LTE consistently outperforms SOTA baselines. Along with our hardware-aware custom kernel implementation, LTE reduces LLaMA2-7B inference latency by 25% at 50% sparsity. Haizhong Zheng, Xiaoyan Bai, Xueshen Liu, Z. Morley Mao, Beidi Chen, Fan Lai 0001, Atul Prakash 0001 |
NeurIPS | 4 |
| 2024 | Vulcan: Automatic Query Planning for Live ML Analytics
Yiwen Zhang 0008, Xumiao Zhang, Ganesh Ananthanarayanan, Anand Padmanabha Iyer, Yuanchao Shu, Paramvir Bahl, Z. Morley Mao, Mosharaf Chowdhury |
NSDI | 7 |
| 2024 | Boosting Collaborative Vehicular Perception on the Edge with Vehicle-to-Vehicle CommunicationabstractCollaborative Vehicular Perception (CVP) enables connected and autonomous vehicles (CAVs) to cooperatively extend their views through wirelessly sharing their sensor data. Existing CVP systems employ either a vehicle-to-vehicle (V2V) or vehicle-to-infrastructure (V2I) view exchange paradigm. In this paper, we advocate a hybrid CVP design: our developed system, Harbor, employs V2I as its fundamental underlying framework, and opportunistically employs V2V to boost the performance. In Harbor, vehicles (helpers) may serve as relays to assist other vehicles (helpees) in reaching an edge node, which performs sensor data merging to produce the extended view. We judiciously partition the workload between the edge and vehicles, develop a robust helper-helpee assignment model, and solve it efficiently at runtime. We conduct both real-world tests and large-scale emulation experiments using two prevailing CAV applications: drivable space detection and object detection. Our real-world evaluation conducted at one of the world's first purpose-built autonomous driving testbeds demonstrates that Harbor outperforms state-of-the-art V2V- or V2I-only CVP schemes by up to 36% in detection accuracy, resulting in significantly fewer collisions under dangerous driving scenarios. Ruiyang Zhu, Xiao Zhu 0001, Anlan Zhang, Xumiao Zhang, Feng Qian 0001, Hang Qiu 0001, Z. Morley Mao, Myungjin Lee |
SenSys | 8 |
| 2024 | On Data Fabrication in Collaborative Vehicular Perception: Attacks and Countermeasures
Qingzhao Zhang 0001, Shuowei Jin, Ruiyang Zhu, Xumiao Zhang, Qi Alfred Chen, Z. Morley Mao |
USENIX Security Symposium | 7 |
| 2024 | State Consistent Edge-enhanced Perception for Connected and Automated VehiclesabstractVehicle function offloading has been an active research topic in the connected and automated vehicles (CAV) domain. Mobile edge computing can execute sophisticated algorithms on abundant computing resources, leading to superior accuracy for vehicle system state estimation. On the other hand, cellular network latency causes edge-computed information to be obsolete.In this paper, by focusing on camera-based object tracking applications, we develop a novel state fusion framework that not only achieves the benefits (enhanced detection accuracy) but also mitigates the disadvantages (unpredictable network latency) of edge computing. This is achieved by carefully managing the system state consistency between the vehicle onboard system and the remote edge system through our novel backward-and-forward algorithms. We evaluate our system by comparing our method with the edge-only and onboard-only counterparts through extensive empirical experiments. The presented framework improves the accuracy of camera-based perception by at least 2x compared to traditional techniques, with an average response time of 48.13 ms (strictly less than the mission-critical latency threshold of 100 ms [1]). Can Carlak, Bo Yu 0007, Fan Bai 0002, Z. Morley Mao |
VTC Fall | 4 |
| 2024 | QUIC is not Quick Enough over Fast InternetabstractQUIC is expected to be a game-changer in improving web application performance. In this paper, we conduct a systematic examination of QUIC's performance over high-speed networks. We find that over fast Internet, the UDP+QUIC+HTTP/3 stack suffers a data rate reduction of up to 45.2% compared to the TCP+TLS+HTTP/2 counterpart. Moreover, the performance gap between QUIC and HTTP/2 grows as the underlying bandwidth increases. We observe this issue on lightweight data transfer clients and major web browsers (Chrome, Edge, Firefox, Opera), on different hosts (desktop, mobile), and over diverse networks (wired broadband, cellular). It affects not only file transfers, but also various applications such as video streaming (up to 9.8% video bitrate reduction) and web browsing. Through rigorous packet trace analysis and kernel- and user-space profiling, we identify the root cause to be high receiver-side processing overhead, in particular, excessive data packets and QUIC's user-space ACKs. We make concrete recommendations for mitigating the observed performance issues. Xumiao Zhang, Shuowei Jin, Yi He 0015, Ahmad Hassan 0004, Z. Morley Mao, Feng Qian 0001, Zhi-Li Zhang |
WWW | 5 |
| 2023 | ADoPT: LiDAR Spoofing Attack Detection Based on Point-Level Temporal Consistency
Minkyoung Cho, Z. Morley Mao |
BMVC | 4 |
| 2023 | A Critical Revisit of Adversarial Robustness in 3D Point Cloud Recognition with Diffusion-Driven Purificationabstract3D point clouds serve as a crucial data representation in numerous real-world applications such as autonomous driving, robotics, and medical imaging. While the advancements in deep learning have spurred the utilization of 3D point clouds, deep models are notoriously vulnerable to adversarial attacks. Various defense solutions have been proposed to build robust models against adversarial attacks. In this work, we pinpoint a major limitation of the leading empirical defense, adversarial training, when applied to 3D point cloud models: gradient obfuscation, which significantly hampers robustness against potent attacks. To bridge the gap, we propose PointDP, a purification strategy that leverages diffusion models to defend against 3D adversarial attacks. Since PointDP does not rely on predefined adversarial examples for training, it can defend against a variety of threats. We conduct a comprehensive evaluation of PointDP across six representative 3D point cloud architectures, employing sixteen strong and adaptive attacks to manifest its foundational robustness. Our evaluation shows that PointDP achieves significantly better (i.e., 12.6%-40.3%) adversarial robustness than state-of-the-art methods under strong attacks bounded by different $\ell_p$ norms. Jiongxiao Wang, Weili Nie, Zhiding Yu, Z. Morley Mao, Chaowei Xiao |
ICML | 5 |
| 2023 | Poster: QUIC is not Quick Enough over Fast InternetabstractQUIC is a multiplexed transport-layer protocol over UDP and comes with enforced encryption. It is expected to be a game-changer in improving web application performance. Together with the network layer and layers below, UDP, QUIC, and HTTP/3 form a new protocol stack for future network communication, whose current counterpart is TCP, TLS, and HTTP/2. In this study, to understand QUIC's performance over high-speed networks and its potential to replace the TCP stack, we carry out a series of experiments to compare the UDP+QUIC+HTTP/3 (QUIC) stack and the TCP+TLS+HTTP/2 (HTTP/2) stack. Preliminary measurements on file download reveal that QUIC suffers from a data rate reduction compared to HTTP/2 across different hosts. Xumiao Zhang, Shuowei Jin, Yi He 0015, Ahmad Hassan 0004, Z. Morley Mao, Feng Qian 0001, Zhi-Li Zhang |
IMC | 5 |
| 2023 | Detecting Data Spoofing in Connected Vehicle based Intelligent Traffic Signal Control using Infrastructure-Side Sensors and Traffic InvariantsabstractConnected Vehicle (CV) technologies are under rapid deployment across the globe and will soon reshape our transportation systems, bringing benefits to mobility, safety, environment, etc. Meanwhile, such technologies also attract attention from cyberattacks. Recent work shows that CV-based Intelligent Traffic Signal Control Systems are vulnerable to data spoofing attacks, which can cause severe congestion effects in intersections. In this work, we explore a general detection strategy for infrastructure-side CV applications by estimating the trustworthiness of CVs based on readily-available infrastructure-side sensors. We implement our detector for the CV-based traffic signal control and evaluate it against two representative congestion attacks. Our evaluation in the industrial-grade traffic simulator shows that the detector can detect attacks with at least 95% true positive rates while keeping false positive rate below 7% and is robust to sensor noises. Junjie Shen 0001, Ziwen Wan, Yunpeng Luo, Yiheng Feng, Z. Morley Mao, Qi Alfred Chen |
IV | 5 |
| 2023 | VPA: Fully Test-Time Visual Prompt AdaptationabstractTextual prompt tuning has demonstrated significant performance improvements in adapting natural language processing models to a variety of downstream tasks by treating hand-engineered prompts as trainable parameters. Inspired by the success of textual prompting, several studies have investigated the efficacy of visual prompt tuning. In this work, we present Visual Prompt Adaptation (VPA), the first framework that generalizes visual prompting with test-time adaptation. VPA introduces a small number of learnable tokens, enabling fully test-time and storage-efficient adaptation without necessitating source-domain information. We examine our VPA design under diverse adaptation settings, encompassing single-image, batched-image, and pseudo-label adaptation. We evaluate VPA on multiple tasks, including out-of-distribution (OOD) generalization, corruption robustness, and domain adaptation. Experimental results reveal that VPA effectively enhances OOD generalization by 3.3% across various models, surpassing previous test-time approaches. Furthermore, we show that VPA improves corruption robustness by 6.5% compared to strong baselines. Finally, we demonstrate that VPA also boosts domain adaptation performance by relatively 5.2%. Our VPA also exhibits marked effectiveness in improving the robustness of zero-shot recognition for vision-language models. Mark Ibrahim, Melissa Hall, Ivan Evtimov, Z. Morley Mao, Cristian Canton, Caner Hazirbas |
ACM Multimedia | 5 |
| 2023 | Robust Real-time Multi-vehicle Collaboration on Asynchronous SensorsabstractCooperative perception significantly enhances the perception performance of connected autonomous vehicles. Instead of purely relying on local sensors with limited range, it enables multiple vehicles and roadside infrastructures to share sensor data to perceive the environment collaboratively. Through our study, we realize that the performance of cooperative perception systems is limited in real-world deployment due to (1) out-of-sync sensor data during data fusion and (2) inaccurate localization of occluded areas. To address these challenges, we develop RAO, an innovative, effective, and lightweight cooperative perception system that merges asynchronous sensor data from different vehicles through our novel designs of motion-compensated occupancy flow prediction and on-demand data sharing, improving both the accuracy and coverage of the perception system. Our extensive evaluation, including real-world and emulation-based experiments, demonstrates that RAO outperforms state-of-the-art solutions by more than 34% in perception coverage and by up to 14% in perception accuracy, especially when asynchronous sensor data is present. RAO consistently performs well across a wide variety of map topologies and driving scenarios. RAO incurs negligible additional latency (8.5 ms) and low data transmission overhead (10.9 KB per frame), making cooperative perception feasible. Qingzhao Zhang 0001, Xumiao Zhang, Ruiyang Zhu, Fan Bai 0002, Mohammad Naserian, Z. Morley Mao |
MobiCom | 6 |
| 2023 | You Can't See Me: Physical Removal Attacks on LiDAR-based Autonomous Vehicles Driving Frameworks
S. Hrushikesh Bhupathiraju, Pirouz Naghavi, Takeshi Sugawara 0001, Z. Morley Mao, Sara Rampazzi |
USENIX Security Symposium | 5 |
| 2023 | Anomaly Detection Against GPS Spoofing Attacks on Connected and Autonomous Vehicles Using Learning From DemonstrationabstractGPS spoofing attacks pose great challenges to connected vehicle (CVs) safety applications and localization of autonomous vehicles (AVs). In this paper, we propose to utilize transportation and vehicle engineering domain knowledge to detect GPS spoofing attacks towards CVs and AVs. A novel detection method using learning from demonstration is developed, which can be implemented in both vehicles and at the transportation infrastructure. A computational-efficient driving model, which can be learned from historical trajectories of the vehicles, is constructed to predict normal driving behaviors. Then a statistical method is developed to measure the dissimilarities between the observed trajectory and the predicted normal trajectory for anomaly detection. We validate the proposed method using two threat models (i.e., attacks targeting the multi-sensor fusion system of AVs and attacks targeting the intersection movement assist application of CVs) on two real-world datasets (i.e., KAIST and Michigan roundabout dataset). Results show that the proposed model is able to detect almost all of the attacks in time with low false positive and false negative rates. Zhen Yang 0031, Junjie Shen 0001, Yiheng Feng, Qi Alfred Chen, Z. Morley Mao, Henry X. Liu |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2022 | Gatekeeper: A Gateway-based Broadcast Authentication Protocol for the In-Vehicle EthernetabstractAutomotive Ethernet is considered to be the next-generation in-vehicle network, because of its high bandwidth, high throughput, and low cost characteristics. However, no common standard has been established for the security protocol of Automotive Ethernet. While there are a few candidates, including MACsec, IPsec, and TLS, there is no widely favored candidate. Most importantly, existing candidates cannot fully satisfy the requirements of in-vehicle communication, specifically source authentication for broadcast/multicast communication. In this paper, we conduct a comprehensive analysis in both security and performance of existing security protocol candidates and identify source authentication and Denial-of-Service (DoS) prevention as two essential but missing properties in these candidates. We propose Gatekeeper, a gateway-based broadcast authentication protocol to ensure source authentication. In general, Gatekeeper introduces an on-path authenticator, which co-locates with the in-vehicle gateway or domain controllers and helps receivers to verify the sender's identity. To defend against DoS threats, we further integrate the time-lock puzzle with Gatekeeper to slow down malicious traffic. Our performance evaluation results show that Gatekeeper only results in 0.03 ms latency overhead for CAN data transmission and outperforms TESLA on both CAN and LiDAR transmission scenarios, highlighting the effectiveness and efficiency of Gatekeeper. Shengtuo Hu, Qingzhao Zhang 0001, André Weimerskirch, Z. Morley Mao |
AsiaCCS | 4 |
| 2022 | On Adversarial Robustness of Trajectory Prediction for Autonomous VehiclesabstractTrajectory prediction is a critical component for autonomous vehicles (AVs) to perform safe planning and navigation. However, few studies have analyzed the adversarial robustness of trajectory prediction or investigated whether the worst-case prediction can still lead to safe planning. To bridge this gap, we study the adversarial robustness of trajectory prediction models by proposing a new adversarial attack that perturbs normal vehicle trajectories to maximize the prediction error. Our experiments on three models and three datasets show that the adversarial prediction increases the prediction error by more than 150%. Our case studies show that if an adversary drives a vehicle close to the target AV following the adversarial trajectory, the AV may make an inaccurate prediction and even make unsafe driving decisions. We also explore possible mitigation techniques via data augmentation and trajectory smoothing. Qingzhao Zhang 0001, Shengtuo Hu, Qi Alfred Chen, Z. Morley Mao |
CVPR | 5 |
| 2022 | A Spectral View of Randomized Smoothing Under Common Corruptions: Benchmarking and Improving Certified Robustness
Akshay Mehra, Bhavya Kailkhura, Dan Hendrycks, Jihun Hamm, Z. Morley Mao |
ECCV (4) | 7 |
| 2022 | Adversarial Unlearning of Backdoors via Implicit Hypergradient
Yi Zeng 0005, Si Chen 0008, Won Park, Z. Morley Mao, Ming Jin 0002, Ruoxi Jia 0001 |
ICLR | 4 |
| 2022 | AVMaestro: A Centralized Policy Enforcement Framework for Safe Autonomous-driving EnvironmentsabstractAutonomous vehicles (AVs) are on the verge of changing the transportation industry. Despite the fast development of autonomous driving systems (ADSs), they still face safety and security challenges. Current defensive approaches usually focus on a narrow objective and are bound to specific platforms, making them difficult to generalize. To solve these limitations, we propose AVMaestro, an efficient and effective policy enforcement framework for full-stack ADSs. AVMaestro includes a code instrumentation module to systematically collect required information across the entire ADS, which will then be feed into a centralized data examination module, where users can utilize the global information to deploy defensive methods to protect AVs from various threats. AVMaestro is evaluated on top of Apollo-6.0 and experimental results confirm that it can be easily incorporated into the original ADS with almost negligible run-time delay. We further demonstrate that utilizing the global information can not only improve the accuracy of existing intrusion detection methods, but also potentially inspire new security applications. Sanjay Sri Vallabh Singapuram, Qingzhao Zhang 0001, David Ke Hong, Brandon Nguyen, Z. Morley Mao, Scott A. Mahlke, Qi Alfred Chen |
IV | 6 |
| 2022 | Automated Runtime Mitigation for Misconfiguration Vulnerabilities in Industrial Control SystemsabstractCyber-physical industrial control systems (ICS) commonly implement configuration parameters that can be remotely tuned by human-machine interfaces (HMI) at runtime. These parameters directly control the behaviors of ICSs thus they can be exploited by attackers to compromise the safety of ICSs, proved by real-world attacks worldwide. However, existing anomaly detection methods, which mostly focus on the programmable logic controller (PLC) programs or sensor signals, lack a comprehensive analysis of configuration’s impact on the entire system and thus cannot effectively detect improper parameters. A tool that automatically analyzes complicated control logic to determine the safety of configuration is absent. To fill this gap, we design SmtConf, a verification-based framework for detecting and mitigating improper parameters in ICSs at runtime. To understand the impact of configuration parameters on complicated control logic, we design a symbolic formal model representing behaviors of the ICS under any possible configuration parameters. Based on the model, SmtConf works as a monitoring system that detects safety violations in real-time when the improper configuration is injected. To further assist developers to determine the safe configuration, SmtConf recommends safe configuration parameters by solving an optimization problem. In 18 test cases collected from two production-level ICS testbeds, SmtConf detects all true violations caused by improper parameters in 0.41 seconds and correctly repairs the ICS with recommended safe parameters in 0.45 seconds. Qingzhao Zhang 0001, Xiao Zhu 0001, Mu Zhang 0001, Z. Morley Mao |
RAID | 4 |
| 2022 | Vivisecting mobility management in 5G cellular networksabstractWith 5G's support for diverse radio bands and different deployment modes, e.g., standalone (SA) vs. non-standalone (NSA), mobility management - especially the handover process - becomes far more complex. Measurement studies have shown that frequent handovers cause wild fluctuations in 5G throughput, and worst, service outages. Through a cross-country (6,200 km+) driving trip, we conduct in-depth measurements to study the current 5G mobility management practices adopted by three major U.S. carriers. Using this rich dataset, we carry out a systematic analysis to uncover the handover mechanisms employed by 5G carriers, and compare them along several dimensions such as (4G vs. 5G) radio technologies, radio (low-, mid- & high-)bands, and deployment (SA vs. NSA) modes. We further quantify the impact of mobility on application performance, power consumption, and signaling overheads. We identify key challenges facing today's NSA 5G deployments which result in unnecessary handovers and reduced coverage. Finally, we design a holistic handover prediction system Prognos and demonstrate its ability to improve QoE for two 5G applications 16K panoramic VoD and realtime volumetric video streaming. We have released the artifacts of our study at https://github.com/SIGCOMM22-5GMobility/artifact. Ahmad Hassan 0004, Arvind Narayanan, Anlan Zhang, Wei Ye 0009, Ruiyang Zhu, Shuowei Jin, Jason Carpenter, Z. Morley Mao, Feng Qian 0001, Zhi-Li Zhang |
SIGCOMM | 8 |
| 2022 | Security Analysis of Camera-LiDAR Fusion Against Black-Box Attacks on Autonomous Vehicles
Spencer Hallyburton, Yupei Liu, Z. Morley Mao, Miroslav Pajic |
USENIX Security Symposium | 4 |
| 2022 | On the Cybersecurity of Traffic Signal Control System With Connected VehiclesabstractConnected vehicle (CV) technology brings both opportunities and challenges to the traffic signal control (TSC) system. While safety and mobility performance could be greatly improved by adopting CV technologies, the connectivity between vehicles and transportation infrastructure may increase the risks of cyber threats. In the past few years, studies related to cybersecurity on the TSC systems were conducted. However, there still lacks a systematic investigation that provides a comprehensive analysis framework. In this study, our aim is to fill the research gap by proposing a comprehensive analysis framework for the cybersecurity problem of the TSC in the CV environment. With potential threats towards the major components of the system and their corresponding impacts on safety and efficiency analyzed, data spoofing attack is considered the most plausible and realistic attack approach. Based on this finding, different attack strategies and defense solutions are discussed. A case study is presented to show the impact of the data spoofing attacks towards a selected CV based TSC system and corresponding mitigation countermeasures. This case study is conducted on a hybrid security testing platform, with virtual traffic and a real V2X communication network. To the best of our knowledge, this is the first study to present a comprehensive analysis framework to the cybersecurity problem of the CV-based TSC systems. Yiheng Feng, Shihong Ed Huang, Wai Wong, Qi Alfred Chen, Z. Morley Mao, Henry X. Liu |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2021 | On Adversarial Robustness of 3D Point Cloud Classification under Adaptive Attacks
Karl Koenig, Qi Alfred Chen, Z. Morley Mao |
BMVC | 5 |
| 2021 | Rethinking the Backdoor Attacks' Triggers: A Frequency PerspectiveabstractBackdoor attacks have been considered a severe security threat to deep learning. Such attacks can make models perform abnormally on inputs with predefined triggers and still retain state-of-the-art performance on clean data. While backdoor attacks have been thoroughly investigated in the image domain from both attackers’ and defenders’ sides, an analysis in the frequency domain has been missing thus far.This paper first revisits existing backdoor triggers from a frequency perspective and performs a comprehensive analysis. Our results show that many current backdoor attacks exhibit severe high-frequency artifacts, which persist across different datasets and resolutions. We further demonstrate these high-frequency artifacts enable a simple way to detect existing backdoor triggers at a detection rate of 98.50% without prior knowledge of the attack details and the target model. Acknowledging previous attacks’ weaknesses, we propose a practical way to create smooth backdoor triggers without high-frequency artifacts and study their detectability. We show that existing defense works can benefit by incorporating these smooth triggers into their design consideration. Moreover, we show that the detector tuned over stronger smooth triggers can generalize well to unseen weak smooth triggers. In short, our work emphasizes the importance of considering frequency analysis when designing both backdoor attacks and defenses in deep learning. Yi Zeng 0005, Won Park, Z. Morley Mao, Ruoxi Jia 0001 |
ICCV | 3 |
| 2021 | Sensor Adversarial Traits: Analyzing Robustness of 3D Object Detection Sensor Fusion ModelsabstractA critical aspect of autonomous vehicles (AVs) is the object detection stage, which is increasingly being performed with sensor fusion models: multimodal 3D object detection models which utilize both 2D RGB image data and 3D data from a LIDAR sensor as inputs. In this work, we perform the first study to analyze the robustness of a high-performance, open source sensor fusion model architecture towards adversarial attacks and challenge the popular belief that the use of additional sensors automatically mitigate the risk of adversarial attacks. We find that despite the use of a LIDAR sensor, the model is vulnerable to our purposefully crafted image-based adversarial attacks including disappearance, universal patch, and spoofing. After identifying the underlying reason, we explore some potential defenses and provide some recommendations for improved sensor fusion models. Won Park, Nan Liu 0010, Qi Alfred Chen, Z. Morley Mao |
ICIP | 4 |
| 2021 | Livelyzer: analyzing the first-mile ingest performance of live video streamingabstractOver-the-top (OTT) live video traffic has grown significantly, fueled by fundamental shifts in how users consume video content (e.g., increased cord-cutting) and by improvements in camera technologies, computing power, and wireless resources. A key determining factor for the end-to-end live streaming QoE is the design of the first-mile upstream ingest path that captures and transmits the live content in real-time, from the broadcaster to the remote video server. This path often involves either a Wi-Fi or cellular component, and is likely to be bandwidth-constrained with time-varying capacity, making the task of high-quality video delivery challenging. Today, there is little understanding of the state of the art in the design of this critical path, with existing research focused mainly on the downstream distribution path, from the video server to end viewers. Xiao Zhu 0001, Subhabrata Sen, Z. Morley Mao |
MMSys | 3 |
| 2021 | EMP: edge-assisted multi-vehicle perceptionabstractConnected and Autonomous Vehicles (CAVs) heavily rely on 3D sensors such as LiDARs, radars, and stereo cameras. However, 3D sensors from a single vehicle suffer from two fundamental limitations: vulnerability to occlusion and loss of details on far-away objects. To overcome both limitations, in this paper, we design, implement, and evaluate EMP, a novel edge-assisted multi-vehicle perception system for CAVs. In EMP, multiple nearby CAVs share their raw sensor data with an edge server which then merges CAVs' individual views to form a more complete view with a higher resolution. The merged view can drastically enhance the perception quality of the participating CAVs. Our core methodological contribution is to make the sensor data sharing scalable, adaptive, and resource-efficient over oftentimes highly fluctuating wireless links through a series of novel algorithms, which are then integrated into a full-fledged cooperative sensing pipeline. Extensive evaluations demonstrate that EMP can achieve real-time processing at 24 FPS and end-to-end latency of 93 ms on average. EMP reduces the end-to-end latency by 49% to 65% compared to the traditional vehicle-to-vehicle (V2V) sharing approach without edge support. Our case studies show that cooperative sensing powered by EMP can detect hazards such as blind spots faster by 0.5 to 1.1 seconds, compared to a single vehicle's perception. Xumiao Zhang, Anlan Zhang, Xiao Zhu 0001, Yihua Guo, Feng Qian 0001, Z. Morley Mao |
MobiCom | 7 |
| 2021 | Adversarially Robust 3D Point Cloud Recognition Using Self-Supervisionsabstract3D point cloud data is increasingly used in safety-critical applications such as autonomous driving. Thus, the robustness of 3D deep learning models against adversarial attacks becomes a major consideration. In this paper, we systematically study the impact of various self-supervised learning proxy tasks on different architectures and threat models for 3D point clouds with adversarial training. Specifically, we study MLP-based (PointNet), convolution-based (DGCNN), and transformer-based (PCT) 3D architectures. Through extensive experimentation, we demonstrate that appropriate applications of self-supervision can significantly enhance the robustness in 3D point cloud recognition, achieving considerable improvements compared to the standard adversarial training baseline. Our analysis reveals that local feature learning is desirable for adversarial robustness in point clouds since it limits the adversarial propagation between the point-level input perturbations and the model's final output. This insight also explains the success of DGCNN and the jigsaw proxy task in achieving stronger 3D adversarial robustness. Christopher B. Choy, Zhiding Yu, Anima Anandkumar, Z. Morley Mao, Chaowei Xiao |
NeurIPS | 6 |
| 2021 | A variegated look at 5G in the wild: performance, power, and QoE implicationsabstractMotivated by the rapid deployment of 5G, we carry out an in-depth measurement study of the performance, power consumption, and application quality-of-experience (QoE) of commercial 5G networks in the wild. We examine different 5G carriers, deployment schemes (Non-Standalone, NSA vs. Standalone, SA), radio bands (mmWave and sub 6-GHz), protocol configurations (_e.g._ Radio Resource Control state transitions), mobility patterns (stationary, walking, driving), client devices (_i.e._ User Equipment), and upper-layer applications (file download, video streaming, and web browsing). Our findings reveal key characteristics of commercial 5G in terms of throughput, latency, handover behaviors, radio state transitions, and radio power consumption under the above diverse scenarios, with detailed comparisons to 4G/LTE networks. Furthermore, our study provides key insights into how upper-layer applications should best utilize 5G by balancing the critical tradeoff between performance and energy consumption, as well as by taking into account the availability of both network and computation resources. We have released the datasets and tools of our study at https://github.com/SIGCOMM21-5G/artifact. Arvind Narayanan, Xumiao Zhang, Ruiyang Zhu, Ahmad Hassan 0004, Shuowei Jin, Xiao Zhu 0001, Denis Rybkin, Zhengxuan Yang, Z. Morley Mao, Feng Qian 0001, Zhi-Li Zhang |
SIGCOMM | 10 |
| 2021 | Automated Discovery of Denial-of-Service Vulnerabilities in Connected Vehicle Protocols
Shengtuo Hu, Qi Alfred Chen, Yiheng Feng, Z. Morley Mao, Henry X. Liu |
USENIX Security Symposium | 5 |
| 2020 | AVGuardian: Detecting and Mitigating Publish-Subscribe Overprivilege for Autonomous Vehicle SystemsabstractAutonomous vehicle (AV) software systems are emerging to enable rapidly developed self-driving functionalities. Since such systems are responsible for safety-critical decisions, it is necessary to secure them in face of cyber attacks. Through an empirical study of representative AV software systems Baidu Apollo and Autoware, we discover a common over privilege problem with the publish-subscribe communication model widely adopted by AV systems: due to the coarse-grained message design for the publish-subscribe communication, some message fields are over-granted with publish/subscribe permissions. To comply with the least-privilege principle and reduce the attack surface resulting from such problem, we argue that the publish/subscribe permissions should be defined and enforced at the granularity of message fields instead of messages. To systematically address such publish-subscribe over-privilege problems, we present AVGuardian, a system that includes (1) a static analysis tool that detects overprivilege instances in AV software and generates the corresponding access control policies at the message field granularity, and (2) a low-overhead, module-transparent, runtime pub-lish/subscribe permission policy enforcement mechanism to perform online policy violation detection and prevention. Using our detection tool, we are able to automatically detect 581 overprivilege instances in total in Baidu Apollo. To demonstrate the severity, we further constructed several concrete exploits that can lead to vehicle collision and identity theft for AV owners, which have been reported to Baidu Apollo and confirmed as valid. For defense, we prototype and evaluate the policy enforcement mechanism, and find that it has very low overhead, does not affect original AV decision logic, and also is resilient to message replay attacks. David Ke Hong, John Kloosterman, Yuqi Jin, Qi Alfred Chen, Scott A. Mahlke, Z. Morley Mao |
EuroS&P | 7 |
| 2020 | CSI: inferring mobile ABR video adaptation behavior under HTTPS and QUICabstractMobile video streaming services have widely adopted Adaptive Bitrate (ABR) streaming to dynamically adapt the streaming quality to variable network conditions. A wide range of third-party entities such as network providers and testing services need to understand such adaptation behavior for purposes such as QoE monitoring and network management. The traditional approach involved conducting test runs and analyzing the HTTP-level information from the associated network traffic to understand the adaptation behavior under different network conditions. However, end-to-end traffic encryption protocols such as HTTPS and QUIC are being increasingly used by streaming services, hindering such traditional traffic analysis approaches. Shichang Xu, Subhabrata Sen, Z. Morley Mao |
EuroSys | 3 |
| 2020 | MPBond: efficient network-level collaboration among personal mobile devicesabstractMPBond is an efficient system allowing multiple personal mobile devices to collaboratively fetch content from the Internet. For example, a smartwatch can assist its paired smartphone with downloading data. Inspired by the success of MPTCP, MPBond applies the concept of distributed multipath transport where multiple subflows can traverse different devices. We develop a cross-device connection management scheme, a buffering strategy, a packet scheduling algorithm, and a policy framework tailored to MPBond's architecture. We implement MPBond on commodity mobile devices such as Android smartphones and smartwatches. Our real-world evaluations using different workloads under various network conditions demonstrate the efficiency of MPBond. Compared to state-of-the-art collaboration frameworks, MPBond reduces file download time by 5% to 46%, and improves the video streaming bitrate by 2% to 118%. Meanwhile, it improves the energy efficiency by 10% to 57%. Xiao Zhu 0001, Xumiao Zhang, Yihua Guo, Feng Qian 0001, Z. Morley Mao |
MobiSys | 6 |
| 2020 | MPBond: efficient network-level collaboration among personal mobile devicesabstractWe demo MPBond, a novel multipath transport system allowing multiple personal mobile devices to collaboratively fetch content from the Internet. Inspired by the success of MPTCP, MPBond applies the concept of distributed multipath transport where multiple subflows can traverse different devices. Other key design aspects of MPBond include a device/connection management scheme, a buffering strategy, a packet scheduling algorithm, and a policy framework tailored to MPBond's architecture. We install MPBond on commodity mobile devices and show how easy it is to configure the usage of MPBond for unmodified apps. We visualize the runtime behavior of MPBond to further illustrate its design. We also demonstrate the download time and energy reduction of file download, as well as the video streaming QoE improvement with MPBond. Xiao Zhu 0001, Xumiao Zhang, Yihua Guo, Feng Qian 0001, Z. Morley Mao |
MobiSys | 6 |
| 2020 | What you see is what you get: measure ABR video streaming QoE via on-device screen recordingabstractAnalyzing delivered QoE for Adaptive Bitrate (ABR) streaming over cellular networks is critical for a host of entities including content providers and mobile network providers. However, existing approaches mostly rely on network traffic analysis. In addition to potential accuracy issues, they are challenged by the increasing use of end-to-end network traffic encryption. In this paper, we explore a very different approach to QoE measurement --- utilizing the screen recording capability widely available on commodity devices to record the video displayed on the mobile device screen, and analyzing the recorded video to measure the delivered QoE. We design a novel system VideoEye to conduct such screen-recording-based QoE analysis. We identify the various technical challenges involved, including distortions introduced by the screen recording process that can make such analysis difficult. We develop techniques to accurately measure video QoE from the screen recordings even in the presence of recording distortions. Our evaluations demonstrate that VideoEye accurately detects important QoE indicators including the track played at different points in time, and stall statistics. The maximal error in detected stall duration is 0.5 s. The accuracy of detecting the displayed tracks is higher than 97%. Shichang Xu, Eric Petajan, Subhabrata Sen, Z. Morley Mao |
NOSSDAV | 4 |
| 2020 | Towards Robust LiDAR-based Perception in Autonomous Driving: General Black-box Adversarial Sensor Attack and Countermeasures
Qi Alfred Chen, Z. Morley Mao |
USENIX Security Symposium | 4 |
| 2019 | Adversarial Sensor Attack on LiDAR-based Perception in Autonomous DrivingabstractIn Autonomous Vehicles (AVs), one fundamental pillar is perception,which leverages sensors like cameras and LiDARs (Light Detection and Ranging) to understand the driving environment. Due to its direct impact on road safety, multiple prior efforts have been made to study its the security of perception systems. In contrast to prior work that concentrates on camera-based perception, in this work we perform the first security study of LiDAR-based perception in AV settings, which is highly important but unexplored. We consider LiDAR spoofing attacks as the threat model and set the attack goal as spoofing obstacles close to the front of a victim AV. We find that blindly applying LiDAR spoofing is insufficient to achieve this goal due to the machine learning-based object detection process.Thus, we then explore the possibility of strategically controlling the spoofed attack to fool the machine learning model. We formulate this task as an optimization problem and design modeling methods for the input perturbation function and the objective function.We also identify the inherent limitations of directly solving the problem using optimization and design an algorithm that combines optimization and global sampling, which improves the attack success rates to around 75%. As a case study to understand the attack impact at the AV driving decision level, we construct and evaluate two attack scenarios that may damage road safety and mobility.We also discuss defense directions at the AV system, sensor, and machine learning model levels. Chaowei Xiao, Benjamin Cyr, Yimeng Zhou, Won Park, Sara Rampazzi, Qi Alfred Chen, Kevin Fu, Z. Morley Mao |
CCS | 9 |
| 2019 | Egret: simplifying traffic management for physical and virtual network functionsabstractTraffic migration is a common procedure performed by operators during planned maintenance and unexpected incidents to prevent/reduce service disruptions. However, current practices of traffic migration often couple operators' intentions (e.g. device upgrades) with network setups (e.g. load-balancers), resulting in poor re-usability and substantial operational complexities. Our study of 205 Methods of Procedure (MOPs) from a major U.S. carrier suggests that generalizing traffic migration with a unified model is feasible. Such generalization along with SDN's automation capability is key to scalable and flexible management of traffic, especially for virtualized network functions with unprecedented scale, heterogeneity, and fast iteration. In this paper, we propose Egret, a generic traffic migration system that simplifies traffic management for physical and virtual network functions. Egret (1) hides intricate implementation details from operators with generic intention-based interfaces, and (2) modularizes common traffic migration procedures to enable plug-and-play by developers and vendors. Leveraging a novel mask-based abstraction of traffic migration jobs, Egret can further simplify reverse traffic migration and enable job interleaving. Yikai Lin, Ajay Mahimkar, Bo Han 0001, Zihui Ge, Vijay Gopalakrishnan, Z. Morley Mao |
CoNEXT | 6 |
| 2019 | A Lightweight Framework for Fine-Grained Lifecycle Control of Android ApplicationsabstractThe lifecycle of Android apps is dynamically managed by the system in an ad hoc manner, which leads to apps' abusing lifecycle entry points to automatically start up and gaming the priority-based memory management mechanism to evade being killed. Such apps exhibit diehard behaviors that keep them long-running in the background, resulting in excessive battery consumption and device performance degradation. Existing battery-saving features are far from being effective in restricting diehard behaviors, due to the lack of systematic, fine-grained control of app lifecycle. Yuru Shao, Ruowen Wang, Ahmed M. Azab, Z. Morley Mao |
EuroSys | 5 |
| 2019 | MP-H2: A Client-only Multipath Solution for HTTP/2abstractMP-H2 is a client-only, HTTP-based multipath solution. It enables an HTTP client to fetch content (an HTTP object) over multiple network paths such as WiFi and cellular on smartphones. Compared to MPTCP, MP-H2 offers several key advantages including server transparency, middlebox compatibility, and friendliness to CDN, anycast, and load balancing. MP-H2 strategically splits the file into byte range requests sent over multipath, and dynamically balances the workload across all paths. Furthermore, MP-H2 leverages new features in HTTP/2 including stream multiplexing, flow control, and application-layer PING to boost the performance. MP-H2 also supports multi-homing where each path contacts a different CDN server for enhanced performance. Evaluations show that MP-H2 offers only slightly degraded performance (6% on average) while being much easier to deploy compared to MPTCP. Compared to other state-of-the-art HTTP multipath solutions, MP-H2 reduces the file download time by up to 47%, and increases the DASH video streaming bitrate by up to 44%. Ashkan Nikravesh, Yihua Guo, Xiao Zhu 0001, Feng Qian 0001, Z. Morley Mao |
MobiCom | 5 |
| 2019 | Leveraging Context-Triggered Measurements to Characterize LTE Handover Performance
Shichang Xu, Ashkan Nikravesh, Z. Morley Mao |
PAM | 3 |
| 2019 | Towards Automated Safety Vetting of PLC Code in Real-World PlantsabstractSafety violations in programmable logic controllers (PLCs), caused either by faults or attacks, have recently garnered significant attention. However, prior efforts at PLC code vetting suffer from many drawbacks. Static analyses and verification cause significant false positives and cannot reveal specific runtime contexts. Dynamic analyses and symbolic execution, on the other hand, fail due to their inability to handle real-world PLC programs that are event-driven and timing sensitive. In this paper, we propose VetPLC, a temporal context-aware, program analysis-based approach to produce timed event sequences that can be used for automatic safety vetting. To this end, we (a) perform static program analysis to create timed event causality graphs in order to understand causal relations among events in PLC code and (b) mine temporal invariants from data traces collected in Industrial Control System (ICS) testbeds to quantitatively gauge temporal dependencies that are constrained by machine operations. Our VetPLC prototype has been implemented in 15K lines of code. We evaluate it on 10 real-world scenarios from two different ICS settings. Our experiments show that VetPLC outperforms state-of-the-art techniques and can generate event sequences that can be used to automatically detect hidden safety violations. Mu Zhang 0001, Chien-Ying Chen, Bin-Chou Kao, Yassine Qamsane, Yuru Shao, Yikai Lin, Elaine Shi, Sibin Mohan, Kira Barton, James R. Moyne, Z. Morley Mao |
IEEE Symposium on Security and Privacy | 11 |
| 2018 | No One In The Middle: Enabling Network Access Control Via Transparent AttributionabstractCommodity small networks typically rely on NAT as a perimeter defense, but are susceptible to a variety of well-known intra-network attacks, such as ARP spoofing. With the increased prevalence of oft-compromised Internet-of-Things (IoT) devices now taking up residence in homes and small businesses, the potential for abuse has never been higher. In this work, we present a novel mechanism for strongly attributing local network traffic to its originating principal, fully-compatible with existing legacy devices. We eliminate Man-in-the-Middle attacks at both the link and service discovery layers, and enable users to identify and block malicious devices from direct attacks against other endpoints. Despite the prevalence of prior work with similar goals, previous solutions have either been unsuited to non-Enterprise environments or have broken compatibility with existing network devices and therefore failed to be adopted. Our prototype imposes negligible performance overhead, runs on an inexpensive commodity router, and retains full compatibility with modern and legacy devices. Jeremy Erickson, Qi Alfred Chen, Xiaochen Yu, Erinjen Lin, Robert Levy, Z. Morley Mao |
AsiaCCS | 6 |
| 2018 | SkyCore: Moving Core to the Edge for Untethered and Reliable UAV-based LTE NetworksabstractThe advances in unmanned aerial vehicle (UAV) technology have empowered mobile operators to deploy LTE base stations (BSs) on UAVs, and provide on-demand, adaptive connectivity to hotspot venues as well as emergency scenarios. However, today's evolved packet core (EPC) that orchestrates the LTE RAN faces fundamental limitations in catering to such a challenging, wireless and mobile UAV environment, particularly in the presence of multiple BSs (UAVs). In this work, we argue for and propose an alternate, radical edge EPC design, called SkyCore that pushes the EPC functionality to the extreme edge of the core network - collapses the EPC into a single, light-weight, self-contained entity that is co-located with each of the UAV BS. SkyCore incorporates elements that are designed to address the unique challenges facing such a distributed design in the UAV environment, namely the resource-constraints of UAV platforms, and the distributed management of pronounced UAV and UE mobility. We build and deploy a fully functional version of SkyCore on a two-UAV LTE network and showcase its (i) ability to interoperate with commercial LTE BSs as well as smartphones, (ii) support for both hotspot and standalone multi-UAV deployments, and (iii) superior control and data plane performance compared to other EPC variants in this environment. Mehrdad Moradi, Karthikeyan Sundaresan, Eugene Chai, Sampath Rangarajan, Z. Morley Mao |
MobiCom | 5 |
| 2018 | Exposing Congestion Attack on Emerging Connected Vehicle based Traffic Signal Control
Qi Alfred Chen, Yucheng Yin, Yiheng Feng, Z. Morley Mao, Henry X. Liu |
NDSS | 4 |
| 2018 | SoftBox: A Customizable, Low-Latency, and Scalable 5G Core Network ArchitectureabstractWe propose a novel cellular core network architecture, SoftBox, combining software-defined networking and network function virtualization to achieve greater flexibility, efficiency, and scalability compared to today's cellular core. Aligned with 5G use cases, SoftBox enables the creation of customized, low latency, and signaling-efficient services on a per user equipment (UE) basis. SoftBox consolidates network policies needed for processing each UE's data and signaling traffic into a light-weight, in-network, and per-UE agent. We design a number of mobility-aware techniques to further optimize: 1) resource usage of agents; 2) forwarding rules and updates needed for steering a UE's traffic through its agent; 3) migration costs of agents needed to ensure their proximity to mobile UEs; and 4) complexity of distributing the LTE mobility function on agents. Extensive evaluations demonstrate the scalability, performance, and flexibility of the SoftBox design. For example, basic SoftBox has 86%, 51%, and 87% lower signaling overheads, data plane delay, and CPU core usage, respectively, than two open source EPC systems. Moreover, our optimizations efficiently cut different types of data and control plane loads in the basic SoftBox by 51%-98%. Mehrdad Moradi, Yikai Lin, Z. Morley Mao, Subhabrata Sen, Oliver Spatscheck |
IEEE J. Sel. Areas Commun. | 3 |
| 2018 | Dragon: Scalable, Flexible, and Efficient Traffic Engineering in Software Defined ISP NetworksabstractTo optimize network cost, performance, and reliability, SDN advocates for centralized traffic engineering (TE) that enables more efficient path and egress point selection as well as bandwidth allocation. In this paper, we argue SDN-based TE for ISP networks can be very challenging. First, ISP networks often are very large in size, imposing significant scalability challenges to the centralized TE. Second, ISP networks usually have diverse types of links, switches, and cost models, leading to a complex combination of optimizations. Third, ISP networks not only have many choices of internal paths but also include rich selections of egress points and interdomain routes, unlike cloud/enterprise networks. To overcome these challenges, we present a novel TE application framework, called Dragon, for existing SDN control planes. To address the scalability challenge, Dragon consists of hierarchical and recursive TE algorithms and mechanisms that divide flow optimization problems into subtasks and execute them in parallel. Further, Dragon allows ISPs to express diverse objectives for different parts of their network. Finally, we extend Dragon to jointly optimize the selection of intradomain and interdomain paths. Using extensive evaluation on real topologies and prototyping with SDN controller and switches, we demonstrate that Dragon outperforms existing TE methods both in speed and optimality. Mehrdad Moradi, Ying Zhang 0022, Z. Morley Mao, Ravi Manghirmalani |
IEEE J. Sel. Areas Commun. | 3 |
| 2018 | Production as a Service: A Digital Manufacturing Framework for Optimizing UtilizationabstractIn current practice, product developers with customized small batch production needs come across the problem of finding capable and flexible manufacturers, whereas manufacturers face underutilization due to inconsistent demand. This paper presents a Production as a Service (PaaS) framework to connect users (consumers or product developers) who have customized small batch manufacturing needs with manufacturers who have existing underutilized resources. PaaS is a cloud-based, centralized framework based on a service-oriented architecture that abstracts the manufacturing steps of a product as individual (production) service requests. Using PaaS, the user is able to reach many capable manufacturers at once and receive quotations for the production request. On the other end, PaaS reduces the effort required to find new customers and enables the manufacturers to easily submit quotations to increase the utilization of their resources. The functionalities and concepts defined in this paper are illustrated through case studies. Note to Practitioners-In order to transition product fabrication from the design phase to manufacturing, there is a need for identifying capable manufacturers with available resources that could be paired with user requirements. We propose Production as a Service (PaaS) in this paper and present initial implementations of the front-end and back-end components with a customizable optimization algorithm. Proposed abstractions and data structures make PaaS a unique, efficient, and intellectual property preserving framework. The current implementation of the framework has been tested with new designs. The PaaS framework has the potential to scale over a large network of manufacturers to effectively coordinate geo-distributed manufacturers for custom manufacturing needs. Efe C. Balta, Yikai Lin, Kira Barton, Dawn M. Tilbury, Z. Morley Mao |
IEEE Trans Autom. Sci. Eng. | 5 |
| 2017 | Client-side Name Collision Vulnerability in the New gTLD Era: A Systematic StudyabstractThe recent unprecedented delegation of new generic top-level domains (gTLDs) has exacerbated an existing, but fallow, problem called name collisions. One concrete exploit of such problem was discovered recently, which targets internal namespaces and enables Man in the Middle (MitM) attacks against end-user devices from anywhere on the Internet. Analysis of the underlying problem shows that it is not specific to any single service protocol, but little attention has been paid to understand the vulnerability status and the defense solution space at the service level. In this paper, we perform the first systematic study of the robustness of internal network services under name collision attacks. Qi Alfred Chen, Matthew Thomas, Eric Osterweil, Z. Morley Mao |
CCS | 6 |
| 2017 | Open Doors for Bob and Mallory: Open Port Usage in Android Apps and Security ImplicationsabstractOpen ports are typically used by server software to serve remote clients, and the usage historically leads to remote exploitation due to insufficient protection. Smartphone operating systems inherit the open port support, but since they are significantly different from traditional server machines in performance and availability guarantees, little is known about how smartphone applications use open ports and what the security implications are. In this paper, we perform the first systematic study of open port usage on mobile platform and their security implications. To achieve this goal, we design and implement OPAnalyzer, a static analysis tool which can effectively identify and characterize vulnerable open port usage in Android applications. Using OPAnalyzer, we perform extensive usage and vulnerability analysis on a dataset with over 100K Android applications. OPAnalyzer successfully classifies 99% of the mobile usage of open ports into 5 distinct families, and from the output, we are able to identify several mobile-specific usage scenarios such as data sharing in physical proximity. In our subsequent vulnerability analysis, we find that nearly half of the usage is unprotected and can be directly exploited remotely. From the identified vulnerable usage, we discover 410 vulnerable applications with 956 potential exploits in total. We manually confirmed the vulnerabilities for 57 applications, including popular ones with 10 to 50 million downloads on the official market, and also an app that is pre-installed on some device models. These vulnerabilities can be exploited to cause highly-severe damage such as remotely stealing contacts, photos, and even security credentials, and also performing sensitive actions such as malware installation and malicious code execution. We have reported these vulnerabilities and already got acknowledged by the application developers for some of them. We also propose countermeasures and improved practices for each usage scenario. Yunhan Jia, Qi Alfred Chen, Yikai Lin, Chao Kong, Z. Morley Mao |
EuroS&P | 5 |
| 2017 | Dissecting VOD services for cellular: performance, root causes and best practicesabstractHTTP Adaptive Streaming (HAS) has emerged as the predominant technique for transmitting video over cellular for most content providers today. While mobile video streaming is extremely popular, delivering good streaming experience over cellular networks is technically very challenging, and involves complex interacting factors. We conduct a detailed measurement study of a wide cross-section of popular streaming video-on-demand (VOD) services to develop a holistic understanding of these services' design and performance. We identify performance issues and develop effective practical best practice solutions to mitigate these challenges. By extending the understanding of how different, potentially interacting components of service design impact performance, our findings can help developers build streaming services with better performance. Shichang Xu, Subhabrata Sen, Z. Morley Mao, Yunhan Jia |
Internet Measurement Conference | 3 |
| 2017 | Towards secure and safe appified automated vehiclesabstractThe advancement in Autonomous Vehicles (AVs) has created an enormous market for the development of self-driving functionalities, raising the question of how it will transform the traditional vehicle development process. One adventurous proposal is to open the AV platform to third-party developers, so that AV functionalities can be developed in a crowd-sourcing way, which could provide tangible benefits to both automakers and end users. Some pioneering companies in the automotive industry have made the move to open the platform so that developers are allowed to test their code on the road. Such openness, however, brings serious security and safety issues by allowing untrusted code to run on the vehicle. In this paper, we introduce the concept of an Appified AV platform that opens the development framework to third-party developers. To further address the safety challenges, we propose an enhanced appified AV design schema called AVGUARD, which focuses primarily on mitigating the threats brought about by untrusted code, leveraging theory in the vehicle evaluation field, and conducting program analysis techniques in the cyber security area. Our study provides guidelines and suggested practice for the future design of open AV platforms. Yunhan Jia, Ding Zhao, Qi Alfred Chen, Z. Morley Mao |
Intelligent Vehicles Symposium | 4 |
| 2017 | Accelerating Multipath Transport Through Balanced Subflow CompletionabstractSimultaneously using multiple network paths (e.g., WiFi and cellular) is an attractive feature on mobile devices. A key component in a multipath system such as MPTCP is the scheduler, which determines how to distribute the traffic over multiple paths. In this paper, we propose DEMS, a new multipath scheduler aiming at reducing the data chunk download time. DEMS consists of three key design decisions: (1) being aware of the chunk boundary and strategically decoupling the paths for chunk delivery, (2) ensuring simultaneous subflow completion at the receiver side, and (3) allowing a path to trade a small amount of redundant data for performance. We have implemented DEMS on smartphones and evaluated it over both emulated and real cellular/WiFi networks. DEMS is robust to diverse network conditions and brings significant performance boost compared to the default MPTCP scheduler (e.g., median download time reduction of 33%--48% for fetching files and median loading time reduction of 6%--43% for fetching web pages), and even more benefits compared to other state-of-the-art schedulers. Yihua Guo, Ashkan Nikravesh, Z. Morley Mao, Feng Qian 0001, Subhabrata Sen |
MobiCom | 3 |
| 2017 | Demo: DEMS: DEcoupled Multipath Scheduler for Accelerating Multipath TransportabstractWe present the demonstration of DEMS, a new multipath scheduler aiming at reducing the data chunk download time. DEMS consists of three key design decisions: (1) being aware of the chunk boundary and strategically decoupling the paths for chunk delivery, (2) ensuring simultaneous subflow completion at the receiver side, and (3) allowing a path to trade a small amount of redundant data for performance. We integrate the DEMS components into a holistic system and implement it on commodity mobile devices, where unmodified mobile applications can use DEMS to transmit data over multipath. We demonstrate the simple configuration of using DEMS over multipath, visualization of multipath scheduling, download time reduction of data chunks with DEMS over both emulated and real cellular/WiFi networks compared to default MinRTT scheduler, and application QoE improvement on mobile phones from DEMS. Yihua Guo, Ashkan Nikravesh, Z. Morley Mao, Feng Qian 0001, Subhabrata Sen |
MobiCom | 3 |
| 2017 | ContexloT: Towards Providing Contextual Integrity to Appified IoT Platforms
Yunhan Jia, Qi Alfred Chen, Shiqi Wang 0002, Amir Rahmati, Earlence Fernandes, Z. Morley Mao, Atul Prakash 0001 |
NDSS | 6 |
| 2017 | Push or Request: An Investigation of HTTP/2 Server Push for Improving Mobile PerformanceabstractIn HTTP/1.1, it is necessary for the client to request an object (e.g. an image in a page) in order for the server to send it, even if the server knows in advance what the client will need. Server Push is a feature introduced in HTTP/2 that promises to improve page load times (PLT) by having the server push content to the browser in advance. In this paper, we investigate the benefits and challenges of using Server Push on mobile devices. We first examine whether pushing all content or just the CSS and Javascript files performs better, and find the former leads to much better web performance. Also, we find that sites making use of domain sharding or which otherwise have content divided across many servers do not benefit much from Server Push, a major challenge for Server Push going forward. Network performance characteristics also play a major role. Server Push is especially effective at improving performance at high loss rates (16% median PLT reduction with a 2% loss rate) and high latencies (14% PLT reduction with 100 ms latency), and has little benefit for high-speed Ethernet connections. This motivates its use on mobile devices, although we also find the limited processing power of these devices limits the benefits of Server Push. Server Push also offers modest energy benefits, with energy savings of 9% on LTE for one device. Overall, Server Push is a promising approach for improving web performance in mobile networks, but there are a number of challenges in achieving the full benefits of Server Push. Sanae Rosen, Bo Han 0001, Shuai Hao 0002, Z. Morley Mao, Feng Qian 0001 |
WWW | 4 |
| 2016 | The Misuse of Android Unix Domain Sockets and Security ImplicationsabstractIn this work, we conduct the first systematic study in understanding the security properties of the usage of Unix domain sockets by both Android apps and system daemons as an IPC (Inter-process Communication) mechanism, especially for cross-layer communications between the Java and native layers. We propose a tool called SInspector to expose potential security vulnerabilities in using Unix domain sockets through the process of identifying socket addresses, detecting authentication checks, and performing data flow analysis. Our in-depth analysis revealed some serious vulnerabilities in popular apps and system daemons, such as root privilege escalation and arbitrary file access. Based on our findings, we propose countermeasures and improved practices for utilizing Unix domain sockets on Android. Yuru Shao, Jason Ott, Yunhan Jia, Zhiyun Qian, Z. Morley Mao |
CCS | 5 |
| 2016 | Understanding On-device Bufferbloat for Cellular Upload
Yihua Guo, Feng Qian 0001, Qi Alfred Chen, Z. Morley Mao, Subhabrata Sen |
Internet Measurement Conference | 4 |
| 2016 | An in-depth understanding of multipath TCP on mobile devices: measurement and system designabstractToday's mobile devices are usually equipped with multiple wireless network interfaces that provide new opportunities for improving application performance. In this paper, we conduct an in-depth study of multipath for mobile settings, focusing on MPTCP, with the goal of developing key insights for evolving the mobile multipath design. First, we conduct to our knowledge the most in-depth and the longest user trial of mobile multipath that focuses not only on MPTCP performance, but also on cross-layer interactions. Second, we identify a new research problem of multipath-aware CDN server selection. We demonstrate its real-world importance and provide recommendations. Third, our measurement findings lead us to design and implement a flexible software architecture for mobile multipath called MPFlex, which strategically employs multiplexing to improve multipath performance (by up to 63% for short-lived flows). MPFlex decouples the high-level scheduling algorithm and the low-level OS protocol implementation, and enables developers to flexibly plug-in new multipath features. MPFlex also provides an ideal vantage point for flexibly realizing user-specified multipath policies and is friendly to middleboxes. Ashkan Nikravesh, Yihua Guo, Feng Qian 0001, Z. Morley Mao, Subhabrata Sen |
MobiCom | 4 |
| 2016 | Kratos: Discovering Inconsistent Security Policy Enforcement in the Android Framework
Yuru Shao, Qi Alfred Chen, Z. Morley Mao, Jason Ott, Zhiyun Qian |
NDSS | 3 |
| 2016 | MitM Attack by Name Collision: Cause Analysis and Vulnerability Assessment in the New gTLD EraabstractRecently, Man in the Middle (MitM) attacks on web browsing have become easier than they have ever been before because of a problem called "Name Collision" and a protocol called the Web Proxy Auto-Discovery (WPAD) protocol. This name collision attack can cause all web traffic of an Internet user to be redirected to a MitM proxy automatically right after the launching of a standard browser. The underlying problem of this attack is internal namespace WPAD query leakage, which itself is a known problem for years. However, it remains understudied since it was not easily exploitable before the recent new gTLD (generic Top-Level Domains) delegation. In this paper, we focus on this newly-exposed MitM attack vector and perform the first systematic study of the underlying problem causes and its vulnerability status in the wild. First, we show the severity of the problem by characterizing leaked WPAD query traffic to the DNS root servers, and find that a major cause of the leakage problem is actually a result of settings on the end user devices. More specifically, we find that under common settings, devices can mistakenly generate internal queries when used outside an internal network (e.g., used at home). Second, we define and quantify a candidate measure of attack surface by defining "highly-vulnerable domains", which are domains routinely exposing a large number of potential victims, and use it to perform a systematic assessment of the vulnerability status. We find that almost all leaked queries are for new gTLD domains we define to be highly-vulnerable, indirectly validating our attack surface definition. We further find that 10% of these highly-vulnerable domains have already been registered, making the corresponding users immediately vulnerable to the exploit at any time. Our results provide a strong and urgent message to deploy proactive protection. We discuss promising directions for remediation at the new gTLD registry, Autonomous System (AS), and end user levels, and use empirical data analysis to estimate and compare their effectiveness and deployment difficulties. Qi Alfred Chen, Eric Osterweil, Matthew Thomas, Z. Morley Mao |
IEEE Symposium on Security and Privacy | 4 |
| 2015 | Caesar: High-Speed and Memory-Efficient Forwarding Engine for Future Internet ArchitectureabstractIn response to the critical challenges of the current Internet architecture and its protocols, a set of so-called clean slate designs has been proposed. Common among them is an addressing scheme that separates location and identity with self-certifying, flat and non-aggregatable address components. Each component is long, reaching a few kilobits, and would consume an amount of fast memory in data plane devices (e.g., routers) that is far beyond existing capacities. To address this challenge, we present Caesar, a high-speed and length-agnostic forwarding engine for future border routers, performing most of the lookups within three fast memory accesses. To compress forwarding states, Caesar constructs scalable and reliable Bloom filters in Ternary Content Addressable Memory (TCAM). To guarantee correctness, Caesar detects false positives at high speed and develops a blacklisting approach to handling them. In addition, we optimize our design by introducing a hashing scheme that reduces the number of hash computations from k to log(k) per lookup based on hash coding theory. We handle routing updates while keeping filters highly utilized in address removals. We perform extensive analysis and simulations using real traffic and routing traces to demonstrate the benefits of our design. Our evaluation shows that Caesar is more energy-efficient and less expensive (in terms of total cost) compared to optimized IPv6 TCAM-based solutions by up to 67% and 43% respectively. In addition, the total cost of our design is approximately the same for various address lengths. Mehrdad Moradi, Feng Qian 0001, Z. Morley Mao, Darrell Bethea, Michael K. Reiter |
ANCS | 4 |
| 2015 | Static Detection of Packet Injection Vulnerabilities: A Case for Identifying Attacker-controlled Implicit Information LeaksabstractOff-path packet injection attacks are still serious threats to the Internet and network security. In recent years, a number of studies have discovered new variations of packet injection attacks, targeting critical protocols such as TCP. We argue that such recurring problems need a systematic solution. In this paper, we design and implement PacketGuardian, a precise static taint analysis tool that comprehensively checks the packet handling logic of various network protocol implementations. The analysis operates in two steps. First, it identifies the critical paths and constraints that lead to accepting an incoming packet. If paths with weak constraints exist, a vulnerability may be revealed immediately. Otherwise, based on "secret" protocol states in the constraints, a subsequent analysis is performed to check whether such states can be leaked to an attacker. Qi Alfred Chen, Zhiyun Qian, Yunhan Jia, Yuru Shao, Z. Morley Mao |
CCS | 5 |
| 2015 | Revisiting Network Energy Efficiency of Mobile Apps: Performance in the WildabstractEnergy consumption due to network traffic on mobile devices continues to be a significant concern. We examine a range of excessive energy consumption problems caused by background network traffic through a two-year user study, and also validate these findings through in-lab testing of the most recent versions of major mobile apps. We discover a new energy consumption problem where foreground network traffic persists after switching from the foreground to the background, leading to unnecessary energy and data drain. Furthermore, while we find some apps have taken steps to improve the energy impact of periodic background traffic, energy consumption differences of up to an order of magnitude exist between apps with near-identical functionality. Finally, by examining how apps are used in the wild, we find that some apps continue to generate unneeded traffic for days when the app is not being used, and in some cases this wasted traffic is responsible for a majority of the app's network energy overhead. We propose that these persistent, widespread and varied sources of excessive energy consumption in popular apps should be addressed through new app management tools that tailor network activity to user interaction patterns. Sanae Rosen, Ashkan Nikravesh, Yihua Guo, Z. Morley Mao, Feng Qian 0001, Subhabrata Sen |
Internet Measurement Conference | 4 |
| 2015 | Automatic generation of mobile app signatures from traffic observationsabstractThere are network management, traffic engineering, and security practices adopted in today's networking that rely on the knowledge about what applications' traffic is passing through the networks. These practices might fail with mobile apps whose identity remains hidden in generic HTTP traffic. The main reason is that unlike traditional applications, most mobile apps do not use specific protocols or IP ports with distinctive features. Many enterprises and service providers are in a great need of regaining control over their networks that increasingly carry mobile traffic. In this paper we propose FLOWR, a system that automatically identifies mobile apps by continually learning the apps' distinguishing features via traffic analysis. FLOWR focuses solely on key-value pairs in HTTP headers and intelligently identifies the pairs suitable for app signatures. Our system employs a custom supervised learning approach that leverages a very limited knowledge of app-signature seeds and autonomously grows its capacity for app identification. The approach is motivated by a simple but effective hypothesis that unknown app-identifying features should co-occur with the known signatures. Our experimental results show a significant growth in flow identification coverage provided by FLOWR. Specifically, we show that FLOWR can achieve identification of 86-95% of flows related to their generating apps. Stanislav Miskovic, Z. Morley Mao, Mario Baldi, Antonio Nucci, Thomas Andrews 0001 |
INFOCOM | 4 |
| 2015 | Performance Characterization and Call Reliability Diagnosis Support for Voice over LTEabstractTo understand VoLTE performance in a commercial deployment, in this paper we conduct the first comprehensive performance characterization of commercially deployed VoLTE, and compare with legacy call and over-the-top (OTT) VoIP call. We confirm that VoLTE excels in most metrics such as audio quality, but its call reliability still lags behind legacy call for all the three major U.S. operators. We propose an on-device VoLTE problem detection tool, which can capture new types of problems concerning audio quality with high accuracy and minimum overhead, and perform stress testing on VoLTE call's reliability. We discover 3 instances of problems in the early deployment of VoLTE lying in the protocol design and implementation. Although the identified problems are all concerned with the immature LTE coverage in the current deployment, we find that they can cause serious impairment on user experience and are urgent to be solved in the developing stage. For example, one such instance can lead to up to 50-second-long muting problem during a VoLTE call! We perform in-depth cross-layer analysis and find that the causes are rooted in the lack of coordination among protocols designed for different purposes, and invalid assumptions made by protocols used in existing infrastructure when integrated with VoLTE. We summarize learnt lessons and suggest solutions. Yunhan Jia, Qi Alfred Chen, Z. Morley Mao, Jie Hui, Kranthi Sontineni, Alex Yoon, Samson Kwong, Kevin Lau |
MobiCom | 3 |
| 2015 | SAMPLES: Self Adaptive Mining of Persistent LExical Snippets for Classifying Mobile Application TrafficabstractWe present SAMPLES: Self Adaptive Mining of Persistent LExical Snippets; a systematic framework for classifying network traffic generated by mobile applications. SAMPLES constructs conjunctive rules, in an automated fashion, through a supervised methodology over a set of labeled flows (the training set). Hongyi Yao, Gyan Ranjan 0001, Alok Tongaonkar, Z. Morley Mao |
MobiCom | 5 |
| 2015 | Performance and Energy Consumption Analysis of a Delay-Tolerant Network for Censorship-Resistant CommunicationabstractDelay Tolerant Networks (DTNs) composed of commodity mobile devices have the potential to support communication applications resistant to blocking and censorship, as well as certain types of surveillance. We analyze the performance and energy consumption of such a network, and consider the impact of random and targeted denial-of-service and censorship attacks. To gather wireless connectivity traces for a DTN composed of human-carried commodity smartphones, we implemented and deployed a prototype DTN-based micro-blogging application, called 1am, in a college town. We analyzed the system during a time period with 111 users. Although the study provided detailed enough connectivity traces to enable analysis, message posting was too infrequent to draw strong conclusions based on user-initiated messages, alone. We therefore simulated more frequent message initiations and used measured connectivity traces to analyze message propagation. Using a flooding protocol, we found that with an adoption rate of 0.2% of a college town's student and faculty population, the median one-week delivery rate is 85% and the median delivery delay is 13 hours. We also found that the network delivery rate and delay are robust to denial-of service and censorship attacks eliminating more than half of the participants. Using a measurement-based energy model, we also found that the DTN system would use less than 10.0% of a typical smartphone's battery energy per day in a network of 2,500 users. David R. Bild, David Adrian, Gulshan Singh, Robert P. Dick, Dan S. Wallach, Z. Morley Mao |
MobiHoc | 7 |
| 2015 | Accelerating Mobile Applications through Flip-Flop ReplicationabstractMobile devices have less computational power and poorer Internet connections than other computers. Computation offload, in which some portions of an application are migrated to a server, has been proposed as one way to remedy this deficiency. Yet, partition-based offload is challenging because it requires applications to accurately predict whether mobile or remote computation will be faster, and it requires that the computation be large enough to overcome the cost of shipping state to and from the server. Further, offload does not currently benefit network-intensive applications. Mark S. Gordon, David Ke Hong, Peter M. Chen, Jason Flinn, Scott A. Mahlke, Z. Morley Mao |
MobiSys | 6 |
| 2015 | Mobilyzer: An Open Platform for Controllable Mobile Network MeasurementsabstractMobile Internet availability, performance and reliability have remained stubbornly opaque since the rise of cellular data access. Conducting network measurements can give us insight into user-perceived network conditions, but doing so requires careful consideration of device state and efficient use of scarce resources. Existing approaches address these concerns in ad-hoc ways. Ashkan Nikravesh, Hongyi Yao, Shichang Xu, David R. Choffnes, Z. Morley Mao |
MobiSys | 5 |
| 2015 | Demo: Mobilyzer: Mobile Network Measurement Made EasyabstractNo abstract available. Shichang Xu, Ashkan Nikravesh, Hongyi Yao, David R. Choffnes, Z. Morley Mao |
MobiSys | 5 |
| 2015 | Poster: Context-Triggered Mobile Network MeasurementabstractWhile the availability and accessibility of cellular network connectivity have improved in recent years, our ability to diagnose and debug network problems in this environment has not. One key challenge is that many of the network problems occur near the edge of the network where only mobile devices can perceive them, but network and battery resources to conduct measurements from these mobile devices are scarce. Traditional network measurement approaches that use continuous, periodic, or random measurements are either infeasible or ineffective in this environment. Shichang Xu, Ashkan Nikravesh, Hongyi Yao, David R. Choffnes, Z. Morley Mao |
MobiSys | 5 |
| 2015 | The Mason Test: A Defense Against Sybil Attacks in Wireless Networks Without Trusted AuthoritiesabstractWireless networks are vulnerable to Sybil attacks, in which a malicious node poses as many identities in order to gain disproportionate influence. Many defenses based on spatial variability of wireless channels exist, but depend either on detailed, multi-tap channel estimation-something not exposed on commodity 802.11 devices-or valid RSSI observations from multiple trusted sources, e.g., corporate access points-something not directly available in ad hoc and delay-tolerant networks with potentially malicious neighbors. We extend these techniques to be practical for wireless ad hoc networks of commodity 802.11 devices. Specifically, we propose two efficient methods for separating the valid RSSI observations of behaving nodes from those falsified by malicious participants. Further, we note that prior signalprint methods are easily defeated by mobile attackers and develop an appropriate challenge-response defense. Finally, we present the Mason test, the first implementation of these techniques for ad hoc and delay-tolerant networks of commodity 802.11 devices. We illustrate its performance in several real-world scenarios. David R. Bild, Robert P. Dick, Z. Morley Mao, Dan S. Wallach |
IEEE Trans. Mob. Comput. | 4 |
| 2015 | Aggregate Characterization of User Behavior in Twitter and Analysis of the Retweet GraphabstractMost previous analysis of Twitter user behavior has focused on individual information cascades and the social followers graph, in which the nodes for two users are connected if one follows the other. We instead study aggregate user behavior and the retweet graph with a focus on quantitative descriptions. We find that the lifetime tweet distribution is a type-II discrete Weibull stemming from a power law hazard function, that the tweet rate distribution, although asymptotically power law, exhibits a lognormal cutoff over finite sample intervals, and that the inter-tweet interval distribution is a power law with exponential cutoff. The retweet graph is small-world and scale-free, like the social graph, but less disassortative and has much stronger clustering. These differences are consistent with it better capturing the real-world social relationships of and trust between users than the social graph. Beyond just understanding and modeling human communication patterns and social networks, applications for alternative, decentralized microblogging systems---both predicting real-word performance and detecting spam---are discussed. David R. Bild, Robert P. Dick, Z. Morley Mao, Dan S. Wallach |
ACM Trans. Internet Techn. | 4 |
| 2014 | SoftMoW: Recursive and Reconfigurable Cellular WAN ArchitectureabstractThe current LTE network architecture is organized into very large regions, each having a core network and a radio access network. The core network contains an Internet edge comprised of packet data network gateways (PGWs). The radio network consists of only base stations. There are minimal interactions among regions other than interference management at the edge. The current architecture has several problems. First, mobile application performance is seriously impacted by the lack of Internet egress points per region. Second, the continued exponential growth of mobile traffic puts tremendous pressure on the scalability of PGWs. Third, the fast growth of signaling traffic known as the signaling storm problem poses a major challenge to the scalability of the control plane. To address these problems, we present SoftMoW, a recursive and reconfigurable cellular WAN architecture that supports seamlessly inter-connected core networks, reconfigurable control plane, and global optimization. Mehrdad Moradi, Wenfei Wu, Li Erran Li, Z. Morley Mao |
CoNEXT | 4 |
| 2014 | QoE Doctor: Diagnosing Mobile App QoE with Automated UI Control and Cross-layer AnalysisabstractSmartphones have become increasingly prevalent and important in our daily lives. To meet users' expectations about the Quality of Experience (QoE) of mobile applications (apps), it is essential to obtain a comprehensive understanding of app QoE and identify the critical factors that affect it. However, effectively and systematically studying the QoE of popular mobile apps such as Facebook and YouTube still remains a challenging task, largely due to a lack of a controlled and reproducible measurement methodology, and limited insight into the complex multi-layer dynamics of the system and network stacks. Qi Alfred Chen, Haokun Luo, Sanae Rosen, Z. Morley Mao, Karthik Iyer, Jie Hui, Kranthi Sontineni, Kevin Lau |
Internet Measurement Conference | 4 |
| 2014 | Discovering fine-grained RRC state dynamics and performance impacts in cellular networksabstractTo conserve power while ensuring good performance on resource-constrained mobile devices, devices transition between different Radio Resource Control (RRC) states in response to network traffic and according to parameters specific to network operators. As RRC states significantly affect application power consumption and performance, it is important to understand how RRC state timers interact with network traffic patterns. In this paper, we show that the impact of RRC states on performance is significantly more complex and diverse than found in previous work. To do so, we introduce an open-source tool that allows the impact of RRC states on network and application performance to be measured in a robust and accurate manner on unmodified user devices, and deploy the tool in 23 countries around the world to test a broad range of cellular network technologies. We detect previously unknown performance problems which increase network latencies by up to several seconds and for LTE, can increase packet losses by an order of magnitude. Through an in-depth cross-layer analysis of several carriers, we examine the lower-layer causes of these problems. We determine that the highly complex state transitions of certain carriers, and in particular poor interactions between state demotions and network traffic, can lead to substantial, unexpected latencies. Sanae Rosen, Haokun Luo, Qi Alfred Chen, Z. Morley Mao, Jie Hui, Aaron Drake, Kevin Lau |
MobiCom | 4 |
| 2014 | Demo: Mapping global mobile performance trends with mobilyzer and mobiPerfabstractMobilyzer is an open-source network measurement library that coordinates network measurement tasks among different applications, facilitates measurement task design, and allows for more effective measurement task management than in existing standalone approaches. Unifying various network tasks into one framework greatly simplifies the problem of developing, deploying and managing measurement tasks which may otherwise interfere with one another. An intelligent scheduler, coordinated by a central server, dynamically schedules tasks to run in the background, preserving the user's battery life and respecting limits set by the user on task frequency and data consumption. We will demo MobiPerf, an open-source mobile network measurement tool built using the Mobilyzer library. MobiPerf collects a wide range of network performance data, ranging from the latency and throughput measurements common in existing client-based measurement frameworks, to HTTP loading times for specific URLs, to inferring RRC state configuration parameters and their impact on performance. We will also demo an interface for viewing a large, open dataset of performance data from around the world collected by MobiPerf. Sanae Rosen, Hongyi Yao, Ashkan Nikravesh, Yunhan Jia, David R. Choffnes, Z. Morley Mao |
MobiSys | 6 |
| 2014 | RadioProphet: Intelligent Radio Resource Deallocation for Cellular Networks
Junxian Huang 0001, Feng Qian 0001, Z. Morley Mao, Subhabrata Sen, Oliver Spatscheck |
PAM | 3 |
| 2014 | Mobile Network Performance from User Devices: A Longitudinal, Multidimensional Analysis
Ashkan Nikravesh, David R. Choffnes, Ethan Katz-Bassett, Z. Morley Mao, Matt Welsh |
PAM | 4 |
| 2014 | Diagnosing Path Inflation of Mobile Client Traffic
Kyriakos Zarifis, Tobias Flach, Srikanth Nori, David R. Choffnes, Ramesh Govindan, Ethan Katz-Bassett, Z. Morley Mao, Matt Welsh |
PAM | 7 |
| 2014 | FLOWR: a self-learning system for classifying mobileapplication trafficabstractNo abstract available. Thomas Andrews 0001, Stanislav Miskovic, Z. Morley Mao, Mario Baldi, Antonio Nucci |
SIGMETRICS | 5 |
| 2014 | Peeking into Your App without Actually Seeing It: UI State Inference and Novel Android Attacks
Qi Alfred Chen, Zhiyun Qian, Z. Morley Mao |
USENIX Security Symposium | 3 |
| 2013 | SocialWatch: detection of online service abuse via large-scale social graphsabstractIn this paper, we present a framework, SocialWatch, to detect attacker-created accounts and hijacked accounts for online services at a large scale. SocialWatch explores a set of social graph properties that effectively model the overall social activity and connectivity patterns of online users, including degree, PageRank, and social affinity features. These features are hard to mimic and robust to attacker counter strategies. We evaluate SocialWatch using a large, real dataset with more than 682 million users and over 5.75 billion directional relationships. SocialWatch successfully detects 56.85 million attacker-created accounts with a low false detection rate of 0.75% and a low false negative rate of 0.61%. In addition, SocialWatch detects 1.95 million hijacked accounts---among which 1.23 million were not detected previously---with a low false detection rate of 2%. Our work demonstrates the practicality and effectiveness of using large social graphs with billions of edges to detect real attacks. Junxian Huang 0001, Yinglian Xie, Fang Yu 0002, Qifa Ke, Martín Abadi, Eliot Gillum, Z. Morley Mao |
AsiaCCS | 7 |
| 2013 | AppProfiler: a flexible method of exposing privacy-related behavior in android applications to end usersabstractAlthough Android's permission system is intended to allow users to make informed decisions about their privacy, it is often ineffective at conveying meaningful, useful information on how a user's privacy might be impacted by using an application. We present an alternate approach to providing users the knowledge needed to make informed decisions about the applications they install. First, we create a knowledge base of mappings between API calls and fine-grained privacy-related behaviors. We then use this knowledge base to produce, through static analysis, high-level behavior profiles of application behavior. We have analyzed almost 80,000 applications to date and have made the resulting behavior profiles available both through an Android application and online. Nearly 1500 users have used this application to date. Based on 2782 pieces of application-specific feedback, we analyze users' opinions about how applications affect their privacy and demonstrate that these profiles have had a substantial impact on their understanding of those applications. We also show the benefit of these profiles in understanding large-scale trends in how applications behave and the implications for user privacy. Sanae Rosen, Zhiyun Qian, Z. Morley Mao |
CODASPY | 3 |
| 2013 | PROTEUS: network performance forecast for real-time, interactive mobile applicationsabstractReal-time communication (RTC) applications such as VoIP, video conferencing, and online gaming are flourishing. To adapt and deliver good performance, these applications require accurate estimations of short-term network performance metrics, e.g., loss rate, one-way delay, and throughput. However, the wide variation in mobile cellular network performance makes running RTC applications on these networks problematic. To address this issue, various performance adaptation techniques have been proposed, but one common problem of such techniques is that they only adjust application behavior reactively after performance degradation is visible. Thus, proactive adaptation based on accurate short-term, fine-grained network performance prediction can be a preferred alternative that benefits RTC applications. In this study, we show that forecasting the short-term performance in cellular networks is possible in part due to the channel estimation scheme on the device and the radio resource scheduling algorithm at the base station. We develop a system interface called PROTEUS, which passively collects current network performance, such as throughput, loss, and one-way delay, and then uses regression trees to forecast future network performance. PROTEUS successfully predicts the occurrence of packet loss within a 0.5s time window for 98% of the time windows and the occurrence of long one-way delay for 97% of the time windows. We also demonstrate how PROTEUS can be integrated with RTC applications to significantly improve the perceptual quality. In particular, we increase the peak signal-to-noise ratio of a video conferencing application by up to 15dB and reduce the perceptual delay in a gaming application by up to 4s. Sanjeev Mehrotra, Z. Morley Mao, Jin Li 0001 |
MobiSys | 3 |
| 2013 | How to Reduce Smartphone Traffic Volume by 30%?
Feng Qian 0001, Junxian Huang 0001, Jeffrey Erman, Z. Morley Mao, Subhabrata Sen, Oliver Spatscheck |
PAM | 4 |
| 2013 | An in-depth study of LTE: effect of network protocol and application behavior on performanceabstractWith lower latency and higher bandwidth than its predecessor 3G networks, the latest cellular technology 4G LTE has been attracting many new users. However, the interactions among applications, network transport protocol, and the radio layer still remain unexplored. In this work, we conduct an in-depth study of these interactions and their impact on performance, using a combination of active and passive measurements. We observed that LTE has significantly shorter state promotion delays and lower RTTs than those of 3G networks. We discovered various inefficiencies in TCP over LTE such as undesired slow start. We further developed a novel and lightweight passive bandwidth estimation technique for LTE networks. Using this tool, we discovered that many TCP connections significantly under-utilize the available bandwidth. On average, the actually used bandwidth is less than 50% of the available bandwidth. This causes data downloads to be longer, and incur additional energy overhead. We found that the under-utilization can be caused by both application behavior and TCP parameter setting. We found that 52.6% of all downlink TCP flows have been throttled by limited TCP receive window, and that data transfer patterns for some popular applications are both energy and network unfriendly. All these findings highlight the need to develop transport protocol mechanisms and applications that are more LTE-friendly. Junxian Huang 0001, Feng Qian 0001, Yihua Guo, Z. Morley Mao, Subhabrata Sen, Oliver Spatscheck |
SIGCOMM | 6 |
| 2012 | Collaborative TCP sequence number inference attack: how to crack sequence number under a secondabstractIn this study, we discover a new class of unknown side channels --- "sequence-number-dependent" host packet counters --- that exist in Linux/Android and BSD/Mac OS to enable TCP sequence number inference attacks. It allows a piece of unprivileged on-device malware to collaborate with an off-path attacker to infer the TCP sequence numbers used between a client and a server, leading to TCP injection and hijacking attacks. We show that the inference takes, in common cases, under a second to complete and is quick enough for attackers to inject malicious Javascripts into live Facebook sessions and to perform malicious actions on behalf of a victim user. Since supporting unprivileged access to global packet counters is an intentional design choice, we believe our findings provide important lessons and offer insights on future system and network design. Zhiyun Qian, Z. Morley Mao, Yinglian Xie |
CCS | 2 |
| 2012 | Innocent by association: early recognition of legitimate usersabstractThis paper presents the design and implementation of Souche, a system that recognizes legitimate users early in online services. This early recognition contributes to both usability and security. Souche leverages social connections established over time. Legitimate users help identify other legitimate users through an implicit vouching process, strategically controlled within vouching trees. Souche is lightweight and fully transparent to users. In our evaluation on a real dataset of several hundred million users, Souche can efficiently identify 85% of legitimate users early, while reducing the percentage of falsely admitted malicious users from 44% to 2.4%. Our evaluation further indicates that Souche is robust in the presence of compromised accounts. It is generally applicable to enhance usability and security for a wide class of online services. Yinglian Xie, Fang Yu 0002, Qifa Ke, Martín Abadi, Eliot Gillum, Krish Vitaldevaria, Jason Walter, Junxian Huang 0001, Z. Morley Mao |
CCS | 9 |
| 2012 | Screen-off traffic characterization and optimization in 3G/4G networksabstractToday's cellular systems operate under diverse resource constraints: limited frequency spectrum, network processing capability, and handset battery life. We consider a novel and important factor, handset screen status, i.e., whether the screen is on or off, which was ignored by previous approaches for optimizing cellular resource utilization. Based on analyzing real smartphone traffic collected from 20 users over five months, we find that off-screen traffic accounts for 58.5% of the total radio energy consumption although their traffic volume contribution is much smaller. Such unexpected results are attributed to the unique cellular resource management policy that is not well understood by developers, leading to cellular-unfriendly mobile apps. We then make a further step by proposing screen-aware optimization, by leveraging the key observation that screen-off traffic is much more delay-tolerant than its screen-on counterpart due to a lack of user interaction. Our proposal can better balance the key tradeoffs in cellular networks. It saves up to 60.92% of the network energy and reduces signaling and delay overhead by 25.33% and 30.59%, respectively. Junxian Huang 0001, Feng Qian 0001, Z. Morley Mao, Subhabrata Sen, Oliver Spatscheck |
Internet Measurement Conference | 3 |
| 2012 | A close examination of performance and power characteristics of 4G LTE networksabstractWith the recent advent of 4G LTE networks, there has been increasing interest to better understand the performance and power characteristics, compared with 3G/WiFi networks. In this paper, we take one of the first steps in this direction. Junxian Huang 0001, Feng Qian 0001, Alexandre Gerber, Z. Morley Mao, Subhabrata Sen, Oliver Spatscheck |
MobiSys | 4 |
| 2012 | Web caching on smartphones: ideal vs. realityabstractWeb caching in mobile networks is critical due to the unprecedented cellular traffic growth that far exceeds the deployment of cellular infrastructures. Caching on handsets is particularly important as it eliminates all network-related overheads. We perform the first network-wide study of the redundant transfers caused by inefficient web caching on handsets, using a dataset collected from 3 million smartphone users of a large commercial cellular carrier, as well as another five-month-long trace contributed by 20 smartphone users. Our findings suggest that redundant transfers contribute 18% and 20% of the total HTTP traffic volume in the two datasets. Also they are responsible for 17% of the bytes, 7% of the radio energy consumption, 6% of the signaling load, and 9% of the radio resource utilization of all cellular data traffic in the second dataset. Most of such redundant transfers are caused by the smartphone web caching implementation that does not fully support or strictly follow the protocol specification, or by developers not fully utilizing the caching support provided by the libraries. This is further confirmed by our caching tests of 10 popular HTTP libraries and mobile browsers. Improving the cache implementation will bring considerable reduction of network traffic volume, cellular resource consumption, handset energy consumption, and user-perceived latency, benefiting both cellular carriers and customers. Feng Qian 0001, Kee Shen Quah, Junxian Huang 0001, Jeffrey Erman, Alexandre Gerber, Z. Morley Mao, Subhabrata Sen, Oliver Spatscheck |
MobiSys | 6 |
| 2012 | You Can Run, but You Can't Hide: Exposing Network Location for Targeted DoS Attacks in Cellular Networks
Zhiyun Qian, Zhaoguang Wang, Z. Morley Mao, Ming Zhang 0005, Yi-Min Wang |
NDSS | 4 |
| 2012 | COMET: Code Offload by Migrating Execution Transparently
Mark S. Gordon, Davoud Anoushe Jamshidi, Scott A. Mahlke, Z. Morley Mao, Xu Chen 0028 |
OSDI | 4 |
| 2012 | Off-path TCP Sequence Number Inference Attack - How Firewall Middleboxes Reduce SecurityabstractIn this paper, we report a newly discovered "off-path TCP sequence number inference" attack enabled by firewall middle boxes. It allows an off-path (i.e., not man-in-the-middle) attacker to hijack a TCP connection and inject malicious content, effectively granting the attacker write-only permission on the connection. For instance, with the help of unprivileged malware, we demonstrate that a successful attack can hijack an HTTP session and return a phishing Face book login page issued by a browser. With the same mechanisms, it is also possible to inject malicious Javascript to post tweets or follow other people on behalf of the victim. The TCP sequence number inference attack is mainly enabled by the sequence-number-checking firewall middle boxes. Through carefully-designed and well-timed probing, the TCP sequence number state kept on the firewall middle box can be leaked to an off-path attacker. We found such firewall middle boxes to be very popular in cellular networks - at least 31.5% of the 149 measured networks deploy such firewalls. Finally, since the sequence-number-checking feature is enabled by design, it is unclear how to mitigate the problem easily. Zhiyun Qian, Z. Morley Mao |
IEEE Symposium on Security and Privacy | 2 |
| 2012 | Periodic transfers in mobile applications: network-wide origin, impact, and optimizationabstractCellular networks employ a specific radio resource management policy distinguishing them from wired and Wi-Fi networks. A lack of awareness of this important mechanism potentially leads to resource-inefficient mobile applications. We perform the first network-wide, large-scale investigation of a particular type of application traffic pattern called periodic transfers where a handset periodically exchanges some data with a remote server every t seconds. Using packet traces containing 1.5 billion packets collected from a commercial cellular carrier, we found that periodic transfers are very prevalent in today's smartphone traffic. However, they are extremely resource-inefficient for both the network and end-user devices even though they predominantly generate very little traffic. This somewhat counter-intuitive behavior is a direct consequence of the adverse interaction between such periodic transfer patterns and the cellular network radio resource management policy. For example, for popular smartphone applications such as Facebook, periodic transfers account for only 1.7% of the overall traffic volume but contribute to 30% of the total handset radio energy consumption. We found periodic transfers are generated for various reasons such as keep-alive, polling, and user behavior measurements. We further investigate the potential of various traffic shaping and resource control algorithms. Depending on their traffic patterns, applications exhibit disparate responses to optimization strategies. Jointly using several strategies with moderate aggressiveness can eliminate almost all energy impact of periodic transfers for popular applications such as Facebook and Pandora. Feng Qian 0001, Zhaoguang Wang, Yudong Gao, Junxian Huang 0001, Alexandre Gerber, Z. Morley Mao, Subhabrata Sen, Oliver Spatscheck |
WWW | 6 |
| 2011 | Identifying diverse usage behaviors of smartphone appsabstractSmartphone users are increasingly shifting to using apps as "gateways" to Internet services rather than traditional web browsers. App marketplaces for iOS, Android, and Windows Phone platforms have made it attractive for developers to deploy apps and easy for users to discover and start using many network-enabled apps quickly. For example, it was recently reported that the iOS AppStore has more than 350K apps and more than 10 billion downloads. Furthermore, the appearance of tablets and mobile devices with other form factors, which also use these marketplaces, has increased the diversity in apps and their user population. Despite the increasing importance of apps as gateways to network services, we have a much sparser understanding of how, where, and when they are used compared to traditional web services, particularly at scale. This paper takes a first step in addressing this knowledge gap by presenting results on app usage at a national level using anonymized network measurements from a tier-1 cellular carrier in the U.S. We identify traffic from distinct marketplace apps based on HTTP signatures and present aggregate results on their spatial and temporal prevalence, locality, and correlation. Jeffrey Erman, Alexandre Gerber, Z. Morley Mao, Jeffrey Pang, Shobha Venkataraman |
Internet Measurement Conference | 4 |
| 2011 | Contrail: Enabling Decentralized Social Networks on Smartphones
Patrick Stuedi, Iqbal Mohomed, Mahesh Balakrishnan 0001, Z. Morley Mao, Venugopalan Ramasubramanian, Douglas B. Terry, Ted Wobber |
Middleware | 4 |
| 2011 | Profiling resource usage for mobile applications: a cross-layer approachabstractDespite the popularity of mobile applications, their performance and energy bottlenecks remain hidden due to a lack of visibility into the resource-constrained mobile execution environment with potentially complex interaction with the application behavior. We design and implement ARO, the mobile Application Resource Optimizer, the first tool that efficiently and accurately exposes the cross-layer interaction among various layers including radio resource channel state, transport layer, application layer, and the user interaction layer to enable the discovery of inefficient resource usage for smartphone applications. To realize this, ARO provides three key novel analyses: (i) accurate inference of lower-layer radio resource control states, (ii) quantification of the resource impact of application traffic patterns, and (iii) detection of energy and radio resource bottlenecks by jointly analyzing cross-layer information. We have implemented ARO and demonstrated its benefit on several essential categories of popular Android applications to detect radio resource and energy inefficiencies, such as unacceptably high (46%) energy overhead of periodic audience measurements and inefficient content prefetching behavior. Feng Qian 0001, Zhaoguang Wang, Alexandre Gerber, Z. Morley Mao, Subhabrata Sen, Oliver Spatscheck |
MobiSys | 4 |
| 2011 | Demo: mobile application resource optimizer (ARO)abstractNo abstract available. Feng Qian 0001, Zhaoguang Wang, Alexandre Gerber, Z. Morley Mao, Subhabrata Sen, Oliver Spatscheck |
MobiSys | 4 |
| 2011 | AccuLoc: practical localization of performance measurements in 3G networksabstractOperators of 3G data networks need to distinguish the performance of each geographic area in their 3G networks to detect and resolve local network problems. This is because the quality of the last mile radio link between 3G base stations and end-user devices is a crucial factor in the end-to-end performance that each user experiences. It is relatively straightforward to measure the performance of all IP traffic in the 3G network from a small number of vantage points in the core network. However, the location information available about each mobile device (e.g., the cell sector/site that it is in) is often too stale to be accurate because of user mobility. Moreover, very costly infrastructure deployment and maintenance of custom equipment would be required to collect fine-grained location information about all mobile devices on an on-going basis in large 3G networks. Thus, it is a challenge to accurately assign IP performance measurements to fine-grained geographic regions of the 3G network using existing standard network components. Fortunately, previous studies have observed that human mobility patterns are very predictable. In this paper, we exploit this predictability to develop a novel clustering algorithm grouping related cell sectors that accurately assigns IP performance measurements to fine-grained geographic regions. We present results from a prototype in a real 3G network that shows our approach provides more accurate performance localization than existing approaches. Eventually, we can either narrow down individual IP performance measurements into only 4 candidate cell sectors consistently with the accuracy of 70% over one week based on a one-day snapshot of fine-grained 3GPP events, or increase the accuracy 20% comparing with site-level accuracy through lightweight handover statistics hourly collected at RNCs. Using our approach, we improve anomaly detection based on IP performance measurements by reducing the number of false positives and false negatives. Our study also sheds light on the mobility patterns of 3G devices. Alexandre Gerber, Z. Morley Mao, Jeffrey Pang |
MobiSys | 3 |
| 2011 | Internet Censorship in China: Where Does the Filtering Occur?
Xueyang Xu, Z. Morley Mao, J. Alex Halderman |
PAM | 2 |
| 2011 | Designing Scalable and Effective Decision Support for Mitigating Attacks in Large Enterprise Networks
Zhiyun Qian, Z. Morley Mao, Ammar Rayes, David Jaffe |
SecureComm | 2 |
| 2011 | An untold story of middleboxes in cellular networksabstractThe use of cellular data networks is increasingly popular as network coverage becomes more ubiquitous and many diverse user-contributed mobile applications become available. The growing cellular traffic demand means that cellular network carriers are facing greater challenges to provide users with good network performance and energy efficiency, while protecting networks from potential attacks. To better utilize their limited network resources while securing the network and protecting client devices the carriers have already deployed various network policies that influence traffic behavior. Today, these policies are mostly opaque, though they directly impact application designs and may even introduce network vulnerabilities. Zhaoguang Wang, Zhiyun Qian, Z. Morley Mao, Ming Zhang 0005 |
SIGCOMM | 4 |
| 2011 | Cellular data network infrastructure characterization and implication on mobile content placementabstractDespite the tremendous growth in the cellular data network usage due to the popularity of smartphones, so far there is rather limited understanding of the network infrastructure of various cellular carriers. Understanding the infrastructure characteristics such as the network topology, routing design, address allocation, and DNS service configuration is essential for predicting, diagnosing, and improving cellular network services, as well as for delivering content to the growing population of mobile wireless users. In this work, we propose a novel approach for discovering cellular infrastructure by intelligently combining several data sources, i.e., server logs from a popular location search application, active measurements results collected from smartphone users, DNS request logs from a DNS authoritative server, and publicly available routing updates. We perform the first comprehensive analysis to characterize the cellular data network infrastructure of four major cellular carriers within the U.S. in our study. Junxian Huang 0001, Zhaoguang Wang, Feng Qian 0001, Alexandre Gerber, Z. Morley Mao |
SIGMETRICS | 6 |
| 2010 | Declarative configuration management for complex and dynamic networksabstractNetwork management and operations are complicated, tedious, and error-prone, requiring signifcant human involvement and domain knowledge. As the complexity involved inevitably grows due to larger scale networks and more complex protocol features, human operators are increasingly short-handed, despite the best effort from existing support systems to make it otherwise. This paper presents coolaid, a system under which the domain knowledge of device vendors and service providers is formally captured by a declarative language. Through effcient and powerful rule-based reasoning on top of a database-like abstraction over a network of devices, coolaid enables new management primitives to perform network-wide reasoning, prevent misconfguration, and automate network confguration, while requiring minimum operator effort. We describe the design and prototype implementation of coolaid, and demonstrate its effectiveness and scalability through various realistic network management tasks. Xu Chen 0028, Yun Mao, Z. Morley Mao, Jacobus E. van der Merwe |
CoNEXT | 3 |
| 2010 | Performance and power modeling in a multi-programmed multi-core environmentabstractThis paper describes a fast, automated technique for accurate on-line estimation of the performance and power consumption of interacting processes in a multi-programmed, multi-core environment. The proposed technique does not require modifying hardware or applications. The performance model uses reuse distance histograms, cache access frequencies, and the relationship between the throughput and cache miss rate of each process to predict throughput. The system-level power model is derived using multi-variable linear regression, accounting for cache contention. Both models are validated on multiple real multi-core systems using SPEC CPU2000 benchmarks; their performance and power estimates are within 3.5% of measured values on average. We explain how to integrate the two models for power estimation during process assignment, helpful for power-aware assignment. Xi Chen 0068, Robert P. Dick, Z. Morley Mao |
DAC | 4 |
| 2010 | Location, location, location!: modeling data proximity in the cloudabstractCloud applications have increasingly come to rely on distributed storage systems that hide the complexity of handling network and node failures behind simple, data-centric interfaces (such as PUTs and GETs on key-value pairs). While these interfaces are very easy to use, the application is completely oblivious to the location of its data in the network; as a result, it has no way to optimize the placement of data or computation. In this paper, we propose exposing the network location of data to applications. The primary challenge is that data does not usually exist at a single point in the network; it can be striped, replicated, cached and coded across different locations, in arbitrary ways that vary across storage systems. For example, an item that is synchronously mirrored in both Seattle and London will appear equally far from both locations for writes, but equally close to both locations for reads. Accordingly, we describe Contour, a system that allows applications to query and manipulate the location of data without requiring them to be aware of the physical machines storing the data, the replication protocols used or the underlying network topology. Birjodh Singh Tiwana, Mahesh Balakrishnan 0001, Marcos K. Aguilera, Hitesh Ballani, Z. Morley Mao |
HotNets | 5 |
| 2010 | TOP: Tail Optimization Protocol For Cellular Radio Resource AllocationabstractIn 3G cellular networks, the release of radio resources is controlled by inactivity timers. However, the timeout value itself, also known as the tail time, can last up to 15 seconds due to the necessity of trading off resource utilization efficiency for low management overhead and good stability, thus wasting considerable amount of radio resources and battery energy at user handsets. In this paper, we propose Tail Optimization Protocol (TOP), which enables cooperation between the phone and the radio access network to eliminate the tail whenever possible. Intuitively, applications can often accurately predict a long idle time. Therefore the phone can notify the cellular network on such an imminent tail, allowing the latter to immediately release radio resources. To realize TOP, we utilize a recent proposal of 3GPP specification called fast dormancy, a mechanism for a handset to notify the cellular network for immediate radio resource release. TOP thus requires no change to the cellular infrastructure and only minimal changes to smartphone applications. Our experimental results based on real traces show that with a reasonable prediction accuracy, TOP saves the overall radio energy (up to 17%) and radio resources (up to 14%) by reducing tail times by up to 60%. For applications such as multimedia streaming, TOP can achieve even more significant savings of radio energy (up to 60%) and radio resources (up to 50%). Feng Qian 0001, Zhaoguang Wang, Alexandre Gerber, Z. Morley Mao, Subhabrata Sen, Oliver Spatscheck |
ICNP | 4 |
| 2010 | Characterizing radio resource allocation for 3G networksabstract3G cellular data networks have recently witnessed explosive growth. In this work, we focus on UMTS, one of the most popular 3G mobile communication technologies. Our work is the first to accurately infer, for any UMTS network, the state machine (both transitions and timer values) that guides the radio resource allocation policy through a light-weight probing scheme. We systematically characterize the impact of operational state machine settings by analyzing traces collected from a commercial UMTS network, and pinpoint the inefficiencies caused by the interplay between smartphone applications and the state machine behavior. Besides basic characterizations, we explore the optimal state machine settings in terms of several critical timer values evaluated using real network traces. Our findings suggest that the fundamental limitation of the current state machine design is its static nature of treating all traffic according to the same inactivity timers, making it difficult to balance tradeoffs among radio resource usage efficiency, network management overhead, device radio energy consumption, and performance. To the best of our knowledge, our work is the first empirical study that employs real cellular traces to investigate the optimality of UMTS state machine configurations. Our analysis also demonstrates that traffic patterns impose significant impact on radio resource and energy consumption. In particular, We propose a simple improvement that reduces YouTube streaming energy by 80% by leveraging an existing feature called fast dormancy supported by the 3GPP specifications. Feng Qian 0001, Zhaoguang Wang, Alexandre Gerber, Z. Morley Mao, Subhabrata Sen, Oliver Spatscheck |
Internet Measurement Conference | 4 |
| 2010 | Cache contention and application performance prediction for multi-core systemsabstractThe ongoing move to chip multiprocessors (CMPs) permits greater sharing of last-level cache by processor cores but this sharing aggravates the cache contention problem, potentially undermining performance improvements. Accurately modeling the impact of inter-process cache contention on performance and power consumption is required for optimized process assignment. However, techniques based on exhaustive consideration of process-to-processor mappings and cycle-accurate simulation are inefficient or intractable for CMPs, which often permit a large number of potential assignments. This paper proposes CAMP, a fast and accurate shared cache aware performance model for multi-core processors. CAMP estimates the performance degradation due to cache contention of processes running on CMPs. It uses reuse distance histograms, cache access frequencies, and the relationship between the throughput and cache miss rate of each process to predict its effective cache size when running concurrently and sharing cache with other processes, allowing instruction throughput estimation.We also provide an automated way to obtain process-dependent characteristics, such as reuse distance histograms, without offline simulation, operating system (OS) modification, or additional hardware. We tested the accuracy of CAMP using 55 different combinations of 10 SPEC CPU2000 benchmarks on a dual-core CMP machine. The average throughput prediction error was 1.57%. Xi Chen 0068, Robert P. Dick, Z. Morley Mao |
ISPASS | 4 |
| 2010 | Anatomizing application performance differences on smartphonesabstractThe use of cellular data networks is increasingly popular due to the widespread deployment of 3G technologies and the rapid adoption of smartphones, such as iPhone and GPhone. Besides email and web browsing, a variety of network applications are now available, rendering smartphones potentially useful substitutes for their desktop counterparts. Nevertheless, the performance of smartphone applications in the wild is still poorly understood due to a lack of systematic measurement methodology. Junxian Huang 0001, Birjodh Singh Tiwana, Z. Morley Mao, Ming Zhang 0005, Paramvir Bahl |
MobiSys | 4 |
| 2010 | On the Safety of Enterprise Policy Deployment
Yudong Gao, Ni Pan, Xu Chen 0028, Z. Morley Mao |
NDSS | 4 |
| 2010 | On Network-level Clusters for Spam Detection
Zhiyun Qian, Z. Morley Mao, Yinglian Xie, Fang Yu 0002 |
NDSS | 2 |
| 2010 | A case for unsupervised-learning-based spam filteringabstractNo abstract available. Feng Qian 0001, Abhinav Pathak, Y. Charlie Hu, Z. Morley Mao, Yinglian Xie |
SIGMETRICS | 4 |
| 2010 | Investigation of Triangular Spamming: A Stealthy and Efficient Spamming TechniqueabstractSpam is increasingly accepted as a problem associated with compromised hosts or email accounts. This problem not only makes the tracking of spam sources difficult but also enables a massive amount of illegitimate or unwanted emails to be disseminated quickly. Various attempts have been made to analyze, backtrack, detect, and prevent spam using both network as well as content characteristics. However, relatively less attention has been given to understanding how spammers actually carry out their spamming activities from a network angle. Spammers' network behavior has significant impact on spammers' common goal, sending spam in a stealthy and efficient manner. Our work thoroughly investigates a fairly unknown spamming technique we name as triangular spamming that exploits routing irregularities of spoofed IP packets. It is highly stealthy and efficient in that triangular spamming enables 1) exploiting bandwidth diversity of botnet hosts to carry out spam campaigns effectively without divulging precious high-bandwidth hosts and 2) bypassing the current SMTP traffic blocking policies. Despite its relative obscurity, its use has been confirmed by the network operator community. Through carefully devised probing techniques and actual deployment of triangular spamming on Planetlab (a wide-area distributed testbed), we investigate the feasibility, impact of triangular spamming and propose practical detection and prevention methods. From our probing experiments, we found that 97% of the networks which block outbound SMTP traffic are vulnerable to triangular spamming and only 44% of them are listed on Spamhaus Policy Blocking List (PBL). Zhiyun Qian, Z. Morley Mao, Yinglian Xie, Fang Yu 0002 |
IEEE Symposium on Security and Privacy | 2 |
| 2010 | iSPY: Detecting IP Prefix Hijacking on My OwnabstractIP prefix hijacking remains a major threat to the security of the Internet routing system due to a lack of authoritative prefix ownership information. Despite many efforts in designing IP prefix hijack detection schemes, no existing design can satisfy all the critical requirements of a truly effective system: real-time, accurate, lightweight, easily and incrementally deployable, as well as robust in victim notification. In this paper, we present a novel approach that fulfills all these goals by monitoring network reachability from key external transit networks to one's own network through lightweight prefix-owner-based active probing. Using the prefix-owner's view of reachability, our detection system, iSPY, can differentiate between IP prefix hijacking and network failures based on the observation that hijacking is likely to result in topologically more diverse polluted networks and unreachability. Through detailed simulations of Internet routing, 25-day deployment in 88 autonomous systems (ASs) (108 prefixes), and experiments with hijacking events of our own prefix from multiple locations, we demonstrate that iSPY is accurate with false negative ratio below 0.45% and false positive ratio below 0.17%. Furthermore, iSPY is truly real-time; it can detect hijacking events within a few minutes. Zheng Zhang 0009, Ying Zhang 0022, Y. Charlie Hu, Z. Morley Mao, Randy Bush |
IEEE/ACM Trans. Netw. | 4 |
| 2009 | PACMAN: a platform for automated and controlled network operations and configuration managementabstractThe lack of automation associated with network operations in general and network configuration management in particular, is widely recognized as a significant contributing factor to user-impacting network events. In this paper we present our work on the PACMAN system, a Platform for Automated and Controlled network operations and configuration MANagement. PACMAN realizes network operations by executing active documents, which systematically capture the dynamics in network management tasks. Active documents not only enable the complete execution of low-level configuration management tasks, but also allow the construction of more sophisticated tasks, while imposing additional reasoning logic to realize network-wide management objectives. We present the design, realization and evaluation of the PACMAN framework and illustrate its utility by presenting the implementation of several sophisticated operational tasks. Xu Chen 0028, Z. Morley Mao, Jacobus E. van der Merwe |
CoNEXT | 2 |
| 2009 | HC-BGP: A light-weight and flexible scheme for securing prefix ownershipabstractThe border gateway protocol (BGP) is a fundamental building block of the Internet infrastructure. However, due to the implicit trust assumption among networks, Internet routing remains quite vulnerable to various types of misconfiguration and attacks. Prefix hijacking is one such misbehavior where an attacker AS injects false routes to the Internet routing system that misleads victim's traffic to the attacker AS. Previous secure routing proposals, e.g., S-BGP, have relied on the global public key infrastructure (PKI), which creates deployment burdens. In this paper, we propose an efficient cryptographic mechanism, HC-BGP, using hash chains and regular public/private key pairs to ensure prefix ownership certificates. HC-BGP is computationally more efficient than previously proposed secure routing schemes, and it is also more flexible for supporting various traffic engineering goals. Our scheme can efficiently prevent common prefix hijacking attacks which announce routes with false origins, including both prefix and sub-prefix hijacking attacks. Ying Zhang 0022, Zheng Zhang 0009, Z. Morley Mao, Y. Charlie Hu |
DSN | 3 |
| 2009 | TCP revisited: a fresh look at TCP in the wildabstractSince the last in-depth studies of measured TCP traffic some 6-8 years ago, the Internet has experienced significant changes, including the rapid deployment of backbone links with 1-2 orders of magnitude more capacity, the emergence of bandwidth-intensive streaming applications, and the massive penetration of new TCP variants. These and other changes beg the question whether the characteristics of measured TCP traffic in today's Internet reflect these changes or have largely remained the same. To answer this question, we collected and analyzed packet traces from a number of Internet backbone and access links, focused on the "heavy-hitter" flows responsible for the majority of traffic. Next we analyzed their within-flow packet dynamics, and observed the following features: (1) in one of our datasets, up to 15.8% of flows have an initial congestion window (ICW) size larger than the upper bound specified by RFC 3390. (2) Among flows that encounter retransmission rates of more than 10%, 5% of them exhibit irregular retransmission behavior where the sender does not slow down its sending rate during retransmissions. (3) TCP flow clocking (i.e., regular spacing between flights of packets) can be caused by both RTT and non-RTT factors such as application or link layer, and 60% of flows studied show no pronounced flow clocking. To arrive at these findings, we developed novel techniques for analyzing unidirectional TCP flows, including a technique for inferring ICW size, a method for detecting irregular retransmissions, and a new approach for accurately extracting flow clocks. Feng Qian 0001, Alexandre Gerber, Z. Morley Mao, Subhabrata Sen, Oliver Spatscheck, Walter Willinger |
Internet Measurement Conference | 3 |
| 2009 | Detecting traffic differentiation in backbone ISPs with NetPoliceabstractTraffic differentiations are known to be found at the edge of the Internet in broadband ISPs and wireless carriers [13, 2]. The ability to detect traffic differentiations is essential for customers to develop effective strategies for improving their application performance. We build a system, called NetPolice, that enables detection of content- and routing-based differentiations in backbone ISPs. NetPolice is easy to deploy since it only relies on loss measurement launched from end hosts. The key challenges in building NetPolice include selecting an appropriate set of probing destinations and ensuring the robustness of detection results to measurement noise. Ying Zhang 0022, Z. Morley Mao, Ming Zhang 0005 |
Internet Measurement Conference | 2 |
| 2009 | Ensemble: Community-Based Anomaly Detection for Popular Applications
Feng Qian 0001, Zhiyun Qian, Z. Morley Mao, Atul Prakash 0001 |
SecureComm | 3 |
| 2009 | ShadowNet: A Platform for Rapid and Safe Network Evolution
Xu Chen 0028, Z. Morley Mao, Jacobus E. van der Merwe |
USENIX ATC | 2 |
| 2008 | Towards an understanding of anti-virtualization and anti-debugging behavior in modern malwareabstractMany threats that plague today’s networks (e.g., phishing, botnets, denial of service attacks) are enabled by a complex ecosystem of attack programs commonly called malware. To combat these threats, defenders of these networks have turned to the collection, analysis, and reverse engineering of malware as mechanisms to understand these programs, generate signatures, and facilitate cleanup of infected hosts. Recently however, new malware instances have emerged with the capability to check and often thwart these defensive activities — essentially leaving defenders blind to their activities. To combat this emerging threat, we have undertaken a robust analysis of current malware and developed a detailed taxonomy of malware defender fingerprinting methods. We demonstrate the utility of this taxonomy by using it to characterize the prevalence of these avoidance methods, to generate a novel fingerprinting method that can assist malware propagation, and to create an effective new technique to protect production systems. Xu Chen 0028, Jonathon Andersen, Z. Morley Mao, Michael D. Bailey, Jose Nazario |
DSN | 3 |
| 2008 | Ascertaining the Reality of Network Neutrality Violation in Backbone ISPs
Ying Zhang 0022, Z. Morley Mao, Ming Zhang 0005 |
HotNets | 2 |
| 2008 | Wide-Area IP Network MobilityabstractIP network mobility is emerging as a major paradigm for providing continuous Internet access while a set of users are on the move in a transportation system. The intense interest on its support has led to the establishment of the NEMO IETF working group and a test-deployment by a major airline equipment vendor - Boeing - on major airline routes. However, the previously proposed solutions are either inefficient or may cause instability to the global Internet. We propose WINMO, a simple, systematic, novel solution for wide-area IP network mobility using techniques including route aggregation, scoped update propagation, and packet mobility states. Our solution provides efficient routing when users travel both across autonomous systems (ASes) and within a single AS, generates minimal global routing overhead to prevent global instability, ensures good location privacy, and helps to defend against denial-of-service attacks. Furthermore, our basic scheme (without packet mobility state) is transparent to both clients and servers. Our extensive evaluations demonstrate the effectiveness of our mobility solution. Li Erran Li, Z. Morley Mao, Yang Richard Yang |
INFOCOM | 3 |
| 2008 | Effective Diagnosis of Routing Disruptions from End Systems
Ying Zhang 0022, Z. Morley Mao, Ming Zhang 0005 |
NSDI | 2 |
| 2008 | Automating Network Application Dependency Discovery: Experiences, Limitations, and New Solutions
Xu Chen 0028, Ming Zhang 0005, Z. Morley Mao, Paramvir Bahl |
OSDI | 3 |
| 2008 | A Measurement Study of Internet Delay Asymmetry
Abhinav Pathak, Himabindu Pucha, Ying Zhang 0022, Y. Charlie Hu, Z. Morley Mao |
PAM | 5 |
| 2008 | Ispy: detecting ip prefix hijacking on my ownabstractIP prefix hijacking remains a major threat to the security of the Internet routing system due to a lack of authoritative prefix ownership information. Despite many efforts in designing IP prefix hijack detection schemes, no existing design can satisfy all the critical requirements of a truly effective system: real-time, accurate, light-weight, easily and incrementally deployable, as well as robust in victim notification. In this paper, we present a novel approach that fulfills all these goals by monitoring network reachability from key external transit networks to one's own network through lightweight prefix-owner-based active probing. Using the prefix-owner's view of reachability, our detection system, iSPY, can differentiate between IP prefix hijacking and network failures based on the observation that hijacking is likely to result in topologically more diverse polluted networks and unreachability. Through detailed simulations of Internet routing, 25-day deployment in 88 ASes (108 prefixes), and experiments with hijacking events of our own prefix from multiple locations, we demonstrate that iSPY is accurate with false negative ratio below 0.45% and false positive ratio below 0.17%. Furthermore, iSPY is truly real-time; it can detect hijacking events within a few minutes. Zheng Zhang 0009, Ying Zhang 0022, Y. Charlie Hu, Z. Morley Mao, Randy Bush |
SIGCOMM | 4 |
| 2007 | Internet routing resilience to failures: analysis and implicationsabstractInternet interdomain routing is policy-driven, and thus physical connectivity does not imply reachability. On average, routing on today's Internet works quite well, ensuring reachability for most networks and achieving reasonable performance across most paths. However, there is a serious lack of understanding of Internet routing resilience to significant but realistic failures such as those caused by the 911 event, the 2003 Northeast blackout, and the recent Taiwan earthquake in December 2006. In this paper, we systematically analyze how the current Internet routing system reacts to various types of failures by developing a realistic failure model, and then pinpoint reliability bottlenecks of the Internet. For validity of our simulation results, we generate topology graphs by addressing concerns over the incompleteness of topology and the inaccuracy of inferred AS relationships. By focusing on the impact of structural and policy properties, our analysis provides guidelines for future Internet design. The simulation tool we provide for analyzing routing resilience is also efficient to scale to Internet-size topologies. Jian Wu 0028, Ying Zhang 0022, Z. Morley Mao, Kang G. Shin |
CoNEXT | 3 |
| 2007 | Practical defenses against BGP prefix hijackingabstractPrefix hijacking, a misbehavior in which a misconfigured or malicious BGP router originates an IP prefix that the router does not own, is becoming an increasingly serious security problem on the Internet. In this paper, we conduct a first comprehensive study on incrementally deployable mitigation solutions against prefix hijacking. We first propose a novel reactive detection-assisted solution based on the idea of bogus route purging and valid route promotion. Our simulations based on realistic settings show that purging bogus routes at 20 highest-degree ASes reduces the polluted portion of the Internet by a random prefix hijack from 50% down to 24%, and adding promotion further reduces the remaining pollution by 33% ~ 57%, We prove that our proposed route purging and promotion scheme preserve the convergence properties of BGP regardless of the number of promoters. We are the first to demonstrate that detection systems based on a limited number of BGP feeds are subject to detection evasion by hijackers. Motivated the need for proactive defenses to complement reactive mitigation response, we evaluate customer route filtering, a best common practice among large ISPs today, and show its limited effectiveness. We also show the added benefits of combining route purging-promotion with customer route filtering. Zheng Zhang 0009, Ying Zhang 0022, Y. Charlie Hu, Z. Morley Mao |
CoNEXT | 4 |
| 2007 | Characterizing Dark DNS Behavior
Jon Oberheide, Manish Karir, Z. Morley Mao |
DIMVA | 3 |
| 2007 | A Firewall for Routers: Protecting against Routing MisbehaviorabstractIn this work, we present the novel idea of route normalization by correcting on the fly routing traffic on behalf of a local router to protect the local network from malicious and misconfigured routing updates. Analogous to traffic normalization for network intrusion detection systems, the proposed RouteNormalizer patches ambiguities and eliminates semantically incorrect routing updates to protect against routing protocol attacks. Furthermore, it serves the purpose of a router firewall by identifying resource-based attacks against routers. Upon detecting anomalous routing changes, it suggests local routing policy modifications to improve route selection decisions. Deploying a RouteNormalizer requires no modification to routers if desired using a transparent TCP proxy setup. In this paper, we present the detailed design of the RouteNormalizer and evaluate it using a prototype implementation based on empirical BGP routing updates. We validate its effectiveness by showing that many well-known routing problems from operator mailing lists are correctly identified. Ying Zhang 0022, Z. Morley Mao, Jia Wang 0001 |
DSN | 2 |
| 2007 | On the impact of route monitor selectionabstractSeveral route monitoring systems have been set up to help understand the Internet routing system. They operate by gathering real-time BGP updates from different networks. Many studies have relied on such data sources by assuming reasonably good coverage and thus representative visibility into the Internet routing system. However, different deployment strategies of route monitors directly impact the accuracy and generality of conclusions. Ying Zhang 0022, Zheng Zhang 0009, Z. Morley Mao, Y. Charlie Hu, Bruce M. Maggs |
Internet Measurement Conference | 3 |
| 2007 | A Framework for Measuring and Predicting the Impact of Routing ChangesabstractRouting dynamics heavily influence Internet data plane performance. Existing studies only narrowly focused on a few destinations and did not consider the predictability of the impact of routing changes on performance metrics such as reachability. In this work, we propose an efficient framework to capture coarse-grained but important performance degradation as a result of BGP routing events using light-weight probing. We deployed our framework across six vantage points for 11 weeks and found that the data plane experienced serious performance degradation in the form of reachability loss and forwarding loops following a significant fraction of updates affecting many destination prefixes and networks across all vantage points studied. Specifically, more than 39% of updates resulted in reachability loss, some lasting for more than 300 seconds, impacting more than 72% of probed prefixes and more than 35% of all the prefixes on the Internet. We identified that more than half of the prefixes have predictable routing behavior. Based on the stationarity of the correlation between routing changes and the data plane performance, we developed a model to accurately predict the severity of the impact due to routing changes. Such a model is directly helpful for making informed decisions for improved routing schemes such as overlay routing and backup path selection. Ying Zhang 0022, Z. Morley Mao, Jia Wang 0001 |
INFOCOM | 2 |
| 2007 | MIDAS: An Impact Scale for DDoS attacksabstractWe usually have well-defined classification scales to estimate the intensity and impact of natural disasters. Prominent examples are the Richter and the Fujita scales for measuring earthquakes and tornadoes respectively. In this paper, we apply similar ideas to estimate the impact of distributed denial of service (DDoS) attacks from the perspective of network operators. Devising such a classification scale improves our understanding of DDoS attacks by assessing the actual damage incurred from an ISP's perspective, and allows comparison of various mitigation strategies. We have designed MIDAS, a DDoS impact scale, based on the economic impact of a DDoS attack, calculated using economic and network data. We then present an approximation of the MIDAS scale that relies only on network measurements for ease of computation. To demonstrate the usefulness of the scale, we perform sensitivity analysis to qualitatively validate the magnitude of the scale value for diverse attacks. Rangarajan Vasudevan, Z. Morley Mao, Oliver Spatscheck, Jacobus E. van der Merwe |
LANMAN | 2 |
| 2007 | Low-Rate TCP-Targeted DoS Attack Disrupts Internet Routing
Ying Zhang 0022, Z. Morley Mao, Jia Wang 0001 |
NDSS | 2 |
| 2007 | Automated Classification and Analysis of Internet Malware
Michael D. Bailey, Jon Oberheide, Jon Andersen, Z. Morley Mao, Farnam Jahanian, Jose Nazario |
RAID | 4 |
| 2007 | Understanding network delay changes caused by routing eventsabstractNetwork delays and delay variations are two of the most important network performance metrics directly impacting real-time applications such as voice over IP and time-critical financial transactions. This importance is illustrated by past work on understanding the delay constancy of Internet paths and recent work on predicting network delays using virtual coordinate systems. Merely understanding currently observed delays is insufficient, as network performance can degrade not only due to traffic variability but also as a result of routing changes. Unfortunately this latter effect so far has been ignored in understanding and predicting delay related performance metrics of Internet paths. Our work is the first to address this short coming by systematically analyzing changes in network delays and jitter of a diverse and comprehensive set of Internet paths. Using empirical measurements, we illustrate that routing changes can result in roundtrip delay increase of converged paths by more than 1 second. Surprisingly, intradomain routing changes can also cause such large delay increase. Himabindu Pucha, Ying Zhang 0022, Z. Morley Mao, Y. Charlie Hu |
SIGMETRICS | 3 |
| 2007 | Accurate Real-time Identification of IP Prefix HijackingabstractWe present novel and practical techniques to accurately detect IP prefix hijacking attacks in real time to facilitate mitigation. Attacks may hijack victim's address space to disrupt network services or perpetrate malicious activities such as spamming and DoS attacks without disclosing identity. We propose novel ways to significantly improve the detection accuracy by combining analysis of passively collected BGP routing updates with data plane fingerprints of suspicious prefixes. The key insight is to use data plane information in the form of edge network fingerprinting to disambiguate suspect IP hijacking incidences based on routing anomaly detection. Conflicts in data plane fingerprints provide much more definitive evidence of successful IP prefix hijacking. Utilizing multiple real-time BGP feeds, we demonstrate the ability of our system to distinguish between legitimate routing changes and actual attacks. Strong correlation with addresses that originate spam emails from a spam honeypot confirms the accuracy of our techniques. Z. Morley Mao |
S&P | 2 |
| 2006 | Hotspots: The Root Causes of Non-Uniformity in Self-Propagating MalwareabstractSelf-propagating malware like worms and bots can dramatically impact the availability and reliability of the Internet. Techniques for the detection and mitigation of Internet threats using content prevalence and scan detectors are based on assumptions of how threats propagate. Some of these assumptions have recently been called into question by observations of huge discrepancies in the quantity of specific threats detected at different points around the Internet. We call these deviations from uniform propagation "hotspots". This paper quantifies and explains these influences on malware propagation. We then propose that hotspots can be explained by two fundamental influences on propagation: algorithmic factors and environmental factors. We use measurement data from sensors deployed at 11 locations around the Internet to demonstrate the impact of these factors on worm and bot propagation. With this understanding, we simulate the outbreak of new threats with hotspots and show how algorithmic and environmental factors reduce the visibility of distributed detectors resulting in the inability to identify new threats. Evan Cooke, Z. Morley Mao, Farnam Jahanian |
DSN | 2 |
| 2006 | Differentiated BGP Update Processing for Improved Routing ConvergenceabstractInternet routers today can be overwhelmed by a large number of BGP updates triggered by events such as session resets, link failures, and policy changes. Such excessive updates can delay routing convergence, which, in turn, degrades the performance of delay- and jitter-sensitive applications. This paper proposes a simple and novel idea of differentiated processing of BGP updates to reduce routers' load and improve routing convergence without changing the protocol semantics. Based on a set of criteria, BGP updates are grouped into different priority classes. Higher-priority updates are processed and propagated sooner, while lower-priority ones, not affecting routing decisions, can be delayed to both reduce routers' load and improve routing convergence. We first present a general methodology for update classification, update processing, and priority-state inference. By analyzing real BGP data obtained from Route Views, we show that our update classification is feasible and beneficial. We further propose two differentiated update processing (DUP) algorithms and evaluate them using the SSFNet BGP simulator on several realistic network topologies. The algorithms are shown to be very effective for large networks, yielding 30% fewer updates and reducing convergence time by 80%. Our scheme is simple and light-weight with little added processing overhead. It can be deployed incrementally, since BGP messages are not modified and every BGP router makes routing decisions independently. Z. Morley Mao, Kang G. Shin |
ICNP | 2 |
| 2006 | On the impact of research network based testbeds on wide-area experimentsabstractAn important stage of wide-area systems and networking research is to prototype a system to understand its performance when deployed in the real Internet. A key requirement of prototyping is that results obtained from the prototype experiments be representative of the behavior if the system were deployed over nodes connected to commercial ISPs. Recently, distributed testbeds such as PlanetLab and RON have become increasingly popular for performing wide-area experimentation. However, such testbeds typically consist of a significant fraction of nodes with connectivity to research and education networks which potentially hinder their usability in prototyping systems.In this paper, we investigate the impact of testbeds with connectivity to research and education networks on the applications and network services so that such testbeds can be leveraged for evaluation and prototyping. Specifically, we investigate when the representativeness of wide-area experiments deployed on such testbeds is affected by studying the routing paths that applications use over such testbeds. We then investigate how the representativeness of wide-area experiments is affected by studying the performance properties of such paths. We further measure the impact of using such testbeds on application performance via application case studies. Finally, we propose a technique that uses the currently available testbeds but reduces their bias by exposing applications evaluated to network conditions more reflective of the conditions in the commercial Internet. Himabindu Pucha, Y. Charlie Hu, Z. Morley Mao |
Internet Measurement Conference | 3 |
| 2006 | A measurement study on the impact of routing events on end-to-end internet path performanceabstractExtensive measurement studies have shown that end-to-end Internet path performance degradation is correlated with routing dynamics. However, the root cause of the correlation between routing dynamics and such performance degradation is poorly understood. In particular, how do routing changes result in degraded end-to-end path performance in the first place? How do factors such as topological properties, routing policies, and iBGP configurations affect the extent to which such routing events can cause performance degradation? Answers to these questions are critical for improving network performance.In this paper, we conduct extensive measurement that involves both controlled routing updates through two tier-1 ISPs and active probes of a diverse set of end-to-end paths on the Internet. We find that routing changes contribute to end-to-end packet loss significantly. Specifically, we study failover events in which a link failure leads to a routing change and recovery events in which a link repair causes a routing change. In both cases, it is possible to experience data plane performance degradation in terms of increased long loss burst as well as forwarding loops. Furthermore, we find that common routing policies and iBGP configurations of ISPs can directly affect the end-to-end path performance during routing changes. Our work provides new insights into potential measures that network operators can undertake to enhance network performance. Feng Wang 0017, Z. Morley Mao, Jia Wang 0001, Lixin Gao 0001, Randy Bush |
SIGCOMM | 2 |
| 2006 | Reval: A Tool for Real-time Evaluation of DDoS Mitigation Strategies
Rangarajan Vasudevan, Z. Morley Mao, Oliver Spatscheck, Jacobus E. van der Merwe |
USENIX ATC, General Track | 2 |
| 2005 | An Empirical Approach to Modeling Inter-AS Traffic Matrices
Hyunseok Chang, Sugih Jamin, Z. Morley Mao, Walter Willinger |
Internet Measurement Conference | 3 |
| 2005 | A measurement study of Internet bottlenecksabstractRecent advances in Internet measurement tools have made it possible to locate bottleneck links that constrain the available bandwidth of Internet paths. In this paper, we provide a detailed study of Internet path bottlenecks. We focus on the following four aspects: the persistence of bottleneck location, the sharing of bottlenecks among destination clusters, the packet loss and queueing delay of bottleneck links, and the relationship with router and link properties, including router CPU load, router memory load, link traffic load, and link capacity. We find that 20% - 30% of the source-destination pairs in our measurement have a persistent bottleneck; fewer than 10% of the destinations in a prefix cluster share a bottleneck more than half of the time; 60% of the bottlenecks on lossy paths can be correlated with a loss point no more than 2 hops away; and bottlenecks can be clearly correlated with link load, while presenting no strong relationship with link capacity, router CPU and memory load. Ningning Hu, Li Erran Li, Z. Morley Mao, Peter Steenkiste, Jia Wang 0001 |
INFOCOM | 3 |
| 2005 | Enriching Intrusion Alerts Through Multi-Host Causality
Samuel T. King, Z. Morley Mao, Dominic G. Lucchetti, Peter M. Chen |
NDSS | 2 |
| 2005 | Finding a Needle in a Haystack: Pinpointing Significant BGP Routing Changes in an IP Network
Jian Wu 0028, Z. Morley Mao, Jennifer Rexford, Jia Wang 0001 |
NSDI | 2 |
| 2005 | HLP: a next generation inter-domain routing protocolabstractIt is well-known that BGP, the current inter-domain routing protocol, has many deficiencies. This paper describes a hybrid link-state and path-vector protocol called HLP as an alternative to BGP that has vastly better scalability, isolation and convergence properties. Using current BGP routing information, we show that HLP, in comparison to BGP, can reduce the churn-rate of route updates by a factor 400 as well as isolate the effect of routing events to a region 100 times smaller than that of BGP. For a majority of Internet routes, HLP guarantees worst-case linear-time convergence. We also describe a prototype implementation of HLP on top of the XORP router platform. HLP is not intended to be a finished and final proposal for a replacement for BGP, but is instead offered as a starting point for debates about the nature of the next-generation inter-domain routing protocol. Lakshminarayanan Subramanian, Matthew Caesar 0001, Cheng Tien Ee, Mark Handley, Z. Morley Mao, Scott Shenker, Ion Stoica |
SIGCOMM | 5 |
| 2005 | On AS-level path inferenceabstractThe ability to discover the AS-level path between two end-points is valuable for network diagnosis, performance optimization, and reliability enhancement. Virtually all existing techniques and tools for path discovery require direct access to the source. However, the uncooperative nature of the Internet makes it difficult to get direct access to any remote end-point. Path inference becomes challenging when we have no access to the source or the destination. Moveover even when we have access to the source and know the forward path, it is nontrivial to infer the reverse path, since the Internet routing is often asymmetric.In this paper, we explore the feasibility of AS-level path inference without direct access to either end-points. We describe RouteScope-a tool for inferring AS-level paths by finding the shortest policy paths in an AS graph obtained from BGP tables collected from multiple vantage points. We identify two main factors that affect the path inference accuracy: the accuracy of AS relationship inference and the ability to determine the first AS hop. To address the issues, we propose two novel techniques: a new AS relation-ship inference algorithm, and a novel scheme to infer the first AS hop by exploiting the TTL information in IP packets. We evaluate the effectiveness of RouteScope using both BGP tables and the AS paths collected from public BGP gateways. Our results show that it achieves 70% - 88% accuracy in path inference. Z. Morley Mao, Lili Qiu, Jia Wang 0001, Yin Zhang 0001 |
SIGMETRICS | 1 |
| 2004 | BorderGuard: detecting cold potatoes from peersabstractInternet Service Providers often establish contractual "peering" agreements, where they agree to forward traffic to each other's customers at no cost. Consistent route advertisement at all peering points is a common provision in these agreements, because it gives an AS the flexibility to select egress points for the traffic (e.g., performing "hot potato" routing). Verifying "consistent export" is challenging because route advertisements are exchanged at multiple peering points and may be modified by routing policies. In this paper, we propose two algorithms to detect inconsistent routes using routing and configuration data from an AS's border routers. The first algorithm requires access to all eBGP routes advertised by a peer. Because this data is often unavailable, we propose another algorithm that detects inconsistencies using readily available data. We have applied our algorithms to the routes advertised by the peers of AT&T's commercial IP backbone. Although a peer may intentionally send inconsistent advertisements to prevent its neighbor from performing hot-potato routing, we also discuss several configuration scenarios where a peer may inadvertently advertise inconsistent routes, despite having consistent export policies. Finally, we explain how simple modifications to the routers could make detection of inconsistent advertisements much easier than it is today. Nick Feamster, Z. Morley Mao, Jennifer Rexford |
Internet Measurement Conference | 2 |
| 2004 | Scalable and Accurate Identification of AS-level Forwarding PathsabstractTraceroute is used heavily by network operators and researchers to identify the IP forwarding path from a source to a destination. In practice, knowing the autonomous system (AS) associated with each hop in the path is also quite valuable. In previous work we showed that the IP-to-AS mapping extracted from BGP routing tables is not sufficient for determining the AS-level forwarding paths. By comparing BGP and traceroute AS paths from multiple vantage points, Z. Morley Mao et al. (2003) proposed heuristics that identify the root causes of the mismatches and fix the inaccurate IP-to-AS mappings. These heuristics, though effective, are labor-intensive and mostly ad hoc. This paper proposes a systematic way to construct accurate IP-to-AS mappings using dynamic programming and iterative improvement. Our algorithm reduces the initial mismatch ratio of 15% between BGP and traceroute AS paths to 5% while changing only 2.9% of the assignments in the initial IP-to-AS mappings. This is in contrast to the results of Z. Morley Mao et al. (2003), where 10% of the assignments were modified and the mismatch ratio was only reduced to 9%. We show that our algorithm is robust and can yield near-optimal results even when the initial mapping is corrupted or when the number of probing sources or destinations is reduced. Our work is a key step towards building a scalable and accurate AS-level traceroute tool Z. Morley Mao, David Johnson 0004, Jennifer Rexford, Jia Wang 0001, Randy H. Katz |
INFOCOM | 1 |
| 2004 | Locating internet routing instabilitiesabstractThis paper presents a methodology for identifying the autonomous system (or systems) responsible when a routing change is observed and propagated by BGP. The origin of such a routing instability is deduced by examining and correlating BGP updates for many prefixes gathered at many observation points. Although interpreting BGP updates can be perplexing, we find that we can pinpoint the origin to either a single AS or a session between two ASes in most cases. We verify our methodology in two phases. First, we perform simulations on an AS topology derived from actual BGP updates using routing policies that are compatible with inferred peering/customer/provider relationships. In these simulations, in which network and router behavior are "ideal", we inject inter-AS link failures and demonstrate that our methodology can effectively identify most origins of instability. We then develop several heuristics to cope with the limitations of the actual BGP update propagation process and monitoring infrastructure, and apply our methodology and evaluation techniques to actual BGP updates gathered at hundreds of observation points. This approach of relying on data from BGP simulations as well as from measurements enables us to evaluate the inference quality achieved by our approach under ideal situations and how it is correlated with the actual quality and the number of observation points. Anja Feldmann, Olaf Maennel, Z. Morley Mao, Arthur W. Berger, Bruce M. Maggs |
SIGCOMM | 3 |
| 2004 | Locating internet bottlenecks: algorithms, measurements, and implicationsabstractThe ability to locate network bottlenecks along end-to-end paths on the Internet is of great interest to both network operators and researchers. For example, knowing where bottleneck links are, network operators can apply traffic engineering either at the interdomain or intradomain level to improve routing. Existing tools either fail to identify the location of bottlenecks, or generate a large amount of probing packets. In addition, they often require access to both end points. In this paper we present Pathneck, a tool that allows end users to efficiently and accurately locate the bottleneck link on an Internet path. Pathneck is based on a novel probing technique called Recursive Packet Train (RPT) and does not require access to the destination. We evaluate Pathneck using wide area Internet experiments and trace-driven emulation. In addition, we present the results of an extensive study on bottlenecks in the Internet using carefully selected, geographically diverse probing sources and destinations. We found that Pathneck can successfully detect bottlenecks for almost 80% of the Internet paths we probed. We also report our success in using the bottleneck location and bandwidth bounds provided by Pathneck to infer bottlenecks and to avoid bottlenecks in multihoming and overlay routing. Ningning Hu, Li Erran Li, Z. Morley Mao, Peter Steenkiste, Jia Wang 0001 |
SIGCOMM | 3 |
| 2004 | Combining routing and traffic data for detection of IP forwarding anomaliesabstractIP forwarding anomalies, triggered by equipment failures, implementation bugs, or configuration errors, can significantly disrupt and degrade network service. Robust and reliable detection of such anomalies is essential to rapid problem diagnosis, problem mitigation, and repair. We propose a simple, robust method that integrates routing and traffic data streams to reliably detect forwarding anomalies. The overall method is scalable, automated and self-training. We find this technique effectively identifies forwarding anomalies, while avoiding the high false alarms rate that would otherwise result if either stream were used unilaterally. Matthew Roughan, Timothy G. Griffin, Z. Morley Mao, Albert G. Greenberg, Brian Freeman |
SIGMETRICS | 3 |
| 2003 | BGP beaconsabstractThe desire to better understand global BGP dynamics has motivated several studies using active measurement techniques, which inject announcements and withdrawals of prefixes from the global routing domain. From these one can measure quantities such as the BGP convergence time. Previously, the route injection infrastructure of such experiments has either been temporary in nature, or its use has been restricted to the experimenters. The routing research community would benefit from a permanent and public infrastructure for such active probes. We use the term BGP Beacon to refer to a publicly documented prefix having global visibility and a published schedule for announcements and withdrawals. A BGP Beacon is to be used for the ongoing study of BGP dynamics, and so should be supportedwith a long-term commitment. We describe several BGP Beacons thathave been set up at various points in the Internet. We then describe techniques for processing BGP updates when a BGP Beacon is observed from a BGP monitoring point such as Oregon's Route Views. Finally, we illustrate the use of BGP Beacons in the analysis of convergence delays, route flap damping, and update inter-arrival times. Z. Morley Mao, Randy Bush, Timothy G. Griffin, Matthew Roughan |
Internet Measurement Conference | 1 |
| 2003 | Towards an accurate AS-level traceroute toolabstractTraceroute is widely used to detect routing problems, characterize end-to-end paths, and discover the Internet topology. Providing an accurate list of the Autonomous Systems (ASes) along the forwarding path would make traceroute even more valuable to researchers and network operators. However, conventional approaches to mapping traceroute hops to AS numbers are not accurate enough. Address registries are often incomplete and out-of-date. BGP routing tables provide a better IP-to-AS mapping, though this approach has significant limitations as well. Based on our extensive measurements, about 10% of the traceroute paths have one or more hops that do not map to a unique AS number, and around 15% of the traceroute AS paths have an AS loop. In addition, some traceroute AS paths have extra or missing AS hops due to Internet eXchange Points, sibling ASes managed by the same institution, and ASes that do not advertise routes to their infrastructure. Using the BGP tables as a starting point, we propose techniques for improving the IP-to-AS mapping as an important step toward an AS-level traceroute tool. Our algorithms draw on analysis of traceroute probes, reverse DNS lookups, BGP routing tables, and BGP update messages collected from multiple locations. We also discuss how the improved IP-to-AS mapping allows us to home in on cases where the BGP and traceroute AS paths differ for legitimate reasons. Z. Morley Mao, Jennifer Rexford, Jia Wang 0001, Randy H. Katz |
SIGCOMM | 1 |
| 2003 | Efficient and robust streaming provisioning in VPNsabstractToday, most large companies maintain virtual private networks (VPNs) to connect their remote locations into a single secure network. VPNs can be quite large covering more than 1000 locations and in most cases use standard Internet protocols and services. Such VPNs are implemented using a diverse set of technologies such as Frame Relay, MPLS, or IPSEC to achieve the goal of privacy and performance isolation from the public Internet.Using VPNs to distribute live content has recently received tremendous interest. For example, a VPN could be used to broadcast a CEO-employee town hall meeting. To distribute this type of content economically without overloading the network, the deployment of streaming caches or splitters is most likely required.In this paper, we address the problem of optimally placing such streaming splitters or caches to broadcast to a given set of VPN endpoints under the constraints typically found within a VPN. In particular, we introduce an efficient algorithm with complexity O(V), V being the number of routers in the VPN. This guarantees the optimal cache placement if interception is used for redirection. We prove that the general problem is NP-hard and introduce multiple heuristics for efficient and robust cache placement suitable under different constraints. At the expense of increased implementation complexity, each heuristic solution provides additional saving in the number of caches required. We evaluate proposed solutions using extensive simulations. In particular, we show our flow-based solution is very close to the optimal. Z. Morley Mao, David Johnson 0004, Oliver Spatscheck, Jacobus E. van der Merwe, Jia Wang 0001 |
WWW | 1 |
| 2002 | Route flap damping exacerbates internet routing convergenceabstractRoute flap damping is considered to be a widely deployed mechanism in core routers that limits the widespread propagation of unstable BGP routing information. Originally designed to suppress route changes caused by link flaps, flap damping attempts to distinguish persistently unstable routes from routes that occasionally fail. It is considered to be a major contributor to the stability of the Internet routing system.We show in this paper that, surprisingly, route flap damping can significantly exacerbate the convergence times of relatively stable routes. For example, a route to a prefix that is withdrawn exactly once and re-announced can be suppressed for up to an hour (using the current RIPE recommended damping parameters). We show that such abnormal behavior fundamentally arises from the interaction of flap damping with BGP path exploration during route withdrawal. We study this interaction using a simple analytical model and understand the impact of various BGP parameters on its occurrence using simulations. Finally, we outline a preliminary proposal to modify route flap damping scheme that removes the undesired interaction in all the topologies we studied. . Z. Morley Mao, Ramesh Govindan, George Varghese, Randy H. Katz |
SIGCOMM | 1 |
| 2002 | A Precise and Efficient Evaluation of the Proximity Between Web Clients and Their Local DNS Servers
Z. Morley Mao, Chuck Cranor, Fred Douglis, Michael Rabinovich, Oliver Spatscheck, Jia Wang 0001 |
USENIX ATC, General Track | 1 |
| 2001 | Network support for mobile multimedia using a self-adaptive distributed proxyabstractRecent advancements in video and audio codec technologies~(e.g., RealV ideo [18] make multimedia streaming possible across a wide range of network conditions. With an increasing trend of ubiquitous connectivity, more and more areas have overlapping coverage of multiple wired and wireless networks. Because the best network service changes as the user moves, to provide good multimedia application performance, the service needs to adapt to user movement as well as network and computational resource variations. For wireless multimedia applications, one must ensure smooth transitions when network connectivity changes. We argue that network adaptations for multimedia applications should be provided at the application layer with help from proxies in the network. The reasons are ease of programming, ease of deployment, better fault-tolerance, and greater scalability. Z. Morley Mao, Hoi-Sheung Wilson So, Byunghoon Kang |
NOSSDAV | 1 |
| 2001 | The Ninja architecture for robust Internet-scale systems and services
Steve D. Gribble, Matt Welsh, J. Robert von Behren, Eric A. Brewer, David E. Culler, Nikita Borisov, Steven E. Czerwinski, Ramakrishna Gummadi, Jon R. Hill, Anthony D. Joseph, Randy H. Katz, Z. Morley Mao, Steven J. Ross, Ben Y. Zhao |
Comput. Networks | 12 |