VLDB 2026 Research / reviewers in the wild / expert
Junjie Zhang 0004
dblp:99/6243-4
· DBLP profile ↗
33ranked-venue papers
5as first author
6since 2021 · last 2024
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 4 first-author · 3 since 2021Computer networks · 10 · 3 since 2021Systems, architecture and hardware · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Website Fingerprinting on Encrypted Proxies: A Flow-Context-Aware Approach and CountermeasuresabstractWebsite fingerprinting (WFP) could infer which websites a user is accessing via an encrypted proxy by passively inspecting the traffic characteristics of accessing different websites between the user and the proxy. Designing WFP attacks is crucial for understanding potential vulnerabilities of encrypted proxies, which guides the design of defensive measures against WFP. In this paper, we design a novel WFP attack against (popular) encrypted proxies that relay connections between the user and the proxy individually (e.g., Shadowsocks, V2Ray), and accordingly implement lightweight countermeasures to effectively defend against the attack. The attack features flow-context-aware and is both accurate and immediately deployable, because it fully considers the obstacle (dubbed training-testing asymmetry) that fundamentally limits the practicability of WFP and addresses the obstacle with built-in spatial-temporal flow correlation mechanism. We implement the countermeasure as middleboxes installed on both the client and server sides of encrypted proxies, without altering any existing infrastructures for compatibility. The middleboxes can obfuscate a website’s flow regularities across different visits. Large-scale experiments in real-world scenarios demonstrate that the WFP attack can generally achieve a detection rate above 98.8% with a false positive rate below 0.2%. The countermeasure forces the attack’s false positive rate to be above 0.2 and true positive rate to be below 0.9 with just five persistent TCP connections while introducing very limited bandwidth overhead (e.g., 0.49%) and almost-zero additional network latency. Xiaobo Ma 0001, Jian Qu, Mawei Shi, Bingyu An, Jianfeng Li 0006, Xiapu Luo, Junjie Zhang 0004, Zhenhua Li 0001, Xiaohong Guan |
IEEE/ACM Trans. Netw. | 7 |
| 2023 | Code Execution Capability as a Metric for Machine Learning-Assisted Software Vulnerability Detection ModelsabstractIn this paper, we consider how the ability to learn Code Execution Tasks affects a model’s accuracy on software vulnerability detection (SVD) benchmark datasets. We initially find that models can achieve near state-of-the-art accuracy on SVD benchmarks regardless of their ability to learn Code Execution Tasks. However, these models fail to generalize well across SVD benchmarks. The results indicate a bias in the datasets that allows models to predict non-SVD signals. Under the theory that different collection methods will reduce biases, we investigate combining the SVD datasets. When trained on combined datasets, SVD accuracy is reduced but correlation with Code Execution Task accuracy improves. Our contributions are (1) using a reversed curriculum learning to evaluate model capabilities, (2) demonstrating the criticality of code execution understanding to machine learning–assisted software vulnerability detection, (3) evidence that improved diversity of SVD datasets will lead to improved accuracy and generalizability, (4) and benchmarks of recent models across multiple SVD datasets. Daniel Grahn, Lingwei Chen, Junjie Zhang 0004 |
TrustCom | 3 |
| 2023 | An Input-Agnostic Hierarchical Deep Learning Framework for Traffic Fingerprinting
Jian Qu, Xiaobo Ma 0001, Jianfeng Li 0006, Xiapu Luo, Lei Xue 0001, Junjie Zhang 0004, Zhenhua Li 0001, Xiaohong Guan |
USENIX Security Symposium | 6 |
| 2023 | Detecting suspicious transactions in a virtual-currency-enabled online social network
Junjie Zhang 0004, Xingyu Zhu 0013, Ting Liu 0002 |
J. Netw. Comput. Appl. | 3 |
| 2021 | Context-aware Website Fingerprinting over Encrypted ProxiesabstractWebsite fingerprinting (WFP) could infer which websites a user is accessing via an encrypted proxy by passively inspecting the traffic between the user and the proxy. The key to WFP is designing a classifier capable of distinguishing traffic characteristics of accessing different websites. However, when deployed in real-life networks, a well-trained classifier may face a significant obstacle of training-testing asymmetry, which fundamentally limits its practicability. Specifically, although pure traffic samples can be collected in a controlled (clean) testbed for training, the classifier may fail to extract such pure traffic samples as its input from raw complicated traffic for testing. In this paper, we are interested in encrypted proxies that relay connections between the user and the proxy individually (e.g., Shadowsocks), and design a context-aware system using built-in spatial-temporal flow correlation to address the obstacle. Extensive experiments demonstrate that our system does not only enable WFP against a popular type of encrypted proxies practical, but also achieves better performance than ideally training/testing pure samples. Xiaobo Ma 0001, Mawei Shi, Bingyu An, Jianfeng Li 0006, Xiapu Luo, Junjie Zhang 0004, Xiaohong Guan |
INFOCOM | 6 |
| 2021 | UFuzzer: Lightweight Detection of PHP-Based Unrestricted File Upload Vulnerabilities Via Static-Fuzzing Co-AnalysisabstractUnrestricted file upload vulnerabilities enable attackers to upload malicious scripts to a web server for later execution. We have built a system, namely UFuzzer, to effectively and automatically detect such vulnerabilities in PHP-based server-side web programs. Different from existing detection methods that use either static program analysis or fuzzing, UFuzzer integrates both (i.e., static-fuzzing co-analysis). Specifically, it leverages static program analysis to generate executable code templates that compactly and effectively summarize the vulnerability-relevant semantics of a server-side web application. UFuzzer then “fuzzes” these templates in a local, native PHP runtime environment for vulnerability detection. Compared to static-analysis-based methods, UFuzzer preserves the semantics of an analyzed program more effectively, resulting in higher detection performance. Different from fuzzing-based methods, UFuzzer exercises each generated code template locally, thereby reducing the analysis overhead and meanwhile eliminating the need of operating web services. Experiments using real-world data have demonstrated that UFuzzer outperforms existing methods in either efficiency, or accuracy, or both. In addition, it has detected 31 unknown vulnerable PHP scripts including 5 CVEs. Junjie Zhang 0004, Jialun Liu, Rui Dai 0002 |
RAID | 2 |
| 2019 | UChecker: Automatically Detecting PHP-Based Unrestricted File Upload VulnerabilitiesabstractUnrestricted file upload vulnerabilities enable attackers to upload and execute malicious scripts in web servers. We have built a system, namely UChecker, to effectively and automatically detect such vulnerabilities in PHP server-side web applications. Towards this end, UChecker first interprets abstract syntax trees (AST) of program source code to perform symbolic execution. It then models vulnerabilities using SMT constraints and further leverages an SMT solver to verify the satisfiability of these constraints. UChecker features a novel vulnerability-oriented locality analysis algorithm to reduce the workload of symbolic execution, an AST-driven symbolic execution engine with compact data structures, and rules to translate PHP-based constraints into SMT-based constraints by mitigating their semantic gaps. Experiments based on real-world examples have demonstrated that UChecker has accomplished a high detection accuracy. In addition, it detected three vulnerable PHP scripts that are previously unknown. Yu Li 0008, Junjie Zhang 0004, Rui Dai 0002 |
DSN | 3 |
| 2019 | ShellBreaker: Automatically detecting PHP-based malicious web shells
Yu Li 0008, Ademola Ayodeji Ikusan, Milliken Mitchell, Junjie Zhang 0004, Rui Dai 0002 |
Comput. Secur. | 5 |
| 2018 | Can We Learn what People are Doing from Raw DNS Queries?abstractDomain Name System (DNS) is one of the pillars of today's Internet. Due to its appealing properties such as low data volume, wide-ranging applications and encryption free, DNS traffic has been extensively utilized for network monitoring. Most existing studies of DNS traffic, however, focus on domain name reputation. Little attention has been paid to understanding and profiling what people are doing from DNS traffic, a fundamental problem in the areas including Internet demographics and network behavior analysis. Consequently, simple questions like “How to determine whether a DNS query for www.google.com means searching or any other behaviors?” cannot be answered by existing studies. In this paper, we take the first step to identify user activities from raw DNS queries. We advance a multiscale hierarchical framework to tackle two practical challenges, i.e., behavior ambiguity and behavior polymorphism. Under this framework, a series of novel methods, such as pattern upward mapping and multi-scale random forest classifier, are proposed to characterize and identify user activities of interest. Evaluation using both synthetic and real-world DNS traces demonstrates the effectiveness of our method. Jianfeng Li 0006, Xiaobo Ma 0001, Xiapu Luo, Junjie Zhang 0004, Wei Li 0029, Xiaohong Guan |
INFOCOM | 5 |
| 2018 | Vulnerability Assessment for Unmanned Systems Autonomy Services Architecture
Yu Li 0008, Ivan Frasure, Ademola Ayodeji Ikusan, Junjie Zhang 0004, Rui Dai 0002 |
NSS | 4 |
| 2018 | Detecting Suspicious Members in an Online Emotional Support Service
Yu Li 0008, Dae Wook Kim, Junjie Zhang 0004, Derek Doran |
SecureComm (2) | 3 |
| 2018 | Designing self-destructing wireless sensors with security and performance assurance
Yu Li 0008, Dae Wook Kim, Junjie Zhang 0004, Rui Dai 0002 |
Comput. Networks | 4 |
| 2018 | Exploiting the Vulnerability of Flow Table Overflow in Software-Defined Network: Attack Model, Evaluation, and DefenseabstractAs the most competitive solution for next-generation network, SDN and its dominant implementation OpenFlow are attracting more and more interests. But besides convenience and flexibility, SDN/OpenFlow also introduces new kinds of limitations and security issues. Of these limitations, the most obvious and maybe the most neglected one is the flow table capacity of SDN/OpenFlow switches. In this paper, we proposed a novel inference attack targeting at SDN/OpenFlow network, which is motivated by the limited flow table capacities of SDN/OpenFlow switches and the following measurable network performance decrease resulting from frequent interactions between data and control plane when the flow table is full. To the best of our knowledge, this is the first proposed inference attack model of this kind for SDN/OpenFlow. We implemented an inference attack framework according to our model and examined its efficiency and accuracy. The evaluation results demonstrate that our framework can infer the network parameters (flow table capacity and usage) with an accuracy of 80% or higher. We also proposed two possible defense strategies for the discovered vulnerability, including routing aggregation algorithm and multilevel flow table architecture. These findings give us a deeper understanding of SDN/OpenFlow limitations and serve as guidelines to future improvements of SDN/OpenFlow. Kaiyue Chen, Junjie Zhang 0004, Junyuan Leng, Yazhe Tang |
Secur. Commun. Networks | 3 |
| 2018 | Probabilistically Inferring Attack Ramifications Using Temporal Dependence NetworkabstractThere is an increasing need of assessing and mitigating the effects of successful attacks. Uncovering malicious and contaminated objects in an attacked computing system is referred to as identification of attack ramifications. Previous methods identify the attack ramifications by directly tracking information flows (or dependences) from the intrusion root (i.e., the entry point of an attack). They face challenges such as undetermined intrusion root and dependence explosion. In this paper, we present a novel, light-weight method capable of identifying attack ramifications without the knowledge of intrusion root and less subject to dependency explosion. The method utilizes a probabilistic reasoning approach to fuse evidence derived from a subset of objects whose security states are known. It first splits the lifetime of an object into consecutive time slices (object-slices) to profile how the security state of this object changes over time. Then, a temporal dependence network (TDN) is constructed from system call traces to correlate object-slices according to information flows between them. Based on that, a Bayesian network (BN) model is built to characterize the uncertainties of infection propagations in the TDN. Finally, the method adopts loopy belief propagation on the BN model to infer the security state of an object. We evaluate the proposed method using a large data set of 389 attacks launched by the real-world malware samples including sophisticated ones such as Stuxnet. Extensive experiments demonstrate that our method is able to identify attack ramifications with a 97.47% precision at 97.21% recall without the knowledge of intrusion root. Yuan Yang 0003, Zhongmin Cai, Chunyan Wang 0012, Junjie Zhang 0004 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2017 | Online-relaying-based image communication in unmanned aerial vehicle networksabstractThe use of small and miniature unmanned aerial vehicles (UAVs) for remote sensing and surveillance applications has become increasingly popular in the last two decades. The intermittent connectivity in a sparse UAV network makes it challenging to efficiently gather sensed image data. This paper investigates the communication of sensed images from a set of mobile survey UAVs to a static base station through the assistance of a relay UAV. Given the planned routes of survey UAVs, a set of relay waypoints are found for the relay UAV to meet the survey UAVs and receive the sensed images. An Online Message Relaying technique (OMR) is proposed to schedule the relay UAV to collect images. Without any global collaboration between the relay UAV and the survey UAVs, OMR utilizes a markov decision process (MDP) that determines the best schedules for the relay UAV such that the image acquisition rate could be maximized. Evaluation results show that the proposed relaying technique outperforms traditional relaying techniques, such as the traveling salesman problem (TSP) and the random walk, in terms of end-to-end delay and frame delivery ratio. Kevon Scott, Rui Dai 0002, Junjie Zhang 0004 |
ICC | 3 |
| 2017 | Tracking You through DNS Traffic: Linking User Sessions by Clustering with Dirichlet Mixture ModelabstractThe Domain Name System (DNS), which does not encrypt domain names such as "bank.us" and "dentalcare.com", commonly accurately reflects the specific network services. Therefore, DNS-based behavioral analysis is extremely attractive for many applications such as forensics investigation and online advertisement. Traditionally, a user can be trivially and uniquely identified by the device's IP address if it is static (i.e., a desktop or a laptop). As more and more wireless and mobile devices are deeply ingrained in our lives and the dynamic IP address such as DHCP has been widely applied, it becomes almost impossible to use one IP address to identify a unique user. In this paper, we propose a new tracking method to identify individual users by the way they query DNS regardless of dynamic changing IP addresses and various types of devices. The method is applicable based on two observations. First, even though users may update IP addresses dynamically during different sessions, their query patterns can be stable across these sessions. Secondly, domain name look ups in sessions are different from users to users according to their personal behaviors. Specifically, we propose the constrained Dirichlet multinomial mixture (CDMM) clustering model to cluster DNS queries of different sessions into groups, each of which is considered being generated by a unique user. Compared with traditional supervised and unsupervised models, our model does not acquire any labeled user information that is very hard to obtain in real networks or the specification of the number of clusters, and meanwhile enforces the maximum number of session data in each cluster, which fits the DNS tracking problem nicely. Experimental results on DNS queries collected from real networks demonstrate that our method accomplishes a high clustering accuracy and outperforms the existing methods. Mingxuan Sun 0001, Guangyue Xu, Junjie Zhang 0004, Dae Wook Kim |
MSWiM | 3 |
| 2017 | Mining repeating pattern in packet arrivals: Metrics, models, and applications
Jianfeng Li 0006, Xiaobo Ma 0001, Junjie Zhang 0004, Pinghui Wang, Xiaohong Guan |
Inf. Sci. | 3 |
| 2017 | Deriving and measuring DNS-based fingerprints
Dae Wook Kim, Junjie Zhang 0004 |
J. Inf. Secur. Appl. | 2 |
| 2015 | Modeling repeating behaviors in packet arrivals: Detection and measurementabstractWith the growing stickiness of the Internet, numerous automated programs running in terminal facilities (e.g., laptops) tend to keep closely connected to the Internet by repetitively interacting with remote services. It is of fundamental importance to study such repeating behaviors of automated programs in areas like traffic engineering and network monitoring. This paper focuses on repeating behaviors in packet arrivals that are of interest, aiming at a hierarchical characterization of packet arrivals, detection methods and quantitative metrics. To this end, we present a structure-oriented characterization of packet arrivals, which reflects the temporal structure of repeating behaviors at different scales. Based on such characterization, a repeating behavior detection method is proposed by leveraging online-learning prediction, and two novel metrics of repeating behaviors are proposed from different aspects. In addition, a denoising method is developed to enhance the noise-tolerant capability of detection and measurement in face of noises. Experimental results based on real-world traces demonstrate the effectiveness of our proposed approaches in automated program behavior detection and behavioral botnet analysis. Jianfeng Li 0006, Xiaobo Ma 0001, Junjie Zhang 0004, Xiaohong Guan |
INFOCOM | 4 |
| 2015 | You Are How You Query: Deriving Behavioral Fingerprints from DNS Traffic
Dae Wook Kim, Junjie Zhang 0004 |
SecureComm | 2 |
| 2015 | Detecting fake anti-virus software distribution webpages
Dae Wook Kim, Peiying Yan, Junjie Zhang 0004 |
Comput. Secur. | 3 |
| 2015 | Accurate DNS query characteristics estimation via active probing
Xiaobo Ma 0001, Junjie Zhang 0004, Zhenhua Li 0001, Jianfeng Li 0006, Xiaohong Guan, John C. S. Lui, Don Towsley |
J. Netw. Comput. Appl. | 2 |
| 2014 | Morphing communications of Cyber-Physical Systems towards moving-target defenseabstractSince the massive deployment of Cyber-Physical Systems (CPSs) calls for long-range and reliable communication services with manageable cost, it has been believed to be an inevitable trend to relay a significant portion of CPS traffic through existing networking infrastructures such as the Internet. Adversaries who have access to networking infrastructures can therefore eavesdrop network traffic and then perform traffic analysis attacks in order to identify CPS sessions and subsequently launch various attacks. As we can hardly prevent all adversaries from accessing network infrastructures, thwarting traffic analysis attacks becomes indispensable. Traffic morphing serves as an effective means towards this direction. In this paper, a novel traffic morphing algorithm, CPSMorph, is proposed to protect CPS sessions. CPSMorph maintains a number of network sessions whose distributions of inter-packet delays are statistically indistinguishable from those of typical network sessions. A CPS message will be sent through one of these sessions with assured satisfaction of its time constraint. CPSMorph strives to minimize the overhead by dynamically adjusting the morphing process. It is characterized by low complexity as well as high adaptivity to changing dynamics of CPS sessions. Experimental results have shown that CPSMorph can effectively performing traffic morphing for real-time CPS messages with moderate overhead. Yu Li 0008, Rui Dai 0002, Junjie Zhang 0004 |
ICC | 3 |
| 2014 | DNSRadar: Outsourcing Malicious Domain Detection Based on Distributed Cache-FootprintsabstractAs the domain name system (DNS) plays a critical role in malicious services and number of networks, especially small enterprise networks and home networks that are generally and poorly managed, grows rapidly, it is highly desired to outsource the malicious domain detection service to a thirdparty system that can aggregate information from multiple vantage points to perform detection. To this end, we propose DNSRadar, a system that explores the coexistence of domain cache-footprints distributed in all networks that participate in the outsourcing service. Bootstrapping from a list of prelabeled malicious domains, DNSRadar leverages link analysis techniques to infer maliciousness likelihood of unknown domains based on coexistence information. As DNSRadar only uses the existence of an unknown domain in a network for detection, privacy concerns have been drastically reduced. Both MapReduce and lightweight matrix analysis techniques are employed to implement DNSRadar, making scalability as a built-in feature. Taking advantage of a large number of open recursive DNS servers, we have performed extensive evaluation at scale. Experimental results have demonstrated that DNSRadar can efficiently detect ~90% malicious domains given a low false positive rate of 1%. Of all these detected malicious domains, ~30% are on average 6 days earlier than public DNS reputation services, indicating DNSRadar's great early detection capability. Xiaobo Ma 0001, Junjie Zhang 0004, Jianfeng Li 0006, Jue Tian, Xiaohong Guan |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2014 | Building a Scalable System for Stealthy P2P-Botnet DetectionabstractPeer-to-peer (P2P) botnets have recently been adopted by botmasters for their resiliency against take-down efforts. Besides being harder to take down, modern botnets tend to be stealthier in the way they perform malicious activities, making current detection approaches ineffective. In addition, the rapidly growing volume of network traffic calls for high scalability of detection systems. In this paper, we propose a novel scalable botnet detection system capable of detecting stealthy P2P botnets. Our system first identifies all hosts that are likely engaged in P2P communications. It then derives statistical fingerprints to profile P2P traffic and further distinguish between P2P botnet traffic and legitimate P2P traffic. The parallelized computation with bounded complexity makes scalability a built-in feature of our system. Extensive evaluation has demonstrated both high detection accuracy and great scalability of the proposed system. Junjie Zhang 0004, Roberto Perdisci, Wenke Lee, Xiapu Luo, Unum Sarfraz |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2013 | Intention and Origination: An Inside Look at Large-Scale Bot Queries
Junjie Zhang 0004, Yinglian Xie, Fang Yu 0002, David Soukal, Wenke Lee |
NDSS | 1 |
| 2011 | Exposing invisible timing-based traffic watermarks with BACKLITabstractTraffic watermarking is an important element in many network security and privacy applications, such as tracing botnet C&C communications and deanonymizing peer-to-peer VoIP calls. The state-of-the-art traffic watermarking schemes are usually based on packet timing information and they are notoriously difficult to detect. In this paper, we show for the first time that even the most sophisticated timing-based watermarking schemes (e.g., RAINBOW and SWIRL) are not invisible by proposing a new detection system called BACKLIT. BACKLIT is designed according to the observation that any practical timing-based traffic watermark will cause noticeable alterations in the intrinsic timing features typical of TCP flows. We propose five metrics that are sufficient for detecting four state-of-the-art traffic watermarks for bulk transfer and interactive traffic. BACKLIT can be easily deployed in stepping stones and anonymity networks (e.g., Tor), because it does not rely on strong assumptions and can be realized in an active or passive mode. We have conducted extensive experiments to evaluate BACKLIT's detection performance using the PlanetLab platform. The results show that BACKLIT can detect watermarked network flows with high accuracy and few false positives. Xiapu Luo, Peng Zhou 0002, Junjie Zhang 0004, Roberto Perdisci, Wenke Lee, Rocky K. C. Chang |
ACSAC | 3 |
| 2011 | Boosting the scalability of botnet detection using adaptive traffic samplingabstractBotnets pose a serious threat to the health of the Internet. Most current network-based botnet detection systems require deep packet inspection (DPI) to detect bots. Because DPI is a computational costly process, such detection systems cannot handle large volumes of traffic typical of large enterprise and ISP networks. In this paper we propose a system that aims to efficiently and effectively identify a small number of suspicious hosts that are likely bots. Their traffic can then be forwarded to DPI-based botnet detection systems for fine-grained inspection and accurate botnet detection. By using a novel adaptive packet sampling algorithm and a scalable spatial-temporal flow correlation approach, our system is able to substantially reduce the volume of network traffic that goes through DPI, thereby boosting the scalability of existing botnet detection systems. We implemented a proof-of-concept version of our system, and evaluated it using real-world legitimate and botnet-related network traces. Our experimental results are very promising and suggest that our approach can enable the deployment of botnet-detection systems in large, high-speed networks. Junjie Zhang 0004, Xiapu Luo, Roberto Perdisci, Guofei Gu, Wenke Lee, Nick Feamster |
AsiaCCS | 1 |
| 2011 | Detecting stealthy P2P botnets using statistical traffic fingerprintsabstractPeer-to-peer (P2P) botnets have recently been adopted by botmasters for their resiliency to take-down efforts. Besides being harder to take down, modern botnets tend to be stealthier in the way they perform malicious activities, making current detection approaches, including, ineffective. In this paper, we propose a novel botnet detection system that is able to identify stealthy P2P botnets, even when malicious activities may not be observable. First, our system identifies all hosts that are likely engaged in P2P communications. Then, we derive statistical fingerprints to profile different types of P2P traffic, and we leverage these fingerprints to distinguish between P2P botnet traffic and other legitimate P2P traffic. Unlike previous work, our system is able to detect stealthy P2P botnets even when the underlying compromised hosts are running legitimate P2P applications (e.g., Skype) and the P2P bot software at the same time. Our experimental evaluation based on real-world data shows that the proposed system can achieve high detection accuracy with a low false positive rate. Junjie Zhang 0004, Roberto Perdisci, Wenke Lee, Unum Sarfraz, Xiapu Luo |
DSN | 1 |
| 2011 | ARROW: GenerAting SignatuRes to Detect DRive-By DOWnloadsabstractA drive-by download attack occurs when a user visits a webpage which attempts to automatically download malware without the user's consent. Attackers sometimes use a malware distribution network (MDN) to manage a large number of malicious webpages, exploits, and malware executables. In this paper, we provide a new method to determine these MDNs from the secondary URLs and redirect chains recorded by a high-interaction client honeypot. In addition, we propose a novel drive-by download detection method. Instead of depending on the malicious content used by previous methods, our algorithm first identifies and then leverages the URLs of the MDN's central servers, where a central server is a common server shared by a large percentage of the drive-by download attacks in the same MDN. A set of regular expression-based signatures are then generated based on the URLs of each central server. This method allows additional malicious webpages to be identified which launched but failed to execute a successful drive-by download attack. The new drive-by detection system named ARROW has been implemented, and we provide a large-scale evaluation on the output of a production drive-by detection system. The experimental results demonstrate the effectiveness of our method, where the detection coverage has been boosted by 96% with an extremely low false positive rate. Junjie Zhang 0004, Christian Seifert, Jack W. Stokes, Wenke Lee |
WWW | 1 |
| 2010 | On the Secrecy of Spread-Spectrum Flow Watermarks
Xiapu Luo, Junjie Zhang 0004, Roberto Perdisci, Wenke Lee |
ESORICS | 2 |
| 2008 | BotSniffer: Detecting Botnet Command and Control Channels in Network Traffic
Guofei Gu, Junjie Zhang 0004, Wenke Lee |
NDSS | 2 |
| 2008 | BotMiner: Clustering Analysis of Network Traffic for Protocol- and Structure-Independent Botnet Detection
Guofei Gu, Roberto Perdisci, Junjie Zhang 0004, Wenke Lee |
USENIX Security Symposium | 3 |