VLDB 2026 Research / reviewers in the wild / expert
Qi Liao 0002
dblp:98/2372-2
· DBLP profile ↗
24ranked-venue papers
9as first author
2since 2021 · last 2025
0000-0001-5520-157XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 3 first-author · 2 since 2021Computer networks · 6 · 4 first-authorGraphics, computer vision, multimedia, augmented reality and games · 4Applied, interdisciplinary, general and emerging computing · 2Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | To insure or not to insure: How attackers exploit cyber-insurance via game theory
Zhen Li 0025, Qi Liao 0002 |
Comput. Secur. | 2 |
| 2022 | Preventive portfolio against data-selling ransomware - A game theory of encryption and deception
Zhen Li 0025, Qi Liao 0002 |
Comput. Secur. | 2 |
| 2020 | Ransomware 2.0: to sell, or not to sell a game-theoretical model of data-selling RansomwareabstractCybercrime such as ransomware denies access to valuable data until a ransom is paid. Recent ransomware attacks on organizations such as hospitals, schools, government agencies and private businesses raise public awareness of the severe impact on the society. In this paper, we propose a hypothetical new revenue model for the ransomware, i.e., selling the stolen data. Through a game-theoretical analysis between attackers and victims, we contribute a novel model to understand the critical decision variables between the traditional ransomware (ransomware 1.0) - demanding ransom only and the new type of ransomware (ransomware 2.0) - selling the data as well as demanding ransom. Both theoretical modeling and simulation studies suggest that in general ransomware 2.0 is more profitable than ransomware 1.0. Common defensive measures that may work to eliminate the financial incentives of ransomware 1.0 may not work on ransomware 2.0, in particular the data backup practice and the never-pay-ransom strategy. Nevertheless, the uncertainties created by this new revenue model may affect attackers' reputation and users' willingness-to-pay. In turn, ransomware 2.0 may not always increase the profitability of attackers. Another finding of the study suggests that reputation maximization is critical in ransomware 1.0 but not in ransomware 2.0, where attackers should seek imperfect reputation for profit maximization. Zhen Li 0025, Qi Liao 0002 |
ARES | 2 |
| 2020 | OnionGraph: Hierarchical topology+attribute multivariate network visualizationabstractHierarchical abstraction is a scalable strategy to deal with large networks. Existing visualization methods have allowed to aggregate the network nodes into hierarchies based on the node attributes or network topology, each of which has its own advantage. Very few previous system has the capability to enjoy the best of both worlds. This paper presents OnionGraph, an integrated framework for the exploratory visual analysis of heterogeneous multivariate networks. OnionGraph allows nodes to be aggregated based on either node attributes, topology, or a hierarchical combination of both. These aggregations can be split, merged and filtered under the focus+context interaction model, or automatically traversed by the information-theoretic navigation method. Node aggregations that contain subsets of nodes are displayed by the onion metaphor, indicating the level and details of the abstraction. We have evaluated the OnionGraph tool in three real-world cases. Performance experiments demonstrate that on a commodity desktop, our method can scale to million-node networks while preserving the interactivity for analysis. Lei Shi 0002, Qi Liao 0002, Hanghang Tong, Yifan Hu 0001, Chaoli Wang 0001, Chuang Lin 0002, Weihong Qian |
Vis. Informatics | 2 |
| 2020 | A Game-theoretic analysis on the economic viability of mobile content pre-staging
Zhen Li 0025, Qi Liao 0002, Aaron Striegel |
Wirel. Networks | 2 |
| 2018 | Harnessing Uncertainty in Vulnerability MarketabstractZero-day vulnerabilities pose significant threats in computer and network security, and have attracted attentions in recent years not only to malicious attackers but government and law enforcement users who need to control (e.g., for forensics purpose) the computer systems which otherwise are inaccessible through traditional channels. Based on the observation that vulnerabilities are acquired and traded in a different way than commodities, we study and propose a vulnerability market model by taking into consideration cheating and uncertainty in the market. The paper illustrates the interactions between the vulnerability sellers and buyers in a game theoretic framework. By modeling the economic aspects of the vulnerability market with a focus on information asymmetry and distinctive incentives of malicious and defensive buyers, we propose active and strategic market participation by defenders to obtain vulnerability information from the marketplace in a cost-effective way. Rather than killing the market, defenders can take advantage of the incomplete information feature of the vulnerability market to improve cyber-security. To further maximize the uncertainty, defenders may also play in the supply side of the vulnerability market to provide low or no value vulnerabilities to dilute the market. Zhen Li 0025, Qi Liao 0002 |
ICCCN | 2 |
| 2018 | Anomaly analysis and visualization for dynamic networks through spatiotemporal graph segmentations
Qi Liao 0002, Benjamin A. Blakely |
J. Netw. Comput. Appl. | 1 |
| 2016 | User password repetitive patterns analysis and visualizationabstractPurpose – Passwords have been designed to protect individual privacy and security and widely used in almost every area of our life. The strength of passwords is therefore critical to the security of our systems. However, due to the explosion of user accounts and increasing complexity of password rules, users are struggling to find ways to make up sufficiently secure yet easy-to-remember passwords. This paper aims to investigate whether there are repetitive patterns when users choose passwords and how such behaviors may affect us to rethink password security policy. Design/methodology/approach – The authors develop a model to formalize the password repetitive problem and design efficient algorithms to analyze the repeat patterns. To help security practitioners to analyze patterns, the authors design and implement a lightweight, Web-based visualization tool for interactive exploration of password data. Findings – Through case studies on a real-world leaked password data set, the authors demonstrate how the tool can be used to identify various interesting patterns, e.g. shorter substrings of the same type used to make up longer strings, which are then repeated to make up the final passwords, suggesting that the length requirement of password policy does not necessarily increase security. Originality/value – The contributions of this study are two-fold. First, the authors formalize the problem of password repetitive patterns by considering both short and long substrings and in both directions, which have not yet been considered in past. Efficient algorithms are developed and implemented that can analyze various repeat patterns quickly even in large data set. Second, the authors design and implement four novel visualization views that are particularly useful for exploration of password repeat patterns, i.e. the character frequency charts view, the short repeat heatmap view, the long repeat parallel coordinates view and the repeat word cloud view. Xiaoying Yu, Qi Liao 0002 |
Inf. Comput. Secur. | 2 |
| 2015 | 1.5D Egocentric Dynamic Network VisualizationabstractDynamic network visualization has been a challenging research topic due to the visual and computational complexity introduced by the extra time dimension. Existing solutions are usually good for overview and presentation tasks, but not for the interactive analysis of a large dynamic network. We introduce in this paper a new approach which considers only the dynamic network central to a focus node, also known as the egocentric dynamic network. Our major contribution is a novel 1.5D visualization design which greatly reduces the visual complexity of the dynamic network without sacrificing the topological and temporal context central to the focus node. In our design, the egocentric dynamic network is presented in a single static view, supporting rich analysis through user interactions on both time and network. We propose a general framework for the 1.5D visualization approach, including the data processing pipeline, the visualization algorithm design, and customized interaction methods. Finally, we demonstrate the effectiveness of our approach on egocentric dynamic network analysis tasks, through case studies and a controlled user experiment comparing with three baseline dynamic network visualization methods. Lei Shi 0002, Huamin Qu, Chuang Lin 0002, Qi Liao 0002 |
IEEE Trans. Vis. Comput. Graph. | 6 |
| 2014 | Hierarchical Focus+Context Heterogeneous Network VisualizationabstractAggregation is a scalable strategy for dealing with large network data. Existing network visualizations have allowed nodes to be aggregated based on node attributes or network topology, each of which has its own advantages. However, very few previous systems have the capability to enjoy the best of both worlds. This paper presents OnionGraph, an integrated framework for exploratory visual analysis of large heterogeneous networks. OnionGraph allows nodes to be aggregated based on either node attributes, topology, or a mixture of both. Subsets of nodes can be flexibly split and merged under the hierarchical focus+context interaction model, supporting sophisticated analysis of the network data. Node aggregations that contain subsets of nodes are displayed with multiple concentric circles, or the onion metaphor, indicating how many levels of abstraction they contain. We have evaluated the OnionGraph tool in two real-world cases. Performance experiments demonstrate that on a commodity desktop, OnionGraph can scale to million-node networks while preserving the interactivity for analysis. Lei Shi 0002, Qi Liao 0002, Hanghang Tong, Yifan Hu 0001, Chuang Lin 0002 |
PacificVis | 2 |
| 2014 | Bridging the Gap of Network Management and Anomaly Detection through Interactive VisualizationabstractLarge-scale networks have become increasingly challenging to manage. It is vital for a system administrator or network manager to be able to analyze the vast amount of log data in order to detect suspicious behaviors or patterns, possibly due to malicious users/applications or faulty devices. While an intrusion detection system (IDS) log can provide a large number of warnings, exactly which alarms are true while the others are false, and more importantly what are the underlying causes are still difficult to know. To bridge the gap between network log and anomaly discovery, we design and implement a visualization tool that combines multiple commodity visualizations with minimum learning curve. While each individual view is well understood, the effects of such views in analyzing network anomalies are not well studied. Since each visualization technique has advantages as well as limitations in addressing a particular task, we show that these views, when combined and linked together, may provide an effective and lightweight network anomaly analysis tool. The web-based open platform may simplify network administration as well as promote collaborative analysis among researchers. Tao Zhang 0059, Qi Liao 0002, Lei Shi 0002 |
PacificVis | 2 |
| 2014 | Is more P2P always bad for ISPs? An analysis of P2P and ISP business modelsabstractInternet Service Providers (ISPs) face increasing bandwidth pressure from rising access demand by users, especially P2P and VoD applications. Traditionally, P2P has been viewed as tremendously negative from the perspective of the ISP. In this paper, we question this assumption and study the impact of P2P applications on the effective ISP functionality. We perform an economic analysis to show that a higher P2P penetration rate does not necessarily lead to increased ISP bottleneck link bandwidth pressure. Our results show that the local serving rate is critical for the sustainability of the ISP business model as well as for the benefit of P2P users. Qi Liao 0002, Zhen Li 0025, Aaron Striegel |
ICCCN | 1 |
| 2013 | Analysis of offense tactics of basketball games using link predictionabstractEvery basketball game has a lot of game records, also called match data. All the data are not only statistical but also logical and spatial. People normally use these kind of data to obtain statistical or summarized information of the games, but few have used these data to analyze the teams' tactics. In this paper, we present an approach to analyze the match data for detecting basketball teams' tactic using link prediction method. The main idea is to create a measure for the team offense tactics based on the Basketball Analysis Graph (BA graph) and use link prediction to extract the information about the cooperation between teammates and offense priority. The information may be used for basketball game strategy assistance. Tao Zhang 0059, Gongzhu Hu, Qi Liao 0002 |
ICIS | 3 |
| 2013 | Scalable network traffic visualization using compressed graphsabstractThe visualization of complex network traffic involving a large number of communication devices is a common yet challenging task. Traditional layout methods create the network graph with overwhelming visual clutter, which hinders the network understanding and traffic analysis tasks. The existing graph simplification algorithms (e.g. community-based clustering) can effectively reduce the visual complexity, but lead to less meaningful traffic representations. In this paper, we introduce a new method to the traffic monitoring and anomaly analysis of large networks, namely Structural Equivalence Grouping (SEG). Based on the intrinsic nature of the computer network traffic, SEG condenses the graph by more than 20 times while preserving the critical connectivity information. Computationally, SEG has a linear time complexity and supports undirected, directed and weighted traffic graphs up to a million nodes. We have built a Network Security and Anomaly Visualization (NSAV) tool based on SEG and conducted case studies in several real-world scenarios to show the effectiveness of our technique. Lei Shi 0002, Qi Liao 0002, Yarui Chen, Chuang Lin 0002 |
IEEE BigData | 2 |
| 2012 | Intelligent network management using graph differential anomaly visualizationabstractManaging large-scale networks involving users and applications is challenging due to the complexity and dynamic nature of the heterogeneous graphs. How to quickly identify the meaningful changes and hidden anomalous activities in the spatiotemporally dynamic network graphs is essential in many aspects of network management, such as security, performance and troubleshooting. In this paper, we explore the viability and efficacy of a novel graph differential anomaly visualization (DAV) model in the area of network management. Our approach combines algorithmic graph analysis methods and visualization technologies by taking advantages from both computer and human intelligence. We focus on DAV at various levels, i.e., nodes, links and communities. Specifically, a novel community-based DAV scheme is proposed that can help understand the managed networks with a right balance of granularity and complexity. More importantly, the community-based DAV algorithm is less susceptible to network dynamics and high churn. The developed visual analytic tool can not only detect but more importantly find the root causes of anomalies in a time efficient manner. Qi Liao 0002, Aaron Striegel |
NOMS | 1 |
| 2012 | Could firewall rules be public - a game theoretical perspectiveabstractAbstract Firewalls are among the most important components in network security. Traditionally, the rules of the firewall are kept private under the assumption that privacy of the ruleset makes attacks on the network more difficult. We posit that this assumption is no longer valid in the Internet of today due to two factors: the emergence of botnets reducing probing difficulty and second, the emergence of distributed applications where private rules increase the difficulty of troubleshooting. We argue that the enforcement of the policy is the key, not the secrecy of the policy itself. In this paper, we demonstrate through the application of game theory thatpublicfirewall rules when coupled with false information (lying) are actually better than keeping firewall rules private, especially when taken in the larger group context of the Internet. Interesting scenarios arise when honest, public firewalls are socially insured by other lying firewalls and networks adopting public firewalls become mutually beneficial to each other. The equilibrium under multiple‐network game is socially optimal because the percentage of required lying firewalls in social optimum is much smaller than the percentage in single‐network equilibrium and the chance of attacking through firewalls is further reduced to zero. Copyright © 2011 John Wiley & Sons, Ltd. Qi Liao 0002, Zhen Li 0025, Aaron Striegel |
Secur. Commun. Networks | 1 |
| 2011 | Visualizing anomalies in sensor networksabstractDiagnosing a large-scale sensor network is a crucial but challenging task due to the spatiotemporally dynamic network behaviors of sensor nodes. In this demo, we present Sensor Anomaly Visualization Engine (SAVE), an integrated system that tackles the sensor network diagnosis problem using both visualization and anomaly detection analytics to guide the user quickly and accurately diagnose sensor network failures. Temporal expansion model, correlation graphs and dynamic projection views are proposed to effectively interpret the topological, correlational and dimensional sensor data dynamics and their anomalies. Through a real-world large-scale wireless sensor network deployment (GreenOrbs), we demonstrate that SAVE is able to help better locate the problem and further identify the root cause of major sensor network failures. Qi Liao 0002, Lei Shi 0002, Yuan He 0004, Rui Li 0047, Zhong Su, Aaron Striegel, Yunhao Liu 0001 |
SIGCOMM | 1 |
| 2011 | Fighting botnets with economic uncertaintyabstractAbstract Botnets have become an increasing security concern in today's Internet. Since current technological defenses against botnets have failed to produce results, it has become necessary to think about different strategies. Given that money is perhaps the single determining force driving the growth in botnet attacks, we propose an interesting economic approach to take away the root cause of botnet, i.e., the financial incentives. In this paper, we model botnet‐related cyber crimes as a result of profit‐maximizing decision‐making optimization problem from the perspective of botmasters. By introducing theuncertaintylevel created by thevirtual bots, we make determining the optimal botnet size infeasible for the botnet operators, and consequently the botnet profitability can fall dramatically. The theoretical model presented here has a large potential to fight off botnet‐related attacks of varying revenue patterns. Copyright © 2010 John Wiley & Sons, Ltd. Zhen Li 0025, Qi Liao 0002, Andrew Blaich, Aaron Striegel |
Secur. Commun. Networks | 2 |
| 2010 | Visualizing graph dynamics and similarity for enterprise network security and managementabstractManaging complex enterprise networks requires an understanding at a finer granularity than traditional network monitoring. The ability to correlate and visualize the dynamics and inter-relationships among various network components such as hosts, users, and applications is non-trivial. In this paper, we propose a visualization approach based on the hierarchical structure of similarity/difference visualization in the context of heterogeneous graphs. The concept of hierarchical visualization starts with the evolution of inter-graph states, adapts to the visualization of intra-graph clustering, and concludes with the visualization of similarity between individual nodes. Our visualization tool, ENAVis (Enterprise Network Activities Visualization), quantifies and presents these important changes and dynamics essential to network operators through a visually appealing and highly interactive manner. Through novel graph construction and transformation, such as network connectivity graphs, MDS graphs, bipartite graphs, and similarity graphs, we demonstrate how similarity/dynamics can be effectively visualized to provide insight with regards to network understanding. Qi Liao 0002, Aaron Striegel, Nitesh V. Chawla |
VizSEC | 1 |
| 2010 | Managing networks through context: Graph visualization and exploration
Qi Liao 0002, Andrew Blaich, Dirk Van Bruggen, Aaron Striegel |
Comput. Networks | 1 |
| 2008 | ENAVis: Enterprise Network Activities Visualization
Qi Liao 0002, Andrew Blaich, Aaron Striegel, Douglas Thain |
LISA | 1 |
| 2008 | Using selective, short-term memory to improve resilience against DDoS exhaustion attacksabstractAbstract Distributed denial of service (DDoS) attacks originating from botnets can quickly bring normally effective web services to a screeching halt. This paper presents SESRAA (selective short‐term randomized acceptance algorithms), an adaptive scheme for maintaining web service despite the presence of multifaceted attacks in a noisy environment. In contrast to existing solutions that rely upon ‘clean’ training data, we presume that a live web service environment makes finding such training data difficult if not impossible. SESRAA functions much like a battlefield surgeon's triage: focusing on quickly and efficiently salvaging good connections with the realization that the chaotic nature of the live environment implicitly limits the accuracy of such detections. SESRAA employs an adaptivek‐means clustering approach using short‐term extraction and limited centroid evolution to defend the legitimate connections in a mixed attack environment. We present the SESRAA approach and evaluate its performance through experimental studies in a diverse attack environment. The results show significant improvements against a wide variety of DDoS configurations and input traffic patterns. Copyright © 2008 John Wiley & Sons, Ltd. Qi Liao 0002, David A. Cieslak, Aaron Striegel, Nitesh V. Chawla |
Secur. Commun. Networks | 1 |
| 2008 | RIPPS: Rogue Identifying Packet Payload Slicer Detecting Unauthorized Wireless Hosts Through Network Traffic ConditioningabstractWireless network access has become an integral part of computing both at home and at the workplace. The convenience of wireless network access at work may be extremely beneficial to employees, but can be a burden to network security personnel. This burden is magnified by the threat of inexpensive wireless access points being installed in a network without the knowledge of network administrators. These devices, termed Rogue Wireless Access Points , may allow a malicious outsider to access valuable network resources, including confidential communication and other stored data. For this reason, wireless connectivity detection is an essential capability, but remains a difficult problem. We present a method of detecting wireless hosts using a local RTT metric and a novel packet payload slicing technique. The local RTT metric provides the means to identify physical transmission media while packet payload slicing conditions network traffic to enhance the accuracy of the detections. Most importantly, the packet payload slicing method is transparent to both clients and servers and does not require direct communication between the monitoring system and monitored hosts. Chad D. Mano, Andrew Blaich, Qi Liao 0002, Yingxin Jiang, David A. Cieslak, David Salyers, Aaron Striegel |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2007 | SAABCOT: Secure application-agnostic bandwidth conservation techniquesabstractHigh speed modern networks are tasked with moving large amounts of data to diverse groups of interested parties. Often under heavy loads, a significant portion of the data exhibits large amounts of redundancy on short and/or long-term time scales. As a result, a large body of work has emerged offering bandwidth conservation exemplified by the work in caching and multicast. The majority of the techniques that have experienced widespread adoption rely on parsing / reacting to application-specific data. With the advent of simplified end-to-end security, as introduced by IPv6, these techniques will no longer have access to the plaintext data. We present a novel technique for preserving security while allowing in-network devices to identify redundant data flows in order to apply bandwidth conservation techniques. Our communication protocol does not require modifications to existing applications nor does it inflict a significant amount of overhead to the existing network infrastructure. Chad D. Mano, David Salyers, Qi Liao 0002, Andrew Blaich, Aaron Striegel |
BROADNETS | 3 |