VLDB 2026 Research / reviewers in the wild / expert
Hongying Dong
dblp:298/5314
· DBLP profile ↗
6ranked-venue papers
5as first author
6since 2021 · last 2025
0000-0002-7846-2649ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 4 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Inside Certificate Chains Beyond Public Issuers: Structure and Usage Analysis from a Campus NetworkabstractDigital certificates are crucial for securing Internet communications. Certificates issued by trusted Certificate Authorities (CAs) can be validated by following the chain of trust, consisting of leaf, intermediate, and root certificates. However, such certificate chain structure may not be followed by issuers who are not subject to public monitoring and auditing. This paper takes a first look at certificate chains involving certificates issued by issuers that do not appear in public databases (e.g., major browsers' root stores and CCADB). Utilizing a year's worth of TLS traffic collected from a campus network, we dissect the certificate chain structures and analyze their usage in TLS connections. While we observe positive acts such as the logging of certificates that are issued by issuers outside public databases and anchored to trust roots into Certificate Transparency (CT) logs, we also identify potential misconfigurations by servers where unnecessary certificates are included in the certificate chains, which may lead to validation and connection failures. Hongying Dong, Yizhe Zhang 0006, Hyeonmin Lee, Yixin Sun 0004 |
IMC | 1 |
| 2024 | Mutual TLS in Practice: A Deep Dive into Certificate Configurations and Privacy IssuesabstractTransport Layer Security (TLS) is widely recognized as the essential protocol for securing Internet communications. While numerous studies have focused on investigating server certificates used in TLS connections, our study delves into the less explored territory of mutual TLS (mTLS) where both parties need to provide certificates to each other. By utilizing TLS connection logs collected from a large campus network over 23 months, we identify over 2.2 million unique server certificates and over 3.4 million unique client certificates used in over 1.2 billion mutual TLS connections. By jointly analyzing TLS connection data (e.g., port numbers) and certificate data (e.g., issuers for server/client certificates), we quantify the prevalent use of untrusted certificates and uncover potential security concerns resulting from misconfigured certificates, sharing of certificates between servers and clients, and long-expired certificates. Furthermore, we present the first in-depth study on the wide range of information included in CommonName (CN) and Subject Alternative Name (SAN), drawing comparison between client and server certificates, as well as revealing sensitive information. Hongying Dong, Yizhe Zhang 0006, Hyeonmin Lee, Kevin Du, Guancheng Tu, Yixin Sun 0004 |
IMC | 1 |
| 2024 | Exploring the Ecosystem of DNS HTTPS Resource Records: An End-to-End PerspectiveabstractThe DNS HTTPS resource record is a new DNS record type designed for the delivery of configuration information and parameters required to initiate connections to HTTPS network services. In addition, it is a key enabler for TLS Encrypted ClientHello (ECH) by providing the cryptographic keying material needed to encrypt the initial exchange. To understand the adoption of this new DNS HTTPS record, we perform a longitudinal study on the server-side deployment of DNS HTTPS for Tranco top million domains, as well as an analysis of the client-side support for DNS HTTPS through snapshots from major browsers. To the best of our knowledge, our work is the first longitudinal study on DNS HTTPS server deployment, and the first known study on client-side support for DNS HTTPS. Despite the rapidly growing trend of DNS HTTPS adoption, our study highlights challenges and concerns in the deployment by both servers and clients, such as the complexity in properly maintaining HTTPS records and connection failure in browsers when the HTTPS record is not properly configured. Hongying Dong, Yizhe Zhang 0006, Hyeonmin Lee, Shumon Huque, Yixin Sun 0004 |
IMC | 1 |
| 2023 | Global Analysis with Aggregation-based Beaconing Detection across Large Campus NetworksabstractWe present a new approach to effectively detect and prioritize malicious beaconing activities in large campus networks by profiling the server activities through aggregated signals across multiple traffic protocols and networks. Key components of our system include a novel time-series analysis algorithm that uncovers hidden periodicity in aggregated signals, and a ranking-based detection pipeline that utilizes self-training and active-learning techniques. We evaluate our detection system on 10 months of real-world traffic collected at two large campus networks, comprising over 75 billion connections. On a daily average, we detect 43% more periodic domains by aggregating signals across multiple networks compared to single-network analysis. Furthermore, our ranking pipeline successfully identifies 1,387 unique malicious domains, out of which 781 (56%) were unknown to the major online threat intelligence platform, VirusTotal, at the time of our detection. Yizhe Zhang 0006, Hongying Dong, Alastair Nottingham, Molly Buchanan, Donald E. Brown, Yixin Sun 0004 |
ACSAC | 2 |
| 2023 | Behind the Scenes: Uncovering TLS and Server Certificate Practice of IoT Device Vendors in the WildabstractIoT devices are increasingly used in consumer homes. Despite recent works in characterizing IoT TLS usage for a limited number of in-lab devices, there exists a gap in quantitatively understanding TLS behaviors from devices in the wild and server-side certificate management. Hongying Dong, Yizhe Zhang 0006, Muhammad Talha Paracha, David R. Choffnes, Santiago Torres-Arias, Danny Yuxing Huang, Yixin Sun 0004 |
IMC | 1 |
| 2023 | Towards Enabling Residential Virtual-Desktop ComputingabstractCommercial virtual-desktop computing is well established using computers optimized to serve as thin clients connected to centralized computing systems. Some common residential applications impose more stringent requirements on both communication bandwidth and latency than those of typical commercial applications. This article describes an objective study of residential applications accessed through thin-client virtual desktops for the purpose of investigating the feasibility of applying virtual-desktop computing to residential users. New metrics are introduced to quantify user-received application performance. The results suggest that certain commercial solutions with a commodity datacenter server show a strong potential for being adapted to residential virtual-desktop computing. Hongying Dong, Aaron T. Kinfe, Jiakai Yu, Daniel C. Kilper, Ronald D. Williams, Malathi Veeraraghavan |
IEEE Trans. Cloud Comput. | 1 |