Guannan Liu 0003

dblp:02/8772-3 · DBLP profile ↗
← Back
9ranked-venue papers
4as first author
8since 2021 · last 2026
0000-0001-9165-420XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 2 first-author · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Too Open to be Secure: An Evaluation of OpenNIC DNS Services and Domains
Dianshi Yang, Xiaoqin Liang, Daiping Liu, Guannan Liu 0003, Shuai Hao 0001, Xing Gao 0001
DSN4
2025 Pathfinder: Exploring Path Diversity for Assessing Internet Censorship Inconsistency
abstract
Internet censorship is commonly enabled by authorities to enforce information control. So far, existing censorship studies have largely focused on country-level characterization, primarily because (1) censorship enforcement is often mandated through nationwide policies and (2) it is difficult to control the routing of probing packets to trigger censorship across different networks within a country. However, censorship mechanisms can vary significantly at the ISP level, revealing a more diverse landscape than previously assumed. In this paper, we investigate Internet censorship from a new perspective by scrutinizing diverse censorship deployments within a country. We design and deploy a measurement framework that utilizes multiple geo-distributed backend servers to probe various network paths from a single vantage point. By generating traffic targeting the same domain but different backend server IPs, we induce path diversity that exposes the traffic to distinct transit networks, and potentially, different censorship devices, thereby enabling a more granular analysis of censorship practices. Through our large-scale experiments and in-depth analysis, we reveal that diverse censorship resulting from varying routing paths within a country is widespread, implying that (1) the implementations of centralized censorship are commonly incomplete or flawed and (2) decentralized censorship is also prevalent. Moreover, we find that different hosting platforms also contribute to inconsistent censorship behavior due to their varying peering relationships with ISPs within a country. Finally, we present detailed case studies to illustrate the configurations that lead to such inconsistencies and to explore their underlying causes.
Xiaoqin Liang, Guannan Liu 0003, Lin Jin, Shuai Hao 0001, Haining Wang 0001
ACSAC2
2024 Poster: Acoustic Side-Channel Attack on Robot Vacuums
abstract
Robot vacuums have become a ubiquitous appliance, offering un- paralleled convenience and efficiency in maintaining cleanliness in both residential and commercial spaces. However, these devices also present a convenient method for attackers to gather information about the robot's surroundings. In this study, we investigate the feasibility of acoustic side-channel attacks on robot vacuums and demonstrate that sensitive information can be easily obtained by analyzing the sound produced by the robot. We extract various characteristic features and spectrograms from the sound emitted during robot movement and classify them using Multilayer Perception and Convolutional Neural Network. The evaluation results demonstrate the effectiveness of the acoustic attacks, with both machine learning models achieving more than 95% accuracy in classifying the robot's movement based on acoustic signals. Using our ML model, we demonstrate that robot cleaning path can be effectively identified with 96% accuracy. To mitigate such a threat, we perform a simulation where random noise is added to the sound samples, which effectively reduce the motion identification accuracy to 43%.
Peter Chen, Guannan Liu 0003, Haining Wang 0001
CCS2
2023 Dial "N" for NXDomain: The Scale, Origin, and Security Implications of DNS Queries to Non-Existent Domains
abstract
Non-Existent Domain (NXDomain) is one type of the Domain Name System (DNS) error responses, indicating that the queried domain name does not exist and cannot be resolved. Unfortunately, little research has focused on understanding why and how NXDomain responses are generated, utilized, and exploited. In this paper, we conduct the first comprehensive and systematic study on NXDomain by investigating its scale, origin, and security implications. Utilizing a large-scale passive DNS database, we identify 146,363,745,785 NXDomains queried by DNS users between 2014 and 2022. Within these 146 billion NXDomains, 91 million of them hold historic WHOIS records, of which 5.3 million are identified as malicious domains including about 2.4 million blocklisted domains, 2.8 million DGA (Domain Generation Algorithms) based domains, and 90 thousand squatting domains targeting popular domains. To gain more insights into the usage patterns and security risks of NXDomains, we register 19 carefully selected NXDomains in the DNS database, each of which received more than ten thousand DNS queries per month. We then deploy a honeypot for our registered domains and collect 5,925,311 incoming queries for 6 months, from which we discover that 5,186,858 and 505,238 queries are generated from automated processes and web crawlers, respectively. Finally, we perform extensive traffic analysis on our collected data and reveal that NXDomains can be misused for various purposes, including botnet takeover, malicious file injection, and residue trust exploitation.
Guannan Liu 0003, Lin Jin, Shuai Hao 0001, Yubao Zhang, Daiping Liu, Angelos Stavrou, Haining Wang 0001
IMC1
2022 Ready Raider One: Exploring the Misuse of Cloud Gaming Services
abstract
Cloud gaming has become an emerging computing paradigm in recent years, allowing computer games to offload complex graphics and logic computation to the cloud. To deliver a smooth and high-quality gaming experience, cloud gaming services have invested abundant computing resources in the cloud, including adequate CPUs, top-tier GPUs, and high-bandwidth Internet connections. Unfortunately, the abundant computing resources offered by cloud gaming are vulnerable to misuse and exploitation for malicious purposes. In this paper, we present an in-depth study on security vulnerabilities in cloud gaming services. Specifically, we reveal that adversaries can purposely inject malicious programs/URLs into the cloud gaming services via game mods. Using the provided features such as in-game subroutines, game launch options, and built-in browsers, adversaries are able to execute the injected malicious programs/URLs in cloud gaming services. To demonstrate that such vulnerabilities pose a serious threat, we conduct four proof-of-concept attacks on cloud gaming services. Two of them are to abuse the CPUs and GPUs in cloud gaming services to mine cryptocurrencies with attractive profits and train machine learning models at a trivial cost. The other two are to exploit the high-bandwidth connections provided by cloud gaming for malicious Command & Control and censorship circumvention. Finally, we present several countermeasures for cloud gaming services to protect their valuable assets from malicious exploitation.
Guannan Liu 0003, Daiping Liu, Shuai Hao 0001, Xing Gao 0001, Kun Sun 0001, Haining Wang 0001
CCS1
2022 Exploring the Unchartered Space of Container Registry Typosquatting
Guannan Liu 0003, Xing Gao 0001, Haining Wang 0001, Kun Sun 0001
USENIX Security Symposium1
2022 Investigating Security Vulnerabilities in a Hot Data Center with Reduced Cooling Redundancy
abstract
Data centers have been growing rapidly in recent years to meet the surging demand of cloud services. However, the expanding scale and powerful servers generate a great amount of heat, resulting in significant cooling costs. A trend in modern data centers is to raise the temperature and maintain all servers in a relatively hot environment. While this can save on cooling costs given benign workloads running in servers, the hot environment increases the risk of a cooling failure. In this article, we unveil a new vulnerability of existing data centers with aggressive cooling energy saving policies. Such a vulnerability might be exploited to launch thermal attacks that could severely worsen the thermal conditions in a data center. Specifically, we conduct thermal measurements and uncover effective thermal attack vectors at the server, rack, and data center levels. We also present damage assessments of thermal attacks. Our results demonstrate that thermal attacks can (1) largely increase the temperature of victim servers degrading their performance and reliability, (2) negatively impact on thermal conditions of neighboring servers causing local hotspots, (3) raise the cooling cost, and (4) even lead to cooling failures. Finally, we propose and evaluate effective server and data center level defenses to enhance thermal stabilities.
Xing Gao 0001, Guannan Liu 0003, Zhang Xu, Haining Wang 0001, Li Li 0064
IEEE Trans. Dependable Secur. Comput.2
2021 An Investigation of Identity-Account Inconsistency in Single Sign-On
abstract
Single Sign-On (SSO) has been widely adopted for online authentication due to its favorable usability and security. However, it also introduces a single point of failure since all service providers fully trust the identity of a user created by the SSO identity provider. In this paper, we investigate the identity-account inconsistency threat, a new SSO vulnerability that can cause the compromise of online accounts. The vulnerability exists because current SSO systems highly rely on a user’s email address to bind an account with a real identity, but ignore the fact that email addresses might be reused by other users. We reveal that under the SSO authentication, such inconsistency allows an adversary controlling a reused email address to take over associated online accounts without knowing any credentials like passwords. Specifically, we first conduct a measurement study on the account management policies for multiple cloud email providers, showing the feasibility of acquiring previously used email accounts. We further perform a systematic study on 100 popular websites using the Google business email service with our own domain address and demonstrate that most online accounts can be compromised by exploiting this inconsistency vulnerability. To shed light on email reuse in the wild, we analyze the commonly used naming conventions that lead to a wide existence of potential email address collisions, and conduct a case study on the account policies of U.S. universities. Finally, we propose several useful practices for end-users, service providers, and identity providers to protect against this identity-account inconsistency threat.
Guannan Liu 0003, Xing Gao 0001, Haining Wang 0001
WWW1
2016 Knowledge transfer: Does more experience yield improved design quality?
abstract
Engineers must be able to transfer knowledge from previous experiences in order to solve complex engineering tasks. Transfer of knowledge is described as “the learning process involved when a person learns to use previously acquired knowledge, skills, competence, or expertise in a new situation” Therefore, we sought to explore how previous engineering, design, and mathematics experiences impact the quality of a design solution. In this study, 23 first-year engineering students, with diverse mathematics and design experiences, participated in research study. In this study, each student completed a pre-study survey, designed a playground for a fictitious neighborhood while thinking aloud, and completed an interview immediately after completing the playground task. They were asked to reflect on previous mathematics and design experiences and asked to make comparisons between those experiences and the design study they had just completed. The design session and the interview were recorded and the design artifacts were collected. Using Hailikari's model, the research team investigated the how knowledge transfer may impact design solution quality. The findings of the research have implications for approaches educators can use to help students apply knowledge from previous experiences and design high quality solutions.
DeLean Tolbert, Reis Lehman, Guannan Liu 0003, Benjamin Sadler, Monica Cardella
FIE3