VLDB 2026 Research / reviewers in the wild / expert
Qiang Li 0007
dblp:72/872-7
· DBLP profile ↗
41ranked-venue papers
11as first author
17since 2021 · last 2025
0000-0001-9833-2836ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 22 · 8 first-author · 6 since 2021Security and privacy · 13 · 2 first-author · 9 since 2021Systems, architecture and hardware · 4 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Automatically Generating Rules of Malicious Software Packages via Large Language ModelabstractToday’s security tools predominantly rely on predefined rules crafted by experts, making them poorly adapted to the emergence of software supply chain attacks. To tackle this limitation, we propose a novel tool, RuleLLM, which leverages large language models (LLMs) to automate rule generation for OSS ecosystems. RuleLLM extracts metadata and code snippets from malware as its input, producing YARA and Semgrep rules that can be directly deployed in software development. Specifically, the rule generation task involves three subtasks: crafting rules, refining rules, and aligning rules. To validate RuleLLM’s effectiveness, we implemented a prototype system and conducted experiments on the dataset of 1,633 malicious packages. The results are promising—RuleLLM generated 763 rules (452 YARA and 311 Semgrep) with a precision of 85.2% and a recall of 91.8%, outperforming state-of-the-art (SOTA) tools and scored-based approaches. We further analyzed generated rules and proposed a rule taxonomy: 11 categories and 38 subcategories. XiangRui Zhang, XueJie Du, Wenjia Niu, Qiang Li 0007 |
DSN | 6 |
| 2025 | An Analysis of Malicious Packages in Open-Source Software in the WildabstractThe open-source software (OSS) ecosystem suffers from security threats caused by malware. However, OSS malware research has three limitations: a lack of high-quality datasets, a lack of malware diversity, and a lack of attack campaign contexts. In this paper, we first build the largest dataset of 24,356 malicious packages from online sources, then propose a knowledge graph to represent the OSS malware corpus and conduct malware analysis in the wild. Our main findings include (1) it is essential to collect malicious packages from various online sources because their data overlapping degrees are small; (2) despite the sheer volume of malicious packages, many reuse similar code, leading to a low diversity of malware; (3) only 28 malicious packages were repeatedly hidden via dependency libraries of 1,354 malicious packages, and dependency-hidden malware has a shorter active time; (4) security reports are the only reliable source for disclosing the malware-based context. Wenjia Niu, Jiqiang Liu, Haining Wang 0001, Qiang Li 0007 |
DSN | 6 |
| 2025 | TSS-ZKP: Enabling Blockchain Account Supervision Without Compromising User IdentityabstractPerforming effective supervision in blockchain networks while preserving public anonymity has long been a challenging issue. Existing solutions often depend on third-party institutions or dual-chain architectures to monitor and recover user identities, but these approaches pose significant risks, such as identity disclosure and increased inter-chain communication costs. To address these concerns, this paper proposes a novel supervised scheme based on Threshold Secret-Sharing (TSS) and Zero-Knowledge Proof (ZKP) on anonymous accounts on the blockchain called TSS-ZKP, while integrating regulatory authority (RA) and multiple traceability centers (TC). Compared to traditional single RA, TSS-ZKP decentralizes the regulatory authority and storage across multiple TCs, significantly reducing the risk of user identity leakage by a single RA. By TSS-ZKP, user identities are recovered through the collaborative generation of sub-secrets by the RA and TCs, without storing actual identity information. By leveraging elliptic curves and using hash functions as secret labels, TSS-ZKP achieves lightweight operations, allowing TCs to efficiently locate sub-secrets without extensive traversal. The comprehensive analysis of security and privacy demonstrated that TSS-ZKP effectively safeguards user privacy while enabling feasible supervision. In addition, comparison experimental results show that the time consumption of the TSS-ZKP is about 30% of that of the comparison scheme. Meanwhile, the simulation results highlight the practicality of the scheme, showing that TSS-ZKP significantly reduces the delays in the identity recovery process while maintaining high usability. In general, TSS-ZKP provides a safer and more feasible solution for enabling the supervision of blockchain accounts. Cong Wang 0004, Qiang Li 0007, Guanquan Xu, Shouling Ji, Jian Weng 0001, Pan Gao 0006, Wei Wang 0012 |
IEEE Internet Things J. | 2 |
| 2025 | Detecting Time-Delay Attacks in Industrial Control Systems Through State-Aware InferenceabstractThe time-delay attacks pose serious security threats to the industrial control systems (ICSs), where ICS infrastructures (e.g., chemical factories) could suffer severe safety consequences. They could bypass current delay detection methods by avoiding triggering packet timeouts. In this article, we reveal that malicious states caused by the time-delay attacks in ICS scenarios can be detected by analyzing ICS programs. We propose detecting a time-delay attack in ICS scenarios by comparing the difference between malicious and benign states, meeting the real-time and noninterference requirements. Specifically, we utilize symbolic execution to analyze ICS programs to generate the benign states of ICS and leverage the key features of time-delay attacks to create the malicious states of ICS, where the states are transferred through the network for remote control and monitoring. We propose a multimodal neural network whose inputs are the malicious states sampled from the ICS network traffic and the time domain features, and the output is whether such a time-delay attack exists. We implement a prototype system and conduct real-world experiments to evaluate the performance of our detection approach. Our experiments cover 102 vulnerable ICS programs and five types of time-delay attacks. The evaluation results show that our approach can detect ICS time-delay attacks in 0.6 s, with 97.2% precision and 98% recall. Kai Yang 0037, Qiang Li 0007, Ting Li 0023, Haining Wang 0001, Limin Sun 0001 |
IEEE Internet Things J. | 2 |
| 2025 | SoFi: Spoofing OS Fingerprints Against Network ReconnaissanceabstractFingerprinting is a network reconnaissance technique utilized for gathering information about online computing systems, including operation systems and applications. Unfortunately, attackers typically leverage fingerprinting techniques to locate, enumerate, and subsequently target vulnerable systems, which is the first primary stage of a cyber attack. In this work, we explore the susceptibility of machine learning (ML)-based classifiers to misclassification, where a slight perturbation in the packet is included to spoof OS fingerprints. We propose SOFI (Spoof OS Fingerprints), an adversarial example generation algorithm under TCP/IP specification constraints, to create effective perturbations in a packet for deceiving an OS fingerprint. Specifically, SOFI has three major technical innovations: (1) it is the first to utilize adversarial examples to automatically perturb fingerprinting techniques; (2) it complies with constraints and integrity of network packets; (3) it achieves a high success rate in spoofing OS fingerprints. We validate the effectiveness of adversarial packets against active and passive OS fingerprints, verifying the transferability and robustness of SOFI. Comprehensive experimental results demonstrate that SOFI automatically identifies applicable and available OS fingerprint features, unlike existing tools relying on expert knowledge. Haocong Li, Wei Wang 0012, Haining Wang 0001, Xiaobo Ma 0001, Shouling Ji, Qiang Li 0007 |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2024 | FirmPorter: Porting RTOSes at the Binary Level for Firmware Re-hosting
Mingfeng Xin, Hui Wen 0001, Liting Deng, Hong Li 0004, Qiang Li 0007, Limin Sun 0001 |
ICICS (2) | 5 |
| 2024 | BFS2Adv: Black-box adversarial attack towards hard-to-attack short texts
Qiang Li 0007, Hongbo Cao, Bin Wang 0062, Xuhua Bao, Yufei Han 0001, Wei Wang 0012 |
Comput. Secur. | 2 |
| 2024 | Fingerprinting Industrial IoT devices based on multi-branch neural network
Kai Yang 0037, Qiang Li 0007, Haining Wang 0001, Limin Sun 0001, Jiqiang Liu |
Expert Syst. Appl. | 2 |
| 2024 | Understanding images of surveillance devices in the wild
Jiongyu Dai, Qiang Li 0007, Haining Wang 0001, Lingjia Liu 0001 |
Knowl. Based Syst. | 2 |
| 2024 | Automatically Identifying CVE Affected Versions With Patches and Developer LogsabstractWhile vulnerability databases are important sources of information for software security, it is known that information in these databases is inconsistent. How to rectify these incorrect data is a challenging issue. In this article, we employ developer logs and patches to automatically identify vulnerable source code versions that each CVE really affects. Our tool organizes all versions of a piece of software into a version tree, and identifies the first vulnerable version, and the last vulnerable versions in the version tree trunk and branches. For evaluation, we took Linux Kernel as the case study and quantified the error rate of the vulnerable versions reported by the NVD. The total number of vulnerable Linux Kernel versions reported by the NVD was 43,727 (as of September 2020), of which the total number of false positives reached 2,497 and the total number of false negatives reached 9,330, accounting for 5.7% and 21.34%, respectively. In addition, we compare our tool with two vulnerability detection tools and show that our tool could achieve high detection accuracy. Sencun Zhu, Wei Wang 0012, Qiang Li 0007 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2024 | PKVIC: Supplement Missing Software Package Information in Security Vulnerability ReportsabstractNowadays security vulnerability reports contain commercial vendor-centric information but fail to include accurate information of open-source software packages. Open-source ecosystems use package managers, such as Maven, NuGet, NPM, and Gem, to cover hundreds of thousands of free code packages. However, we uncover that vulnerability reports frequently miss the vulnerable software package information when the software package comes from open-source ecosystems. To fill in this gap, we propose a framework called PKVIC (softwarepackagevulnerabilityinformationcalibration), as the first tool to automatically associate security vulnerability reports with affected software packages from different open-source ecosystems. Specifically, PKVIC designs an ecosystem classifier to determine which ecosystem a vulnerability report belongs to. From the reports written in natural language, PKVIC extracts the entities closely related to software names in ecosystems. To efficiently and accurately locate the affected software packages from millions of packages, we propose a recursive traversal method to generate the package identifier based on the naming scheme and candidate named entities. We implemented the prototype of PKVIC and conducted comprehensive experiments to validate its efficacy. In particular, we ran PKVIC over 421,808 vulnerability reports from 20 well-known sources of security vulnerabilities and identified 11,279 unique vulnerability reports that affected 2,703 open-source software packages. PKVIC successfully found the accurate reference URLs for these 2,703 software packages across 6 open-source ecosystems, including Pypi, Gem, NPM, Packagist, Nuget, and Maven. Jinke Song, Qiang Li 0007, Haining Wang 0001, Jiqiang Liu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Toward Automatically Connecting IoT Devices with Vulnerabilities in the WildabstractWith the increasing number of Internet of Things (IoT) devices connected to the internet, the industry and research community have become increasingly concerned about their security impact. Adversaries or hackers often exploit public security flaws to compromise IoT devices and launch cyber attacks. However, despite this growing concern, little effort has been made to investigate the detection of IoT devices and their underlying risks. To address this gap, this article proposes to automatically establish relationships between IoT devices and their vulnerabilities in the wild. Specifically, we construct a deep neural network (DNN) to extract semantic information from IoT packets and generate fine-grained fingerprints of IoT devices. This enables us to annotate IoT devices in cyberspace, including their device type, vendor, and product information. We collect vulnerability reports from various security sources and extract IoT device information from these reports to automatically match vulnerabilities with the fingerprints of IoT devices. We implemented a prototype system and conducted extensive experiments to validate the effectiveness of our approach. The results show that our DNN model achieved a 98% precision rate and a 95% recall rate in IoT device fingerprinting. Furthermore, we collected and analyzed over 13,063 IoT-related vulnerability reports and our method automatically built 5,458 connections between IoT device fingerprints and their vulnerabilities. These findings shed light on the ongoing threat of cyber-attacks on IoT systems as both IoT devices and disclosed vulnerabilities are targets for malicious attackers. Jinke Song, Shangfeng Wan, Jiqiang Liu, Limin Sun 0001, Qiang Li 0007 |
ACM Trans. Sens. Networks | 6 |
| 2023 | DevTag: A Benchmark for Fingerprinting IoT DevicesabstractNowadays, various Internet of Things (IoT) devices, such as routers, webcams, and network printers, have been deployed across the Internet. For security and management purposes, it is important to accurately fingerprint IoT devices. In this work, we build a first benchmark called DevTag (IoT Device Tagging) for fingerprinting IoT devices. Specifically, DevTag supports retrieving packet-level features from IoT devices through two different data collections, passive monitoring, and active probing. For detecting IoT devices, DevTag integrates model-based and rule-based fingerprinting methods. For the model-based detection, we reimplemented five typical deep algorithms to infer IoT device classification models. For the rule-based detection, we generated nearly 41 117 rules in a unified format by analyzing several open-source tools. Furthermore, we conducted a systematic analysis to explore the advantages and limitations of those two methods for detecting IoT devices. Our analysis results reveal that the model-based detection has a significant advantage in distinguishing coarse-grained IoT devices (e.g., device type and vendor), while it is not suitable to detect product information as the label amount is massive. The rule-based detection is capable of extracting fine-grained device information with high precision in a short time. However, rules also suffer several inherent problems, such as multiple matching, conflicting, and overlapping issues. Finally, we implemented and distributed a prototype of DevTag working as the first benchmark for detecting IoT devices in the network community. Shangfeng Wan, Qiang Li 0007, Haining Wang 0001, Hong Li 0004, Limin Sun 0001 |
IEEE Internet Things J. | 2 |
| 2022 | IoTminer: Semantic Information Extraction in the Packet PayloadsabstractNowadays, massive Internet-of-Thing (IoT) devices are connecting with cyberspace, yet they suffer increased attack risks from known vulnerabilities to low-hanging exploitable manners. A proactive defense can help security professionals to discover potential risks, where IoT device identification is a necessary requisite. However, existing approaches suffer from coarse-grained and manual labor. In this work, we propose an automated semantic extraction approach, called IoTminer, which generates IoT device annotation from the packet payload. Specifically, IoTminer leverages relations between device types, vendors, and products to mine relevant entities for an annotation tuple (type, vendor, product). Further, we have implemented a prototype of IoTminer and conducted a real-world experiment to validate its efficacy. Results show that our IoTminer generates IoT device information at a fine-grained level, achieving 91.33% precision, 93% recall, and 90% F1 score. Moreover, the IoTminer can discover new IoT devices compared with state-of-the-art tools. Qiang Li 0007, Limin Sun 0001 |
GLOBECOM | 3 |
| 2022 | Understanding Security Risks of Embedded Devices Through Fine-Grained Firmware FingerprintingabstractAn increasing number of embedded devices are connecting to the Internet, ranging from cameras, routers to printers, while an adversary can exploit security flaws already known to compromise those devices. Security patches are usually associated with the device firmware, which relies on the device vendors and products. Due to compatibility and release-time issues, many embedded devices are still using outdated firmware with known vulnerabilities or flaws. In this article, we conduct a systematic study on device vulnerabilities by leveraging firmware fingerprints. Specifically, we use a web crawler to gather 9,716 firmware images from official websites of device vendors, and 347,685 security reports scattered across data archives, blogs, and forums. We propose to generate fine-grained fingerprints based on the subtle differences between the filesystems of various firmware images. Furthermore, machine learning algorithms and regex are used to identify device vulnerabilities and corresponding device firmware fingerprints. We perform real-world experiments to validate the performance of the firmware fingerprint, which yields high accuracy of 91% precision and 90% recall. We reveal that 6,898 reports have the firmware and related vulnerability information, and there are more than 10% of firmware vulnerabilities without any patches or solutions for mitigating underlying security risks. Qiang Li 0007, Dawei Tan, Haining Wang 0001, Zhi Li 0018, Jiqiang Liu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | PDGraph: A Large-Scale Empirical Study on Project Dependency of Security VulnerabilitiesabstractThe reuse of libraries in software development has become prevalent for improving development efficiency and software quality. However, security vulnerabilities of reused libraries propagated through software project dependency pose a severe security threat, but they have not yet been well studied. In this paper, we present the first large-scale empirical study of project dependencies with respect to security vulnerabilities. We developed PDGraph, an innovative approach for analyzing publicly known security vulnerabilities among numerous project dependencies, which provides a new perspective for assessing security risks in the wild. As a large-scale software collection in dependency, we find 337,415 projects and 1,385,338 dependency relations. In particular, PDGraph generates a project dependency graph, where each node is a project, and each edge indicates a dependency relationship. We conducted experiments to validate the efficacy of PDGraph and characterized its features for security analysis. We revealed that 1,014 projects have publicly disclosed vulnerabilities, and more than 67,806 projects are directly dependent on them. Among these, 42,441 projects still manifest 67,581 insecure dependency relationships, indicating that they are built on vulnerable versions of reused libraries even though their vulnerabilities are publicly known. During our eight-month observation period, only 1,266 insecure edges were fixed, and corresponding vulnerable libraries were updated to secure versions. Furthermore, we uncovered four underlying dependency risks that can significantly reduce the difficulty of compromising systems. We conducted a quantitative analysis of dependency risks on the PDGraph. Qiang Li 0007, Jinke Song, Dawei Tan, Haining Wang 0001, Jiqiang Liu |
DSN | 1 |
| 2021 | GeoCAM: An IP-Based Geolocation Service Through Fine-Grained and Stable Webcam LandmarksabstractIP-based geolocation is essential for various location-aware Internet applications, such as online advertisement, content delivery, and online fraud prevention. Achieving accurate geolocation enormously relies on the number of high-quality (i.e., the fine-grained and stable over time) landmarks. However, the previous efforts of garnering landmarks have been impeded by the limited visible landmarks on the Internet and manual time cost. In this paper, we leverage the availability of numerous online webcams used to monitor physical surroundings as a rich source of promising high-quality landmarks for serving IP-based geolocation. In particular, we present a new framework called GeoCAM, which is designed to automatically generate qualified landmarks from online webcams, providing an IP-based geolocation service with high accuracy and wide coverage. GeoCAM periodically monitors websites hosting live webcams and uses the natural language processing technique to extract the IP addresses and latitude/longitude of webcams for generating landmarks at a large-scale. Given latency and topology constraints among webcam landmarks, GeoCAM uses the maximum likelihood estimation to approximately pinpoint the geolocation of a target host. We develop a prototype of GeoCAM and conduct real-world experiments for validating its efficacy. Our results show that GeoCam can detect 282,902 live webcams hosted in webpages with 94.2% precision and 90.4% recall, and then generate 16,863 stable and fine-grained landmarks, which are two orders of magnitude more than the landmarks used in prior works. To demonstrate the superiority of using large-scale webcams as landmarks, we implement four different geolocation algorithms and compare their performance between webcam landmarks and open-source landmarks. The evaluation results show that all the algorithms can significantly improve geolocation accuracy by using webcam landmarks. Qiang Li 0007, Dawei Tan, Jinke Song, Haining Wang 0001, Limin Sun 0001, Jiqiang Liu |
IEEE/ACM Trans. Netw. | 1 |
| 2020 | Towards IP-based Geolocation via Fine-grained and Stable Webcam LandmarksabstractIP-based geolocation is essential for various location-aware Internet applications, such as online advertisement, content delivery, and online fraud prevention. Achieving accurate geolocation enormously relies on the number of high-quality (i.e., the fine-grained and stable over time) landmarks. However, the previous efforts of garnering landmarks have been impeded by the limited visible landmarks on the Internet and manual time cost. In this paper, we leverage the availability of numerous online webcams that are used to monitor physical surroundings as a rich source of promising high-quality landmarks for serving IP-based geolocation. In particular, we present a new framework called GeoCAM, which is designed to automatically generate qualified landmarks from online webcams, providing IP-based geolocation services with high accuracy and wide coverage. GeoCAM periodically monitors websites that are hosting live webcams and uses the natural language processing technique to extract the IP addresses and latitude/longitude of webcams for generating landmarks at large-scale. We develop a prototype of GeoCAM and conduct real-world experiments for validating its efficacy. Our results show that GeoCam can detect 282,902 live webcams hosted in webpages with 94.2% precision and 90.4% recall, and then generate 16,863 stable and fine-grained landmarks, which are two orders of magnitude more than the landmarks used in prior works. Thus, by correlating a large scale of landmarks, GeoCAM is able to provide a geolocation service with high accuracy and wide coverage. Qiang Li 0007, Jinke Song, Haining Wang 0001, Limin Sun 0001 |
WWW | 2 |
| 2020 | iFinger: Intrusion Detection in Industrial Control Systems via Register-Based FingerprintingabstractNowadays, the industrial control system (ICS) plays a vital role in critical infrastructures like the power grid. However, there is an increasing security concern that ICS devices are being vulnerable to malicious users/attackers, where any subtle changing or tampering attack would cause significant damage to industrial manufacturing. In this paper, we propose the iFinger, a novel detection approach designed to mitigate ICS attacks adapting to various industrial scenes. We take advantage of an important insight that industrial protocol packets include register status values that are used to reflect the physical characteristics of ICS controllers. The iFinger utilizes register states to generate ICS fingerprints to detect malicious attacks on industrial networks. Specifically, the boolean logic represents every register state sequence of the ICS controller, and the deterministic finite automaton (DFA) generates a device fingerprint. To discover the ICS attacks, we propose two detection approaches based on device fingerprints, including passive and active detection. We present a prototype of the iFinger and conduct real-world experiments to validate its performance. Results show that our approach achieves 97.1% F1 score in ICS device identification. Furthermore, we simulate two typical ICS attacks (replacement and code modification) to validate the effectiveness of our iFinger in industrial networks. Our device fingerprints would detect those malicious attacks within 2s latency at 98.0% recall. Kai Yang 0037, Qiang Li 0007, Xiaodong Lin 0001, Xin Chen 0123, Limin Sun 0001 |
IEEE J. Sel. Areas Commun. | 2 |
| 2019 | Understanding and Securing Device Vulnerabilities through Automated Bug Report Analysis
Xuan Feng 0005, Xiaojing Liao, XiaoFeng Wang 0001, Haining Wang 0001, Qiang Li 0007, Kai Yang 0037, Hongsong Zhu, Limin Sun 0001 |
USENIX Security Symposium | 5 |
| 2019 | Towards automatic fingerprinting of IoT devices in the cyberspace
Kai Yang 0037, Qiang Li 0007, Limin Sun 0001 |
Comput. Networks | 2 |
| 2019 | Towards IP geolocation with intermediate routers based on topology discoveryabstractIP geolocation determines geographical location by the IP address of Internet hosts. IP geolocation is widely used by target advertising, online fraud detection, cyber-attacks attribution and so on. It has gained much more attentions in these years since more and more physical devices are connected to cyberspace. Most geolocation methods cannot resolve the geolocation accuracy for those devices with few landmarks around. In this paper, we propose a novel geolocation approach that is based on common routers as secondary landmarks (Common Routers-based Geolocation, CRG). We search plenty of common routers by topology discovery among web server landmarks. We use statistical learning to study localized (delay, hop)-distance correlation and locate these common routers. We locate the accurate positions of common routers and convert them as secondary landmarks to help improve the feasibility of our geolocation system in areas that landmarks are sparsely distributed. We manage to improve the geolocation accuracy and decrease the maximum geolocation error compared to one of the state-of-the-art geolocation methods. At the end of this paper, we discuss the reason of the efficiency of our method and our future research. Hong Li 0004, Qiang Li 0007, Wei Li 0059, Hongsong Zhu, Limin Sun 0001 |
Cybersecur. | 3 |
| 2018 | DTaint: Detecting the Taint-Style Vulnerability in Embedded Device FirmwareabstractA rising number of embedded devices are reachable in the cyberspace, such as routers, cameras, printers, etc. Those devices usually run firmware whose code is proprietary with few public documents. Furthermore, most of the firmware images cannot be analyzed in dynamic analysis due to various hardware-specific peripherals. As a result, it hinders traditional static analysis and dynamic analysis techniques. In this paper, we propose a static binary analysis approach, DTaint, to detect taint-style vulnerabilities in the firmware. The taint-style vulnerability is a typical class of weakness, where the input data reaches a sensitive sink through an unsafe path. Specifically, we generate data dependency in a bottom-up manner through traversing callees before callers. To reduce the influence of the binary firmware, DTaint identifies pointer aliasing, interprocedural data flow, and similarity of the data structure layout. We have implemented a prototype of DTaint and conducted experiments to evaluate its performance. Our results show that DTaint discovers more vulnerabilities in less time, compared with the existing techniques. Furthermore, we illustrate the effectiveness of DTaint through applying it over six firmware images from four manufacturers. We have found 21 vulnerabilities, where 13 of them are previously-unknown and zero-day vulnerabilities. Qiang Li 0007, Yaowen Zheng, Limin Sun 0001, Zhenkai Liang |
DSN | 2 |
| 2018 | Towards Fine-grained Fingerprinting of Firmware in Online Embedded DevicesabstractAn increasing number of embedded devices are connecting to the Internet at a surprising rate. Those devices usually run firmware and are exposed to the public by device search engines. Firmware in embedded devices comes from different manufacturers and product versions. More importantly, many embedded devices are still using outdated versions of firmware due to compatibility and release-time issues, raising serious security concerns. In this paper, we propose generating fine-grained fingerprints based on the subtle differences between the filesystems of various firmware images. We leverage the natural language processing technique to process the file content and the document object model to obtain the firmware fingerprint. To validate the fingerprints, we have crawled 9,716 firmware images from official websites of device vendors and conducted real-world experiments for performance evaluation. The results show that the recall and precision of the firmware fingerprints exceed 90%. Furthermore, we have deployed the prototype system on Amazon EC2 and collected firmware in online embedded devices across the IPv4 space. Our findings indicate that thousands of devices are still using vulnerable firmware on the Internet. Qiang Li 0007, Xuan Feng 0005, Haining Wang 0001, Zhi Li 0018, Limin Sun 0001 |
INFOCOM | 1 |
| 2018 | Acquisitional Rule-based Engine for Discovering Internet-of-Thing Devices
Xuan Feng 0005, Qiang Li 0007, Haining Wang 0001, Limin Sun 0001 |
USENIX Security Symposium | 2 |
| 2018 | Image editing by object-aware optimal boundary searching and mixed-domain compositionabstractWhen combining very different images which often contain complex objects and backgrounds, producing consistent compositions is a challenging problem requiring seamless image editing. In this paper, we propose a general approach, called object-aware image editing , to obtain consistency in structure, color, and texture in a unified way. Our approach improves upon previous gradient-domain composition in three ways. Firstly, we introduce an iterative optimization algorithm to minimize mismatches on the boundaries when the target region contains multiple objects of interest. Secondly, we propose a mixed-domain consistency metric for measuring gradients and colors, and formulate composition as a unified minimization problem that can be solved with a sparse linear system. In particular, we encode texture consistency using a patch-based approach without searching and matching. Thirdly, we adopt an object-aware approach to separately manipulate the guidance gradient fields for objects of interest and backgrounds of interest, which facilitates a variety of seamless image editing applications. Our unified method outperforms previous state-of-the-art methods in preserving global texture consistency in addition to local structure continuity. Shiming Ge, Xin Jin 0015, Qiting Ye, Zhao Luo, Qiang Li 0007 |
Comput. Vis. Media | 5 |
| 2018 | Understanding the Usage of Industrial Control System Devices on the InternetabstractIndustrial control system (ICS) devices play a crucial role in critical infrastructures, such as power grid. In recent years, numerous ICS devices are accessible on the Internet, resulting in potential security issues. However, there is a lack of deep understanding of these devices' characteristics in the cyberspace. In this paper, we take the first step in this direction by investigating these visible ICS devices on the Internet. Because of the critical nature of ICSs, the detection of online ICS devices should be done in a nonintrusive and timely manner. We first analyze 17 industrial protocols widely used in ICSs and train a probability model through the learning algorithm to improve detection accuracy. Then, we discover online ICS devices in the IPv4 space while reducing the negative effects caused by industrial honeypots and dynamic IP addresses. To observe the dynamics of ICS devices in a relatively long run, we have deployed our discovery system on Amazon EC2 and detected online ICS devices in the whole IPv4 space for eight times from August 2015 to March 2016. Based on the ICS device data collection, we conduct a comprehensive data analysis to characterize the usage of ICS devices, especially in answer to the following three questions: 1) what are the distribution features of ICS devices; 2) who use these ICS devices; and 3) what are the functions of these ICS devices. Qiang Li 0007, Xuan Feng 0005, Haining Wang 0001, Limin Sun 0001 |
IEEE Internet Things J. | 1 |
| 2017 | Automatically Discovering Surveillance Devices in the CyberspaceabstractSurveillance devices with IP addresses are accessible on the Internet and play a crucial role in monitoring physical worlds. Discovering surveillance devices is a prerequisite for ensuring high availability, reliability, and security of these devices. However, today's device search depends on keywords of packet head fields, and keyword collection is done manually, which requires enormous human efforts and induces inevitable human errors. The difficulty of keeping keywords complete and updated has severely impeded an accurate and large-scale device discovery. To address this problem, we propose to automatically generate device fingerprints based on webpages embedded in surveillance devices. We use natural language processing to extract the content of webpages and machine learning to build a classification model. We achieve real-time and non-intrusive web crawling by leveraging network scanning technology. We implement a prototype of our proposed discovery system and evaluate its effectiveness through real-world experiments. The experimental results show that those automatically generated fingerprints yield very high accuracy of 99% precision and 96% recall. We also deploy the prototype system on Amazon EC2 and search surveillance devices in the whole IPv4 space (nearly 4 billion). The number of devices we found is almost 1.6 million, about twice as many as those using commercial search engines. Qiang Li 0007, Xuan Feng 0005, Haining Wang 0001, Limin Sun 0001 |
MMSys | 1 |
| 2016 | Identification of visible industrial control devices at Internet scaleabstractNowadays industrial control devices are crucial for infrastructure-critical systems such as factories, power plants, and water treatment facilities. Devices with IP addresses are visible on the Internet and they connect cyber space and physical world. The first step in protecting devices from attackers is a deep understanding of the devices' characteristics in the cyber space. In this paper, we take a first step in this direction by investigating physical devices running one of the two specific protocols that are widely adopted in industrial control systems. In order to detect these devices in real-time, we propose a two-stage discovery mechanism: first filtering out unqualified hosts from 4 billion remote hosts and then identifying physical devices from qualified candidates. We have conducted a real-world experiment to verify the mechanism and identified dozens of thousands of physical devices from the entire Internet. Results show that our method discovers all devices in 20 hours with 89.5% precision and 79.3% recall. Xuan Feng 0005, Qiang Li 0007, Qi Han 0001, Hongsong Zhu, Yan Liu 0021, Limin Sun 0001 |
ICC | 2 |
| 2016 | Active Profiling of Physical Devices at Internet ScaleabstractNowadays, more and more physical devices embed computing and networking capabilities and are visible on the Internet. These devices include webcams, net-printers, and industrial control equipments, etc. Collecting information about these devices is crucial to preserve cyber-security and facilitate security auditing for system administrators. In this paper, we propose a scalable framework for physical device profiling. It leverages banner grabbing to identify device types and running services, and uses clock skew to determine a device ID. Our framework scales well. We implement a prototype system and use it to profile Webcams and industrial control device. The results show that our system can effectively profile and identify Webcams in real time. We deploy it on the cloud server and use it to detect 4 billion IP addresses to profile 1.2 million Webcams and more than 60 thousand industrial control devices in 20 hours. Xuan Feng 0005, Qiang Li 0007, Qi Han 0001, Hongsong Zhu, Yan Liu 0021, Limin Sun 0001 |
ICCCN | 2 |
| 2016 | Characterizing industrial control system devices on the InternetabstractIndustrial control system (ICS) devices with IP addresses are accessible on the Internet and play a crucial role for critical infrastructures like power grid. However, there is a lack of deep understanding of these devices' characteristics in the cyberspace. In this paper, we take a first step in this direction by investigating these accessible industrial devices on the Internet. Because of critical nature of industrial control systems, the detection of online ICS devices should be done in a real-time and non-intrusive manner. Thus, we first analyze 17 industrial protocols widely used in industrial control systems, and train a probability model through the learning algorithm to improve detection accuracy. Then, we discover online ICS devices in the IPv4 space while reducing the noise of industrial honeypots. To observe the dynamics of ICS devices in a relatively long run, we have deployed our discovery system on Amazon EC2 and detected online ICS devices in the whole IPv4 space for eight times from August 2015 to March 2016. Based on the ICS device data collection, we conduct a comprehensive data analysis to characterize the usage of ICS devices, especially in the answer to the following three questions: (1) what are the distribution features of ICS devices, (2) who use these ICS devices, and (3) what are the functions of these ICS devices. Xuan Feng 0005, Qiang Li 0007, Haining Wang 0001, Limin Sun 0001 |
ICNP | 2 |
| 2016 | ASCEND: A search engine for online industrial control devicesabstractIndustrial control system (ICS) devices with IP addresses are accessible on the Internet and play a crucial role for critical infrastructures like power grid. However, there is a lack of deep understanding on these devices' characteristics in the cyber space. In this paper, we propose ASCEND, a search engine for online industrial control devices. ASCEND analyse 17 industrial protocols and use it to discover almost all online ICS devices in the IPv4 while reducing the noise of industrial honeypots. It provides a big picture of online ICS devices: who are using ICS devices; where they are located and what functions these ICS device have. In order to demonstrate how ASCEND works, we have implemented the prototype system and verified it in the real-world experiments. Xuan Feng 0005, Qiang Li 0007, Haining Wang 0001, Limin Sun 0001 |
ICNP | 2 |
| 2016 | GUIDE: Graphical user interface fingerprints physical devicesabstractNowadays, the number of visible physical devices exposed on the Internet is dynamically increasing and they play a crucial role for bridging between the cyber space and the physical world, such as network printer, Webcam, and industrial control devices. Discovering these devices brings about the deep understanding on these devices' characteristics and help secure device security in the cyber space. A device fingerprint is a prerequisite of device discovery in the Internet. However, today's online device search depends on keywords of packet head fields and the keyword collection is done manually. This impedes an accurate and large-scale device discovery, due to high human efforts and inevitable human errors, as well as the difficulty of keeping keywords complete and updated. To address this problem, we propose GUIDE, a framework to automatically generate device fingerprints based on webpages embedded in these devices. In order to demonstrate how GUIDE works, we also develop its prototype system and provide a case study which discover surveillance devices in the cyber space. Qiang Li 0007, Xuan Feng 0005, Zhi Li 0018, Haining Wang 0001, Limin Sun 0001 |
ICNP | 1 |
| 2016 | Collaborative Recognition of Queuing Behavior on Mobile PhonesabstractNowadays people spend a substantial amount of time waiting in different places such as supermarkets and amusement parks. Detecting the status of queuing may benefit both users and business. In this paper, we present QueueSense, a queuing recognition system to assist in a queue management system. QueueSense consists of clients on smartphones that provide automatic, energy-efficient, and accurate queuing recognition, and a server in the cloud that collects data, identifies multi-queue lines, and provides waiting time estimation. In order to be useful, QueueSense should be able to recognize queuing behavior in various queuing scenarios without greatly decreasing the battery life of mobile phones. We present features of queuing and build the classifier on smartphones to automatically recognize queue classifier without human input. We investigate the complicated nature of energy consumption for queue recognition on phones and design an effective algorithm to maximize energy savings while guaranteeing accuracy of queue recognition. We evaluate QueueSense performance using the data set from real world queuing scenarios collected over a three-month period. Empirical results show that QueueSense is adaptive to various queuing scenarios with both high recognition accuracy and energy efficiency. We further implemented a prototype of QueueSense, the first queue detection system using smartphones. We conducted real-world experiments in a dining hall and a supermarket near a university campus. Through implementation and evaluation, we demonstrate that QueueSense is capable of detecting waiting lines that occur in our daily lives. Qiang Li 0007, Qi Han 0001, Limin Sun 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2015 | Influential Spatial Facility Prediction over Dynamic Objects
Hongtao Wang 0002, Qiang Li 0007, Feng Yi, Qi Han 0001, Limin Sun 0001 |
WASA | 2 |
| 2015 | A Poisson Distribution Based Topology Control Algorithm for Wireless Sensor Networks Under SINR Model
Kan Yu 0001, Zhi Li 0018, Qiang Li 0007, Jiguo Yu |
WASA | 3 |
| 2014 | Poster: Crowdsourcing for video traffic surveillanceabstractNo abstract available. Hui Wen 0001, Qiang Li 0007, Qi Han 0001, Shiming Ge, Limin Sun 0001 |
MobiSys | 2 |
| 2014 | QueueSense: Collaborative recognition of queuing on mobile phonesabstractNowadays people spend a substantial amount of time waiting in different places such as supermarkets and amusement parks. Detecting the status of queuing may benefit both users and business. In this paper, we present QueueSense, a queuing recognition system on mobile phones to assist in a queue management system. QueueSense extracts features of queuing behavior and classifies queueing via collaboration among people waiting in line. It measures the disparity of people in different lines using relative position changing rate and partitions different queues using a hierarchical clustering approach. We implement a prototype of QueueSense on Android platforms using widely available multi-modal sensors and it is the first queue detection system on mobile phones. We conduct real-world experiments at a dining hall and a supermarket near a university campus. Through implementation and evaluation, we demonstrate that QueueSense is capable of detecting waiting lines that occur in our daily lives with high accuracy. Qiang Li 0007, Qi Han 0001, Xiuzhen Cheng, Limin Sun 0001 |
SECON | 1 |
| 2014 | UserIntent: Detection of user intent for triggering smartphone sensing applicationsabstractUser intent is an integral part of mobile phone applications as it delivers events to applications, notifies applications of relevant events, or triggers applications. Current smartphone applications either require users to manually start them or they run as background jobs. In this work, we propose UserIntent, a new paradigm for automatically selecting the right smartphone application based on user intent captured. UserIntent consist of two parts: user intent detection and mechanism for triggering a smartphone app. Action cues act as user intent and a context-aware selection algorithm chooses a suitable smartphone application. In order to demonstrate how UserIntent works, we also develop a concrete application that recognizes speaker and talk content based on gestures captured. Qiang Li 0007, Qi Han 0001, Limin Sun 0001 |
SECON | 1 |
| 2013 | Context-Aware Handoff on SmartphonesabstractNowadays smartphone users often enjoy the availability of multi-networks by switching between the networks for better network performance, energy efficiency of smartphones, and more data offloading to less expensive networks. However, network switching inevitably brings about network disruptions leading to user experience degradation. In this paper, we propose an application context model that is used in conjunction with a heuristic network selection mechanism, which selects a network using three metrics (i.e., network performance, energy consumption, and cost). A Bayes classifier is used to provide a probability for the network selection given applications running during network disruptions. We construct the classifier via crowd-sourced data by considering smartphone users profile and the operating environments. We implement a prototype context-aware handoff on the Android platform and conducted an experiment in a real world scenario through one case study, switching between cellular and WiFi networks. The evaluation results suggest that context aware handoff achieves 25% energy cost, nearly one-third data offloading, and more than twice throughput with only one third of the network switchings. Qiang Li 0007, Qi Han 0001, Limin Sun 0001 |
MASS | 1 |
| 2011 | RestThing: A Restful Web Service Infrastructure for Mash-Up Physical and Web ResourcesabstractIn the field of Cyber Physical Systems and Pervasive Computing, physical resources and web resources can be easily handled and seamlessly integrated into our life. However, due to the heterogeneity of devices and tight coupling of individual information systems, the developers cannot easily create their specific applications by combining with physical and web resources. In this paper, we proposed Rest Thing which is a restful web service infrastructure based on REST principles in order to hide the heterogeneity of devices and provide a seamless way to integrate embedded devices with existing web applications. Besides, we implemented a prototyping system, which provided the restful accessible way of the wireless sensors, and built a demo application on the smart phone to collect and merge physical and web resources. Finally, we gave the performance evaluation of the prototyping system. Weijun Qin, Qiang Li 0007, Limin Sun 0001, Hongsong Zhu, Yan Liu 0021 |
EUC | 2 |