VLDB 2026 Research / reviewers in the wild / expert
Yunsen Lei
dblp:259/7890
· DBLP profile ↗
6ranked-venue papers
3as first author
5since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 3 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Making (Only) the Right Calls: Preventing Remote Code Execution Attacks in PHP Applications with Contextual, State-Sensitive System Call Filtering
Yunsen Lei, Craig A. Shue |
DIMVA (1) | 1 |
| 2025 | Mobile SDNs: Associating End-User Commands with Network Flows in Android DevicesabstractABSTRACT Mobile devices pose several distinct challenges from a security perspective. First, they have varied and ephemeral network connections, often using a cellular provider network as a backup option when connectivity is not available via wireless local access networks. This varied network connectivity makes it difficult to comprehensively deploy in‐network solutions, such as firewalls or intrusion detection systems, since they would have to be active in every network the device would use. Second, with personally owned devices, the device owner may have security goals and privacy priorities that are distinct from organizations that provide connectivity or data assets, such as employers or schools. These complex relationships may complicate efforts to protect the devices. This paper explores a technique that runs on the mobile device endpoints to learn about the usage patterns associated with the device, in order to enforce network policy. We explore sensors that examine the mobile device's user interface, using physical inputs via finger taps, and that link them with the network activity on the device. We incorporate with allow‐list policies that can be provided by organizations to make on‐device access control decisions. Using IP address and DNS host name allow‐lists as a baseline, we explore the accuracy of interface‐aware allow‐lists. We find the interface‐aware allow‐lists can reach over 98.5% accuracy, even when user‐specified destinations are used, greatly exceeding the baseline accuracy. Our performance evaluation indicates our approach introduces a median of 3.87 ms of overall delay with low CPU usage. Shuwen Liu 0009, Craig A. Shue, Joseph P. Petitti, Yunsen Lei |
IET Commun. | 4 |
| 2023 | Attackers as Instructors: Using Container Isolation to Reduce Risk and Understand Vulnerabilities
Yunsen Lei, Julian P. Lanson, Craig A. Shue, Timothy W. Wood |
DIMVA | 1 |
| 2022 | Exploring Phone-Based Authentication Vulnerabilities in Single Sign-On Systems
Matthew M. Tolbert, Elie M. Hess, Mattheus C. Nascimento, Yunsen Lei, Craig A. Shue |
ICICS | 4 |
| 2022 | Visualizing Web Application Execution Logs to Improve Software Security Defect LocalizationabstractInteractive web-based applications play an important role for both service providers and consumers. However, web applications tend to be complex, produce high-volume data, and are often ripe for attack. Attack analysis and remediation are complicated by adversary obfuscation and the difficulty in assembling and analyzing logs. In this work, we explore the web application analysis task through log file fusion, distillation, and visualization. Our approach consists of visualizing the logs of web and database traffic with detailed function execution traces. We establish causal links between events and their associated behaviors. We evaluate the effectiveness of this process using data volume reduction statistics, user interaction models, and usage scenarios. Across a set of scenarios, we find that our techniques can filter at least 97.5% of log data and reduce analysis time by 93–96%. Matthew A. Puentes, Yunsen Lei, Noëlle Rakotondravony, Lane Harrison, Craig A. Shue |
SANER | 2 |
| 2019 | Detecting Root-Level Endpoint Sensor Compromises with Correlated Activity
Yunsen Lei, Craig A. Shue |
SecureComm (2) | 1 |