Deep Learning (DL) technologies have recently gained significant attention and have been applied to Network Intrusion Detection Systems (NIDS). However, DL is known to be vulnerable to adversarial attacks, which evade detection by introducing perturbations to input data. Meanwhile, eXplainable Artificial Intelligence (XAI) helps us to understand predictions made by DL models and is an essential technology for ensuring accountability. This paper focuses on the relationship between the DL model’s decision-making processes and adversarial examples (AEs) and proposes a new AE generation method based on XAI. Our method utilizes XAI to identify important features when making predictions and perturb them in real (traffic) space to evade detection by DL-based NIDS. We implemented our proposed method in a real-world network environment. We confirmed that our AEs completely evade detection without compromising the malicious nature of the attack communications. This experiment reveals that, unlike many existing studies, our proposed method is feasible in the traffic space.
For contemporary IT services, Wireless communication, facilitated by mobile phones, is a fundamental infrastructure. 5G comprises RAN (Radio Access Network) and Mobile Core (5GC) technologies. Specifically, 5GC handles communication from smartphones and IoT devices, enabling communication tailored to each use case, thereby solidifying its position as the Mobile Core system within the 5G network. With the recent proliferation of smartphones and IoT devices, along with advancements such as digital twins, there has been a substantial increase in traffic demand on 5GC. This surge has compelled telecom companies to invest heavily in equipment upgrades and operational maintenance to ensure stable 5GC communication. To address the challenges in the Mobile Core, our research has aimed at reimagining the 5GC architecture. We introduced Cloud5GC, a groundbreaking solution that transitions away from traditional function-based systematization towards a more cohesive micro Mobile core architecture. Implementing Cloud5GC on a public cloud platform demonstrated its flexibility, resilience, and fault-tolerance. Our findings underscore the architectural excellence of Cloud5GC, representing a significant advancement in 5G communications.
Low-Rate denial of service (LDoS) attacks degrade the quality of service with less traffic than ordinary DoS attacks. LDoS attacks can easily evade conventional counter-DoS detection mechanisms because their time-averaged flow is small and, therefore, become a serious problem. With the recent spread of IoT devices, Zigbee has attracted much attention. Zigbee is a low-power wireless communication protocol that sacrifices transfer range and bandwidth. Since Zigbee consumes very low power, it is widely adopted for small inexpensive IoT devices. The advantage of the low power consumption of Zigbee is due to the indirect transmission. We have already pointed out LDoS attack methods exploiting the characteristics of the indirect transmission, proposed algorithms detecting attackers, and evaluated the accuracy of the algorithms. In this paper, we focus on memory efficient implementation of the algorithm. First, we found that straightforward implementation of the algorithm needs large memory. Then, we propose an improved implementation which requires much less memory. Furthermore, we implement it on a resource-constrained single-board computer and confirm that our proposed algorithm can work correctly with much less memory space and shorter execution time than our previously proposed method. These results prove that the proposed detection algorithm is feasible for a wider range of IoT devices.
In standard Mobile Core Network (CN), a single Network Function (NF) serves a large number of User Equipments (UEs), and the context of a UE is kept across multiple NFs. This architecture has a large impact range when a problem or operation occurs in a NF, which may cause a major outage. In this paper, we propose novel 5G Core Network (5GC) architecture named Procedure-based 5GC (Proc5GC) that provides reactive and stateless procedural processing for each UE. This paper describes a proof-of-concept implementation of a minimum system of Proc5GC and confirms that it works.
We propose a novel distributed denial of service (DDoS) attack suppression system that significantly reduces discarding of normal traffic (i.e., the traffic from Internet of Things (IoT) devices that are not infected with a malware) with a small number of equipment by controlling the priority of frames in a network accommodating IoT devices. Experimental results showed that our proposed system prevented the discarding of the normal traffic in a few seconds when attack traffic was generated by a traffic generator. Moreover, we constructed Mirai-based DDoS attack traffic and experimentally demonstrated that the discarding of the normal traffic was prevented in 30 milliseconds in our proposed system. We also confirmed that the attack traffic detected by a DDoS protector that was installed in front of an IoT server was autonomously blocked at the switches that the traffic came through from the IoT devices (i.e., the entrances to a backbone network) by integrating various vendors’ products.
In software system testing using Bluetooth Low Energy (BLE), it is necessary to evaluate the system, including the wireless communication. However, it is difficult to build a test environment for testing with physical machines because of installation costs. This problem can be solved by emulation to reproduce BLE communication on computers; however, a BLE emulator is required. In this paper, we propose a BLE emulator called BluMoon for testing software systems using BLE. We impose the following requirements on the BLE emulator: (1) calculating the received signal strength for each frame and (2) imitating radio interference. To satisfy these requirements, we devised a software-implemented BLE controller with a host controller interface as a boundary and devised a data format called the BluMoon frame for sending and receiving data frame by frame. We designed and implemented BluMoon, and performed functional and performance evaluation as well as a comparative experiment with a physical environment. The results revealed that it is possible to implement a BLE emulator that meets the aforementioned requirements.
An aggregating switch (SW) network offers cost-effective accommodation to Internet-of-Things (IoT) traffic by aggregating the traffic. In such a network, it is crucial to eliminate the discarded traffic caused by the simultaneous transmission of massive IoT devices, namely microburst. Traffic shaping is a technique of storing traffic in one SW to mitigate microbursts. Conventional traffic shaping is limited because only one SW performs shaping with a limited queue length. Thus, we propose cooperated traffic shaping using multiple SWs to accommodate more traffic. We formulated equations to derive the minimum queue length with shaping rates which gradually decrease in geometric progression. To acquire the queue length using general SWs without short-cycle monitoring, we propose a scheme for estimating the instantaneous input rate and data size of microburst traffic required for our equations. If the calculated queue length cannot be prepared in the current path, we propose reallocating the path to another one with more SWs. We experimentally demonstrated the proposed coordinated traffic shaping technique by implementing it in commercial SWs with 125 emulated IoT devices. The results showed that the difference between the experimental and numerical results was below 4.2%, and the queue length can be reduced by 40% when there are three SWs. In addition, a path with two SWs was successfully reallocated to one with three SWs.
Services premised on wireless communication are diversifying, and their reliability of the communication is required. On the other hand, many factors are involved in the parameter change of the wireless section, and it is difficult to clearly determine the cause and effect when the wireless section is actually incorporated into the evaluation environment. By emulating the wireless section and fixing the quality of the wireless section, the behavior of the implementation of a specific wireless service can be efficiently evaluated. We have been developing StarBED, which is a large-scale network testbed built with wired networks, and NETorium, which enables application evaluation by imitating a wireless section on a wired network on a large scale. We are designing and prototyping supporting software that can flexibly introduce new functions as an alternative to the supporting software SpringOS that has been operated on StarBED. This paper describes the design of architecture and implementation of the supporting software when the wireless emulation function is realized as an additional function.
This demonstration shows an interactive urban flood damage prediction system "ARIA" that simulates urban flood, the sufferer, and network failure in an integrated manner. In terms of disaster mitigation, it is important to confirm an affected area and issue an evacuation advisory. ARIA predicts flood damages - the number of sufferers or the locations of flooded roads - and figures out the suitable timing of an evacuation advisory while incorporating actual measurement values like precipitation, river water level and person flow data observed during flood occurrence using data assimilation method. We propose flood damage prediction system, which cooperates conventional proprietary simulators for flood/evacuation/network damage analysis using simulation and emulation federation platform "Smithsonian". ARIA aims to accurately simulate actual disaster phenomena to consider how flood damages affect evacuation behavior based on the mutual impact of road condition and network damage caused by floods.
In the Internet of Things (IoT), Bluetooth Low Energy (BLE) plays the important role of providing a path between a terminal device and a gateway. For the development of BLE applications, testing is important; however, two major problems exist in that physical device preparation is costly and replay testing is difficult. To avoid these problems, we propose a novel approach to BLE application testing that employs emulation using the newly designed BluMoon architecture, which is a BLE emulation system with utilization software. The BluMoon emulation system design follows the communication model of actual BLE. However, BluMoon uses software-implemented pseudo controllers instead of physical controllers. Interaction with remote devices is emulated through exchange of virtual packets, where each virtual packet encapsulates an entire BLE link layer packet format in its payload. Here, we implement a pseudo controller with an advertising function, establishing a connection and exchanging data. We also evaluate the BluMoon implementation performance and measure the resource usage at BluMoon execution, the received packet loss rate, and the response time of HCI command execution. The results show that BluMoon exhibits performance satisfactory for practical application, for all measured items.
In this study, we propose AOBAKO, a testbed for context-aware applications, which focuses on the testing of mobile applications using Bluetooth Low Energy (BLE) for indoor positioning. AOBAKO emulates BLE-beacon communications based on accurate frame-level emulation. In the proposed testbed, the emulation result is transferred to a physical space and beacon frames are emitted via radio waves. AOBAKO makes it possible to verify context awareness in a mobile application and can reduce the cost of a field survey.
In the Internet of Things (loT), Bluetooth Low Energy (BLE) plays the important role of providing a path between a terminal device and a gateway. For the development of 131,E applications, testing is important; however, two major problems exist in that physical device preparation is costly and replay testing is difficult. To avoid these problems, we propose a novel approach to BLE application testing that employs emulation using the newly designed BluMoon architecture, which is a BLE emulation system with utilization software. The BluMoon emulation system design follows the communication model of actual BLE. However, BluMoon uses software -implemented pseudo controllers instead of physical controllers. Interaction with remote devices is emulated through exchange of virtual packets, where each virtual packet encapsulates an entire BLE link layer packet format in its payload. Here, we implement a pseudo controller with an advertising function, establishing a connection and exchanging data. We also evaluate the BluMoon implementation performance and measure the resource usage at Moon execution, the received packet loss rate, and the response time of HCI command execution. The results show that BluMoon exhibits performance satisfactory for practical application, for all measured items.
Testbed management tool is developed for the purpose of supporting user's experiments. On the other hand, there are researches that developed a tool to enable experiments that testbed does not targeted. Although there are requests from users for using these tools, many are not provided to users in Testbed. Therefore, it is necessary to provide a framework for users to easily use or implement such tools in Testbed.We aimed to make it possible to use new tools easily without modifying of conventional Testbed management tool by implementing subsystem on testbed. In this paper, we describe the result of a case study for building the environment on StarBED resources using TopDL description which is the topology description language proposed by DeterLab.
Wireless networks take advantage of various technologies that wired networks do not use, such as authentication and ad hoc networks. Although it is important to verify such wireless network technologies, it is expensive or technologically difficult to repeatedly reproduce the wireless environments required for verification. Additionally, large-scale wireless network environments such as IoT environments are also required for verification of wireless technologies. However, conventional verification approaches cannot provide large-scale wireless network environments that, emulate radio propagation or verify actual wireless technologies and applications. We propose NETorium, which provides large-scale wireless network environments that are suitable for verification of wireless network technologies. NETorium comprises Meteor, a radio propagation emulator, and Asteroid, a virtual wireless network software for building virtual wireless network environments that employ hardware emulators in a wired network. Meteor can handle network protocols that, conventional radio propagation emulators cannot and is capable of emulating radio propagation in large-scale wireless network environments. Asteroid constructs virtual wireless networks that can transmit actual wireless frames. We demonstrate that NETorium can handle 1000-node wireless networks; conventional approaches can only handle a maximum of 100 nodes. Additionally, a performance evaluation of a simulated network with WPA2 authentication in the ad hoc mode demonstrates that NETorium can emulate large-scale wireless network environments with high-fidelity.
Wireless networks take advantage of various technologies that wired networks do not use, such as authentication and ad hoc networks. Although it is important to verify such wireless network technologies, it is expensive or technologically difficult to repeatedly reproduce the wireless environments required for verification. Additionally, large-scale wireless network environments such as IoT environments are also required for verification of wireless technologies. However, conventional verification approaches cannot provide large-scale wireless network environments that, emulate radio propagation or verify actual wireless technologies and applications.
Application-level network traffic analysis and sophisticated analysis techniques such as machine learning and stream data processing for network traffic require considerable computational resources. In addition, developing an application protocol analyzer is a tedious and time-consuming task. Therefore, we propose a scalable and flexible traffic analysis platform (SF-TAP) that provides an efficient and flexible application-level stream analysis of high-bandwidth network traffic. Our platform's flexibility and modularity allow developers to easily implement multicore scalable application-level stream analyzers. Furthermore, SF-TAP is horizontally scalable and can therefore manage high-bandwidth network traffic. We achieve this scalability by separating network traffic based on traffic flows, forwarding the separated flows to multiple SF-TAP cells, each of which consists of a traffic capturer and application-level analyzers. In this study, we discuss the design and implementation of SF-TAP and provide details of its evaluation.
Follow the icons throughout the Conference Program below. You can combine days of training or workshops with days of Conference Program content to build the conference that meets your needs. Pick and choose the sessions that best fit your interest—focus on just one topic or mix and match.
IPv4 addresses are nearly exhausted worldwide. For some time until IPv6 becomes pervasive as an ultimate solution, deployment of Carrier Grade NAT (CGN) devices becomes necessary, especially in the mobile carriers' networks which anticipate a large and growing number of new users. In this context, we tackle the evaluation of the impact of inserting a CGN device in the network, and in conjunction with the mobile network communication delays. We compare the Connection Establishment Rate (CER) with or without a CGN device, also with or without the emulated mobile network communication delays. Against our anticipation, the types of time-varying mobile network delays do not have a significant impact on CER. The effect of the changing delay fades away in the aggregation of many user traffic at the core part of the network, even though the time-varying mobile network communication delays are individually and separately emulated for each user. To the best of our knowledge, this is the first to study the relationship between the CGN performance and the mobile network's communication delays. The result suggests that modeling the aggregate traffic trend (such as the constant delay portion in the network dynamics) is more important rather than emulating each user's traffic separately.
Yoichi Shinoda合作论文数Japan Advanced Institute of Science and Technology;Center for Information Science9