EDBT 2026 Demo / reviewers in the wild / expert
Xiaowei Yang 0001
dblp:y/XiaoweiYang
· DBLP profile ↗
46ranked-venue papers
9as first author
11since 2021 · last 2026
0000-0002-0664-3846ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 36 · 9 first-author · 8 since 2021Systems, architecture and hardware · 4Security and privacy · 4 · 3 since 2021Databases, data management, data science and information retrieval · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Improving the Reliability of Cable Broadband Networks via Proactive Network MaintenanceabstractCable broadband networks are one of the few "last-mile" broadband technologies widely available in the U.S. Unfortunately, they have poor reliability after decades of deployment. The cable industry proposed a framework called Proactive Network Maintenance (PNM) to diagnose the cable networks. However, there is little public knowledge or systematic study on how to use these data to detect and localize cable network problems. Existing tools in the public domain have prohibitive high false-positive rates. In this paper, we propose CableMon, the first public-domain system that applies machine learning techniques to PNM data to improve the reliability of cable broadband networks. CableMon tackles two key challenges faced by cable ISPs: accurately detecting failures, and distinguishing whether a failure occurs within a network or at a subscriber's premise. CableMon uses statistical models to generate features from time series data and uses customer trouble tickets as hints to infer abnormal/failure thresholds for these generated features. Further, CableMon employs an unsupervised learning model to group cable devices sharing similar anomalous patterns and effectively identify impairments that occur inside a cable network and impairments occur at a subscriber's premise, as these two different faults require different types of technical personnel to repair them. We use eight months of PNM data and customer trouble tickets from an ISP and experimental deployment to evaluate CableMon's performance. Our evaluation results show that CableMon can effectively detect and distinguish failures from PNM data and outperforms existing public-domain tools. Jiyao Hu, Xiaowei Yang 0001, Jacob Malone, Jonathan W. Williams |
IEEE Trans. Netw. | 3 |
| 2025 | PreAcher: Secure and Practical Password Pre-Authentication by Content Delivery Networks
Shihan Lin, Suting Chen, Yunming Xiao, Yanqi Gu, Aleksandar Kuzmanovic, Xiaowei Yang 0001 |
NSDI | 6 |
| 2025 | Characterizing Anycast Flipping: Prevalence and Impact
Shihan Lin, Tingshan Huang, Bruce M. Maggs, Kyle Schomp, Xiaowei Yang 0001 |
PAM | 6 |
| 2024 | Browsing without Third-Party Cookies: What Do You See?abstractThird-party web cookies are often used for privacy-invasive behavior tracking. Partly due to privacy concerns, browser vendors have started to block all third-party cookies in recent years. To understand the effects of such third-party cookieless browsing, we crawled and measured the top 10,000 Tranco websites. We developed a framework to remove third-party cookies and analyze the differences between the appearance of web pages with and without these cookies. We find that disabling third-party cookies has no substantial effect on website appearance including layouts, text, and images. This validates the industry-wide shift towards cookieless browsing as a way to protect user privacy without compromising on the user experience. Maxwell Lin, Shihan Lin, Helen Wu, Karen Wang, Xiaowei Yang 0001 |
IMC | 5 |
| 2023 | Remote Procedure Call as a Managed System Service
Jingrong Chen 0002, Shihan Lin, Yechen Xu, Xinhao Kong, Thomas E. Anderson, Matthew Lentz, Xiaowei Yang 0001, Danyang Zhuo |
NSDI | 8 |
| 2023 | Quantifying User Password Exposure to Third-Party CDNs
Rui Xin 0002, Shihan Lin, Xiaowei Yang 0001 |
PAM | 3 |
| 2023 | Regional IP Anycast: Deployments, Performance, and PotentialsabstractRecent studies show that an end system's traffic may reach a distant anycast site within a global IP anycast system, resulting in high latency. To address this issue, some private and public CDNs have implemented regional IP anycast, a technique that involves dividing content-hosting sites into geographic regions, announcing a unique IP anycast prefix for each region, and utilizing DNS and IP-geolocation to direct clients to CDN sites in their corresponding geographic regions. In this work, we aim to understand how a regional anycast CDN partitions its sites and maps its customers' clients to its sites, and how a regional anycast CDN performs compared to its global anycast counterpart. We study the deployment strategies and the performance of two CDNs (Edgio and Imperva) that currently deploy regional IP anycast. We find that both Edgio and Imperva partition their sites and clients following continent or country borders. Furthermore, we compare the client latency distribution in Imperva's regional anycast CDN with its similar-scale DNS global anycast network, while accounting for and mitigating the relevant deployment differences between the two networks. We find that regional anycast can effectively alleviate the pathology in global IP anycast where BGP routes clients' traffic to distant CDN sites. However, DNS mapping inefficiencies, where DNS returns a sub-optimal regional IP anycast address that does not cover a client's low-latency CDN sites, can harm regional anycast's performance. Finally, we show what performance benefits regional IP anycast can achieve with a latency-based region partition method using the Tangled testbed. When compared to global anycast, regional anycast significantly reduces the 90th percentile client latency by 58.7% to 78.6% for clients across different geographic areas. Minyuan Zhou, Shuai Hao 0001, Xiaowei Yang 0001, Jiaqi Zheng 0001, Guihai Chen, Wan-Chun Dou |
SIGCOMM | 4 |
| 2022 | InviCloak: An End-to-End Approach to Privacy and Performance in Web Content DistributionabstractIn today's web ecosystem, a website that uses a Content Delivery Network (CDN) shares its Transport Layer Security (TLS) private key or session key with the CDN. In this paper, we present the design and implementation of InviCloak, a system that protects the confidentiality and integrity of a user and a website's private communications without changing TLS or upgrading a CDN. InviCloak builds a lightweight but secure and practical key distribution mechanism using the existing DNS infrastructure to distribute a new public key associated with a website's domain name. A web client and a website can use the new key pair to build an encryption channel inside TLS. InviCloak accommodates the current web ecosystem. A website can deploy InviCloak unilaterally without a client's involvement to prevent a passive attacker inside a CDN from eavesdropping on their communications. If a client also installs InviCloak's browser extension, the client and the website can achieve end-to-end confidential and untampered communications in the presence of an active attacker inside a CDN. Our evaluation shows that InviCloak increases the median page load times (PLTs) of realistic web pages from 2.0s to 2.1s, which is smaller than the median PLTs (2.8s) of a state-of-the-art TEE-based solution. Shihan Lin, Rui Xin 0002, Aayush Goel, Xiaowei Yang 0001 |
CCS | 4 |
| 2022 | Characterizing Physical-Layer Transmission Errors in Cable Broadband Networks
Jiyao Hu, Xiaowei Yang 0001 |
NSDI | 3 |
| 2021 | Speeding Up TCP with Selective Loss PreventionabstractLow latency is an important design goal for reliable data transmission protocols such as TCP and QUIC. However, timeout-based loss recovery can unnecessarily increase end-to-end latency. Previous work in reducing timeout-based loss recovery latency either duplicates every packet to avoid loss or focuses on fine-tuning the timeout timers to shorten the timeout latency without causing spurious packet retransmissions. In this work, we propose a new mechanism called Selective Loss Prevention (SLP) to reduce the loss recovery latency of a reliable transport protocol. Through extensive trace analysis, we find that not all lost packets are equal. The loss of packets with certain flags, such as SYN and PSH, is more likely to cause timeouts than other packets. Based on this observation, we propose to selectively duplicate an "important" packet whose loss is likely to increase a connection's latency. We design an algorithm to determine when to duplicate a lost packet proactively and incorporate it into TCP's congestion control algorithm so that duplicate packets will not congest the network. We incorporate SLP into Linux's kernel and evaluate its performance. Our results show that SLP can reduce timeout-based latency caused by the loss of important packets in a connection, and its overhead is low. Xiaowei Yang 0001 |
ICNP | 2 |
| 2021 | AnyOpt: predicting and optimizing IP Anycast performanceabstractThe key to optimizing the performance of an anycast-based system (e.g., the root DNS or a CDN) is choosing the right set of sites to announce the anycast prefix. One challenge here is predicting catchments. A naïve approach is to advertise the prefix from all subsets of available sites and choose the best-performing subset, but this does not scale well. We demonstrate that by conducting pairwise experiments between sites peering with tier-1 networks, we can predict the catchments that would result if we announce to any subset of the sites. We prove that our method is effective in a simplified model of BGP, consistent with common BGP routing policies, and evaluate it in a real-world testbed. We then present AnyOpt, a system that predicts anycast catchments. Using AnyOpt, a network operator can find a subset of anycast sites that minimizes client latency without using the naïve approach. In an experiment using 15 sites, each peering with one of six transit providers, AnyOpt predicted site catchments of 15,300 clients with 94.7% accuracy and client RTTs with a mean error of 4.6%. AnyOpt identified a subset of 12 sites, announcing to which lowers the mean RTT to clients by 33ms compared to a greedy approach that enables the same number of sites with the lowest average unicast latency. Tanmoy Sen, Tim April, Balakrishnan Chandrasekaran 0002, David R. Choffnes, Bruce M. Maggs, Haiying Shen, Ramesh K. Sitaraman, Xiaowei Yang 0001 |
SIGCOMM | 10 |
| 2020 | CableMon: Improving the Reliability of Cable Broadband Networks via Proactive Network Maintenance
Jiyao Hu, Xiaowei Yang 0001, Jacob Malone, Jonathan W. Williams |
NSDI | 3 |
| 2019 | Trigger relationship aware mobile traffic classificationabstractNetwork traffic classification is important to network operators to ensure visibility of traffic. Network management, monitoring, and other services are built upon such classification results for improving quality of service. Compared with traffic classification in non-mobile setting, classification in mobile settings focuses on applications and has become increasingly important. Traditionally, a rule-based method is deployed in a deep packet inspector (DPI) engine for traffic classification. However, with the explosive growth in application usage, the complicated relationships including the use of content delivery networks (CDN) and sharing behaviors among applications make such methods less effective. The traffic may be identified wrongly when one application is connected to another application's server. Heyi Tang, Yong Cui 0001, Xiaowei Yang 0001 |
IWQoS | 4 |
| 2016 | PacketCloud: A Cloudlet-Based Open Platform for In-Network ServicesabstractThe Internet was designed with the end-to-end principle where the network layer provided merely the best-effort forwarding service. This design makes it challenging to add new services into the Internet infrastructure. However, as the Internet connectivity becomes a commodity, users and applications increasingly demand new in-network services. This paper proposes PacketCloud, a cloudlet-based open platform to host in-network services. Different from standalone, specialized middleboxes, cloudlets can efficiently share a set of commodity servers among different services, and serve the network traffic in an elastic way. PacketCloud can help both Internet Service Providers (ISPs) and emerging application/content providers deploy their services at strategic network locations. We have implemented a proof-of-concept prototype of PacketCloud. PacketCloud introduces a small additional delay, and can scale well to handle high-throughput data traffic. We have evaluated PacketCloud in both a fully functional emulated environment, and the real Internet. Yang Chen 0001, Yu Chen 0091, Qiang Cao 0005, Xiaowei Yang 0001 |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2015 | Combating Friend Spam Using Social RejectionsabstractUnwanted friend requests in online social networks (OSNs), also known as friend spam, are among the most evasive malicious activities. Friend spam can result in OSN links that do not correspond to social relationship among users, thus pollute the underlying social graph upon which core OSN functionalities are built, including social search engine, ad targeting, and OSN defense systems. To effectively detect the fake accounts that act as friend spammers, we propose a system called Rejecto. It stems from the observation on social rejections in OSNs, i.e., Even well-maintained fake accounts inevitably have their friend requests rejected or they are reported by legitimate users. Our key insight is to partition the social graph into two regions such that the aggregate acceptance rate of friend requests from one region to the other is minimized. This design leads to reliable detection of a region that comprises friend spammers, regardless of the request collusion among the spammers. Meanwhile, it is resilient to other strategic manipulations. To efficiently obtain the graph cut, we extend the Kernighan-Lin heuristic and use it to iteratively detect the fake accounts that send out friend spam. Our evaluation shows that Rejecto can discern friend spammers under a broad range of scenarios and that it is computationally practical. Qiang Cao 0005, Michael Sirivianos, Xiaowei Yang 0001, Kamesh Munagala |
ICDCS | 3 |
| 2014 | Uncovering Large Groups of Active Malicious Accounts in Online Social NetworksabstractThe success of online social networks has attracted a constant interest in attacking and exploiting them. Attackers usually control malicious accounts, including both fake and compromised real user accounts, to launch attack campaigns such as social spam, malware distribution, and online rating distortion. To defend against these attacks, we design and implement a malicious account detection system called SynchroTrap. We observe that malicious accounts usually perform loosely synchronized actions in a variety of social network context. Our system clusters user accounts according to the similarity of their actions and uncovers large groups of malicious accounts that act similarly at around the same time for a sustained period of time. We implement SynchroTrap as an incremental processing system on Hadoop and Giraph so that it can process the massive user activity data in a large online social network efficiently. We have deployed our system in five applications at Facebook and Instagram. SynchroTrap was able to unveil more than two million malicious accounts and 1156 large attack campaigns within one month. Qiang Cao 0005, Xiaowei Yang 0001, Jieqi Yu, Christopher Palow |
CCS | 2 |
| 2014 | In-Network Compute Extensions for Rate-Adaptive Content Delivery in Mobile NetworksabstractTraffic from mobile wireless networks has been growing at a fast pace in recent years and is expected to surpass wired traffic very soon. Service providers face significant challenges at such scales including providing seamless mobility, efficient data delivery, security, and provisioning capacity at the wireless edge. In the Mobility First project, we have been exploring clean slate enhancements to the network protocols that can inherently provide support for at-scale mobility and trustworthiness in the Internet. An extensible data plane using pluggable compute-layer services is a key component of this architecture. We believe these extensions can be used to implement in-network services to enhance mobile end-user experience by either off-loading work and/or traffic from mobile devices, or by enabling en-route service-adaptation through context-awareness (e.g., Knowing contemporary access bandwidth). In this work we present details of the architectural support for in-network services within Mobility First, and propose protocol and service-API extensions to flexibly address these pluggable services from end-points. As a demonstrative example, we implement an in network service that does rate adaptation when delivering video streams to mobile devices that experience variable connection quality. We present details of our deployment and evaluation of the non-IP protocols along with compute-layer extensions on the GENI test bed, where we used a set of programmable nodes across 7 distributed sites to configure a Mobility First network with hosts, routers, and in-network compute services. Francesco Bronzino, Yang Chen 0001, Kiran Nagaraja, Xiaowei Yang 0001, Ivan Seskar, Dipankar Raychaudhuri |
ICNP | 5 |
| 2014 | Leveraging Social Feedback to Verify Online Identity ClaimsabstractAnonymity is one of the main virtues of the Internet, as it protects privacy and enables users to express opinions more freely. However, anonymity hinders the assessment of the veracity of assertions that online users make about their identity attributes, such as age or profession. We propose FaceTrust, a system that uses online social networks to provide lightweight identity credentials while preserving a user’s anonymity. FaceTrust employs a “game with a purpose” design to elicit the opinions of the friends of a user about the user’s self-claimed identity attributes, and uses attack-resistant trust inference to assign veracity scores to identity attribute assertions. FaceTrust provides credentials, which a user can use to corroborate his assertions. We evaluate our proposal using a live Facebook deployment and simulations on a crawled social graph. The results show that our veracity scores are strongly correlated with the ground truth, even when dishonest users make up a large fraction of the social network and employ the Sybil attack. Michael Sirivianos, Kyungbaek Kim, Jian Wei Gan, Xiaowei Yang 0001 |
ACM Trans. Web | 4 |
| 2012 | DARD: Distributed Adaptive Routing for Datacenter NetworksabstractData center networks typically have many paths connecting each host pair to achieve high bisection bandwidth for arbitrary communication patterns. Fully utilizing the bisection bandwidth may require flows between the same source and destination pair to take different paths. However, existing routing protocols have little support for load-sensitive adaptive routing. We propose DARD, a Distributed Adaptive Routing architecture for Data center networks. DARD allows each end host to move traffic from overloaded paths to under loaded paths without central coordination. We use an Open Flow implementation and simulations to show that DARD can effectively use a data center network's bisection bandwidth under both static and dynamic traffic patterns. It outperforms previous solutions based on random path selection by 10%, and performs similarly to previous work that assigns flows to paths using a centralized controller. We use competitive game theory to show that DARD's path selection algorithm makes progress in every step and converges to a Nash equilibrium in finite steps. Our evaluation results suggest that DARD can achieve a close-to-optimal solution in practice. Xiaowei Yang 0001 |
ICDCS | 2 |
| 2012 | Aiding the Detection of Fake Accounts in Large Scale Social Online Services
Qiang Cao 0005, Michael Sirivianos, Xiaowei Yang 0001, Tiago Pregueiro |
NSDI | 3 |
| 2012 | FaaS: filtering IP spoofing traffic as a serviceabstractNo abstract available. Bingyang Liu, Jun Bi, Xiaowei Yang 0001 |
SIGCOMM | 3 |
| 2012 | NetPilot: automating datacenter network failure mitigationabstractDriven by the soaring demands for always-on and fast-response online services, modern datacenter networks have recently undergone tremendous growth. These networks often rely on commodity hardware to reach immense scale while keeping capital expenses under check. The downside is that commodity devices are prone to failures, raising a formidable challenge for network operators to promptly handle these failures with minimal disruptions to the hosted services. Daniel Turner, Chao-Chih Chen, David A. Maltz, Xiaowei Yang 0001, Ming Zhang 0005 |
SIGCOMM | 5 |
| 2011 | SocialFilter: Introducing social trust to collaborative spam mitigationabstractWe propose SocialFilter, a trust-aware collaborative spam mitigation system. Our proposal enables nodes with no email classification functionality to query the network on whether a host is a spammer. It employs Sybil-resilient trust inference to weigh the reports concerning spamming hosts that collaborating spam-detecting nodes (reporters) submit to the system. It weighs the spam reports according to the trustworthiness of their reporters to derive a measure of the system's belief that a host is a spammer. SocialFilter is the first collaborative unwanted traffic mitigation system that assesses the trustworthiness of spam reporters by both auditing their reports and by leveraging the social network of the reporters' administrators. The design and evaluation of our proposal offers us the following lessons: a) it is plausible to introduce Sybil-resilient Online-Social-Network-based trust inference mechanisms to improve the reliability and the attack-resistance of collaborative spam mitigation; b) using social links to obtain the trustworthiness of reports concerning spammers can result in comparable spam-blocking effectiveness with approaches that use social links to rate-limit spam (e.g., Ostra); c) unlike Ostra, in the absence of reports that incriminate benign email senders, SocialFilter yields no false positives. Michael Sirivianos, Kyungbaek Kim, Xiaowei Yang 0001 |
INFOCOM | 3 |
| 2011 | Bootstrapping Accountability in the Internet We Have
Ang Li 0002, Xin Liu 0059, Xiaowei Yang 0001 |
NSDI | 3 |
| 2011 | CloudProphet: towards application performance prediction in cloudabstractChoosing the best-performing cloud for one's application is a critical problem for potential cloud customers. We propose CloudProphet, a trace-and-replay tool to predict a legacy application's performance if migrated to a cloud infrastructure. CloudProphet traces the workload of the application when running locally, and replays the same workload in the cloud for prediction. We discuss two key technical challenges in designing CloudProphet, and some preliminary results using a prototype implementation. Ang Li 0002, Xuanran Zong, Srikanth Kandula, Xiaowei Yang 0001, Ming Zhang 0005 |
SIGCOMM | 4 |
| 2010 | CloudCmp: comparing public cloud providersabstractWhile many public cloud providers offer pay-as-you-go computing, their varying approaches to infrastructure, virtualization, and software services lead to a problem of plenty. To help customers pick a cloud that fits their needs, we develop CloudCmp, a systematic comparator of the performance and cost of cloud providers. CloudCmp measures the elastic computing, persistent storage, and networking services offered by a cloud along metrics that directly reflect their impact on the performance of customer applications. CloudCmp strives to ensure fairness, representativeness, and compliance of these measurements while limiting measurement cost. Applying CloudCmp to four cloud providers that together account for most of the cloud customers today, we find that their offered services vary widely in performance and costs, underscoring the need for thoughtful provider selection. From case studies on three representative cloud applications, we show that CloudCmp can guide customers in selecting the best-performing provider for their applications. Ang Li 0002, Xiaowei Yang 0001, Srikanth Kandula, Ming Zhang 0005 |
Internet Measurement Conference | 2 |
| 2010 | NetFence: preventing internet denial of service from inside outabstractDenial of Service (DoS) attacks frequently happen on the Internet, paralyzing Internet services and causing millions of dollars of financial loss. This work presents NetFence, a scalable DoS-resistant network architecture. NetFence uses a novel mechanism, secure congestion policing feedback, to enable robust congestion policing inside the network. Bottleneck routers update the feedback in packet headers to signal congestion, and access routers use it to police senders' traffic. Targeted DoS victims can use the secure congestion policing feedback as capability tokens to suppress unwanted traffic. When compromised senders and receivers organize into pairs to congest a network link, NetFence provably guarantees a legitimate sender its fair share of network resources without keeping per-host state at the congested link. We use a Linux implementation, ns-2 simulations, and theoretical analysis to show that NetFence is an effective and scalable DoS solution: it reduces the amount of state maintained by a congested router from per-host to at most per-(Autonomous System). Xin Liu 0059, Xiaowei Yang 0001, Yong Xia 0008 |
SIGCOMM | 2 |
| 2010 | Improving XCP to achieve max-min fair bandwidth allocation
Xiaowei Yang 0001, Yanbin Lu, Lei Zan |
Comput. Networks | 1 |
| 2010 | Ads-portal domains: Identification and measurementsabstractAn ads-portal domain refers to a Web domain that shows only advertisements, served by a third-party advertisement syndication service, in the form of ads listing. We develop a machine-learning-based classifier to identify ads-portal domains, which has 96% accuracy. We use this classifier to measure the prevalence of ads-portal domains on the Internet. Surprisingly, 28.3/25% of the (two-level) *. com /*. net web domains are ads-portal domains. Also, 41/39.8% of *. com /*. net ads-portal domains are typos of well-known domains, also known as typo-squatting domains. In addition, we use the classifier along with DNS trace files to estimate how often Internet users visit ads-portal domains. It turns out that ∼5% of the two-level *. com , *. net , *. org , *. biz and *. info web domains on the traces are ads-portal domains and ∼50% of these accessed ads-portal domains are typos. These numbers show that ads-portal domains and typo-squatting ads-portal domains are prevalent on the Internet and successful in attracting many visits. Our classifier represents a step towards better categorizing the web documents. It can also be helpful to search engines ranking algorithms, helpful in identifying web spams that redirects to ads-portal domains, and used to discourage access to typo-squatting ads-portal domains. Mishari Al Mishari, Xiaowei Yang 0001 |
ACM Trans. Web | 2 |
| 2009 | SafeGuard: safe forwarding during route changesabstractThis paper presents the design and evaluation of SafeGuard, an intra-domain routing system that can safely forward packets to their destinations even when routes are changing. SafeGuard is based on the simple idea that packets carry a destination address plus a local estimate of the remaining path cost. We show that this simple design enables routers to detect path inconsistencies during route changes and resolve on a working path for anticipated failure and restoration scenarios. This in turn means that route changes do not disrupt connectivity although routing tables are inconsistent over the network. We evaluate the router performance of SafeGuard using a prototype based on NetFPGA and Quagga. We show that SafeGuard is amenable to high-speed hardware implementation with low overhead. We evaluate the network performance of SafeGuard via simulation. The results show that SafeGuard converges faster than a state-of-the-art IP fast restoration mechanism and reduces periods of disruption to a minimal duration, i.e., the failure detection time. Ang Li 0002, Xiaowei Yang 0001, David Wetherall |
CoNEXT | 2 |
| 2009 | Internet Protocol Made Accountable
Xiaowei Yang 0001, Xin Liu 0059 |
HotNets | 1 |
| 2009 | Robust and efficient incentives for cooperative content distribution
Michael Sirivianos, Xiaowei Yang 0001, Stanislaw Jarecki |
IEEE/ACM Trans. Netw. | 2 |
| 2008 | Passport: Secure and Adoptable Source Authentication
Xin Liu 0059, Ang Li 0002, Xiaowei Yang 0001, David Wetherall |
NSDI | 3 |
| 2008 | To filter or to authorize: network-layer DoS defense against multimillion-node botnetsabstractThis paper presents the design and implementation of a filter-based DoS defense system (StopIt) and a comparison study on the effectiveness of filters and capabilities. Central to the StopIt design is a novel closed-control, open-service architecture: any receiver can use StopIt to block the undesired traffic it receives, yet the design is robust to various strategic attacks from millions of bots, including filter exhaustion attacks and bandwidth flooding attacks that aim to disrupt the timely installation of filters. Our evaluation shows that StopIt can block the attack traffic from a few millions of attackers within tens of minutes with bounded router memory. We compare StopIt with existing filter-based and capability-based DoS defense systems under simulated DoS attacks of various types and scales. Our results show that StopIt outperforms existing filter-based systems, and can prevent legitimate communications from being disrupted by various DoS flooding attacks. It also outperforms capability-based systems in most attack scenarios, but a capability-based system is more effective in a type of attack that the attack traffic does not reach a victim, but congests a link shared by the victim. These results suggest that both filters and capabilities are highly effective DoS defense mechanisms, but neither is more effective than the other in all types of DoS attacks. Xin Liu 0059, Xiaowei Yang 0001, Yanbin Lu |
SIGCOMM | 2 |
| 2008 | TVA: a DoS-limiting network architecture
Xiaowei Yang 0001, David Wetherall, Thomas E. Anderson |
IEEE/ACM Trans. Netw. | 1 |
| 2007 | On improving the efficiency and manageability of NotViaabstractThis paper presents techniques that improve the efficiency and manageability of an IP Fast Reroute (IPFRR) technology: NotVia. NotVia provides the IPFRR service for all destinations in an ISP's network upon any single link or node failure, while previous proposals such as Loop-free Alternates (LFA) can not guarantee this level of coverage. However, NotVia increases the computational and memory costs of the IPFRR service, and poses new challenges to network management, as routers are unaware of the links and nodes (hence the amount of traffic) that they actually protect. This paper introduces three techniques: NotVia aggregation, prioritized NotVia computation, and the rNotVia algorithm that collectively reduce the overhead of NotVia and improve its manageability. We use simulations to evaluate these techniques on real ISP topologies as well as on randomly generated topologies. The results show that the computational and memory overhead of NotVia are reduced to a fraction of their previous values on various topologies, suggesting that the techniques proposed in this paper make NotVia a more efficient and easy-to-manage IPFRR solution. Ang Li 0002, Pierre François, Xiaowei Yang 0001 |
CoNEXT | 3 |
| 2007 | Improving XCP to Achieve Max-Min Fair Bandwidth Allocation
Lei Zan, Xiaowei Yang 0001 |
Networking | 2 |
| 2007 | Dandelion: Cooperative Content Distribution with Robust Incentives
Michael Sirivianos, Jong Han Park, Xiaowei Yang 0001, Stanislaw Jarecki |
USENIX ATC | 3 |
| 2007 | NIRA: a new inter-domain routing architecture
Xiaowei Yang 0001, David D. Clark, Arthur W. Berger |
IEEE/ACM Trans. Netw. | 1 |
| 2006 | A Technical Approach to Net Neutrality
Xiaowei Yang 0001, Gene Tsudik, Xin Liu 0059 |
HotNets | 1 |
| 2006 | Source selectable path diversity via routing deflectionsabstractWe present the design of a routing system in which end-systems set tags to select non-shortest path routes as an alternative to explicit source routes. Routers collectively generate these routes by using tags as hints to independently deflect packets to neighbors that lie off the shortest-path. We show how this can be done simply, by local extensions of the shortest path machinery, and safely, so that loops are provably not formed. The result is to provide end-systems with a high-level of path diversity that allows them to bypass unde-sirable locations within the network. Unlike explicit source routing, our scheme is inherently scalable and compatible with ISP policies because it derives from the deployed Internet routing. We also sug-gest an encoding that is compatible with common IP usage, making our scheme incrementally deployable at the granularity of individual routers. Xiaowei Yang 0001, David Wetherall |
SIGCOMM | 1 |
| 2005 | A DoS-limiting network architectureabstractWe present the design and evaluation of TVA, a network architecture that limits the impact of Denial of Service (DoS) floods from the outset. Our work builds on earlier work on capabilities in which senders obtain short-term authorizations from receivers that they stamp on their packets. We address the full range of possible attacks against communication between pairs of hosts, including spoofed packet floods, network and host bottlenecks, and router state exhaustion. We use simulation to show that attack traffic can only degrade legitimate traffic to a limited extent, significantly outperforming previously proposed DoS solutions. We use a modified Linux kernel implementation to argue that our design can run on gigabit links using only inexpensive off-the-shelf hardware. Our design is also suitable for transition into practice, providing incremental benefit for incremental deployment. Xiaowei Yang 0001, David Wetherall, Thomas E. Anderson |
SIGCOMM | 1 |
| 2004 | Compact Routing on Internet-like GraphsabstractThe Thorup-Zwick (TZ) compact routing scheme is the first generic stretch-3 routing scheme delivering a nearly optimal per-node memory upper bound. Using both direct analysis and simulation, we derive the stretch distribution of this routing scheme on Internet-like inter-domain topologies. By investigating the TZ scheme on random graphs with power-law node degree distributions, P/sub k//spl sime/k/sup -/spl gamma//, we find that the average TZ stretch is quite low and virtually independent of /spl gamma/. In particular, for the Internet inter-domain graph with /spl gamma//spl sime/2.1, the average TZ stretch is around 1.1, with up to 70% of all pairwise paths being stretch-1 (shortest possible). As the network grows, the average stretch slowly decreases. We find routing table sizes to be very small (around 50 records for 104-node networks), well below their theoretical upper bounds. Furthermore, we find that both the average shortest path length (i.e. distance) d~ and width of the distance distribution /spl sigma/ observed in the real Internet inter-AS graph have values that are very close to the minimums of the average stretch in the d~- and /spl sigma/ -directions. This leads us to the discovery of a unique critical point of the average TZ stretch as a function of d~ and /spl sigma/. The Internet's distance distribution is located in a close neighborhood of this point. This is remarkable given the fact that the Internet inter-domain topology has evolved without any direct attention paid to properties of the stretch distribution. It suggests the average stretch function may be an indirect indicator of the optimization criteria influencing the Internet's inter-domain topology evolution. Dmitri V. Krioukov, Kevin R. Fall, Xiaowei Yang 0001 |
INFOCOM | 3 |
| 2002 | Designing traffic profiles for bursty Internet trafficabstractThe paper proposes a new class of traffic profiles that is better suited for metering bursty Internet traffic streams than the traditional token bucket profile. A good traffic profile should satisfy two criteria: first, it should consider packets from a conforming traffic stream as in-profile with high probability to ensure a strong QoS guarantee; second, it should limit the network resources consumed by a non-conforming traffic stream to no more than that consumed by a conforming stream. We model a bursty Internet traffic stream as an ON/OFF stream, where both the ON-period and the OFF-period have a heavy-tailed distribution. Our study shows that the heavy-tailed distribution leads to an excessive randomness in the long-term session rate distribution. Therefore, it is inherently difficult for any profile that limits the long-term average session rate to give a strong QoS guarantee for the conforming traffic streams. Our simulation demonstrates that a token bucket profile that couples the average rate control and the burst size control has a weak QoS guarantee. Based on this result, we propose a new class of traffic profiles that decouples the long term average rate control from the burst size control. Compared to a token bucket profile, this profile improves the level of QoS for a conforming traffic stream, yet limits the "effective bandwidth" consumed by a non-conforming traffic stream. Xiaowei Yang 0001 |
GLOBECOM | 1 |
| 2001 | A passive approach for detecting shared bottlenecksabstractThere is a growing interest in discovering Internet path characteristics using end-to-end measurements. However, the current mechanisms for performing this task either send probe traffic, or require the sender to cooperate by time stamping the packets or sending them back-to-back. Furthermore, most of these techniques require the packets to carry sequence numbers to detect losses, and a few of them assume the existence of multicast. This paper introduces a completely passive approach for learning Internet path characteristics. In particular, we show that by noting the time difference between consecutive packets, a passive observer can cluster the flows into groups, such that all the flows in one group share the same bottleneck. Our approach relies on the observation that the correct clustering minimizes the entropy of the inter-packet spacing seen by the observer. It does not inject any probe traffic into the network, does not require any cooperation from the senders, and works with any type of traffic whether it is TCP, UDP, or even multicast. Dina Katabi, Issam Bazzi, Xiaowei Yang 0001 |
ICCCN | 3 |
| 1999 | A Model for Window Based Flow Control in Packet-Switched NetworksabstractNetworks have increased rapidly both in scale and speed. Problems related to the control and management are of increasing interest. The average throughput and end-to-end delay of a network flow are important design factors. However, there is no satisfactory tool to obtain such parameters. The traditional packet-by-packet event driven simulation is slow when the network speed is high. The time driven simulation faces the difficulty of choosing the right time interval when simulating packet-switched networks. As the Transmission Control Protocol (TCP) is the most widely used transport layer protocol, and it uses a window based flow control mechanism, classic queuing theories involving Markov chain assumptions are not applicable. This paper describes a model for window based flow control packet-switched networks. The model attempts to provide a way to obtain the steady state results for large and high speed networks using TCP. We discuss in detail the construction, implementation and application of the model. This paper also compares the results obtained from the model with those from the packet-by-packet event driven simulation. The comparison shows the model is correctly modeling the networks. Xiaowei Yang 0001 |
INFOCOM | 1 |