VLDB 2026 Research / reviewers in the wild / expert
Mengqi Zhan
dblp:252/8510
· DBLP profile ↗
8ranked-venue papers
6as first author
7since 2021 · last 2024
0000-0002-3572-3458ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 first-author · 3 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | 5GC-SDP: Security Enhancement of 5G Core Networks With Zero TrustabstractThe 5G core network (5GC) architecture based on Service-Based Architecture (SBA) has brought unprecedented flexibility and innovation. However, this architecture also comes with potential security challenges. The integration of different signaling protocols and the complexity of virtualization in 5GC have increased security risks within the core network. The concept of zero trust is considered a new solution, and Software-Defined Perimeter (SDP) represents a best practice for zero trust. In this paper, we propose a 5GC-SDP architecture that provides secure communication within the core network through authentication-based methods. Single Package Authorization (SPA) is the key technology of this study. Only Network Functions (NF) that have been authenticated and authorized by SPA can access each other. To the best of our knowledge, this is the first study to combine SDP with StandAlone (SA) 5GC. At the same time, we fully consider that although SPA technology can withstand most DoS attacks, DoS attacks caused by SPA packets will still become a problem. Therefore, we design a SPA enhancement module, and machine learning algorithms are used for SPA-DoS detection. We have conducted practical exploration on the proposed 5GC-SDP architecture and implemented testing on port scanning, DoS, and DDoS attacks. The experiments have shown that 5GC-SDP achieves enhanced protection of the core network by limiting network exposure and implementing fine-grained access control. Zeqing Yan, Guangxi Yu, Mengqi Zhan, Yan Zhang 0014, Jiaxi Hu |
CSCWD | 3 |
| 2024 | Toward Automated Field Semantics Inference for Binary Protocol Reverse EngineeringabstractNetwork protocol reverse engineering is the basis for many security applications. A common class of protocol reverse engineering methods is based on the analysis of network message traces. After performing message field identification by segmenting messages into multiple fields, a key task is to infer the semantics of the fields. One of the limitations of existing field semantics inference methods is that they usually infer semantics for only a few fields and often require a lot of manual effort. In this paper, we propose an automated field semantics inference method for binary protocol reverse engineering (FSIBP). FSIBP aims to automatically learn semantics inference knowledge from known protocols and use it to infer the semantics of any field of an unknown protocol. To achieve this goal, we design a feature extraction method that can extract features of the field itself and of the field context. We also propose a semantic category aggregation method that abstracts the fine-grained semantics of all fields of known protocols into aggregated semantic categories. Moreover, we make FSIBP infer semantics based on the similarity of fields to semantic categories. The above design enables FSIBP to utilize the semantic knowledge of all fields of known protocols and infer the semantics of any fields of unknown protocols. The whole process of FSIBP does not require any expert knowledge or manual parameter setting. We conduct extensive experiments to demonstrate the effectiveness of FSIBP. Moreover, we find a utility for FSIBP besides field semantics inference, its output can help to detect the mis-segmented fields generated during the message field identification. Mengqi Zhan, Yang Li 0192, Bo Li 0063, Jinchao Zhang 0002, Chuanrong Li, Weiping Wang 0005 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | GuardBox: A High-Performance Middlebox Providing Confidentiality and Integrity for PacketsabstractThe deepening of digital transformation has led to an increasing amount of data from industries being transmitted over the Internet. However, packets in plaintext originally designed for transmission in private networks suffer from significant security threats on the Internet. Unfortunately, existing encryption schemes, such as the representative TLS, are difficult to be applied to these industrial protocols due to their specific requirements and conditions such as low latency requirements and restricted operating environments. In this paper, we present a high-performance encryption/decryption middlebox called GuardBox to provide confidentiality and integrity for packets. GuardBox is expected to transparently encrypt/decrypt packets sent/received by protected industrial equipment with low latency and supports almost any application-layer protocol. To do that, we design a high-performance packet I/O framework and an optimized encryption/decryption scheme for GuardBox. More importantly, we use commodity trusted hardware, Intel SGX, to ensure the security of keys and the encryption/decryption process. Our extensive evaluation demonstrates that GuardBox can provide confidentiality and integrity for packets transmitted over the Internet with low latency and a near-native throughput. Mengqi Zhan, Yang Li 0192, Guangxi Yu, Yan Zhang 0014, Bo Li 0063, Weiping Wang 0005 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Website-Aware Protocol Confusion Network for Emergent HTTP/3 Website FingerprintingabstractWebsite fingerprinting is exploited to analyze encrypted traffic traces and infer the visited website. Existing website fingerprinting methods can achieve satisfying performance for the HTTP traffic visiting websites over TCP. Recently, a new protocol QUIC has been proposed, and HTTP-over-QUIC has been formalized as the next generation HTTP, named HTTP/3. Thus, it is necessary to classify HTTP/3 traces. However, since HTTP/3 is newly proposed and is being deployed, it is difficult to collect a large number of HTTP/3 traces. Intuitively, we can use sufficient TCP traces to improve the performance of the QUIC trace classifier. Unfortunately, the protocol discrepancy exists between TCP and QUIC traces, which undermines the generalization ability of the classifier. In this paper, for practical website fingerprinting of HTTP/3, we propose a Website-Aware Protocol Confusion Network (WAPCN), which exploits only a few QUIC traces to train a website classifier with the help of lots of available TCP traces. It consists of four main parts: a feature extractor, a website classifier, a protocol discriminator, and a website-aware adaptor. The feature extractor aims to extract trace representations from both TCP and QUIC traces. It cooperates with the website classifier to learn the discriminative representation for the website classification. The role of the protocol discriminator is to confuse protocols and guide the feature extractor to learn protocol-invariant representations. The website-aware adaptor can enhance protocol-invariant representations to be aware of the website classification boundary. Extensive experiments are conducted on various tasks to demonstrate the effectiveness of WAPCN. Mengqi Zhan, Yang Li 0192, Yongchun Zhu, Guangxi Yu, Yan Zhang 0014, Bo Li 0063, Weiping Wang 0005 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Coda: Runtime Detection of Application-Layer CPU-Exhaustion DoS Attacks in ContainersabstractDenial of service (DoS) attacks have increasingly exploited vulnerabilities in algorithms or implementation methods in application-layer programs. In this type of attack, called CPU-exhaustion DoS attack, a few well-crafted requests may consume a lot of server resources, which is essentially different from traditional volumetric DoS attacks. Due to the lack of recognizable patterns, the traditional network-layer defense mechanism is usually unable to detect such sophisticated DoS attacks. In this paper, we proposeCoda, a framework for detecting application-layer CPU-exhaustion DoS attacks in containers.Codamonitors the CPU time consumed by each connection and uses statistical methods to detect attacks. It traces system calls and other related information from the container based on Linux eBPF at the host level. Some specific system calls are used to indicate the establishment and closure of the connection, which in turn indicate the start/end of the request processing. After triggering these specific system calls,Codastarts/ends monitoring the CPU time consumed by a connection. An attack can be detected when the CPU time consumed by an attack connection is statistically different from that consumed by a legitimate connection.Codahas the following key advantages. First, it works with programs built in different programming languages. Second, it remains agnostic to the source code of protected programs. Third, it supports monitoring the container and is transparent to the container. Through evaluation of real-world attacks, we demonstrate thatCodacan accurately detect ongoing application-layer CPU-exhaustion DoS attacks with low additional overhead. Mengqi Zhan, Yang Li 0192, Huiran Yang, Guangxi Yu, Bo Li 0063, Weiping Wang 0005 |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | ActDetector: A Sequence-based Framework for Network Attack Activity DetectionabstractThe cyber security situation is not optimistic in recent years due to the rapid growth of security threats. What's more worrying is that threats are tending to be more sophis-ticated, which poses challenges to attack activity analysis. It is quite important for analysts to understand attack activities from a holistic perspective, rather than just pay attention to alerts. Currently, the attack activity analysis generally relies on human resources, which is a heavy workload for manual analysis. Besides, it's difficult to achieve high detection accuracy due to the missing and false-positive alerts. In this paper, we propose a new framework, ActDetector, to detect attack activities automatically from the raw Network Intrusion Detection System (NIDS) alerts, which will greatly reduce the workload of security analysts. We extract attack phase descriptions from alerts and embed attack activity descriptions to obtain their numerical expression. Finally, we use a temporal-sequence-based model to detect potential attack activities. We evaluate ActDetector with three datasets. Experimental results demonstrate that ActDetector can detect attack activities from the raw NIDS alerts with an average of 94.8% Precision, 95.0% Recall, and 94.6% F1-score. Jiaqi Kang, Huiran Yang, Yan Zhang 0014, Yueyue Dai, Mengqi Zhan, Weiping Wang 0005 |
ISCC | 5 |
| 2022 | Detecting DNS over HTTPS based data exfiltration
Mengqi Zhan, Yang Li 0192, Guangxi Yu, Bo Li 0063, Weiping Wang 0005 |
Comput. Networks | 1 |
| 2020 | NSAPs: A novel scheme for network security state assessment and attack prediction
Mengqi Zhan, Yang Li 0192, Xinghua Yang, Yulin Fan |
Comput. Secur. | 1 |