Liang Wang 0054

dblp:56/4499-54 · DBLP profile ↗
← Back
10ranked-venue papers
1as first author
9since 2021 · last 2026
0000-0002-3713-6089ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 1 first-author · 7 since 2021Computer networks · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Cryptographically-Secured Domain Validation
abstract
Certificate Authorities (CAs) bootstrap HTTPS-based privacy and trust on the Internet by authenticating the identity of domain names via a process known as domain control validation (DV). Ironically, currently used DV mechanisms rely on unauthenticated web protocols, including plaintext DNS and HTTP, and have been shown vulnerable to a range of network attacks. To address this critical challenge, we propose a framework for cryptographic verification of domain control, which fundamentally mitigates network-layer attacks. Our framework rethinks live DV protocol mechanisms using a domain owner specified security policy which constrains CAs to use authenticated channels and provide cryptographic verification. Our approach minimizes deployment burden on CAs by leveraging existing pieces of the Web PKI and DNS ecosystems,such as Certificate Authority Authorization (CAA) policies and secure DNS. We demonstrate the security properties of our design formally using the Tamarin verification tool and empirically via ethically-conducted real-world attacks. We showcase the feasibility of our framework through collaboration with a major anonymous CA: we analyze DNS and certificate issuance practices of over 400M live domains to understand the current state of CAA policies and secure DNS. We also report on the CA’s experiences implementing parts of our design in production. Finally, to realize our framework in the live Web PKI, we led a successful standardization effort for mandatory use of secure DNS by CAs at the CA/Browser Forum.
Grace H. Cimaszewski, Henry Birge-Lee, Cyrill Krähenbühl, Liang Wang 0054, Aaron Gable, Prateek Mittal
Proc. Priv. Enhancing Technol.4
2026 QUICstep: Evaluating connection migration based QUIC censorship circumvention
abstract
Internet censors often rely on information in the first few packets of a connection to censor unwanted traffic. With the rise of the QUIC transport protocol, prior work has suggested the method of using QUIC connection migration to conceal the first few handshake packets using a different network path (e.g., an encrypted proxy channel). However, the use of connection migration for censorship circumvention has not been explored or validated in terms of feasibility or performance. We bridge this gap by providing a rigorous quantitative evaluation of this approach that we name QUICstep. We develop a lightweight, application-agnostic prototype of QUICstep and demonstrate that QUICstep is able to circumvent a real-world QUIC SNI censor. We find that not only does QUICstep outperform a fully encrypted channel in diverse settings, but also that it can significantly reduce traffic load for encrypted channel providers. We also propose using QUICstep as a tool for measuring QUIC connection migration support in the wild and show that support for connection migration is on the rise. While as of now QUIC and connection migration support is limited, we envision that QUICstep can be a useful tool for the future where QUIC is the de facto norm for the Internet.
Seungju Lee, Mona Wang, Watson Jia, Henry Birge-Lee, Liang Wang 0054, Prateek Mittal
Proc. Priv. Enhancing Technol.6
2025 A Framework to Evaluate MPIC Security using Real-World BGP Announcements
abstract
Multiple Perspective Issuance Corroboration (MPIC) is a defense that strengthens the Domain Control Validation protocol run by Certificate Authorities (CAs) against network attacks (e.g., routing hijacks). Despite its recent adoption as a requirement by the CA/Browser Forum, the quantitative security benefits of MPIC in light of real-world routing behaviors are not well understood. We seek to address this challenge by creating a framework to test the effects of real-world BGP hijacks on millions of potential MPIC perspective deployments. Our framework launches around 1500 ethical BGP hijacks on IP prefixes we own and analyzes how potential MPIC perspectives route under these attacks. We consider over 100 global MPIC perspective locations spread across 3 major cloud providers. We find that optimal MPIC deployments can prevent certificate misissuance for over 87% of our evaluated real-world BGP hijacks. We further show that different routing behaviors by cloud providers, such as cold potato routing, have a substantial effect on MPIC's ability to limit the impact of BGP attacks. Finally, our framework computes optimized sets of MPIC perspective locations for CAs to use given their preference of cloud provider and perspective count. Our recommendations have already impacted the MPIC deployment at Google Trust Services, and have been adopted as the default recommendation by the Open MPIC project.
Henry Birge-Lee, Ari Brown, Christine Guo, Cyrill Krähenbühl, Sohom Pal, Liang Wang 0054, Prateek Mittal
IMC6
2025 Scaling SCIERA: A Journey Through the Deployment of a Next-generation Network
abstract
The SCION Next-Generation Network (NGN) architecture has expanded steadily since 2017, with today 20+ ISPs offering SCION connectivity. In production, IP-to-SCION-to-IP translation by SCION-IP-Gateways (SIGs) is used, such that applications are unaware of the NGN communication. To accelerate innovation and deployments, our aim is to increase the number of native SCION use cases, where the application is fully SCION-aware and optimizes communication across all path choices offered by the network. We set out to achieve two core objectives: (1) facilitating simple native connectivity for applications, and (2) enhancing the scalability of SCION deployment at academic sites.
François Wirz, Marten Gartner, Jelte van Bommel, Elham Ehsani Moghadam, Grace H. Cimaszewski, Anxiao He, Yizhe Zhang 0006, Henry Birge-Lee, Felix Kottmann, Cyrill Krähenbühl, Jonghoon Kwon, Kyveli Mavromati, Liang Wang 0054, Daniel Bertolo, Marco Canini, Buseung Cho, Ronaldo A. Ferreira, Simon Peter Green, David Hausheer, Junbeom Hur, Xiaohua Jia, Heejo Lee, Prateek Mittal, Omo Oaiya, Chanjin Park, Adrian Perrig, Jerry Sobieski, Yixin Sun 0004, Cong Wang 0001, Klaas Wierenga
SIGCOMM13
2023 How Effective is Multiple-Vantage-Point Domain Control Validation?
Grace H. Cimaszewski, Henry Birge-Lee, Liang Wang 0054, Jennifer Rexford, Prateek Mittal
USENIX Security Symposium3
2023 RAVEN: Stateless Rapid IP Address Variation for Enterprise Networks
abstract
Enterprise networks face increasing threats against the privacy of their clients. Existing enterprise services like Network Address Translation (NAT) offer limited privacy protection, at the cost of requiring per-flow state. In this paper, we introduce RAVEN (Rapid Address Variation for Enterprise Networks), a network-based privacy solution that is complementary to application-layer defenses. RAVEN protects privacy by frequently changing the client's public IP address. With RAVEN, a client is not limited to using a single IP address at a given time, or even for a given connection. RAVEN goes further, breaking the association between packets that belong to the same connection by frequently changing the client's IP address within a single connection. RAVEN achieves this through a novel division of labor: the client uses a transport protocol, like QUIC, that supports seamless connection migration, and decides when to switch its IP address, while the enterprise network actually changes the client's IP address in a stateless manner at line rate and ensures end-to-end packet delivery. We implement RAVEN using QUIC and off-the-shelf programmable switches. We deploy RAVEN in a test IPv6 network and evaluate its defense against webpage fingerprinting attacks. Even with a strong adversary, the average precision of the best adaptive attacks drops from 0.96 to 0.84, with a 0.5% degradation in client throughput. When RAVEN changes IP addresses at unpredictable frequency, the precision of the best attacks falls to 0.78---the same effectiveness as WTF-PAD.
Liang Wang 0054, Hyojoon Kim, Prateek Mittal, Jennifer Rexford
Proc. Priv. Enhancing Technol.1
2022 Creating a Secure Underlay for the Internet
Henry Birge-Lee, Joel Wanner, Grace H. Cimaszewski, Jonghoon Kwon, Liang Wang 0054, François Wirz, Prateek Mittal, Adrian Perrig, Yixin Sun 0004
USENIX Security Symposium5
2022 Leveraging strategic connection migration-powered traffic splitting for privacy
abstract
Network-level adversaries have developed increasingly sophisticated techniques to surveil and control users’ network traffic. In this paper, we exploit our observation that many encrypted protocol connections are no longer tied to device IP address (e.g., the connection migration feature in QUIC, or IP roaming in WireGuard and Mosh), due to the need for performance in a mobile-first world. We design and implement a novel framework, Connection Migration Powered Splitting (CoMPS), that utilizes these performance features for enhancing user privacy. With CoMPS, we can split traffic mid-session across network paths and heterogeneous network protocols. Such traffic splitting mitigates the ability of a network-level adversary to perform traffic analysis attacks by limiting the amount of traffic they can observe. We use CoMPS to construct a website fingerprinting defense that is resilient against traffic analysis attacks by a powerful adaptive adversary in the open-world setting. We evaluate our system using both simulated splitting data and real-world traffic that is actively split using CoMPS. In our real-world experiments, CoMPS reduces the precision and recall of VarCNN to 29.9% and 36.7% respectively in the openworld setting with 100 monitored classes. CoMPS is not only immediately deployable with any unaltered server that supports connection migration, but also incurs little overhead, decreasing throughput by only 5-20%.
Mona Wang, Anunay Kulshrestha, Liang Wang 0054, Prateek Mittal
Proc. Priv. Enhancing Technol.3
2021 Experiences Deploying Multi-Vantage-Point Domain Validation at Let's Encrypt
Henry Birge-Lee, Liang Wang 0054, Daniel McCarney, Roland Shoemaker, Jennifer Rexford, Prateek Mittal
USENIX Security Symposium2
2019 SICO: Surgical Interception Attacks by Manipulating BGP Communities
abstract
The Border Gateway Protocol (BGP) is the primary routing protocol for the Internet backbone, yet it lacks adequate security mechanisms. While simple BGP hijack attacks only involve an adversary hijacking Internet traffic destined to a victim, more complex and challenging interception attacks require that adversary intercept a victim's traffic and forward it on to the victim. If an interception attack is launched incorrectly, the adversary's attack will disrupt its route to the victim making it impossible to forward packets. To overcome these challenges, we introduce SICO attacks (Surgical Interception using COmmunities): a novel method of launching interception attacks that leverages BGP communities to scope an adversary's attack and ensure a route to the victim. We then show how SICO attacks can be targeted to specific source IP addresses for reducing attack costs. Furthermore, we ethically perform SICO attacks on the real Internet backbone to evaluate their feasibility and effectiveness. Results suggest that SICO attacks can achieve interception even when previously proposed attacks would not be feasible and outperforms them by attracting traffic from an additional 16% of Internet hosts (worst case) and 58% of Internet hosts (best case). Finally, we analyze the Internet topology to find that at least 83% of multi-homed ASes are capable of launching these attacks.
Henry Birge-Lee, Liang Wang 0054, Jennifer Rexford, Prateek Mittal
CCS2