Graduation Year
2026
Document Type
Dissertation
Degree
Ph.D.
Degree Name
Doctor of Philosophy (Ph.D.)
Degree Granting Department
Computer Science and Engineering
Major Professor
Yao Liu, Ph.D.
Committee Member
Nasir Ghani, Ph.D.
Committee Member
Wenbo Shen, Ph.D.
Committee Member
Attila Yavuz, Ph.D.
Committee Member
Mehran Mozaffari Kermani, Ph.D.
Keywords
Advanced Persistent Threats, Data Provenance, Geolocation APIs, Network Security, Wi-Fi Spoofing Attacks, Reverse Engineering, Instruction Detection Systems
Abstract
Modern networked systems increasingly depend on wireless sensing and large-scale telemetry to provide critical services and maintain security. However, many of these systems function as black boxes or encounter significant scalability limitations, which leave them vulnerable to sophisticated adversaries. In this dissertation, I present my research on enhancing the security and efficiency of networked systems through measurement-driven vulnerability analysis and the design of scalable defense mechanisms.
First, I present my research on the security and privacy risks of Wi-Fi–based localization services. Although location spoofing attacks against Wi-Fi positioning systems have been studied for over a decade, constructing practical attacks in dense urban environments remains challenging due to the extensive deployment of legitimate Wi-Fi access points (APs). To address this gap, I systematically probe commercial Geolocation APIs as black-box localization systems from major vendors such as Google and Apple. Through this measurement-driven analysis, I identify a critical vulnerability in the Google Geolocation API, which estimates device location based on observable Wi-Fi AP information. I demonstrate that adversaries can reverse-engineer the underlying localization behavior, enabling practical and highly successful location-spoofing attacks even in urban areas with dense AP coverage. Beyond spoofing, I further show that this vulnerability introduces severe privacy risks.
Second, I address the scalability challenges of provenance-based intrusion detection for Advanced Persistent Threats (APTs). While fine-grained system logs enable accurate forensic analysis and precise attack reconstruction, their massive volume poses significant barriers to real-time deployment and practical adoption. To overcome this challenge, I present Nano, a real-time log reduction framework that consolidates execution dependencies into program-specific provenance while preserving attack-relevant relationships. Nano introduces two novel data structures: the profile hierarchy and the access network. Instead of maintaining fine-grained parent–child relationships between individual subjects, the profile hierarchy abstracts subject origins by capturing execution relationships among programs. Meanwhile, the access network merges activities of subjects that share identical execution sequences, consolidating their interactions into dependencies between executing programs and system entities, while carefully retaining dependencies associated with attack behaviors.
Finally, I outline my broader vision for strengthening security guarantees in localization systems and advancing scalable, practical defenses for provenance-based intrusion detection.
Scholar Commons Citation
Han, Xiao, "Understanding and Defending Large-Scale Networked Systems: From Wi-Fi Localization to Provenance- Based Intrusion Detection" (2026). USF Tampa Graduate Theses and Dissertations.
https://digitalcommons.usf.edu/etd/11299
