Xiaofan Li 0009

dblp:50/3937-9 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
4since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Blockchain and cryptocurrency security · 67% Systems and software security · 33%
Software engineering, system software, and programming languages
2 papers
Software maintenance and evolution · 100%
Computer networks
1 paper
Software-defined and programmable networks · 100%

Topics — the 6 heaviest of 6, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Blockchain and cryptocurrency security
smart contract security
0.812024
Characterizing Ethereum Upgradable Smart Contracts and Their Security Implications · WWW 2024
Systems and software security
software supply chain security
0.812024
Toward Understanding the Security of Plugins in Continuous Integration Services · CCS 2024
Blockchain and cryptocurrency security › smart contract
upgradeable smart contract
0.812024
Characterizing Ethereum Upgradable Smart Contracts and Their Security Implications · WWW 2024
Software maintenance and evolution
software ecosystems
0.812024
Toward Understanding the Security of Plugins in Continuous Integration Services · CCS 2024
Software-defined and programmable networks
SDN security
0.712023
SDN Application Backdoor: Disrupting the Service via Poisoning the Topology · INFOCOM 2023
Software maintenance and evolution
software updates
0.212024
Characterizing Ethereum Upgradable Smart Contracts and Their Security Implications · WWW 2024

Methods — techniques the papers use, named apart from their topics

transaction analysis · 1.5large-scale measurement · 1.5bytecode analysis · 1.5attack vector analysis · 1.5
YearPublicationVenuePosition
2025 Secretscout: Effective Hard-Coded Secrets Detection in Ci Configuration Files
abstract
Continuous Integration (CI) has been widely adopted for automated software building and testing. In CI workflows, various third-party services can be integrated to enhance functionalities. During the integration process, secrets such as tokens and credentials are often used for authentication and authorization. Unfortunately, secret leakage regularly occurs, potentially causing serious consequences. Existing secret scanners detect secrets by matching tokens and credentials through regular expressions, which suffer from low recall rates. In this paper, we identify several issues in regular expression-based secret detectors and propose SecretScout, a new method for scanning hard-coded secrets by detecting their names. SecretScout contains carefully designed detectors to extract candidates. It considers special flags where secrets might exist, and further applies filters to reduce false positives. SecretScout can detect secrets in both structured files (e.g., CI configuration files) and unstructured files (e.g., log files). To demonstrate the effectiveness, we evaluate SecretScout and different versions of GitLeaks and TruffleHog using labeled configuration files. The results show that SecretScout achieves$7.3 \times$and$100 \times$higher recall rates compared to the default versions of GitLeaks and TruffleHog, respectively. We also conduct a measurement study on open-source projects' configuration files, and demonstrate that many true secrets might be leaked.
Chu Qiao, Yacong Gu, Xiaofan Li 0009, Xing Gao 0001
SRDS3
2024 Toward Understanding the Security of Plugins in Continuous Integration Services
abstract
Mainstream Continuous Integration (CI) platforms have provided the plugin functionality to accelerate the development of CI pipelines. Unfortunately, CI plugins, which are essentially reusable code snippets, also expose new attack surfaces as plugins might be developed by less trusted users. In this paper, we present an in-depth study to understand potential security risks in existing CI plugins. We conduct a comprehensive analysis of plugin implementations on four mainstream CI platforms (GitHub Actions, GitLab CI, CircleCI, and Azure Pipelines), and investigate several weak links in existing plugin distributions and isolation mechanisms. We investigate seven attack vectors that can enable attackers to hijack plugins and distribute malicious code without plugins users being aware, and further exploit hijacked plugins to manipulate the workflow execution. Additionally, we find that plugin dependency (a plugin references other plugins) might further amplify the attack impact of our disclosed attacks. To evaluate the potential impact, we conduct a large-scale measurement on GitHub and GitLab, covering a total of 1,328,912 repositories using the aforementioned CI platforms. Our measurement results show that a large number of repositories and existing plugins, including many widely used ones, are potentially vulnerable to the proposed attacks. We have duly reported the identified vulnerabilities and received positive responses.
Xiaofan Li 0009, Yacong Gu, Chu Qiao, Zhenkai Zhang 0002, Daiping Liu, Lingyun Ying, Hai-Xin Duan, Xing Gao 0001
CCS1
2024 Characterizing Ethereum Upgradable Smart Contracts and Their Security Implications
abstract
Upgradeable smart contracts (USCs) have been widely adopted to enable modifying deployed smart contracts. While USCs bring great flexibility to developers, improper usage might introduce new security issues, potentially allowing attackers to hijack USCs and their users. In this paper, we conduct a large-scale measurement study to characterize USCs and their security implications in the wild. We summarize six commonly used USC patterns and develop a tool, USCDetector, to identify USCs without needing source code. Particularly, USCDetector collects various information such as bytecode and transaction information to construct upgrade chains for USCs and disclose potentially vulnerable ones. We evaluate USCDetector using verified smart contracts (i.e., with source code) as ground truth and show that USCDetector can achieve high accuracy with a precision of 96.26%. We then use USCDetector to conduct a large-scale study on Ethereum, covering a total of 60,251,064 smart contracts. USCDetecor constructs 10,218 upgrade chains and discloses multiple real-world USCs with potential security issues.
Xiaofan Li 0009, Yuzhe Tang, Xing Gao 0001
WWW1
2023 SDN Application Backdoor: Disrupting the Service via Poisoning the Topology
abstract
Software-Defined Networking (SDN) enables the deployment of diversified networking applications by providing global visibility and open programmability on a centralized controller. As SDN enters its second decade, several well-developed open source controllers have been widely adopted in industry, and various commercial SDN applications are built to meet the surging demand of network innovation. This complex ecosystem inevitably introduces new security threats, as malicious applications can significantly disrupt network operations. In this paper, we introduce a new vulnerability in existing SDN controllers that enable adversaries to create a backdoor and further deploy malicious applications to disrupt network service via a series of topology poisoning attacks. The root cause of this vulnerability is that SDN systems simply process received Packet-In messages without checking the integrity, and thus can be misguided by manipulated messages. We discover that five popular SDN controllers (i.e., Floodlight, ONOS, OpenDaylight, POX and Ryu) are potentially vulnerable to the disclosed attack, and further propose six new attacks exploiting this vulnerability to disrupt SDN services from different layers. We evaluate the effectiveness of these attacks with experiments in real SDN testbeds, and discuss feasible countermeasures.
Shuhua Deng, Xian Qing, Xiaofan Li 0009, Xing Gao 0001, Xieping Gao 0001
INFOCOM3