SearcharxivSearch

arXiv subjects

Wanqing Tu

Publications and source records attributed to Wanqing Tu.

7 recordsLinked to original sources

A Binary and System Integrated Analysis Approach for Securing the QUIC Protocol

The Quick UDP Internet Connections (QUIC) protocol is increasingly used to provide secure transport for Internet of Things (IoT) firmware and applications. Existing security analyses of QUIC focus on the captured network traffic, while binary-level analyses of QUIC implementations remain unexplored, leaving open the question of whether a defence specified by the QUIC standard is both present in the compiled binary and active when the server is under attack. This paper evaluates the Binary and System Integrated Security Analysis (BSISA) approach, in which a binary-level analysis of the compiled QUIC server is combined with a system-level analysis of the captured network traffic, on four production QUIC server implementations under six attack scenarios. Across 24 cells, the combined classifier configuration is the only configuration that correctly classifies at least one cell on every attack scenario, achieving 45.8% overall accuracy compared with 37.5% for the binary-level configuration and 25.0% for the system-level configuration. BSISA also identifies the specific defence function in the compiled binary that absorbed each attack, and flags declared-but-silent defences, routines that are present in the compiled binary (Retry-token validation in three of four stacks, anti-amplification in quiche) but never execute during attack, a class of finding that network capture alone cannot produce. In terms of efficiency, picoquic loses legitimate-client availability under slowloris and connection- ID exhaustion with failure rates of 72.4% and 73.3% respectively, while the other three implementations hold the failure rate at or below 0.5%. We hope these insights will be informative for QUIC security evaluations in IoT firmware deployments.

cs.NI

Turn Your Face Into An Attack Surface: Screen Attack Using Facial Reflections in Video Conferencing

In video conferencing, human faces serve as the primary visual focal points, playing multifaceted roles that enhance visual communication and emotional connection. However, we argue that a human face is also a side channel, which can unwittingly leak on-screen information through online video feeds. To demonstrate this, we conduct feasibility studies, which reveal that, illuminated by both ambient light and light emitted from displays, the human face can reflect optical variations of different on-screen content. The paper then proposes FaceTell, a novel side-channel attack system that eavesdrops on fine-grained application activities from pervasive yet subtle facial reflections during video conferencing. We implement FaceTell in a real-world testbed with three different brands of laptops and four mainstream video conferencing platforms. FaceTell is then evaluated with 24 human subjects across 13 unique indoor environments. With more than 12 hours of video data, FaceTell achieves a high accuracy of 99.32% for eavesdropping on 28 popular applications and is resilient to many practical impact factors. Finally, potential countermeasures are proposed to mitigate this new attack.

cs.CR

T2T: Captioning Smartphone Activities Using Mobile Traffic

This paper studies the creation of textual descriptions of user activities and interactions on smartphones. Our approach of referring to encrypted mobile traffic exceeds traditional smartphone activity classification methods in terms of model scalability and output readability. The paper addresses two obstacles to the realization of this idea: the semantic gap between traffic features and smartphone activity captions, and the lack of textually annotated traffic data. To overcome these challenges, we introduce a novel smartphone activity captioning system, called T2T (Traffic-to-Text). T2T consists of a flow feature encoder that converts low-level traffic characteristics into meaningful latent features and a caption decoder to yield readable transcripts of smartphone activities. In addition, T2T achieves the automatic textual annotation of mobile traffic by feeding synchronized screen capture videos into the Qwen-VL-Max vision-language model, and proposing multi-stage losses for effective cross-model training. We evaluate T2T on 40,000 traffic-description pairs collected in two real-world environments, involving 8 smartphone users and 20 mobile apps. T2T achieves a BLEU-4 score of 58.1, a METEOR score of 38.3, a ROUGE-L score of 70.5, and a CIDEr score of 108.7. The quantitative and qualitative analyses show that T2T can generate semantically accurate captions that are comparable to the vision-language model.

cs.CR

Securing UAV Communications by Fusing Cross-Layer Fingerprints

The open nature of wireless communications renders unmanned aerial vehicle (UAV) communications vulnerable to impersonation attacks, under which malicious UAVs can impersonate authorized ones with stolen digital certificates. Traditional fingerprint-based UAV authentication approaches rely on a single modality of sensory data gathered from a single layer of the network model, resulting in unreliable authentication experiences, particularly when UAVs are mobile and in an open-world environment. To transcend these limitations, this paper proposes SecureLink, a UAV authentication system that is among the first to employ cross-layer information for enhancing the efficiency and reliability of UAV authentication. Instead of using single modalities, SecureLink fuses physical-layer radio frequency (RF) fingerprints and application-layer micro-electromechanical system (MEMS) fingerprints into reliable UAV identifiers via multimodal fusion. SecureLink first aligns fingerprints from channel state information measurements and telemetry data, such as feedback readings of onboard accelerometers, gyroscopes, and barometers. Then, an attention-based neural network is devised for in-depth feature fusion. Next, the fused features are trained by a multi-similarity loss and fed into a one-class support vector machine for open-world authentication. We extensively implement our SecureLink using three different types of UAVs and evaluate it in different environments. With only six additional data frames, SecureLink achieves a closed-world accuracy of 98.61% and an open-world accuracy of 97.54% with two impersonating UAVs, outperforming the existing approaches in authentication robustness and communication overheads. Finally, our datasets collected from these experiments are available on GitHub: https://github.com/PhyGroup/SecureLink\_data.

cs.CR

Resource-Efficient Seamless Transitions For High-Performance Multi-hop UAV Multicasting

Many UAV-related applications require group communications between UAVs to reliably and efficiently deliver rich media content as well as to extend line-of-sight coverage between sky and ground. This paper studies fast yet resource-efficient UAV transitions while maintaining high multicasting performance. We develop a set of analytic and algorithmic results to form the efficient transition formation (ETF) algorithm that deals with different UAV transition scenarios in a multicasting environment. The ETF algorithm first evaluates the seamlessness of a straight-line trajectory (SLT), by processing low-complexity computations (e.g., Euclidean distances) or a chain of fast checks with controlled traffic overheads. For an interrupted SLT, ETF establishes a new trajectory consisting of a minimum number of seamless straight lines that join at specially selected locations in terms of controlling mobile UAVs' seamless travel distances. Our simulation studies quantify the multicasting performance gains that ETF allows, outperforming compared studies when seamlessly transiting UAV group members.

cs.NI

An Efficient Transition Algorithm For Seamless Drone Multicasting

Many drone-related applications (e.g., drone-aided video capture, drone traffic and safety management) require group communications between drones to efficiently disseminate data or reliably deliver critical information, making use of the line-of-sight coverage of drones to realise services that ground devices may not be capable of. This paper studies highperformance yet resource-efficient mobile drone multicasting via trajectory adjustment. We first analyse the trajectory adjustment condition to determine whether a straight-line trajectory is fully covered by the multicast or not, by conducting simple computation tasks and with controlled overhead traffic. We then propose the trajectory adjustment scheme to provide a new trajectory with controlled travel distances. The ETTA algorithm is finally presented to apply the trajectory adjustment condition and scheme to a drone transiting between forwarders whose coverage do not overlap. The algorithm relies on multicasting forwarders, instead of additional transition forwarders, to fully cover the adjusted trajectory, helping to control interference and network traffic load. Our NS2 simulation results demonstrate that ETTA, as compared to other mobile multicasts, can achieve guaranteed performance for drone receivers in a multicast with heavier traffic loads.

cs.NI

A Vehicle Transmission Scheduling Scheme for Supporting Vehicle Trust Management

Recent developments in advanced sensors, wireless communications and intelligent vehicle control technologies have enabled vehicles to detect traffic anomalies on the road and then notify surrounding vehicles to improve traffic safety. However, due to the high-speed movement of vehicles and the frequent topological changes between vehicles, it is difficult for vehicles to evaluate the credibility of received messages. Quite a lot of research effort has been carried out to establish various trustworthiness platforms. These studies mostly focus on how to enhance the accuracy of credibility evaluation, overlooking that the transmission performance may affect the quality of vehicle messages. In this paper, we aim to support the improvement of credibility evaluation in vehicle networks by enhancing the transmission experience of vehicles. The proposed solution utilizes the vehicle's trajectory information, detection range and a roadside unit (RSU) coverage to form a controlled number of detection zones, which guarantees that events can be detected and reported while limiting the number of transmission vehicles. Furthermore, our scheme takes account of vehicle credibility and interference ranges when selecting reporting vehicles, supporting the timely and reliable delivery of vehicles' event reports when accidents occur. Our ns2 evaluation shows that our scheme can greatly reduce delay and loss rates of vehicle messages to help existing studies on accurate vehicle credibility evaluation.

cs.NI