SearcharxivSearch

arXiv subjects

Geoffrey Xie

Publications and source records attributed to Geoffrey Xie.

4 recordsLinked to original sources

Generalizing UxV Network Control Optimization with Disruption Tolerant Networking

Military and disaster relief operations increasingly rely on unmanned vehicles (UxVs). It is important to develop a network control system (NCS) that can continuously coordinate and optimize the movement of UxVs based on mission objectives. However, prior research on NCS aims to always maintain a connected network topology, which limits the utility of the resulting systems. In this paper, we present an approach to systematically increase the topology flexibility for an NCS by leveraging the well-studied concept of disruption-tolerant networking (DTN). We design a DTN-compatible communication utility model that, while allowing some nodes to temporarily disconnect from others, provides for a fine-grain specification of the minimum communication frequency and the maximum hops permitted for message delivery between each pair of nodes. As such, the model supports what-if analyses before a mission to determine the best communication parameters to use for a given set of UxVs. Furthermore, we incorporate our communication model into an existing NCS and evaluate its performance in a simulated scenario involving the use of five UxVs searching for an enemy ship. The results show that our model not only enables the NCS to find the enemy ship faster but also facilitates new capabilities, such as dividing the UxVs into multiple teams responsible for different search areas.

cs.NI

Towards Centralized Orchestration of Cyber Protection Condition (CPCON)

The United States Cyber Command (USCYBERCOM) Cyber Protection Condition (CPCON) framework mandates graduated security postures across Department of Defense (DoD) networks, but current implementation remains largely manual, inconsistent, and error-prone. This paper presents a prototype system for centralized orchestration of CPCON directives, enabling automated policy enforcement and real-time threat response across heterogeneous network environments. Building on prior work in host-based intrusion response, our system leverages a policy-driven orchestrator to standardize security actions, isolate compromised subnets, and verify enforcement status. We validate the system through emulated attack scenarios, demonstrating improved speed, accuracy, and verifiability in CPCON transitions with human-in-the-loop oversight.

cs.CR

A Case for Network-wide Orchestration of Host-based Intrusion Detection and Response

Recent cyber incidents and the push for zero trust security underscore the necessity of monitoring host-level events. However, current host-level intrusion detection systems (IDS) lack the ability to correlate alerts and coordinate a network-wide response in real time. Motivated by advances in system-level extensions free of rebooting and network-wide orchestration of host actions, we propose using a central IDS orchestrator to remotely program the logic of each host IDS and collect the alerts generated in real time. In this paper, we make arguments for such a system concept and provide a high level design of the main system components. Furthermore, we have developed a system prototype and evaluated it using two experimental scenarios rooted from real-world attacks. The evaluation results show that the host-based IDS orchestration system is able to defend against the attacks effectively.

cs.CR

A Case for Enabling Delegation of 5G Core Decisions to the RAN

Under conventional 5G system design, the authentication and continuous monitoring of user equipment (UE) demands a reliable backhaul connection between the radio access network (RAN) and the core network functions (AMF, AUSF, UDM, etc.). This is not a given, especially in disaster response and military operations. We propose that, in these scenarios, decisions made by core functions can be effectively delegated to the RAN by leveraging the RAN's computing resources and the micro-service programmability of the O-RAN system architecture. This paper presents several concrete designs of core-RAN decision delegation, including caching of core decisions and replicating some of the core decision logic. Each design has revealed interesting performance and security trade-offs that warrant further investigation.

cs.NI