Xiang Li 0108

dblp:40/1491-108 · DBLP profile ↗
← Back
25ranked-venue papers
6as first author
25since 2021 · last 2026
0000-0001-7388-1329ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 20 · 6 first-author · 20 since 2021Computer networks · 4 · 4 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 LLM-Recognizer: Generative-Discriminative Feature Fusion for Sentence-Level Detection
Xiang Li 0108
ICIC2
2026 CtPhishCapture: Uncovering Credential-Theft-Based Phishing Scams Targeting Cryptocurrency Wallets
Zhenrui Zhang, Xiang Li 0108, Anpeng Zhou, Chenghui Wu, Man Hou, Jia Zhang 0004, Zongpeng Li
NDSS3
2026 One Char to Rule Them All: Systematically Exploring and Exploiting DNS Silent Vulnerabilities in Domain Name Resolution
Fasheng Miao, Xiang Li 0108, Changqing An, Jilong Wang 0001
SP2
2026 Knocking on the Front Door: An LLM-Guided Systematic Analysis of DNS Query Processing Vulnerabilities
Yuqi Qiu, Xiang Li 0108, Zheli Liu
SP2
2025 RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday Paradox
abstract
DNS cache poisoning is a persistent game of attack and defense, posing an enduring challenge for the DNS community. Significant efforts have been made to uncover, detect, and mitigate vulnerabilities that increase the risk of cache poisoning. However, no work has systematically revisited whether the original cache poisoning attack based on the Birthday Paradox remains effective. In this work, we introduce RebirthDay, a novel DNS cache poisoning attack targeting recursive resolvers and forwarders, reviving the classic DNS Birthday attack that no longer works since 2002. RebirthDay exploits newly uncovered, protocol-compliant vulnerabilities in DNS extension implementations to bypass the query aggregation mechanism intended to prevent DNS Birthday attacks that has not been well understood. We uncovered that 18 out of 22 mainstream DNS software are vulnerable due to weaknesses in the processing of a DNS extension (i.e., ECS option), specifically lacking or incorrectly implemented ECS coherence checks when handling DNS queries and responses, demonstrating the widespread susceptibility to RebirthDay. These flaws could be exploited to circumvent the query aggregation mechanism and launch RebirthDay attacks. Through comprehensive evaluation, we showed that RebirthDay attacks are highly practical and can have significant real-world impact, affecting 16 router vendors, 14 public DNS services, and 365K (15%) open DNS resolvers. We have reported the identified vulnerabilities to affected vendors and discussed mitigation solutions with them. To date, we have received acknowledgments from 8 vendors, including BIND, Unbound, PowerDNS, and Quad9, and have been assigned 50 CVE-ids. Our study emphasizes the need for greater attention to the importance of ECS verification and DNS extension implementations, revealing new security risks introduced by them.
Xiang Li 0108, Mingming Zhang 0010, Zuyao Xu, Fasheng Miao, Yuqi Qiu, Baojun Liu 0002, Jia Zhang 0004, Hai-Xin Duan, Zheli Liu, Yunhai Zhang, Dunqiu Fan
CCS1
2025 Exploring and Analyzing Cross Layer DoS Attack Against UDP-based Services on Linux
abstract
The layered architecture of the TCP/IP protocol stack enables protocol layers to be implemented independently and flexibly. However, this layered design introduces potential security risks when shared resources are not properly managed between different layers. This paper investigates a neglected cross-layer shared resource risk, termed SocketFilled, which exploits the insecure usage of the UDP send buffer at the transport layer by the link layer, resulting in the interruption of response packets from the upper application layer. To explore the root causes of cross-layer DoS vulnerabilities resulting from the implementation of the TCP/IP protocol stack, we systematically analyzed the protocol standards of address resolution and reviewed the implementation in mainstream open-source operating systems. Moreover, we conducted a comprehensive experimental evaluation of mainstream operating systems (e.g., Linux and FreeBSD) and UDP services (e.g., DNS and QUIC). The experimental results show that the latest version of Linux and UDP service software (e.g., BIND9, PowerDNS, and Nginx) are affected, causing significant packet loss and even complete service interruption. Then, we estimated the impact range of SocketFilled in the wild and demonstrated that 17.3% of open resolvers,54.3% of authoritative servers of the Tranco Top 100K domains, and 3.8% of these well-known domains' HTTP/3 servers are potentially affected, including Bing, Amazon, and Shopee, after excluding the influence of cloud servers. We have conducted responsible disclosure by reporting the vulnerability to the Linux community. Our research highlights the effectiveness of cross-layer mechanisms in DoS attacks and calls for heightened attention to the layered complexity of protocol stack implementations within the security community.
Dashuai Wu, Baojun Liu 0002, Xiang Li 0108, Eihal Alowaisheq, Hai-Xin Duan
CCS4
2025 Poster: A First Look at Large Language Model Applications in the Wild from Dual Perspectives
abstract
Large language models (LLMs) have become the foundational technology for numerous applications. Various self-hosted LLM-related applications are deployed on the Internet for purposes such as intelligent assistants. However, their Internet exposure can introduce new security risks. To address this issue, this study conducts a large-scale, long-term measurement of LLM application exposure in the wild through active probing. Numerous publicly accessible instances of various LLM applications, such as Ollama, are deployed without authentication, posing risks of unauthorized access or data leakage. Meanwhile, this paper deploys a series of honeypots that mimic LLM applications to uncover the behaviors and strategies of scanners targeting online LLM applications.
Deliang Chang, Xuedong Wu, Xiang Li 0108, Zhengpeng Yang 0001, Asiya, Shujun Tang
IMC4
2025 Poster: RMap: Uncovering Risky DNS Resolution Chains and Misconfigurations
abstract
In recent years, large-scale network outages caused by DNS misconfigurations have become increasingly common. The intricate inter-domain dependencies, along with emerging mechanisms (Such as DNSSEC, EDNS, and 0x20), have made DNS resolution increasingly complex and fault localization more challenging. We present RMap, a tool that rapidly probes all potential resolution chains of a domain, reveals its resolution dependency topology, and detects security risks. We experimentally demonstrate the effectiveness of RMap and its broad applicability. Our findings reveal that domain configurations in real-world environments remain concerning, with potential issues observed even in several well-known top-level domains. RMap is avaliable in https://github.com/ahlien/rmap.
Fasheng Miao, Shuying Zhuang, Xiang Li 0108, Changqing An, Deliang Chang, Baojun Liu 0002, Jia Zhang 0004, Jilong Wang 0001
IMC3
2025 Analyzing Compliance and Complications of Integrating Internationalized X.509 Certificates
abstract
The global PKI supports the issuance of Unicerts, which are X.509 certificates that integrate internationalized content such as IDNs and multilingual text. This integration introduces complexity in Unicert issuance and usage. Past incidents showed that poor Unicode handling can cause security risks, including spoofing and remote code execution, yet threats specific to PKI and Unicerts remain underexplored. This paper presents the first large-scale study of Unicerts, examining both issuance and parsing compliance. By analyzing 34.8 million Unicerts from CT logs and 9 mainstream TLS libraries, we found the PKI ecosystem struggles with adopting Unicode. On the issuing side, 373 issuers produced 249.3K (0.72%) noncompliant Unicerts due to weak validation on character ranges, normalization, and formatting, of which 65.3% arise from publicly trusted CAs. These issues arise from overly complex standard requirements. On the parsing side, TLS libraries like GnuTLS and PyOpenSSL exhibited issues in decoding and handling special characters, such as incompatible decoding and improper escaping, which could lead to incorrect entity extraction or subfield forgery. We further empirically identified threat surfaces, including user spoofing, CT monitor misleading, and traffic obfuscation. Finally, we analyzed root causes and proposed recommendations to enhance Unicert compliance in the global PKI ecosystem.
Mingming Zhang 0010, Jinfeng Guo, Yiming Zhang 0009, Shenglin Zhang, Baojun Liu 0002, Xiang Li 0108, Hai-Xin Duan
IMC7
2025 Invade the Walled Garden: Evaluating GTP Security in Cellular Networks
abstract
Cellular backhaul and core networks have traditionally been considered as Walled Garden, with their security ensured by physical isolation. Therefore, prior security studies primarily focused on radio access networks with limited treatment of backhaul and core network interfaces. In this paper, we performed a security evaluation of real-world GPRS Tunnelling Protocol (GTP) deployments. GTP is the fundamental protocol for user traffic management between base stations and core networks (inside the Walled Garden) from 3G to 5G, thus often assumed inaccessible and non-exploitable from the Internet. However, our study reveals for the first time the troubling state of GTP access control in real-world deployments. Aided by a semi-automated tool, our measurements discovered around 749,000 valid GTP hosts accessible via the public Internet, spanning across 1,176 service providers in 162 countries. Our results demonstrate potential exposure of mobile core network infrastructures to external threats. We then evaluated the attack surface of exposed GTP infrastructures, and found out that as many as 38 types of GTP messages can be misused to launch various attacks such as denial-of-service and session hijacking. Our experiments using open source 4G and 5G projects in isolated lab environments further confirm the feasibility of those GTP-based attacks, including remote hijacking of user traffic sent through cellular core networks. In addition to threats against cellular networks and their subscribers, exposed GTP devices could also be weaponized to launch large-scale reflective denial-of-services (RDoS) attacks. We hope our findings will increase awareness of GTP vulnerabilities among operators and the security community, highlighting the urgent need to further strengthen security in cellular core networks.
Yiming Zhang 0009, Tao Wan 0004, Hai-Xin Duan, Jianjun Chen 0005, Zixiang Wei, Xiang Li 0108
SP8
2025 Detection and Mitigation of Unknown Threats in IPv6 Networks via Layered Data Adaptation
abstract
With the rapid proliferation of IPv6 deployment, traditional threat detection approaches are increasingly challenged by the scale, diversity, and concealment of emerging attack behaviors. This paper tackles three key limitations in IPv6 threat detection: poor adaptability across diverse network environments, insufficient result validation mechanisms, and the absence of globally applicable detection toolsets. To address these challenges, we propose a data-driven, layer-adaptive detection framework that forms a closed-loop pipeline of detection, validation, and mitigation. Our framework constructs a hierarchical dataset covering multiple detection scenarios, including open sensitive ports, entropy-based traffic anomalies, and TensorFlow-enhanced machine learning inputs. We introduce a novel validation technique, the Daily Active Mutual Access Index Matrix, which captures inter-prefix interaction patterns to identify coordinated malicious behavior. Additionally, we deploy a global-scale threat intelligence resolution and measurement system to validate detection outcomes and uncover cross-border threats missed by conventional models. Extensive analysis of abuse reports and complaint email interactions reveals that 65.53% of observed abuse involves sensitive service ports, and 38.64% of detected addresses exhibit verifiable abuse behavior. Notably, detection methods based on information entropy and AI models demonstrate higher abuse report delivery rates compared to commercial threat intelligence sources. Experimental results confirm that our multi-modal, adaptive approach significantly enhances the accuracy of unknown threat detection and the effectiveness of coordinated response, offering scalable and robust technical support for IPv6 security operations.
Youjun Huang, Xiang Li 0108, Jia Zhang 0004, Hai-Xin Duan
TrustCom2
2024 Understanding the Implementation and Security Implications of Protective DNS Services
Mingxuan Liu 0006, Yiming Zhang 0009, Xiang Li 0108, Chaoyi Lu, Baojun Liu 0002, Hai-Xin Duan
NDSS3
2024 BreakSPF: How Shared Infrastructures Magnify SPF Vulnerabilities Across the Internet
Chuhan Wang 0001, Yasuhiro Kuranaga, Mingming Zhang 0010, Linkai Zheng, Xiang Li 0108, Jianjun Chen 0005, Hai-Xin Duan, Yanzhong Lin, Qingfeng Pan
NDSS6
2024 ReqsMiner: Automated Discovery of CDN Forwarding Request Inconsistencies and DoS Attacks with Grammar-based Fuzzing
Linkai Zheng, Xiang Li 0108, Chuhan Wang 0001, Run Guo, Hai-Xin Duan, Jianjun Chen 0005, Chao Zhang 0008, Kaiwen Shen
NDSS2
2024 DNSBomb: A New Practical-and-Powerful Pulsing DoS Attack Exploiting DNS Queries-and-Responses
abstract
DNS employs a variety of mechanisms to guarantee availability, protect security, and enhance reliability. In this paper, however, we reveal that these inherent beneficial mechanisms, including timeout, query aggregation, and response fast-returning, can be transformed into malicious attack vectors.We propose a new practical and powerful pulsing DoS attack, dubbed the DNSBomb attack. DNSBomb exploits multiple widely-implemented DNS mechanisms to accumulate DNS queries that are sent at a low rate, amplify queries into large-sized responses, and concentrate all DNS responses into a short, high-volume periodic pulsing burst to simultaneously overwhelm target systems. Through an extensive evaluation on 10 mainstream DNS software, 46 public DNS services, and around 1.8M open DNS resolvers, we demonstrate all DNS resolvers could be exploited to conduct more practical-and-powerful DNSBomb attacks than previous pulsing DoS attacks. Small-scale experiments show the peak pulse magnitude can approach 8.7Gb/s and the bandwidth amplification factor could exceed 20,000x. Our controlled attacks cause complete packet loss or service degradation on both stateless and stateful connections (TCP, UDP, and QUIC). In addition, we present effective mitigation solutions with detailed evaluations. We have responsibly reported our findings to all affected vendors, and received acknowledgement from 24 of them, which are patching their software using our solutions, such as BIND, Unbound, PowerDNS, and Knot. 10 CVE-IDs are assigned.
Xiang Li 0108, Dashuai Wu, Hai-Xin Duan, Qi Li 0002
SP1
2024 TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed Packets
abstract
DNS can be compared to a game of chess in that its rules are simple, yet the possibilities it presents are endless. While the fundamental rules of DNS are straightforward, DNS implementations can be extremely complex. In this study, we intend to explore the complexities and vulnerabilities in DNS response pre-processing by systematically analyzing DNS RFCs and DNS software implementations. We present the discovery of three new types of logic vulnerabilities, leading to the proposal of three novel attacks, namely the TuDoor attack. These attacks involve the use of malformed DNS response packets to carry out DNS cache poisoning, denial- of-service, and resource consuming attacks. By performing comprehensive experiments, we demonstrate the attack’s feasibility and significant real-world impacts of TUDOOR. In total, 24 mainstream DNS software, including BIND, PowerDNS, and Microsoft DNS, are affected by TuDoor. Attackers can instigate cache poisoning and denial-of-service attacks against vulnerable resolvers using a handful of crafted packets within 1 second or circumvent the query limit to deplete resolution resources (e.g., CPU). Besides, to determine the vulnerable resolver population in the wild, we collect and evaluate 16 popular Wi-Fi routers, 6 prevalent router OSes, 42 public DNS services, and around 1.8M open DNS resolvers. Our measurement results indicate that TUDOOR could exploit 7 routers (OSes), 18 public DNS services, and 424,652 (23.1%) open DNS resolvers. Following the best practice of responsible disclosure, we have reported these vulnerabilities to all affected vendors, and 18 of them, including BIND, Chrome, Cloudflare, and Microsoft, have acknowledged our findings and discussed mitigation solutions with us. Furthermore, 33 CVE IDs are assigned to our discovered vulnerabilities, and we provide an online detection tool as one of the mitigation measures. Our research highlights the urgent need for standardization of DNS response pre-processing logic to enhance the security of DNS.
Xiang Li 0108, Wei Xu 0064, Baojun Liu 0002, Mingming Zhang 0010, Zhou Li 0001, Jia Zhang 0004, Deliang Chang, Chuhan Wang 0001, Jianjun Chen 0005, Hai-Xin Duan, Qi Li 0002
SP1
2024 ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
Qifan Zhang 0002, Xuesong Bai, Xiang Li 0108, Hai-Xin Duan, Qi Li 0002, Zhou Li 0001
USENIX Security Symposium3
2024 Rethinking the Security Threats of Stale DNS Glue Records
Baojun Liu 0002, Hai-Xin Duan, Min Zhang 0054, Xiang Li 0108, Fan Shi 0003, Chengxi Xu, Eihal Alowaisheq
USENIX Security Symposium5
2023 TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS Amplifiers
abstract
In this paper, we present a new DNS amplification attack, named TsuKing. Instead of exploiting individual DNS resolvers independently to achieve an amplification effect, TsuKing deftly coordinates numerous vulnerable DNS resolvers and crafted queries together to form potent DoS amplifiers. We demconstrate that with TsuKing, an initial small amplification factor can inrease exponentially through the internal layers of coordinated amplifiers, resulting in an extremely powerful amplification attack. TsuKing has three variants, including DNSRetry, DNSChain, and DNSLoop, all of which exploit a suite of inconsistent DNS implementations to achieve enormous amplification effect. With comprehensive measurements, we found that about 14.5% of 1.3M open DNS resolvers are potentially vulnerable to TsuKing. Real-world controlled evaluations indicated that attackers can achieve a packet amplification factor of at least 3,700X (DNSChain). We have reported vulnerabilities to affected vendors and provided them with mitigation recommendations. We have received positive responses from 6 vendors, including Unbound, MikroTik, and AliDNS, and 3 CVEs were assigned. Some of them are implementing our recommendations.
Wei Xu 0064, Xiang Li 0108, Chaoyi Lu, Baojun Liu 0002, Hai-Xin Duan, Jia Zhang 0004, Jianjun Chen 0005, Tao Wan 0004
CCS2
2023 Under the Dark: A Systematical Study of Stealthy Mining Pools (Ab)use in the Wild
abstract
Cryptocurrency mining is a crucial operation in blockchains, and miners often join mining pools to increase their chances of earning rewards. However, the energy-intensive nature of PoW cryptocurrency mining has led to its ban in New York State of the United States, China, and India. As a result, mining pools, serving as a central hub for mining activities, have become prime targets for regulatory enforcement. Furthermore, cryptojacking malware refers to self-owned stealthy mining pools to evade detection techniques and conceal profit wallet addresses. However, no systematic research has been conducted to analyze it, largely due to a lack of full understanding of the protocol implementation, usage, and port distribution of the stealth mining pool.
Zhenrui Zhang, Geng Hong, Xiang Li 0108, Zhuoqun Fu, Jia Zhang 0004, Mingxuan Liu 0006, Chuhan Wang 0001, Jianjun Chen 0005, Baojun Liu 0002, Hai-Xin Duan, Chao Zhang 0008, Min Yang 0002
CCS3
2023 Wolf in Sheep's Clothing: Evaluating Security Risks of the Undelegated Record on DNS Hosting Services
abstract
Leveraging DNS for covert communications is appealing since most networks allow DNS traffic, especially the ones directed toward renowned DNS hosting services. Unfortunately, most DNS hosting services overlook domain ownership verification, enabling miscreants to host undelegated DNS records of a domain they do not own. Consequently, miscreants can conduct covert communication through such undelegated records for whitelisted domains on reputable hosting providers. In this paper, we shed light on the emerging threat posed by undelegated records and demonstrate their exploitation in the wild. To the best of our knowledge, this security risk has not been studied before.
Fenglu Zhang, Baojun Liu 0002, Eihal Alowaisheq, Lingyun Ying, Xiang Li 0108, Zaifeng Zhang, Ying Liu 0024, Hai-Xin Duan, Min Zhang 0054
IMC6
2023 Ghost Domain Reloaded: Vulnerable Links in Domain Name Delegation and Revocation
Xiang Li 0108, Baojun Liu 0002, Xuesong Bai, Mingming Zhang 0010, Qifan Zhang 0002, Zhou Li 0001, Hai-Xin Duan, Qi Li 0002
NDSS1
2023 Temporal CDN-Convex Lens: A CDN-Assisted Practical Pulsing DDoS Attack
Run Guo, Jianjun Chen 0005, Keran Mu, Baojun Liu 0002, Xiang Li 0108, Chao Zhang 0008, Hai-Xin Duan
USENIX Security Symposium6
2023 The Maginot Line: Attacking the Boundary of DNS Caching Protection
Xiang Li 0108, Chaoyi Lu, Baojun Liu 0002, Qifan Zhang 0002, Zhou Li 0001, Hai-Xin Duan, Qi Li 0002
USENIX Security Symposium1
2021 Fast IPv6 Network Periphery Discovery and Security Implications
abstract
Numerous measurement researches have been performed to discover the IPv4 network security issues by leveraging the fast Internet-wide scanning techniques. However, IPv6 brings the 128-bit address space and renders brute-force network scanning impractical. Although significant efforts have been dedicated to enumerating active IPv6 hosts, limited by technique efficiency and probing accuracy, large-scale empirical measurement studies under the increasing IPv6 networks are infeasible now. To fill this research gap, by leveraging the extensively adopted IPv6 address allocation strategy, we propose a novel IPv6 network periphery discovery approach. Specifically, XMap, a fast network scanner, is developed to find the periphery, such as a home router. We evaluate it on twelve prominent Internet service providers and harvest 52M active peripheries. Grounded on these found devices, we explore IPv6 network risks of the unintended exposed security services and the flawed traffic routing strategies. First, we demonstrate the unintended exposed security services in IPv6 networks, such as DNS, and HTTP, have become emerging security risks by analyzing 4.7M peripheries. Second, by inspecting the periphery's packet routing strategies, we present the flawed implementations of IPv6 routing protocol affecting 5.8M router devices. Attackers can exploit this common vulnerability to conduct effective routing loop attacks, inducing DoS to the ISP's and home routers with an amplification factor of \gt 200. We responsibly disclose those issues to all involved vendors and ASes and discuss mitigation solutions. Our research results indicate that the security community should revisit IPv6 network strategies immediately.
Xiang Li 0108, Baojun Liu 0002, Hai-Xin Duan, Qi Li 0002, Youjun Huang
DSN1