EDBT 2026 Demo / reviewers in the wild / expert
Biao Han 0003
dblp:96/9826-3
· DBLP profile ↗
45ranked-venue papers
11as first author
20since 2021 · last 2026
0000-0002-5082-5727ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 33 · 6 first-author · 14 since 2021Systems, architecture and hardware · 5 · 4 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LLMs Unleashed: Generating Protocol Code from RFC SpecificationsabstractRFC (Request for Comments) documents constitute the foundation of network protocol standardization. However, they are expressed in natural language, they tend to be lengthy and ambiguous, forcing protocol implementers to rely on extensive manual parsing and coding—a process that is both labor-intensive and prone to errors. This makes the automated parsing and comprehension of RFC documents a major challenge in network protocol research. To address this gap, we introduce large language models (LLMs) into the task of automatic network protocol code generation from RFC documents (RFC2Code) and propose a comprehensive evaluation framework to quantitatively assess LLM performance. We develop an end-to-end automated protocol generation system, APG (Automated Protocol-Generation), which supports implementations of ICMP, IGMP, NTP, and TCP. Compared to prior NLP (Natural language processing) methods, APG achieves a fully automated workflow with approximately 3.17× faster processing, 95% compile success and behavioral correctness for stateless protocols like ICMP, and 90% interoperability for complex stateful protocols such as TCP, requiring only minimal manual intervention. Junfeng Long, Jinshu Su, Biao Han 0003 |
AAAI | 3 |
| 2026 | PacketLoom: A Unified Preprocessing Framework for Multi-Modal Network Traffic Analysis
Guanping Liang, Sudan Li, Biao Han 0003, Xiaoyan Wang 0003 |
INFOCOM | 4 |
| 2026 | DTCC: Decision Transformer-driven framework for adaptive network congestion controlabstractExisting learning-based congestion control methods suffer from myopic decision-making due to their reliance on single-timestep states and fail to model long-term dependencies due to architectural constraints (e.g., recurrent networks’ vanishing gradients). To address these issues, we propose a Decision Transformer-based network congestion control framework named DTCC. DTCC is the first to unify long-context modeling and real-time decision-making within a 4-layer autoregressive Transformer, replacing traditional Markov decision paradigms with sequence-to-action mapping. With enhancement learning strategy such as stochasticity-aware training, DTCC achieves efficient and generalizable performance from heterogeneous dataset. Extensive experiments demonstrate DTCC’s supremacy: it achieves 16.67–29.55% higher winning rate compared to state-of-the-art baselines (e.g., Sage) across diverse network scenarios and 8.33%–29.17% higher winning rate under unseen highly variable network. Leveraging a lightweight Transformer, DTCC enables real-time deployment with approximately 2.8 ms inference per step on general CPU devices. To the best of our knowledge, this is the first work to employ Decision Transformer for training an intelligent congestion control mechanism. Our work, therefore, showcases the potential of combining reinforcement learning with advanced Transformer architectures in real-time network control. Xiaolan Ji, Biao Han 0003, Xiaoliang Wang 0001, Ruidong Li 0001, Jinshu Su |
Comput. Networks | 2 |
| 2026 | Pao-Ding: Accelerating Cross-Edge Video Analytics via Automated CNN Model Partitioning
Guanping Liang, Biao Han 0003, Ruidong Li 0001, Xueqiang Han, Zhigang Sun 0002 |
IEEE Trans. Mob. Comput. | 2 |
| 2026 | ICCP: Toward Congestion Control Agent via Controlling Logic Decoupling and Algorithm Integration
Xiaolan Ji, Biao Han 0003, Yuedong Xu 0001, Jinshu Su |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2025 | Dynamic Multi-Objective Service Function Chain Placement Based on Deep Reinforcement LearningabstractService function chain placement is crucial to support services flexibility and diversity for different users and vendors. Specifically, this problem is proved to be NP-hard. Existing deep reinforcement learning based methods either can only handle a limited number of objectives, or their training time are too long. Concomitantly, they are unable to satisfy when the number of objectives is dynamic. It is necessary to model service function chain placement as a multi-objective problem. The multi-objective problem can decomposed into multiple sub-problems by the weight vectors. In this paper, we first reveal the relationship between weight vectors and solution position, which can reduce the training time to gain a better placement model. Then, we design a novel algorithm for the service function chain placement problem, called rzMODRL. The weight vectors are divided into zones for training in parallel, and the order is defined for the final models located at the end of a training process, which can save time and improve the quality of the model. Dynamic objective placement method is based on the high-dimensional model to avoid retraining for a low-dimensional placement. Evaluation results show that the proposed algorithms improve the service acceptance ratio up to 32% and the hyper-volume values with 14% in the multi-objective service function chain placement, where hyper-volume has been widely applied to evaluate the convergence and diversity simultaneously in multi-objective optimization. And it is also effective in solving the dynamic objective service function chain placement problem that the difference of average hyper-volume values is 10.44%. Baokang Zhao, Fengxiao Tang, Biao Han 0003 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2024 | Aquilas: Adaptive QoS-Oriented Multipath Packet Scheduler with Hierarchical Intelligence for QUICabstractMultipath packet scheduler is responsible for deliv-ering each packet to an appropriate path. However, rules-based schedulers struggle to adapt to varying network conditions and diverse Quality of Service (QoS) requirements. Despite learning- based scheduler can adapt to various network conditions, reacting quickly to network changes is still challenging. Moreover, for diverse QoS requirements, learning-based schedulers often neces-sitates training from scratch. To solve the above challenges, we propose a multi-head mapping model that selects an optimal sub- scheduler based on the current state. It works with a shared state encoder, a multi-head Q-value decoder, and QoS-oriented reward decomposition. Furthermore, we propose Aquilas, an adaptive multi path packet scheduler with hierarchical intelligence for the Quick UDP Internet Connection (QUIC) protocol. Aquilas adopts a learning-based scheduler selector, thereby enabling selection of an optimal policy from a pool of sub-schedulers. This sub- scheduler pool encompasses a wide range of knowledge for handling various network conditions. In coarse time intervals, the learning-based scheduler selector operates, while during fine- grained time intervals, the selected sub-scheduler delivers each packet to the corresponding path. Aquilas has been evaluated in both controlled emulation and real-world networks. Compared with the state-of-the-art schedulers, Aquilas improves transmis-sion performance in various network conditions and diverse traffic types. Congxi Song, Biao Han 0003, Ruidong Li 0001, Xueqiang Han, Jinshu Su |
ICDCS | 2 |
| 2024 | 4D-MAP: Multipath Adaptive Packet Scheduling for Live Streaming over QUIC
Congxi Song, Biao Han 0003, Jinshu Su |
J. Comput. Sci. Technol. | 2 |
| 2024 | MPR-QUIC: Multi-path partially reliable transmission for priority and deadline-aware video streaming
Biao Han 0003, Cao Xu, Xiaoyan Wang 0003, Peng Xun |
J. Syst. Archit. | 1 |
| 2024 | Multi-agent DRL-based Multipath Scheduling for Video Streaming with QUICabstractThe popularization of video streaming brings challenges in satisfying diverse Quality of Service (QoS) requirements. The multipath extension of the Quick UDP Internet Connection (QUIC) protocol, also called MPQUIC, has the potential to improve video streaming performance with multiple simultaneously transmitting paths. The multipath scheduler of MPQUIC determines how to distribute the packets onto different paths. However, while applying current multipath schedulers into MPQUIC, our experimental results show that they fail to adapt to various receive buffer sizes of different devices and comprehensive QoS requirements of video streaming. These problems are especially severe under heterogeneous and dynamic network environments. To tackle these problems, we propose MARS, a Multi-agent deep Reinforcement learning (MADRL)-based Multipath QUIC Scheduler, which is able to promptly adapt to dynamic network environments. It exploits the MADRL method to learn a neural network for each path and generate scheduling policy. Besides, it introduces a novel multi-objective reward function that takes out-of-order queue size and different QoS metrics into consideration to realize adaptive scheduling optimization. We implement MARS in an MPQUIC prototype and deploy in Dynamic Adaptive Streaming over HTTP system. Then, we compare it with the state-of-the-art multipath schedulers in both emulated and real-world networks. Experimental results show that MARS outperforms the other schedulers with better adaptive capability regarding the receive buffer sizes and QoS. Xueqiang Han, Biao Han 0003, Congxi Song |
ACM Trans. Multim. Comput. Commun. Appl. | 2 |
| 2023 | MARS: An Adaptive Multi-Agent DRL-based Scheduler for Multipath QUIC in Dynamic NetworksabstractThe multipath extension of the Quick UDP Internet Connection (QUIC) protocol, also called MPQUIC, is currently attracting increasing attention from both industry and academia. The multipath scheduler of MPQUIC determines how to distribute the packets onto different paths. However, our experimental results show that they fail to adapt to various receive buffer sizes and Quality of Service (QoS) requirements while applying current multipath schedulers into MPQUIC due to the diversity of devices and applications. These problems are especially severe under heterogeneous and dynamic network environments. To tackle these problems, we propose MARS, a Multi-Agent deep Reinforcement learning (MADRL) based Multipath QUIC Scheduler, which is able to promptly adapt to dynamic network environments. It exploits the MADRL method to learn a neural network for each path and generate scheduling policy. Besides, it introduces a novel multi-objective reward function that takes out-of-order (OFO) queue size and different QoS metrics into consideration to realize adaptive scheduling optimization. We implement MARS in an MPQUIC prototype and compare it with the state-of-the-art multipath schedulers in both emulated and real-world networks. Experimental results show that MARS outperforms the other schedulers with better adaptive capability regarding the receive buffer sizes and QoS. Xueqiang Han, Biao Han 0003, Ruidong Li 0001, Xiaolan Ji |
IWQoS | 2 |
| 2023 | Demo: A Prototype for Detecting and Localizing Hidden Devices in Unfamiliar EnvironmentsabstractWe have designed PanguVision: an Android software system that can be deployed on personal handheld devices (cell phones, PCs, etc.). The prototype described enables the detection of hidden devices and recognition of their types. It utilizes augmented reality to visualize the location of these hidden devices, facilitating swift identification. The demo showcases a prototype mounted on a user's handheld device, enabling users to detect and recognize hidden devices in unfamiliar environments. Test results show that the prototype achieves 98% accuracy in recognizing IoT device types, and the average error is controlled at 0.8m when locating the device. Xiangyu Ju, Biao Han 0003, Yitang Chen |
MobiHoc | 2 |
| 2023 | FPGA-CPU Architecture Accelerated Regular Expression Matching With Fast PreprocessingabstractAbstract Regular Expression Matching (REM) is the core of Deep Packet Inspection (DPI), which is important for various network security applications. The burgeoning Software Defined Network and Network Function Virtualization technologies make the network evolve more dynamic, which brings serious challenges for DPI engines to achieve high matching performance with fast rule-set update capability. To meet these challenges, this paper proposes a heterogeneous Field Programmable Gate Array (FPGA)-Central Processing Unit (CPU) architecture to accelerate Deterministic Finite Automaton (DFA)-based REM with high preprocessing performance. Firstly, a novel regex decomposition technique is proposed to solve the DFA state explosion problem, which splits each regex into one prefix and several postfixes. Secondly, heterogeneous architecture is presented to collaboratively handle regex matching, in which prefixes are matched in parallel in an FPGA and postfixes are matched in a CPU. To further improve the matching performance, several well-designed DFA compression techniques and regex decomposition optimizations are proposed. Our design has been implemented in a DPI prototype employing a medium-end FPGA. Extensive experiments are conducted to evaluate the performance. Results reveal that our proposed architecture achieves 6.33 Gbps matching throughput on the Snort rule-set (v3.0), which is close to state-of-the-art FPGA NFA-based schemes. However, the rule-set preprocessing time is significantly reduced to <7 minutes, compared with up to several hours of FPGA NFA-based countermeasures. Jincheng Zhong, Shuhui Chen, Biao Han 0003 |
Comput. J. | 3 |
| 2023 | Adaptive QoS-aware multipath congestion control for live streaming
Xiaolan Ji, Biao Han 0003, Cao Xu, Congxi Song, Jinshu Su |
Comput. Networks | 2 |
| 2023 | FLoRa: Sequential fuzzy extractor based physical layer key generation for LPWANabstractThe security of Low-Power Wide-Area Network (LPWAN) mainly relies on encryption for ensuring packet integrity and confidentiality. Unfortunately, the latest LPWAN specifications refrain from specifying how to distribute keys for encryption. In this paper, we tackle this problem via physical layer security, which exploits the channel characteristics to generate secret keys at the physical layer. In order to generate consistent keys from noisy feature sources and to achieve high reconciliation success rate, we propose FLoRa, a physical layer key generation system for LPWAN based on sequential fuzzy extractor. An adaptive multi-bit quantization algorithm is first proposed to generate the initial key, which accelerates the bit generation rate at the start-up procedure. We then design a novel fuzzy extractor by sequentially slicing the initial key, which improves the reconciliation success rate, as well as reduces the key reconciliation time. We implement FLoRa in a LoRaWAN based network prototype and evaluate it by conducting extensive indoor and outdoor experiments. Experimental results reveal that FLoRa is capable of generating consistent secret keys with high key generation performance in both static and dynamic network environments. Biao Han 0003, Xiaoyan Wang 0003, Hanxun Li, Jinsen Huang |
Future Gener. Comput. Syst. | 1 |
| 2023 | A Multivariate KPIs Anomaly Detection Framework With Dynamic Balancing Loss TrainingabstractAnomaly detection on multivariate KPIs (Key Performance Indicators, such as CPU utilization, sockets status, and HTTP requests per second) is of utmost importance to the systems’ reliability. Unsupervised methods have been of considerable interests and have significantly progressed due to their superior effectiveness. However, the state-of-art unsupervised anomaly detection methods still suffer from high false or missed alarm rates. To this end, in this paper, we propose MM, a practicalMultivariate KPIs anomaly detection framework following the principles ofMulti-task learning with the proposed dynamic balancing loss function. To capture KPIs’ characteristics to the most extent, we simultaneously train multiple sequential autoencoders with different connections based on a designed semi-Random Connection Recurrent Neural Network (sRC-RNN). These autoencoders can be treated as different reconstruction tasks while training. Furthermore, we propose a dynamic loss function to adaptively balance the tasks’ weights. Extensive experiments show that MM outperforms the state-of-art unsupervised multivariate KPIs anomaly detection algorithms and achieves an average F1-score of 0.95 on two public machine-level KPIs datasets and 0.96 on an internal container-level KPIs dataset. Biao Han 0003, Ruidong Li 0001, Jinshu Su |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2022 | ACCeSS: Adaptive QoS-aware Congestion Control for Multipath TCPabstractMultipath TCP (MPTCP) enables multi-home devices to establish multiple paths for simultaneous data transmission. However, due to diverse Quality of Service (QoS) requirements in real network, existing multipath congestion control algorithms (CCAs) fail to fast adapt to dynamic traffic, which leads to performance degradation, especially in heterogeneous network environments. To tackle these problems, in this paper, we first observe the performance limitations of current multipath CCAs by conducting extensive experiments. Then we propose ACCeSS, an adaptive QoS-aware multipath congestion control framework, which is able to promptly adapt to network changes and QoS requirements with a novel control policy optimization phase. In order to adjust and stimulate improvement of the preferred performance metric, ACCeSS exploits Random Forest Regressing (RFR) method to perform QoS-specific utility function optimization. ACCeSS is implemented and compared with other multipath CCAs in Linux kernel. Performances of ACCeSS are evaluated in both emulated and real-world networks, which reveal that ACCeSS outperforms classic multipath CCAs and the state-of-the-art learning based multipath CCA with better adaptive capability of QoS. Xiaolan Ji, Biao Han 0003, Ruidong Li 0001, Cao Xu, Jinshu Su |
IWQoS | 2 |
| 2021 | ModelCoder: A Fault Model based Automatic Root Cause Localization Framework for Microservice SystemsabstractMicroservice system is an architectural style to develop a single application as a suite of small services running in its process and communicating with lightweight message mechanisms. Although microservice architecture enables rapid, frequent and reliable delivery of large, complex applications, it is increasingly challenging for operational staffs to locate the root cause of a microservice fault, which usually occurs on a service node and propagates to affect the entire system. To this end, in this paper, we first introduce the concept of deployment graph and service dependency graph to depict the deployment status and calling relationship between service nodes. Then we formulate the root cause localization problem in microservice systems based on the constructed graphs, in which fault model is defined to capture the characteristics of a fault’s root cause. A fault model based automatic root cause localization framework called ModelCoder is later developed to figure out the root cause of unknown faults by comparing with the predefined fault models. We evaluate ModelCoder on a real-world microservice system monitoring data set spanning 15 days. Through extensive experiments, it is revealed that ModelCoder can localize the fault root cause nodes within 80 seconds on average and improve the root cause localization accuracy (to 93%) by 12% compared with the state-of-the-art root cause localization algorithm. Biao Han 0003, Jie Li 0002, Jinshu Su |
IWQoS | 2 |
| 2021 | SeqAD: An Unsupervised and Sequential Autoencoder Ensembles based Anomaly Detection Framework for KPIabstractKey Performance Indicator (KPI), a kind of time-series data, its anomalies are the most intuitive characteristics when failures occurred in IT systems. KPI anomaly detection is increasingly critical to provide reliable and stable services for IT systems. Unsupervised learning is a promising method because of lacking labels and the unbalance in KPI samples. However, existing unsupervised KPI anomaly detection methods suffer from high false alarm rates. They handle KPI sequence as non-sequential data and ignore the time information, which is an essential KPI character. To this end, in this paper, we propose an unsupervised and sequential autoencoder ensembles based anomaly detection framework called SeqAD. SeqAD inherits the advantages both from the sequence-to-sequence model and autoencoder ensembles. SeqAD reduces the KPI over-fitting problem effectively by introducing autoencoder ensembles. In order to better capture the time information of KPI, we propose a random step connection based recurrent neural network (RSC-RNN) to train the KPI sequence, which can provide random connections to construct autoencoders with different structures and retain time information to the most extent. Extensive experiments are conducted on two public KPI data-sets from real-world deployed systems to evaluate the efficiency and robustness of our proposed SeqAD framework. Results show that SeqAD is able to smoothly capture most of the characteristics in all KPI data-sets, as well as to achieve a high F1 score between 0.93 and 0.98, which is better than the state-of-art unsupervised KPI anomaly detection methods. Biao Han 0003, Jinshu Su |
IWQoS | 2 |
| 2021 | TraceModel: An Automatic Anomaly Detection and Root Cause Localization Framework for Microservice SystemsabstractMicroservice system is a web application architecture that divides a single application into a suite of service nodes running as separate processes and communicating with lightweight message mechanisms. Although microservice can improve the abstraction, modularity and extensibility of web applications, it makes the anomaly detection and fault root cause localization more challenging for operational staff. To this end, in this paper, we first introduce the concept of service dependency graph (SDG) to depict the complex calling relationship between nodes and then develop an anomaly detection and root cause localization framework called TraceModel which consists of TraceVAE and ModelCoder. TraceVAE divides user requests into different request classes according to well-constructed trace and analysis them separately with variational autoencoder(VAE) to figures out abnormal requests. Based on the anomaly detection results of TraceVAE, ModelCoder localizes the root cause of unknown faults by comparing their fault features with the predefined fault models. By evaluating TraceModel on a realworld microservice system monitoring data set spanning 15 days, it is revealed that TraceModel can detect the anomaly and localize the fault root cause nodes within 110 seconds on average. Furthermore, it improves the root cause localization accuracy (to 97%) by 17.5% compared with the state-of-the-art root cause localization algorithm. Biao Han 0003, Jinshu Su, Xiaoyan Wang 0003 |
MSN | 2 |
| 2020 | A TORA-based Wireless Protocol for MANET with Low Routing Overhead at Link LayerabstractMobile Ad hoc Network (MANET) is an emerging technology that allows users to transmit data without any physical infrastructure. Among those MANET protocols, Temporally Ordered Routing Algorithm (TORA) is an on-demand MANET routing protocol that attempts to find routes according to the directed acyclic graph (DAG). However, the TORA protocol requires strict synchronization. The routing overhead of TORA will increase linearly with the packet transmission rate. Motivated by Apple Wireless Direct Link (AWDL), we propose an ad hoc link-layer protocol called TORA-based Wireless Protocol (TWP) in this article. TWP can be deployed on embedded devices with Linux-kernel systems. Besides, it has unique frame structures and mechanisms. Also, it can implement synchronization and a TORA-like routing function at the link layer. We analyze the performance of TWP via experiments on Raspberry Pis. The results show that TWP can perform routing and data transmission successfully. It performs well in synchronization and can effectively reduce the routing overhead during the process of network routing. Biao Han 0003, Yusheng Ji, Xiaoyan Wang 0003 |
MASS | 1 |
| 2019 | Online Incentive Mechanism for Crowdsourced Radio Environment Map ConstructionabstractConstructing Radio Environment Map (REM) accurately and cost-efficiently is of great importance to realize dynamic spectrum access. Two kinds of approaches are widely investigated recently, i.e., radio propagation model based approaches and sensor monitoring based approaches. However, these existing approaches are suffering from either inaccurate spectrum availability or high deployment cost. To this end, outsourcing the spectrum sensing task to mobile users that are outfitted with spectrum sensors could greatly reduce the operator's expenditure, and meanwhile, achieve a satisfactory accuracy. The key of crowdsourced REM construction is to attract user participation. In this paper, we propose a novel online incentive mechanism for constructing a fine-grained REM with crowdsourcing in a realistic scenario, where the mobile users arrive and leave in an online manner. The proposed mechanism is proven to satisfy the truthfulness, individual rationality, computational efficiency and consumer sovereignty. Evaluation results demonstrate that the proposed mechanism outperforms the baseline schemes substantially. Xiaoyan Wang 0003, Masahiro Umehira, Biao Han 0003, Peng Li 0017, Yu Gu 0003, Celimuge Wu |
ICC | 3 |
| 2019 | A Heterogeneous Parallel Packet Processing Architecture for NFV AccelerationabstractNetwork function virtualization (NFV) offers a new way to design, deploy and manage networking services. It is of vital importance to exploit heterogeneous parallelism between hardware and software, in order to improve virtulization performance and quality of virtualized network services. In this poster, we propose a novel heterogeneous parallel architecture that highly exploits the parallelism inside packet processing, and implementation efficacy with hardware processing engines and software threads. We present two packet processing pipelines with three implemented VNF instances to better demonstrate the efficiency of heterogeneous parallelism in accelerating NFV. We show the performance of our proposed architecture with various virtualized requirements and traffics in a well-deployed network environment. Experimental results reveal that it can achieve accelerated NFV performance, as well as provide a wide class of VNFs to improve the quality of virtualized network services. Jinshu Su, Biao Han 0003, Gaofeng Lv, Tao Li 0008, Zhigang Sun 0002 |
ICNP | 2 |
| 2019 | Distributed Physical Layer Key Generation for Secure LPWAN CommunicationabstractLow-Power Wide Area Networks (LPWAN) has emerged as the dominant open specification in recent years due to its ability to offer affordable connectivity to the low-power devices distributed over large geographical areas. However, security issues have not been fully addressed in LPWAN specifications, especially, key distribution and key management. Physical layer key generation, which exploits wireless channel reciprocity and randomness to generate secure keys, has attracted considerable attention in recent years. In this paper, we exploit the physical layer key generation problem in LPWAN communication and present a distributed and lightweight key generation scheme for Long Range (LoRa) based network. It explores the shared randomness extracted from measured RSSI (Received Signal Strength Indicator) as consensus information to generate secure keys. To negotiate the RSSI signal as a bidirectional consistent key sequence, we propose a novel level-crossing quantization algorithm with an improved Cascade key agreement protocol to improve the key generation rate, as well as to avoid information leakage during transmission. We implement the proposed physical layer key generation scheme in a LoRa network prototype. Then we conduct extensive experiments in stationary and mobile indoor environments to evaluate the efficiency of the proposed key generation scheme. Experimental results show that its achievable key rate can reach 29.5% in stationary scenario and 35.5% in mobile scenario. Its key generation rate can exceed 1 bit/s with a lightweight implementation on the LoRa network prototype. For the 128-bit key sequence, it passes the the NIST suite of statistical tests. Biao Han 0003, Sirui Peng, Xiaoyan Wang 0003 |
ICPADS | 1 |
| 2018 | Exploiting Full-Duplex Communication in AP-Based Wireless Networks via a Novel MAC ProtocolabstractNowadays, most mobile terminals access the Internet via access points (APs) but AP is easy to become the performance bottleneck of the network. In-band full-duplex (IBFD) technique can theoretically double the network performance of an AP. However, how to solve the channel contention problem and fully utilize the channel resources under full-duplex mode at AP is a challenging problem. In this paper, we aim to exploit the full-duplex communication opportunities in AP- based wireless networks and present a novel medium access control (MAC) protocol named BiAP. To solve the channel contention problem, we first design a novel polling-based transmission mechanism and make comprehensive investigations on the effect of polling profile in full-duplex communication. Then, the channel contention problem is translated into finding a polling profile with the minimum transmission time and proved to be NP-Complete. Thus, we develop a stream-like heuristic algorithm to generate an efficient polling profile and it can work with the packet transmission procedure in parallel. By transmitting packets according to the generated polling profile, potential full-duplex opportunities are utilized. Simulation results show that our proposed MAC protocol can significantly improve the network throughput and reduce transmission delay, compared with state-of- the-art protocols. Song Liu 0005, Wei Peng 0005, Biao Han 0003 |
ICC | 3 |
| 2018 | OverWatch: A Cross-Plane DDoS Attack Defense Framework with Collaborative Intelligence in SDNabstractDistributed Denial of Service (DDoS) attacks are one of the biggest concerns for security professionals. Traditional middle-box based DDoS attack defense is lack of network-wide monitoring flexibility. With the development of software-defined networking (SDN), it becomes prevalent to exploit centralized controllers to defend against DDoS attacks. However, current solutions suffer with serious southbound communication overhead and detection delay. In this paper, we propose a cross-plane DDoS attack defense framework in SDN, called OverWatch, which exploits collaborative intelligence between data plane and control plane with high defense efficiency. Attack detection and reaction are two key procedures of the proposed framework. We develop a collaborative DDoS attack detection mechanism, which consists of a coarse-grained flow monitoring algorithm on the data plane and a fine-grained machine learning based attack classification algorithm on the control plane. We propose a novel defense strategy offloading mechanism to dynamically deploy defense applications across the controller and switches, by which rapid attack reaction and accurate botnet location can be achieved. We conduct extensive experiments on a real-world SDN network. Experimental results validate the efficiency of our proposed OverWatch framework with high detection accuracy and real-time DDoS attack reaction, as well as reduced communication overhead on SDN southbound interface. Biao Han 0003, Xiangrui Yang 0002, Zhigang Sun 0002, Jinshu Su |
Secur. Commun. Networks | 1 |
| 2017 | P5: Programmable Parsers with Packet-level Parallel Processing for FPGA-based SwitchesabstractThis paper presents P5, a programmable packet parser with packet-level parallel processing for FPGA-based switches. P5 overcomes both limitations. First, P5 has the programmability of dynamically updating parsing algorithms at run-time. Second, P5 exploits packet-level parallelism in the bottleneck of parsing pipeline to compensate FPGA's low clock frequency, and reduces resource consumption through a one-block recirculated strategy. Junnan Li 0002, Zhigang Sun 0002, Biao Han 0003 |
ANCS | 3 |
| 2017 | SDN-Based DDoS Attack Detection with Cross-Plane Collaboration and Lightweight Flow MonitoringabstractDistributed Denial of Service (DDoS) attacks are one of the biggest concerns for security professionals. Traditional DDoS attack detection mechanisms are based on middle-box devices or SDN controllers, which either lack network-wide monitoring information or suffer with serious southbound communication overhead and detection delay. In this paper, we propose a SDN-based DDoS attack detection framework with cross-plane collaboration called OverWatch, which performs a two-stage granularity filtering procedure between coarse-grained detection data plane and fine- grained detection control plane for abnormal flows. It leverages computational capabilities that currently underutilized on OpenFlow switches to shrink the detection range for fine-grained DDoS attack detections. In OverWatch, we propose a lightweight flow monitoring algorithm to capture the key features of DDoS attack traffics on the data plane by polling the values of counters in OpenFlow switches. Experiments are conducted in an evaluating network with a FPGA-based OpenFlow switch prototype and the Ryu controller, which reveal that our proposed OverWatch framework and flow monitoring algorithm can greatly improve the detection efficiency, as well as reduce the detection delay and southbound communication overhead. Xiangrui Yang 0002, Biao Han 0003, Zhigang Sun 0002 |
GLOBECOM | 2 |
| 2017 | Automatic privacy leakage detection for massive android apps via a novel hybrid approachabstractAndroid apps frequently leak private data off the device with or without intentions. Researchers have proposed a large number of methods, for example, static and dynamic analysis methods, to pick out the apps which tend to leak private data. However, they are only able to identify part of private data leakage vulnerabilities, due to the dynamic features in codes or code coverage problem. This paper presents a novel hybrid approach that can find out more private data leakages than the existing static or dynamic methods. The approach, realized in a tool, called HybriDroid, which employs both static and dynamic analysis methods to extract the models of each apps, and then refines the behavior model to a more adequate one according to the dynamic analysis result. As a consequence, HybriDroid inherits the advantages of both static and dynamic analysis methods, which not only achieves a high code coverage, but also can deal with the dynamic features in codes. The evaluation results show that HybriDroid is effective in detecting privacy leakages for both inter- and intra-app communication. Comparing with the existing methods, it can achieve considerable improvements in data leakage detection performance with a 97.8% precision and 90% recall on the selected apps from DroidBench 3.0 test suite. Ho-fung Leung, Biao Han 0003, Jinshu Su |
ICC | 3 |
| 2016 | A 60Gbps DPI Prototype based on Memory-Centric FPGAabstractDeep packet inspection (DPI) is widely used in content-aware network applications to detect string features. It is of vital importance to improve the DPI performance due to the ever-increasing link speed. In this demo, we propose a novel DPI architecture with a hierarchy memory structure and parallel matching engines based on memory-centric FPGA. The implemented DPI prototype is able to provide up to 60Gbps full-text string matching throughput and fast rules update speed. Jinshu Su, Shuhui Chen, Biao Han 0003, Xin Wang 0076 |
SIGCOMM | 3 |
| 2016 | Efficient mismatched packet buffer management with packet order-preserving for OpenFlow networks
Jianbiao Mao, Biao Han 0003, Zhigang Sun 0002, Xicheng Lu |
Comput. Networks | 2 |
| 2016 | Design and implementation of Software Defined Hardware Counters for SDN
Tao Li 0008, Biao Han 0003, Zhigang Sun 0002 |
Comput. Networks | 3 |
| 2015 | FRINGE: Improving the scalability of Ethernet DCN via efficient software-defined edge controlabstractThis paper introduces a topology-independent software-defined edge control framework named FRINGE to scale out the Ethernet Datacenter Network (DCN). FRINGE exploits programmable OpenFlow-enabled switches deployed at the edge of DCN to aggregate the forwarding rules without introducing extra packet headers. We implement the proposed FRINGE framework in an SDN prototyping environment and validate it under three typical DCN topologies including Multi-Root Tree, HyperX and Jellyfish, where three different types of DCN workloads are applied. Evaluation results reveal that FRINGE can significantly reduce the total number of rules in all network devices and suppress most of the useless broadcast packets in the DCN. Jianbiao Mao, Biao Han 0003, Gaofeng Lv, Zhigang Sun 0002, Xicheng Lu |
IWQoS | 2 |
| 2015 | A Novel Location Privacy Mining Threat in Vehicular Internet Access Service
Yipin Sun, Shuhui Chen, Biao Han 0003, Bofeng Zhang, Jinshu Su |
WASA | 3 |
| 2015 | Secrecy Capacity Optimization via Cooperative Relaying and Jamming for WANETsabstractCooperative wireless networking, which is promising in improving the system operation efficiency and reliability by acquiring more accurate and timely information, has attracted considerable attentions to support many services in practice. However, the problem of secure cooperative communication has not been well investigated yet. In this paper, we exploit physical layer security to provide secure cooperative communication for wireless ad hoc networks (WANETs) where involve multiple source-destination pairs and malicious eavesdroppers. By characterizing the security performance of the system by secrecy capacity, we study the secrecy capacity optimization problem in which security enhancement is achieved via cooperative relaying and cooperative jamming. Specifically, we propose a system model where a set of relay nodes can be exploited by multiple source-destination pairs to achieve physical layer security. We theoretically present a corresponding formulation for the relay assignment problem and develop an optimal algorithm to solve it in polynomial time. To further increase the system secrecy capacity, we exploit the cooperative jamming technique and propose a smart jamming algorithm to interfere the eavesdropping channels. Through extensive experiments, we validate that our proposed algorithms significantly increase the system secrecy capacity under various network settings. Biao Han 0003, Jie Li 0002, Jinshu Su, Minyi Guo, Baokang Zhao |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2014 | Demostration of Self-Described Buffer for Accelerating Packet Forwarding on Multi-core ServersabstractNetwork processing platform based on the multi-core CPU becomes more and more prevailing in nowadays. Buffer allocation/deallocation operations consume a large number of CPU cycles in packet I/O process. The problem becomes even worse in the scenario of packet forwarding, as buffer allocation/deallocation operations are more frequent than the host-based network applications. We thus propose a novel data structure for packet buffer management on multi-cores, named Self-Described Buffer (SDB), which merges the separated descriptor and metadata into packet buffer. SDB management overhead can be greatly reduced by utilizing the compact data structure, and zero-overhead buffer management can be further achieved by offloading SDB allocation/deallocation operations to NIC. We have prototyped SDB enabled NIC, named BcNIC, on NetFPGA-10G. In the demo, we will illustrate the advantages of the SDB scheme by comparing the performance of BcNIC with the traditional NIC on multi-core platforms. Zhigang Sun 0002, Tao Li 0008, Biao Han 0003, Gaofeng Lv |
CloudCom | 4 |
| 2014 | The Demonstration of Hyper Software Defined Hardware CountersabstractSoftware Defined Networking (SDN) provides efficient network and traffic management for data center network. As underlying devices in SDN, SDN switches must maintain a large number of hardware counters. Implementation of these counters faces serious challenges for SDN switches, i.e., High memory consumption and inflexibility. Thus, we previously proposed Software Defined Hardware Counters (SDHC), which decouples definition and implementation of counters to overcome these challenges. However, like traditional hardware counters, SDHC only supports passive statistical mode (i.e., The values of the counters can be only read passively by the controller). Based on the passive mode, most of applications need to send request messages at some frequency to obtain statistics, which causes some critical problems for SDN: i) low statistical accuracy, ii) high network bandwidth consumption. Hyper Software Defined Hardware Counters (Hyper SDHC) is thus proposed by extending SDHC. Through introducing the timer-triggering and updating-triggering statistics-reporting mechanisms, Hyper SDHC can naturally support active statistical mode, i.e., Counters actively report their values according to triggering condition. It can greatly enhance the statistical accuracy and reduce network bandwidth consumption between controller and switch. The demo of Hyper SDHC is implemented based on Net Magic platform. The demo will exhibit how Hyper SDHC works and how it supports a typical video quality monitor application. Tao Li 0008, Biao Han 0003, Zhigang Sun 0002 |
CloudCom | 3 |
| 2014 | Smart error estimating coding: Using symbol error structure in wireless networksabstractError estimating coding has attracted significant attention recently. It enables a receiver to estimate bit error rate (BER) of a partially correct packet. Our study in this paper shows that based on the popular M-QAM modulation schemes, symbol errors have a well-defined structure, which is ultimately translated into a strong correlation in the BER of bits that constitute a symbol. We leverage this correlation to design smart error estimating coding (Smart-EEC). Smart-EEC can be used to boost the estimating accuracy of error estimating codes, e.g., EEC. Through extensive evaluation, we demonstrate that Smart-EEC helps EEC achieve a much better tradeoff between the space redundancy and estimating accuracy. Biao Han 0003, Wei Yang 0037, Yuanming Gao, Wenhua Dou |
ICCCN | 2 |
| 2014 | Design of Software Defined hardware counters for SDNabstractImplementation of counters is a critical challenge for switches in today's Software-Defined Networking (SDN). In this paper, we address the current challenges in implementing SDN counters: high memory consumption, low utilization, and inflexibility. We introduce the concept of software defined hardware counters (SDHCs) for SDN. Our main idea is to make the switch-local CPU flexibly allocate memory space to each counter required by controllers. The ASIC of SDN switches transmits event records to the CPU, which contain updating information of the counters. Furthermore, the ASIC provides non-semantic counter memory space to be allocated by the CPU. Based on the proposed SDHC, an SDN controller can flexibly apply/release various counters for each counter category (e.g., each flow entry, each port) through the south-bound interface. It is shown that SDHC achieves high flexibility while reducing the memory space on ASIC. It also improves the update performance through alleviating the CPU overhead. Finally, we evaluate the performance of SDHC through comprehensive simulation study. Tao Li 0008, Biao Han 0003, Zhigang Sun 0002 |
LANMAN | 3 |
| 2013 | Optimal relay assignment for secrecy capacity maximization in cooperative ad-hoc networksabstractPhysical layer security has emerged as a key technique for providing trustworthy and reliable future wireless networks and has witnessed a significant growth in the past few years. In this paper, we aim to improve the physical layer security and provide secure cooperative communication through cooperative relay assignment. By characterizing the security performance of the system by secrecy capacity, we study the secrecy capacity maximization problem in cooperative ad hoc networks with the involvement of multiple malicious eavesdroppers. Specifically, we propose a system model where a set of relay nodes can be exploited by multiple source-destination pairs to achieve physical layer security. We theoretically present a corresponding formulation for the secrecy capacity maximization problem. Then we develop an optimal relay assignment algorithm to solve the problem in polynomial time. The basic idea behind our proposed algorithm is to boost the capacity of the primary channel by simultaneously decreasing the capacity of the eavesdropping channel. Through extensive experiments, we validate that our proposed relay assignment algorithm significantly increase the system secrecy capacity under various network settings. Biao Han 0003, Jie Li 0002, Jinshu Su |
ICC | 1 |
| 2013 | Secrecy capacity maximization for secure cooperative ad-hoc networksabstractThis paper investigates secure cooperative communication with the involvement of multiple malicious eavesdroppers. By characterizing the security performance of the system by secrecy capacity, we study the secrecy capacity maximization problem in cooperative communication aware ad hoc networks. Specifically, we propose a system model where secrecy capacity enhancement is achieved by the assignment of cooperative relays. We theoretically present a corresponding formulation for the problem and discuss the security gain brought by the relay assignment process. Then, we develop an optimal relay assignment algorithm to solve the secrecy capacity maximization problem in polynomial time. The basic idea behind our proposed algorithm is to boost the capacity of the primary channel by simultaneously decreasing the capacity of the eavesdropping channel. To further increase the system secrecy capacity, we exploit the jamming technique and propose a smart jamming algorithm to interfere the eavesdropping channels. Analysis and experimental results reveal that our proposed algorithms significantly increase the system secrecy capacity under various network settings. Biao Han 0003, Jie Li 0002 |
INFOCOM | 1 |
| 2013 | Optimal relay node placement for multi-pair cooperative communication in wireless networksabstractRelaying and cooperation have emerged as important research topics in wireless communication over the past half-decade. During cooperative communication, spatial diversity can be achieved by exploiting the relaying capabilities of the involved relay nodes, which may vastly enhance the achieved system capacity. The potential gains largely depend on the location of relay nodes. In this paper, we study the relay node placement problem for multi-pair cooperative communication in wireless networks, where a finite number of candidate relay nodes can be placed to help the transmission of multiple source-destination pairs. Our objective is to maximize the system capacity. After formulating the relay node placement problem, we comprehensively study the effect of relay location on cooperative link capacity and show several attractive properties of the considered problem. As the main contribution, we develop a geographic aware relay node placement algorithm which optimally solves the relay node placement problem in polynomial time. The basic idea is to place a set of relay nodes to the optimum locations so as to maximize the system capacity. The efficiency of our proposed algorithm is evaluated by the results of series experimental studies. Biao Han 0003, Jie Li 0002, Jinshu Su |
WCNC | 1 |
| 2012 | Delay-bounded sink mobility in wireless sensor networksabstractThis paper exploits sink mobility to prolong the network lifetime in wireless sensor networks (WSNs) where the information delay caused by moving the sink should be bounded. We build a unified framework for analyzing this joint sink mobility and routing problem. We offer a mathematical modeling that is general and captures diversified issues, e.g. sink mobility, routing, delay, etc. We discuss the induced subproblems and present efficient solutions for them. Then, we generalize these solutions and propose a polynomial-time optimal algorithm for the origin problem. In simulations, we show the benefits of involving a mobile sink. We also show that the impact of the delay bound on the network lifetime. Yu Gu 0003, Yusheng Ji, Jie Li 0002, Biao Han 0003, Baohua Zhao |
ICC | 4 |
| 2012 | Self-Supported Cooperative Networking for Emergency Services in Multi-Hop Wireless NetworksabstractOne of the challenging issues for supporting emergency services in wireless networks is coordinating the network under emergent situations. Cooperative communication (CC) is a promising approach which can offer significant enhancements in multi-hop wireless networks. This paper investigates the potential issues in using this communication paradigm to support emergency services. We focus on promoting energy-efficient and congestion-aware cooperative networking for emergency services based on the idea of Do-It-Yourself. We propose a novel cross-layer design which jointly considers the problems of route selection in network layer, congestion and non-cooperation avoidance among multiple links in MAC layer under cooperative multi-hop wireless environments. We formulate the multi-hop cooperative flow routing and relay node selection process as an optimization problem. Based on the formulations and models, we propose a self-supported networking scheme including three novel components that make the solution procedure highly efficient. Analysis and simulation results show that our approaches significantly achieve better network performance and typically satisfy the requirements for emergency services in multi-hop wireless networks. Biao Han 0003, Jie Li 0002, Jinshu Su, Jiannong Cao 0001 |
IEEE J. Sel. Areas Commun. | 1 |
| 2011 | Self-supported congestion-aware networking for emergency services in WANETsabstractOne of the challenging issues for supporting emergency services in wireless ad hoc networks (WANETs) is coordinating the network under emergency situations. It may lead to inefficient use of the network resources by increasing congestion, as well as affect the network connectivity due to the non-cooperation behaviors of some selfish users. In this paper, we focus on promoting self-supported and congestion-aware networking for emergency services in WANETs based on the idea of Do-It-Yourself1. We model network congestion and non-cooperation behaviors according to the relations between nodes in the constructed dependency graph. Then we propose an energy-efficient and congestion-aware routing protocol for the emergency services of WANETs. Based on the proposed model and routing protocol, we design two novel movement schemes, called Direct Movement to potential selfish/busy Relays (DMR) scheme and Iterative Movement to potential selfish/busy Relays (IMR) scheme for urgent sources to support themselves and to avoid congestion and non-cooperation. Analysis and simulation results show that our approaches significantly achieve better network performance and typically satisfy the requirements for emergency services in WANETs. Biao Han 0003, Jie Li 0002, Jinshu Su |
INFOCOM | 1 |