Jianfeng Li 0006

dblp:10/3844-6 · DBLP profile ↗
← Back
38ranked-venue papers
12as first author
26since 2021 · last 2026
0000-0002-3453-0195ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 18 · 8 first-author · 12 since 2021Security and privacy · 13 · 2 first-author · 10 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-authorSystems, architecture and hardware · 1
YearPublicationVenuePosition
2026 NEST: A Node-Interactive Generative Emulation Framework for Synthetic Traffic Generation
Jianfeng Li 0006, Jian Qu, Xiaobo Ma 0001
INFOCOM1
2026 $\mathbb {ABC}$ABC-$ {\mathbb{Channel}}$Channel: An Advanced Blockchain-Based Covert Channel
abstract
Establishing efficient and robust covert channels is crucial for secure communication within insecure network environments. With its inherent benefits of decentralization and anonymization, blockchain has gained considerable attention in developing covert channels. To guarantee a highly secure covert channel, channel negotiation should be contactlessbeforethe communication, carrier transaction features must be indistinguishable from normal transactionsduringthe communication, and communication identities must be untraceableafterthe communication. Such a full-lifecycle covert channel is indispensable to defend against a versatile adversary who intercepts two communicating parties comprehensively (e.g., on-chain and off-chain). Unfortunately, it has not been thoroughly investigated in the literature. We make the first effort to achieve a full-lifecycle covert channel, a novel blockchain-based covert channel namedABC-Channel. We tackle a series of challenges, such as off-chain contact dependency, increased masquerading difficulties as growing transaction volume, and time-evolving, communicable yet untraceable identities, to achieve contactless channel negotiation, indistinguishable transaction features, and untraceable communication identities, respectively. We develop a working prototype to validateABC-Channeland conduct extensive tests on the Bitcoin testnet. The experimental results demonstrate thatABC-Channelachieves substantially secure covert capabilities. In comparison to existing methods, it also exhibits state-of-the-art transmission efficiency.
Xiaobo Ma 0001, Pengyu Pan, Jianfeng Li 0006, Wei Wang 0012, Weizhi Meng 0001, Xiaohong Guan
IEEE Trans. Dependable Secur. Comput.3
2026 Characterizing Contactless Side-Channel Eavesdropping on Wireless Chargers
abstract
Today, there are an increasing number of smartphones equipped with wireless charging capabilities that use electromagnetic induction to transfer power from a wireless charger to devices that are being charged. In this paper, we unveil a novelcontactlessandcontext-awareside-channel attack in wire less charging, which harnesses two physical phenomena,i.e., the coil whine and the magnetic field perturbations, emanating from the wireless charging process and further infers user interactions on the charging smartphone. To validate the feasibility of this new side channel, we design and implement a three-stage attack framework, dubbed WISERS+, that first captures the coil whine and the magnetic field perturbation emitted by the wireless charger, then infers (i) inter-interface switches (e.g., switching from the home screen to an app interface) and (ii) intra-interface activities (e.g., keyboard inputs inside an app) to builduser interaction contexts, and further reveals sensitive information. We extensively evaluate the effectiveness of our proposed attacks with different commercial-off-the-shelf (COTS) smartphones and wireless chargers. Our evaluation results suggest that WISERS+canachieve over 90.4% accuracy in inferring sensitive information, such as the unlocking passcode on the screen and the launch of mobile apps. In addition, our study also demonstrates that WISERS+ is resilient to several practical impact factors, and presents its potential to be extended to attack the fast charging mode. Finally, we propose effective countermeasures and mitigate threats from the WISERS+ attack.
Tao Ni 0003, Chaoshun Zuo, Jianfeng Li 0006, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao
IEEE Trans. Dependable Secur. Comput.3
2026 AirCloak: An App-Transparent Traffic Cloaking Middleware Against Wireless Fingerprinting Attack
Huafeng Bian, Jianfeng Li 0006, Haodan Luo, Xiaobo Ma 0001, Zhenhua Li 0001, Jigang Wang, Wei Wang 0012
IEEE Trans. Netw.2
2026 Enabling Entangled Cache Probing for Remotely Reconstructing DNS Query Dynamics
Jianfeng Li 0006, Wen Li 0007, Qinyu Liu, Xiaobo Ma 0001, Wei Wang 0012, Xiapu Luo, Xiaohong Guan
IEEE Trans. Netw.1
2025 Cross-Environmental Website Fingerprinting
Jianfeng Li 0006, Xiaobo Ma 0001, Xiapu Luo, Xiaohong Guan
INFOCOM1
2025 Interpretable Defense Against Structural Adversarial Attacks on Android Malware Detection
abstract
Android, being one of the most widely used mobile systems, is facing pressing threats from malware. Despite the effectiveness of Android malware detection (AMD) systems, they are still vulnerable to state-of-the-art adversarial attacks. Existing defense methods require the knowledge of target adversaries, such as attack algorithms or obfuscation strategies, which is impractical in real-world scenarios. Additionally, these approaches may adversely affect the performance of the detection model and fail to defend against problem-space attacks, which not only deceive the detection models but also generate executable adversarial software. To address this research gap, we propose a novel interpretable Android guard system, named IADGuard, to help AMD defend against attacks. IADGuard first designs a novel graph explainable method, AGExplainer, to identify suspicious functions and invocations in adversarial malware. With the guidance of AGExplainer, IADGuard develops a rectifier to reverse adversarial modifications on apps’ function invocation relations, which facilitates the detection of adversarial malware by victim AMD. It is noteworthy that IADGuard requires zero knowledge of adversarial models and victim models, thereby preserves the performance of victim AMD. We validate IADGuard over three state-of-the-art problem space attacks that modify apps’ function invocation relations to deceive victim AMD. Experimental results show that IADGuard achieves over 90.5% defense success rate, i.e., helps victim AMD identify adversarial malware. Furthermore, AGExplainer surpasses representative interpreters in identifying essential modifications, helps IADGuard reduce false positives to 1.5%, and improves the detection efficiency by up to 10.4 times.
Wenying Wei, Kaifa Zhao, Hao Zhou 0043, Jianfeng Li 0006, Shuohan Wu, Ming Fan 0002, Xiapu Luo, Ting Wang 0006, Kai Zhou 0001, Ting Liu 0002, Yuzhe Tang
IEEE Trans. Inf. Forensics Secur.4
2024 DNSScope: Fine-Grained DNS Cache Probing for Remote Network Activity Characterization
abstract
The domain name system (DNS) is indispensable to nearly every Internet service. It has been extensively utilized for network activity characterization in passive and active approaches. Compared to the passive approach, active DNS cache probing is privacy-preserving and low-cost, enabling worldwide characterization of remote network activities in different networks. Unfortunately, existing probing-based methods are too coarse-grained to characterize the time-varying features of network activities, substantially limiting their applications in time-sensitive tasks. In this paper, we advance DNSScope, a fine-grained DNS cache probing framework by tackling three challenges: sample sparsity, observational distortion, and cache entanglement. DNSScope synthesizes statistical learning and self-supervised transfer learning to achieve time-varying characterization. Extensive evaluations demonstrate that it can accurately estimate the time-varying DNS query arrival rates on recursive DNS resolvers. Its average mean absolute error is 0.124, as low as one-sixth that of the baseline methods.
Jianfeng Li 0006, Xiaobo Ma 0001, Jian Qu, Xiapu Luo, Xiaohong Guan
INFOCOM1
2024 Following the "Thread": Toward Finding Manipulatable Bottlenecks in Blockchain Clients
abstract
Blockchain clients are the fundamental element of the blockchain network, each keeping a copy of the blockchain’s ledger. They play a crucial role in ensuring the network’s decentralization, integrity, and stability. As complex software systems, blockchain clients are not exempt from bottlenecks. Some bottlenecks create new attack surfaces, where attackers deliberately overload these weak points to congest client’s execution, thereby causing denial of service (DoS). We call them manipulatable bottlenecks. Existing research primarily focuses on a few such bottlenecks, and heavily relies on manual analysis. To the best of our knowledge, there has not been any study proposing a systematic approach to identify manipulatable bottlenecks in blockchain clients. To bridge the gap, this paper delves into the primary causes of bottlenecks in software, and develops a novel tool named ThreadNeck to monitor the symptoms that signal these issues during client runtime. ThreadNeck models the clients as a number of threads, delineating their inter-relationship to accurately characterize the client’s behavior. Building on this, we can identify the suspicious bottlenecks and determine if they could be exploited by external attackers. After applying ThreadNeck to four mainstream clients developed in different programming languages, we totally discover 13 manipulatable bottlenecks, six of which are previously unknown.
Shuohan Wu, Zihao Li 0001, Hao Zhou 0043, Xiapu Luo, Jianfeng Li 0006, Haoyu Wang 0003
ISSTA5
2024 Robust App Fingerprinting Over the Air
abstract
Mobile apps have significantly transformed various aspects of modern life, leading to growing concerns about privacy risks. Despite widespread encrypted communication, app fingerprinting (AF) attacks threaten user privacy substantially. However, existing AF attacks, when targeted at wireless traffic, face four fundamental challenges, namely 1) sample inseparability; 2) app multiplexing; 3) signal attenuation; and 4) open-world recognition. In this paper, we advance a novel AF attack, dubbed PacketPrint, to recognize app user activities over the air in an open-world setting. We introduce two novel models, i.e., sequential XGBoost and hierarchical bag-of-words model, to tackle sample inseparability and enhance robustness against noise packets arising from app multiplexing. We also propose the environment-aware model enhancement to bolster PacketPrint’s robustness in handling packet loss at the sniffer caused by signal attenuation. We conduct extensive experiments to evaluate the proposed attack in a series of challenging scenarios, including 1) open-world setting; 2) simultaneous use of different apps; 3) severe packet loss at the sniffer; and 4) cross-dataset recognition. The experimental results show that PacketPrint can accurately recognize app user activities. It achieves the average F1-score 0.947 for open-world app recognition and the average F1-score 0.959 for in-app user action recognition.
Jianfeng Li 0006, Jian Qu, Shuohan Wu, Hao Zhou 0043, Xiaobo Ma 0001, Ting Wang 0006, Xiapu Luo, Xiaohong Guan
IEEE/ACM Trans. Netw.1
2024 Website Fingerprinting on Encrypted Proxies: A Flow-Context-Aware Approach and Countermeasures
abstract
Website fingerprinting (WFP) could infer which websites a user is accessing via an encrypted proxy by passively inspecting the traffic characteristics of accessing different websites between the user and the proxy. Designing WFP attacks is crucial for understanding potential vulnerabilities of encrypted proxies, which guides the design of defensive measures against WFP. In this paper, we design a novel WFP attack against (popular) encrypted proxies that relay connections between the user and the proxy individually (e.g., Shadowsocks, V2Ray), and accordingly implement lightweight countermeasures to effectively defend against the attack. The attack features flow-context-aware and is both accurate and immediately deployable, because it fully considers the obstacle (dubbed training-testing asymmetry) that fundamentally limits the practicability of WFP and addresses the obstacle with built-in spatial-temporal flow correlation mechanism. We implement the countermeasure as middleboxes installed on both the client and server sides of encrypted proxies, without altering any existing infrastructures for compatibility. The middleboxes can obfuscate a website’s flow regularities across different visits. Large-scale experiments in real-world scenarios demonstrate that the WFP attack can generally achieve a detection rate above 98.8% with a false positive rate below 0.2%. The countermeasure forces the attack’s false positive rate to be above 0.2 and true positive rate to be below 0.9 with just five persistent TCP connections while introducing very limited bandwidth overhead (e.g., 0.49%) and almost-zero additional network latency.
Xiaobo Ma 0001, Jian Qu, Mawei Shi, Bingyu An, Jianfeng Li 0006, Xiapu Luo, Junjie Zhang 0004, Zhenhua Li 0001, Xiaohong Guan
IEEE/ACM Trans. Netw.5
2024 On Smartly Scanning of the Internet of Things
abstract
Cyber search engines, such as Shodan and Censys, have gained popularity due to their strong capability of indexing the Internet of Things (IoT). They actively scan and fingerprint IoT devices for unearthing IP-device mapping. Because of the large address space of the Internet and the mapping’s mutative nature, efficiently tracking the evolution of IP-device mapping with a limited budget of scans is essential for building timely cyber search engines. An intuitive solution is to use reinforcement learning to schedule more scans to networks with high churn rates of IP-device mapping. However, such an intuitive solution has never been systematically studied. In this paper, we take the first step toward demystifying this problem based on our experiences in maintaining a global IoT scanning platform. Inspired by the measurement study of large-scale real-world IoT scan records, we land reinforcement learning onto a system capable of smartly scanning IoT devices in a principled way. We disclose key parameters affecting the effectiveness of different scanning strategies, and real-world experiments demonstrate that our system can scan up to around 40 times as many IP-device mapping mutations as random/sequential scanning.
Jian Qu, Xiaobo Ma 0001, Wenmao Liu, Hongqing Sang, Jianfeng Li 0006, Lei Xue 0001, Xiapu Luo, Zhenhua Li 0001, Xiaohong Guan
IEEE/ACM Trans. Netw.5
2023 Demystifying DeFi MEV Activities in Flashbots Bundle
abstract
Decentralized Finance, mushrooming in permissionless blockchains, has attracted a recent surge in popularity. Due to the transparency of permissionless blockchains, opportunistic traders can compete to earn revenue by extracting Miner Extractable Value (MEV), which undermines both the consensus security and efficiency of blockchain systems. The Flashbots bundle mechanism further aggravates the MEV competition because it empowers opportunistic traders with the capability of designing more sophisticated MEV extraction. In this paper, we conduct the first systematic study on DeFi MEV activities in Flashbots bundle by developing ActLifter, a novel automated tool for accurately identifying DeFi actions in transactions of each bundle, and ActCluster, a new approach that leverages iterative clustering to facilitate us to discover known/unknown DeFi MEV activities. Extensive experimental results show that ActLifter can achieve nearly 100% precision and recall in DeFi action identification, significantly outperforming state-of-the-art techniques. Moreover, with the help of ActCluster, we obtain many new observations and discover 17 new kinds of DeFi MEV activities, which occur in 53.12% of bundles but have not been reported in existing studies.
Zihao Li 0001, Jianfeng Li 0006, Zheyuan He, Xiapu Luo, Ting Wang 0006, Xiaoze Ni, Wenwu Yang, Ting Chen 0002
CCS2
2023 CydiOS: A Model-Based Testing Framework for iOS Apps
abstract
To make an app stand out in an increasingly competitive market, developers must ensure its quality to deliver a better user experience. UI testing is a popular technique for quality assurance, which can thoroughly test the app from the users’ perspective. However, while considerable research has already studied UI testing on the Android platform, there is no research on iOS. This paper introduces CydiOS, a novel approach to performing model-based testing for iOS apps. CydiOS enhances the existing static analysis to build a more complete static model for the app under test. We propose an approach to retrieve runtime information to obtain real-time app context that can be mapped in the model. To improve the effectiveness of UI testing, we also introduce a potential-aware search algorithm to guide testing execution. We compare CydiOS with four representative algorithms(i.e., random, depth-first, stoat, and ape). We have evaluated CydiOS on 50 popular apps from App Store, and the results show that CydiOS outperforms other tools, achieving both higher code coverage and screen coverage. We open source CydiOS at https://github.com/SoftWare2022Testing/CydiOS, and a demo video can be found there.
Shuohan Wu, Jianfeng Li 0006, Hao Zhou 0043, Yongsheng Fang, Kaifa Zhao, Haoyu Wang 0001, Chenxiong Qian, Xiapu Luo
ISSTA2
2023 Exploiting Contactless Side Channels in Wireless Charging Power Banks for User Privacy Inference via Few-shot Learning
abstract
Recently, power banks for smartphones have begun to support wireless charging. Although these wireless charging power banks appear to be immune to most reported vulnerabilities in either power banks or wireless charging, we have found a new contactless wireless charging side channel in these power banks that leaks user privacy from their wireless charging smartphones without compromising either power banks or victim smartphones. We have proposed BankSnoop to demonstrate the practicality of the newly discovered wireless charging side channel in power banks. Specifically, it leverages the coil whine and magnetic field disturbance emitted by a power bank when wirelessly charging a smartphone and adopts the few-shot learning to recognize the app running on the smartphone and uncover keystrokes. We evaluate the effectiveness of BankSnoop using commodity wireless charging power banks and smartphones, and the results show it achieves over 90% accuracy on average in recognizing app launching and keystrokes. It also presents high adaptability when apply to different smartphone models, power banks, etc., achieving over 85% accuracy with 10-shot learning.
Tao Ni 0003, Jianfeng Li 0006, Xiaokuan Zhang, Chaoshun Zuo, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao
MobiCom2
2023 DeepInfer: Deep Type Inference from Smart Contract Bytecode
abstract
Smart contracts play an increasingly important role in Ethereum platform. It provides various functions implementing numerous services, whose bytecode runs on Ethereum Virtual Machine. To use services by invoking corresponding functions, the callers need to know the function signatures. Moreover, such signatures provide crucial information for many downstream applications, e.g., identifying smart contracts, fuzzing, detecting vulnerabilities, etc. However, it is challenging to infer function signatures from the bytecode due to a lack of type information. Existing work solving this problem depended heavily on limited databases or hard-coded heuristic patterns. However, these approaches are hard to be adapted to semantic differences in distinct languages and various compiler versions when developing smart contracts. In this paper, we propose a novel framework DeepInfer that first leverages deep learning techniques to automatically infer function signatures and returns. The novelties of DeepInfer are: 1) DeepInfer lifts the bytecode into the Intermediate Representation (IR) to preserve code semantics; 2) DeepInfer extracts the type-related knowledge (e.g., critical data flows, constant values, and control flow graphs) from the IR to recover function signatures and returns. We conduct experiments on Solidity and Vyper smart contracts and the results show that DeepInfer performs faster and more accurate than existing tools, while being immune to changes in different languages and various compiler versions.
Kunsong Zhao, Zihao Li 0001, Jianfeng Li 0006, He Ye, Xiapu Luo, Ting Chen 0002
ESEC/SIGSOFT FSE3
2023 Uncovering User Interactions on Smartphones via Contactless Wireless Charging Side Channels
abstract
Today, there is an increasing number of smartphones supporting wireless charging that leverages electromagnetic induction to transmit power from a wireless charger to the charging smartphone. In this paper, we report a new contactless and context-aware wireless-charging side-channel attack, which captures two physical phenomena (i.e., the coil whine and the magnetic field perturbation) generated during this wireless charging process and further infers the user interactions on the charging smartphone. We design and implement a three-stage attack framework, dubbed WISERS, to demonstrate the practicality of this new side channel. WISERS first captures the coil whine and the magnetic field perturbation emitted by the wireless charger, then infers (i) inter-interface switches (e.g., switching from the home screen to an app interface) and (ii) intra-interface activities (e.g., keyboard inputs inside an app) to build user interaction contexts, and further reveals sensitive information. We extensively evaluate the effectiveness of WISERS with popular smartphones and commercial-off-the-shelf (COTS) wireless chargers. Our evaluation results suggest that WISERS can achieve over 90.4% accuracy in inferring sensitive information, such as screen-unlocking passcode and app launch. In addition, our study also shows that WISERS is resilient to a list of impact factors.
Tao Ni 0003, Xiaokuan Zhang, Chaoshun Zuo, Jianfeng Li 0006, Zhenyu Yan 0002, Wubing Wang, Weitao Xu, Xiapu Luo, Qingchuan Zhao
SP4
2023 An Input-Agnostic Hierarchical Deep Learning Framework for Traffic Fingerprinting
Jian Qu, Xiaobo Ma 0001, Jianfeng Li 0006, Xiapu Luo, Lei Xue 0001, Junjie Zhang 0004, Zhenhua Li 0001, Xiaohong Guan
USENIX Security Symposium3
2022 Landing Reinforcement Learning onto Smart Scanning of The Internet of Things
abstract
Cyber search engines, such as Shodan and Censys, have gained popularity due to their strong capability of indexing the Internet of Things (IoT). They actively scan and fingerprint IoT devices for unearthing IP-device mapping. Because of the large address space of the Internet and the mapping’s mutative nature, efficiently tracking the evolution of IP-device mapping with a limited budget of scans is essential for building timely cyber search engines. An intuitive solution is to use reinforcement learning to schedule more scans to networks with high churn rates of IP-device mapping. However, such an intuitive solution has never been systematically studied. In this paper, we take the first step toward demystifying this problem based on our experiences in maintaining a global IoT scanning platform. Inspired by the measurement study of large-scale real-world IoT scan records, we land reinforcement learning onto a system capable of smartly scanning IoT devices in a principled way. We disclose key parameters affecting the effectiveness of different scanning strategies, and find that our system would achieve growing advantages with the proliferation of IoT devices.
Jian Qu, Xiaobo Ma 0001, Wenmao Liu, Hongqing Sang, Jianfeng Li 0006, Lei Xue 0001, Xiapu Luo, Zhenhua Li 0001, Xiaohong Guan
INFOCOM5
2022 Packet-Level Open-World App Fingerprinting on Wireless Traffic
Jianfeng Li 0006, Shuohan Wu, Hao Zhou 0043, Xiapu Luo, Ting Wang 0006, Xiaobo Ma 0001
NDSS1
2022 SAID: State-aware Defense Against Injection Attacks on In-vehicle Network
Lei Xue 0001, Kaifa Zhao, Jianfeng Li 0006, Le Yu 0002, Xiapu Luo, Yajin Zhou, Guofei Gu
USENIX Security Symposium5
2022 FOAP: Fine-Grained Open-World Android App Fingerprinting
Jianfeng Li 0006, Hao Zhou 0043, Shuohan Wu, Xiapu Luo, Ting Wang 0006, Xian Zhan, Xiaobo Ma 0001
USENIX Security Symposium1
2022 Inferring Hidden IoT Devices and User Interactions via Spatial-Temporal Traffic Fingerprinting
abstract
With the popularization of Internet of Things (IoT) devices in smart home and industry fields, a huge number of IoT devices are connected to the Internet. However, what devices are connected to a network may not be known by the Internet Service Provider (ISP), since many IoT devices are placed within small networks (e.g., home networks) and are hidden behind network address translation (NAT). Without pinpointing IoT devices in a network, it is unlikely for the ISP to appropriately configure security policies and effectively manage the network. Additionally, inferring fine-grained user interactions of IoT devices is also an interesting yet unresolved problem. In this paper, we design an efficient and scalable system via spatial-temporal traffic fingerprinting from an ISP’s perspective in consideration of practical issues like learning-testing asymmetry. Our system can accurately identify typical IoT devices in a network, with the additional capability of identifying what devices are hidden behind NAT and the number of each type of device that share the same IP address. Our system can also detect user interactions and meanwhile identify their (concurrent) number through a multi-output regression model. Through extensive evaluation, we demonstrate that the system can generally identify IoT devices with an F1-Score above 0.999, and estimate the number of the same type of IoT device behind NAT with an average error below 5%. By studying 29 user interactions of 7 devices, we show that our system is promising in detecting user interactions.
Xiaobo Ma 0001, Jian Qu, Jianfeng Li 0006, John C. S. Lui, Zhenhua Li 0001, Wenmao Liu, Xiaohong Guan
IEEE/ACM Trans. Netw.3
2021 Structural Attack against Graph Based Android Malware Detection
abstract
Malware detection techniques achieve great success with deeper insight into the semantics of malware. Among existing detection techniques, function call graph (FCG) based methods achieve promising performance due to their prominent representations of malware's functionalities. Meanwhile, recent adversarial attacks not only perturb feature vectors to deceive classifiers (i.e., feature-space attacks) but also investigate how to generate real evasive malware (i.e., problem-space attacks). However, existing problem-space attacks are limited due to their inconsistent transformations between feature space and problem space.
Kaifa Zhao, Hao Zhou 0043, Yulin Zhu 0001, Xian Zhan, Kai Zhou 0001, Jianfeng Li 0006, Le Yu 0002, Wei Yuan 0001, Xiapu Luo
CCS6
2021 Context-aware Website Fingerprinting over Encrypted Proxies
abstract
Website fingerprinting (WFP) could infer which websites a user is accessing via an encrypted proxy by passively inspecting the traffic between the user and the proxy. The key to WFP is designing a classifier capable of distinguishing traffic characteristics of accessing different websites. However, when deployed in real-life networks, a well-trained classifier may face a significant obstacle of training-testing asymmetry, which fundamentally limits its practicability. Specifically, although pure traffic samples can be collected in a controlled (clean) testbed for training, the classifier may fail to extract such pure traffic samples as its input from raw complicated traffic for testing. In this paper, we are interested in encrypted proxies that relay connections between the user and the proxy individually (e.g., Shadowsocks), and design a context-aware system using built-in spatial-temporal flow correlation to address the obstacle. Extensive experiments demonstrate that our system does not only enable WFP against a popular type of encrypted proxies practical, but also achieves better performance than ideally training/testing pure samples.
Xiaobo Ma 0001, Mawei Shi, Bingyu An, Jianfeng Li 0006, Xiapu Luo, Junjie Zhang 0004, Xiaohong Guan
INFOCOM4
2021 Inaccurate Prediction Is Not Always Bad: Open-World Driver Recognition via Error Analysis
abstract
Driver identification is of fundamental importance in many vehicle-related applications, such as fleet monitoring and anti-theft system. The vast majority of existing methods work under the closed-world assumption, which may be unrealistic in practice. In this paper, we consider a more practical but challenging scenario, i.e., open-world driver recognition, and propose a systematic method dubbed DRIVERPRINT. To recognize the driver of interest, DRIVERPRINT takes advantage of the behavioral predictability of the driver himself, thereby no need to collect data from other drivers for model training. Specifically, DRIVERPRINT predicts the behavior-related traveling speed with a driver-specific predictor, compares the prediction error with a pre-trained error model and finally recognizes drivers via error analysis. Besides open-world setting, our method is also compatible with closed-world driver classification. Real-world experiments demonstrate our method achieves reasonable accuracy. The average F1-score for open-world driver recognition is up to 0.91, while that for closed-world driver classification is up to 0.973.
Jianfeng Li 0006, Kaifa Zhao, Yajuan Tang, Xiapu Luo, Xiaobo Ma 0001
VTC Spring1
2020 Pinpointing Hidden IoT Devices via Spatial-temporal Traffic Fingerprinting
abstract
With the popularization of Internet of Things (IoT) devices in smart home and industry fields, a huge number of IoT devices are connected to the Internet. However, what devices are connected to a network may not be known by the Internet Service Provider (ISP), since many IoT devices are placed within small networks (e.g., home networks) and are hidden behind network address translation (NAT). Without pinpointing IoT devices in a network, it is unlikely for the ISP to appropriately configure security policies and effectively manage the network. In this paper, we design an efficient and scalable system via spatial-temporal traffic fingerprinting. Our system can accurately identify typical IoT devices in a network, with the additional capability of identifying what devices are hidden behind NAT and how many they are. Through extensive evaluation, we demonstrate that the system can generally identify IoT devices with an F-Score above 0.999, and estimate the number of the same type of IoT device behind NAT with an average error below 5%. We also perform small-scale (labor-intensive) experiments to show that our system is promising in detecting user-IoT interactions.
Xiaobo Ma 0001, Jian Qu, Jianfeng Li 0006, John C. S. Lui, Zhenhua Li 0001, Xiaohong Guan
INFOCOM3
2020 Taming energy cost of disk encryption software on data-intensive mobile devices
John C. S. Lui, Xiaobo Ma 0001, Jianfeng Li 0006
Future Gener. Comput. Syst.5
2019 Protecting internet infrastructure against link flooding attacks: A techno-economic perspective
Xiaobo Ma 0001, Jianfeng Li 0006, Yajuan Tang, Bo An 0001, Xiaohong Guan
Inf. Sci.2
2018 Can We Learn what People are Doing from Raw DNS Queries?
abstract
Domain Name System (DNS) is one of the pillars of today's Internet. Due to its appealing properties such as low data volume, wide-ranging applications and encryption free, DNS traffic has been extensively utilized for network monitoring. Most existing studies of DNS traffic, however, focus on domain name reputation. Little attention has been paid to understanding and profiling what people are doing from DNS traffic, a fundamental problem in the areas including Internet demographics and network behavior analysis. Consequently, simple questions like “How to determine whether a DNS query for www.google.com means searching or any other behaviors?” cannot be answered by existing studies. In this paper, we take the first step to identify user activities from raw DNS queries. We advance a multiscale hierarchical framework to tackle two practical challenges, i.e., behavior ambiguity and behavior polymorphism. Under this framework, a series of novel methods, such as pattern upward mapping and multi-scale random forest classifier, are proposed to characterize and identify user activities of interest. Evaluation using both synthetic and real-world DNS traces demonstrates the effectiveness of our method.
Jianfeng Li 0006, Xiaobo Ma 0001, Xiapu Luo, Junjie Zhang 0004, Wei Li 0029, Xiaohong Guan
INFOCOM1
2018 Shoot at a Pigeon and Kill a Crow: On Strike Precision of Link Flooding Attacks
Xiaobo Ma 0001, Jianfeng Li 0006, Lei Xue 0001
NSS3
2018 Revisiting Website Fingerprinting Attacks in Real-World Scenarios: A Case Study of Shadowsocks
Yankang Zhao, Xiaobo Ma 0001, Jianfeng Li 0006, Shui Yu 0001, Wei Li 0172
NSS3
2017 Mining repeating pattern in packet arrivals: Metrics, models, and applications
Jianfeng Li 0006, Xiaobo Ma 0001, Junjie Zhang 0004, Pinghui Wang, Xiaohong Guan
Inf. Sci.1
2015 Modeling repeating behaviors in packet arrivals: Detection and measurement
abstract
With the growing stickiness of the Internet, numerous automated programs running in terminal facilities (e.g., laptops) tend to keep closely connected to the Internet by repetitively interacting with remote services. It is of fundamental importance to study such repeating behaviors of automated programs in areas like traffic engineering and network monitoring. This paper focuses on repeating behaviors in packet arrivals that are of interest, aiming at a hierarchical characterization of packet arrivals, detection methods and quantitative metrics. To this end, we present a structure-oriented characterization of packet arrivals, which reflects the temporal structure of repeating behaviors at different scales. Based on such characterization, a repeating behavior detection method is proposed by leveraging online-learning prediction, and two novel metrics of repeating behaviors are proposed from different aspects. In addition, a denoising method is developed to enhance the noise-tolerant capability of detection and measurement in face of noises. Experimental results based on real-world traces demonstrate the effectiveness of our proposed approaches in automated program behavior detection and behavioral botnet analysis.
Jianfeng Li 0006, Xiaobo Ma 0001, Junjie Zhang 0004, Xiaohong Guan
INFOCOM1
2015 Accurate DNS query characteristics estimation via active probing
Xiaobo Ma 0001, Junjie Zhang 0004, Zhenhua Li 0001, Jianfeng Li 0006, Xiaohong Guan, John C. S. Lui, Don Towsley
J. Netw. Comput. Appl.4
2014 DNSRadar: Outsourcing Malicious Domain Detection Based on Distributed Cache-Footprints
abstract
As the domain name system (DNS) plays a critical role in malicious services and number of networks, especially small enterprise networks and home networks that are generally and poorly managed, grows rapidly, it is highly desired to outsource the malicious domain detection service to a thirdparty system that can aggregate information from multiple vantage points to perform detection. To this end, we propose DNSRadar, a system that explores the coexistence of domain cache-footprints distributed in all networks that participate in the outsourcing service. Bootstrapping from a list of prelabeled malicious domains, DNSRadar leverages link analysis techniques to infer maliciousness likelihood of unknown domains based on coexistence information. As DNSRadar only uses the existence of an unknown domain in a network for detection, privacy concerns have been drastically reduced. Both MapReduce and lightweight matrix analysis techniques are employed to implement DNSRadar, making scalability as a built-in feature. Taking advantage of a large number of open recursive DNS servers, we have performed extensive evaluation at scale. Experimental results have demonstrated that DNSRadar can efficiently detect ~90% malicious domains given a low false positive rate of 1%. Of all these detected malicious domains, ~30% are on average 6 days earlier than public DNS reputation services, indicating DNSRadar's great early detection capability.
Xiaobo Ma 0001, Junjie Zhang 0004, Jianfeng Li 0006, Jue Tian, Xiaohong Guan
IEEE Trans. Inf. Forensics Secur.4
2013 Boosting practicality of DNS cache probing: A general estimator based on Bayesian forecasting
abstract
It is an important task in Internet demography and security monitoring to accurately measure the user population of an application in a network. In previous works, the Domain Name System (DNS) cache probing technique was proposed to estimate λ¯, the average DNS querying rate for a domain name associated with the given application. One can readily obtain the user population given another empirical parameter from DNS traces, i.e., average number of DNS queries per user. The previous estimator for λ¯ was based on the assumption that the DNS query arrivals can be described by a homogeneous Poisson process. In this paper, we verify this assumption by measuring real DNS traces and find that it is over-simplified. In fact, the DNS query arrivals exhibit non-stationary property dominated by a diurnal pattern in general, thereby making the previous estimator underestimate λ¯. Then, an asymptotically unbiased estimator is proposed using the Bayesian forecasting. The proposed estimator is more general as compared with the previous one because it can accurately estimate λ¯ when the DNS query arrivals can be described by either homogeneous or non-homogeneous Poisson processes. The proposed estimator meets the minimum mean squared error principle, and the experimental results show that it significantly outperforms the previous one. The DNS cache probing technique offers promising applications because it is low-cost, less invasive and privacy preserving. Our work greatly boosts the practicability of this technique.
Jianfeng Li 0006, Xiaobo Ma 0001, Xiaohong Guan
ICC1
2012 Towards active measurement for DNS query behavior of botnets
abstract
Domain names play an increasingly important role for the botnet activities. Traditionally, DNS traces from several local DNS servers are used passively to measure the DNS query behavior. However, since botnets are a wide-scale threat and usually reside in geographically dispersed networks, the vantage point of several local DNS servers is sometimes too small to help us understand the DNS query behavior (e.g., whether queried or not, average query rate) of botnets. In this paper, we actively measure the DNS query behavior of botnets in geographically dispersed networks via the DNS cache probing technique. We first analytically characterize how multiple domain names are queried by botnets in different networks under certain circumstances. Then, we actively measure real botnet samples in the wild to gain insight into how multiple domain names are queried by botnets in 480 geographically dispersed networks globally, and show that our analytical characterization well describes the DNS query behavior of the botnet samples. The active measurement technique can help to acquire extensive DNS query information in different networks and thus potentially facilitate various DNS-related research and applications.
Xiaobo Ma 0001, Jianfeng Li 0006, Xiaohong Guan
GLOBECOM2