VLDB 2026 Research / reviewers in the wild / expert
Liancheng Zhang
dblp:57/8599
· DBLP profile ↗
14ranked-venue papers
3as first author
12since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 1 first-author · 5 since 2021Systems, architecture and hardware · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | 6Massive: An Efficient IPv6 Large-Scale Target Generation Framework
Shunlong Hao, Liancheng Zhang, Ruosi Cheng, Lanxin Cheng, Wenhao Xia, Jichang Wang |
INFOCOM | 2 |
| 2026 | 6Hunter: An Efficient Framework for Discovering Router Interfaces in IPv6 Network
Liancheng Zhang, Junhu Zhu, Jichang Wang, Lanxin Cheng, Wenhao Xia, Yangxiang Zhou |
SECON | 2 |
| 2026 | TimelineReasoner: Advancing Timeline Summarization with Large Reasoning Models
Liancheng Zhang, Xiaoxi Li 0005, Zhicheng Dou |
SIGIR | 1 |
| 2025 | Alias6: An IPv6 Alias Resolution Technology Based on Multiple Fingerprint Features
Liancheng Zhang, Mingyue Ren, Yangxiang Zhou, Jichang Wang, Wenhao Xia, Lanxin Cheng |
ICIC (4) | 1 |
| 2025 | DualS-Geo: A Large-Scale Dual-Stack Landmark Mining Framework for IP Geolocation
Ruosi Cheng, Shichang Ding, Liancheng Zhang, Xiangyang Luo 0001 |
PAKDD (2) | 3 |
| 2025 | Finder6: Efficient IPv6 Addresses Scanning Based on Hostname Correlation in IPv6-Only NetworkabstractExisting on-link IPv6 address scanning technologies based on IPv6-only information rely on protocol features such as ICMPv6, MLD, and other protocol features to induce responses. However, these scanning packets are easily intercepted by the default security mechanisms of modern operating systems (OSs), leading to issues such as low OS coverage and incomplete IPv6 address scan results of alive nodes. On-link IPv6 address scanning technologies based on dual-stack correlation information overly rely on IPv4 networks, resulting in low IPv6 address scanning efficiency and inability to operate in IPv6-only networks. To this end, we propose an efficient IPv6 addresses scanning technology based on hostname correlation in IPv6-only network (HFinder6), which passively captures DHCPv6 Solicit messages sent by both currently alive and newly joined nodes, and constructs Router Advertisement messages of neighbor discovery protocol to trigger alive nodes to proactively send DHCPv6 Solicit messages, enabling the rapid acquisition of hostname information for on-link nodes. Subsequently, the IPv6 address information is queried in parallel using the mDNS protocol and LLMNR protocol, thereby achieving efficient scanning of IPv6 addresses for alive nodes in IPv6-only network. A typical IPv6-only and dual-stack network environment was established, comprising 14 versions of OSs such as Windows and Linux. HFinder6 was tested in this environment and compared with 4 IPv6 address scanning scripts based on IPv6-only information from the Nmap tool and 3 IPv6 address scanning tools based on dual-stack correlation information (e.g., LinkScan6, LLMNR6, and FScan6). Experimental results show that HFinder6 can discover 31 IPv6 addresses across 12 OS versions in an average of just 10.19 seconds within IPv6-only network. In terms of OS coverage and IPv6 address scanning completeness, HFinder6 performs on par with FScan6 and outperforms 6 other scripts and tools, successfully identifies at more 9 additional OS versions and scans 27 more IPv6 addresses, thereby enhancing the completeness of IPv6 address scanning by up to 7.76 times. Moreover, in terms of IPv6 address scanning efficiency, HFinder6 can identify 2.23 more IPv6 addresses per second, outperforming 7 other scripts and tools. Liancheng Zhang, Ruijuan Wang, Yakai Fang |
TrustCom | 2 |
| 2025 | P4NSA: P4-based security protection technology for IPv6 neighbor solicitation and advertisement spoofing
Wenhao Xia, Liancheng Zhang, Lanxin Cheng |
Comput. Secur. | 2 |
| 2024 | A High-Performance IPv6 Fragment Evasion Threat Detection Method Based on eBPF and XDPabstractThe IPv6 fragment header can be exploited by threateners to evade security systems like firewalls, leading to IPv6 fragment evasion threats. Current detection techniques for these threats face limitations in identification capabilities and poor detection performance. To address these issues, a high-performance threat detection method based on eBPF and XDP (named FragEva6-Guard) is proposed. First, XDP is employed at the network driver level to filter IPv6 packets in real time, allowing threat packets to be identified and processed at the earliest stage. Then, an eBPF program is used to further analyze packets that have passed the initial filtering and detect potential threats. A feature matching based upper-layer header integrity detection method is introduced to identify IPv6 fragment evasion threats. FragEva6-Guard extracts critical threat features and performs feature matching during packet analysis. Finally, the XDP decision making module executes appropriate actions based on the feature matching results to complete the detection process. Experimental results show that FragEva6-Guard successfully detects all 16 types of IPv6 fragment evasion threats from the Frag6-TestSuite, achieving an average detection rate of approximately 99.98% across various threat intensities, FragEva6-Guard outperforms both Baseline and Suricata. In terms of processing latency, FragEva6-Guard reduces delays by an average of 99.96% compared to Baseline and by approximately 8% compared to Suricata, while also lowering CPU usage by an average of 95.03% and 85.77%, respectively. Additionally, FragEva6-Guard has minimal impact on network performance, maintaining a consistent packet loss rate of 0%. Liancheng Zhang, Qingtao Wang |
HPCC | 2 |
| 2024 | 6DoubleTree: IPv6 Address Prediction Algorithm Based on Double Space TreeabstractThe discovery and management of network assets are crucial for network security. Faced with the vast IPv6 address space, traditional IP scanning methods are no longer applicable. Existing IPv6 address prediction algorithms suffer from low hit rates and insufficient sub-prefix coverage. Therefore, the paper proposes 6DoubleTree, an IPv6 address prediction algorithm that adopts a prefix and suffix partition tree structure. 6DoubleTree divides IPv6 addresses into prefix (high 64-bit) and suffix (low 64-bit) parts, and performs IPv6 address pattern mining and refinement on the BGP prefix space to generate IPv6 target addresses. Comparative experiments were conducted in a real IPv6 network environment, and experimental results on 3 IPv6 seed sets of 25k, 50k, and 0.1M showed that under the same budget conditions, compared to 7 algorithms based on seed address structural information, such as 6Forest and 6Graph, 6DoubleTree averagely increased the number of active addresses by 54.92% and the number of active /64 prefixes by 60.25%. Mingyue Ren, Liancheng Zhang, Shunlong Hao |
HPCC | 2 |
| 2024 | AScan6: IPv6 Address Fast Scanning Technology Based on Service Instance Name AssociationabstractTo quickly detect active IPv6 addresses of Apple nodes, an IPv6 address fast scanning technology based on service instance name association (named AScan6) is proposed. Firstly, AScan6 initiates the discovery of active IPv6 hosts by sending ICMPv6 packets with invalid extension headers. Subsequently, it leverages the DNS-SD protocol to obtain the service types of these hosts. Then, AScan6 queries service details to retrieve their service instance names. Finally, it employs the mDNS protocol to acquire IPv6 addresses associated with these service instance names. A typical IPv6 network environment, comprising 4 desktop Apple versions (macOS) and 6 mobile Apple versions (iOS and iPadOS), is constructed to test AScan6 and compare AScan6 with LLMNR6, LinkScan6 and 4 Nmap scripts. Experimental results show that LLMNR6 and LinkScan6 detected none of valid IPv6 addresses, while AScan6 could detect 20 more IPv6 addresses than the 4 Nmap scripts, thus improving the completeness of IPv6 address scanning results. When focusing on individual Apple node, AScan6 detected 1 to 2 additional IPv6 global unicast addresses compared with the 4 Nmap scripts. In terms of AScan6’s scanning capability for Linux operating systems, AScan6 identified between 1.29 to 2.57 times more IPv6 addresses than the 4 Nmap scripts. Yakai Fang, Liancheng Zhang |
LCN | 2 |
| 2024 | Research on Security Protection Evasion Mechanism Based on IPv6 Fragment HeadersabstractThe IPv6 fragment headers are crucial for packet fragmentation but can be exploited to evade security systems, posing substantial threats. Despite RFC 7112 highlighting the implications of "IPv6 fragment evasion behavior", comprehensive evaluation is lacking, impeding assessment of compliance with standards. Concurrently, existing IPv6 fragment evasion behaviors have primarily focused on tiny/overlapping fragments, overlooking the combination of other IPv6 extension headers. Consequently, this paper proposes an IPv6 fragment evasion (FragEva6) behavior model, demonstrating the step-by-step construction process from the IPv6 header to the FragEva6 mechanism. Next, a test suite named FragEva6-Build encompassing 16 types of FragEva6 behaviors is realized through 3 steps. Subsequently, an evaluation of 17 mainstream operating systems and 4 security systems reveals that the latest versions of Windows and Apple operating systems comply with RFC 7112 when handling IPv6 fragmentations, while Linux operating systems exhibit partial non-compliance. Further, security systems (Windows Defender 20230503.1, ip6 tables 1.8.9, Suricata v6.0.12, and Snort v3.1.61.0) exhibit inadequate mitigation, leaving them susceptible to evasion threats through manipulation of IPv6 fragment headers. Finally, to illustrate the gravity of these behaviors, this study implements an on-link host scanning activity based on the FragEva6 mechanism, successfully evading firewalls and eliciting target responses. Liancheng Zhang, Yakai Fang |
LCN | 2 |
| 2023 | Trace6: A Practical Threatener Traceback Model in IPv6 NetworkabstractThe increasing severity of Internet threats and the rapid digitization process worldwide have made network security more important than ever. Proactive defense technologies, such as threat traceback, have become essential for protection. However, current threatener traceback systems are not feasible due to lack of sufficient information, low reliability of traceback results, and an inability to meet both universality and lightweight. To address these issues, a practical threatener traceback model in IPv6 networks (Trace6) has been developed using the unique features of the huge IPv6 address space and extended address field. Trace6 proposes user information generated addresses that are rich in user information to determine the mapping relationship between natural persons and addresses. It introduces and combines two technologies, user authentication and address verification, to strengthen the determined mapping relationship. Furthermore, Trace6 enhances the address lease after Portal authentication and distinguishes the address status to ensure that it is both universal and lightweight. The experimental results from the prototype system’s tests indicate that Trace6 can further ensure reliability, universality, and lightweight while maintaining effectiveness. Chaoqiang Yang, Liancheng Zhang, Yi Gou, Wenhao Xia, Jichang Wang |
MSN | 2 |
| 2019 | CATH: an effective method for detecting denial-of-service attacks in software defined networks
Fu Miao, Liancheng Zhang |
Sci. China Inf. Sci. | 3 |
| 2018 | Survey on network flow watermarking: model, interferences, applications, technologies and securityabstractCompared with passive flow correlation technologies based on flow characteristics, network flow watermarking, a kind of active flow correlation technology, is characterised by high accuracy, low false positive rate and short observation time. The basic framework and main elements of flow watermarking are formally described. The robustness and invisibility focused by flow watermarking as well as typical application scenarios (such as stepping‐stone traceback, anonymous abuser correlation) of flow watermarking are expounded. The intra‐flow and inter‐flow interferences (such as repacketisation, packet reorder, delay normalisation, flow mixing, flow splitting and flow merging) faced by flow watermarking are briefly introduced. Analysis and comparison on different watermark carriers (packet payload, traffic rate, packet timing, packet number, packet length, packet order and hybrid carrier) based typical flow watermarking technologies, including flow fingerprinting technologies, are conducted, then, a review on security threats faced by flow watermarking, including multi‐flow attack, mean‐square autocorrelation attack, Kolmogorov–Smirnov test, BACKLIT detection and replication attack, and main countermeasures for increasing invisibility of flow watermarking is carried out. Current research hotspots and future development trends of flow watermarking are summarised and prospected from the aspects of architecture design, invisibility enhancement, adaptive capability improvement, performance evaluation, deployment and application. Liancheng Zhang, Yazhou Kong, Juwei Yan |
IET Commun. | 1 |