Source author record

Xiaojie Feng

Xiaojie Feng appears in the imported research catalog. Authorship, coauthor and topic links are available while profile ownership is still unclaimed.

ResearcherUnclaimed source record

Catalog footprint

What is connected

2works
3topics
4close collaborators

Actions

Connect this record

Log in to claim

Research graph

See the researcher in context

Open full explorer

Inspect adjacent papers, topics, institutions and collaborators without losing the researcher page.

Building this map preview

BZPEER is loading the nearby papers, people, topics and institutions for this page.

Published work

2 published item(s)

preprint2023arXiv

A Practical Runtime Security Policy Transformation Framework for Software Defined Networks

Software-defined networking (SDN) has been widely utilized to enforce the security of traditional networks, thereby promoting the process of transforming traditional networks into SDN networks. However, SDN-based security enforcement mechanisms rely heavily on the security policies containing the underlying information of data plane. With increasing the scale of underlying network, the current security policy management mechanism will confront more and more challenges. The security policy transformation for SDN networks is to research how to transform the high-level security policy without containing the underlying information of data plane into the practical flow entries used by the OpenFlow switches automatically, thereby implementing the automation of security policy management. Based on this insight, a practical runtime security policy transformation framework is proposed in this paper. First of all, we specify the security policies used by SDN networks as a system model of security policy (SPM). From the theoretical level, we establish the system model for SDN network and propose a formal method to transform SPM into the system model of flow entries automatically. From the practical level, we propose a runtime security policy transformation framework to solve the problem of how to find a connected path for each relationship of SPM in the data plane, as well as how to generate the practical flow entries according to the system model of flow entries. In order to validate the feasibility and effectiveness of the framework, we set up an experimental system and implement the framework with POX controller and Mininet emulator.

preprint2020arXiv

Progressive Neural Index Search for Database System

As a key ingredient of the DBMS, index plays an important role in the query optimization and processing. However, it is a non-trivial task to apply existing indexes or design new indexes for new applications, where both data distribution and query distribution are unknown. To address the issue, we propose a new indexing approach, NIS (Neural Index Search), which searches for the optimal index parameters and structures using a neural network. In particular, NIS is capable for building a tree-like index automatically for an arbitrary column that can be sorted/partitioned using a customized function. The contributions of NIS are twofold. First, NIS constructs a tree-like index in a layer-by-layer way via formalizing the index structure as abstract ordered and unordered blocks. Ordered blocks are implemented using B+-tree nodes or skip lists, while unordered blocks adopt hash functions with different configurations. Second, all parameters of the building blocks (e.g., fanout of B+-tree node, bucket number of hash function and etc.) are tuned by NIS automatically. We achieve the two goals for a given workload and dataset with one RNN-powered reinforcement learning model. Experiments show that the auto-tuned index built by NIS can achieve a better performance than the state-of-the-art index.