VLDB 2026 Research / reviewers in the wild / expert
Xiaodong Zang
dblp:187/5908
· DBLP profile ↗
8ranked-venue papers
6as first author
8since 2021 · last 2026
0000-0002-8377-5877ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 4 first-author · 5 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Mitigating the Lateral Movement of APT in IIoT With an Efficient Moving Target Defense and Cyber Deception ApproachabstractThe convergence of Information Technology (IT) and Operational Technology (OT) has made Industrial Internet of Things (IIoT) systems a prominent target for Advanced Persistent Threats (APTs). Lateral movement is a critical stage in APT infiltration, yet most existing mitigation methods rely on static, reactive approaches, leaving proactive defense mechanisms underexplored. Moreover, in real-world scenarios, attackers and defenders act sequentially under bounded rationality, rendering existing proactive schemes unable to adapt dynamically to evolving adversarial strategies. To address these challenges, this paper proposes a novel hybrid defense framework that integrates Moving Target Defense (MTD) with cyber deception. Our approach actively confuses attackers through camouflage information, dynamically adapts the attack surface, and optimizes defense strategies in real time. We model the strategic interaction between defender and attacker using a Stackelberg game framework enhanced with Prospect Theory (PT) to account for bounded rationality, and we design an efficient algorithm to compute optimal defense policies. Additionally, we introduce a subnet shuffling technique designed to prevent attackers with low privileges from exploiting zero-day vulnerabilities to penetrate higher-privilege subnets. The proposed framework is validated through comprehensive simulations and real-world experiments on a Software-Defined Networking (SDN) testbed. Experimental results demonstrate that our method effectively mitigates lateral movement attacks while maintaining an acceptable level of network shuffling overhead in IIoT environments. Xiaodong Zang, Fangbo Hou, Xuan Liu 0006, Muhammad Khurram Khan, Daohua Liu |
IEEE Trans. Reliab. | 1 |
| 2025 | A Strategy for Edge Node Anonymous Verification and Protection Incorporating Reputation CenterabstractThe rapidly evolving Internet of Things (IoT) continues to serve as a critical bridge between the physical world and digital space, driving increasing demands for optimized communication capabilities and time-sensitive data acquisition. However, traditional cloud computing architectures are becoming increasingly insufficient to meet these stringent demands. Mobile Edge Computing (MEC) has thus emerged as a promising paradigm. By delegating data processing tasks from centralized cloud servers to edge nodes (ENs) located near end-users, MEC significantly enhances service efficiency while simultaneously introducing heightened privacy and security risks. To mitigate both external threats during task interactions and internal adversaries within the network, this paper proposes a Lightweight Verification and Protection (LVP) strategy for ENs. LVP primarily leverages secure computation techniques to ensure the anonymity and confidentiality of private information during transmission and verification. It further incorporates a reputation-based evaluation framework to mitigate the impact of insider threats. Specifically, the integrity of user-uploaded task data is first verified, followed by anonymous matching between users and ENs through paired index. A reputation-based anonymous authentication algorithm is then designed to prevent exposure or linkage of reputation information during usage. Finally, reputation values are dynamically updated by jointly considering temporal relevance and historical behavior. Theoretical analysis confirms the robustness and correctness of all LVP sub-algorithms, while experimental evaluations demonstrate the scheme’s effectiveness and feasibility under low computational and communication overhead. Guowei Zhang 0003, Jiayuan Du, Xiuhua Lu, Xiaodong Zang, Yang Yang 0001 |
IEEE Internet Things J. | 4 |
| 2024 | Encrypted malicious traffic detection based on natural language processing and deep learning
Xiaodong Zang, Tongliang Wang, Peng Gao 0005, Guowei Zhang 0003 |
Comput. Networks | 1 |
| 2024 | PhishHunter: Detecting camouflaged IDN-based phishing attacks via Siamese neural network
Maoli Wang, Xiaodong Zang, Jianbo Cao, Shengbao Li |
Comput. Secur. | 2 |
| 2023 | Attack scenario reconstruction via fusing heterogeneous threat intelligence
Xiaodong Zang, Guiqing Li |
Comput. Secur. | 1 |
| 2023 | IP traffic behavior characterization via semantic mining
Xiaodong Zang, Maoli Wang, Peng Gao 0005, Guowei Zhang 0003 |
J. Netw. Comput. Appl. | 1 |
| 2023 | Encrypted DNS Traffic Analysis for Service Intention InferringabstractService intention refers to what service or which service the server provides. The former includes service classification, service type, or service behavior classification. The latter contains service content classification, such as shopping online or uploading and downloading, etc.. Port-based classification and payload-based classification are two widely used service classification schemes, both of which have many limitations, such as only focusing on server-side scenarios or just designing for non-encrypted requests. In this paper, we propose an encryption-independent approach from a network-side perspective by analyzing the communication behavior of the IPs. Firstly, we identify similar service behavior clusters by employing service influence metrics. Then, we devise a semantic mining mechanism to infer whether they serve a fixed user group or provide interactive service. Finally, we use open-source benchmark datasets, synthetic datasets, and the real Netflow data collected from the China Education Research Network backbone (CERNET) to verify our proposal. Experimental results demonstrate that the accuracy and recall rate of the proposed approach is better than other similar state-of-the-art methods. Besides, our work can also distinguish malicious behavior clusters. Extensive experiments demonstrate that our work is efficient for network management and security monitoring. Xiaodong Zang, Maoli Wang, Peng Gao 0005 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2021 | Identifying DGA Malware via Behavior AnalysisabstractThe behavior of the domain name is actually demonstrated by the behavior of the IP address. By observing the traffic behavior of their resolved IPs, the maliciousness of the domain names can be further divided. Deep packets inspection, reverse engineering and other approaches based on clustering technique in detecting malware using domain generation algorithms(DGA) are inefficient and with lots of false positives in large-scale networks. To address these challenges, this paper introduces a novel idea to identify DGA-based malware via behavior analysis. More specifically, four different types of traffic behaviors are focused, such as the rhythmic behavior, the cyclical behavior, the access stable behavior and the service diversity behavior. These behaviors are characterized, modeled and evaluated by using the metrics of the number of flows in each period of time, the access interval, the number of corresponding communication IPs in each period of time and the number of application types. NetFlow data of the resolved IP corresponding to the domain names collected from China Education Research Network backbone (CERNET) is applied to verify our proposal. Experimental results demonstrate that the application of IP address traffic behavior analysis can detect C& C channels of DGA-based malware regardless of its payload content. Xiaodong Zang, Ping Zong |
WCNC | 1 |