Kun Du

dblp:150/8306 · DBLP profile ↗
← Back
13ranked-venue papers
3as first author
2since 2021 · last 2024
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 3 first-author · 1 since 2021Artificial intelligence and machine learning · 2Computer networks · 2 · 1 since 2021Software engineering, systems software and programming languages · 1Graphics, computer vision, multimedia, augmented reality and games · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Web and mobile security · 72% Network security · 28%
Databases, data mining, and information retrieval
3 papers
Information retrieval · 54% Web and social media mining · 46%
Computer networks
3 papers
Internet architecture and protocols · 86% Network measurement and analytics · 14%

Topics — the 7 heaviest of 10, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Internet architecture and protocols
domain name system
0.522017
Don't Let One Rotten Apple Spoil the Whole Barrel: Towards Automated Detection of Shadowed Domains · CCS 2017
The Ever-Changing Labyrinth: A Large-Scale Analysis of Wildcard DNS Powered Blackhat SEO · USENIX Security Symposium 2016
Information retrieval › query understanding
query analysis
0.312017
How to Learn Klingon without a Dictionary: Detection and Measurement of Black Keywords Used by the Underground Economy · IEEE Symposium on Security and Privacy 2017
Web and mobile security › web attacks
blackhat SEO
0.212016
The Ever-Changing Labyrinth: A Large-Scale Analysis of Wildcard DNS Powered Blackhat SEO · USENIX Security Symposium 2016
Web and mobile security › malicious advertising
malicious advertisement detection
0.212016
Seeking Nonsense, Looking for Trouble: Efficient Promotional-Infection Detection through Semantic Inconsistency Search · IEEE Symposium on Security and Privacy 2016
Web and mobile security
web security
0.212016
Seeking Nonsense, Looking for Trouble: Efficient Promotional-Infection Detection through Semantic Inconsistency Search · IEEE Symposium on Security and Privacy 2016
Information retrieval
search engines
0.112016
Seeking Nonsense, Looking for Trouble: Efficient Promotional-Infection Detection through Semantic Inconsistency Search · IEEE Symposium on Security and Privacy 2016
Information retrieval › search engines
search result analysis
0.112016
Seeking Nonsense, Looking for Trouble: Efficient Promotional-Infection Detection through Semantic Inconsistency Search · IEEE Symposium on Security and Privacy 2016

Methods — techniques the papers use, named apart from their topics

automated detection · 0.9text similarity clustering · 0.6semantic analysis · 0.5search engine querying · 0.5natural language processing · 0.5large-scale measurement · 0.5
YearPublicationVenuePosition
2024 Nonlinear energy harvesting based alternate cooperative nonorthogonal multiple access with adaptive interference cancellation
Chao Zhai 0001, Jiachao Yu, Kun Du, Xinhua Wang 0002
Comput. Networks3
2021 Mingling of Clear and Muddy Water: Understanding and Detecting Semantic Confusion in Blackhat SEO
Kun Du, Yubao Zhang, Shuai Hao 0001, Haining Wang 0001, Jia Zhang 0004, Hai-Xin Duan
ESORICS (1)2
2020 Understanding Promotion-as-a-Service on GitHub
abstract
As the world’s leading software development platform, GitHub has become a social networking site for programmers and recruiters who leverage its social features, such as star and fork, for career and business development. However, in this paper, we found a group of GitHub accounts that conducted promotion services in GitHub, called “promoters”, by performing paid star and fork operations on specified repositories. We also uncovered a stealthy way of tampering with historical commits, through which these promoters are able to fake commits retroactively. By exploiting such a promotion service, any GitHub user can pretend to be a skillful developer with high influence.
Kun Du, Yubao Zhang, Hai-Xin Duan, Haining Wang 0001, Shuang Hao 0001, Zhou Li 0001, Min Yang 0002
ACSAC1
2020 A Market in Dream: the Rapid Development of Anonymous Cybercrime
Gengqian Zhou, Jianwei Zhuge, Yunqian Fan, Kun Du, Shuqiang Lu
Mob. Networks Appl.4
2019 Casino royale: a deep exploration of illegal online gambling
abstract
The popularity of online gambling could bring negative social impact, and many countries ban or restrict online gambling. Taking China for example, online gambling violates Chinese laws and hence is illegal. However, illegal online gambling websites are still thriving despite strict restrictions, since they are able to make tremendous illicit profits by trapping and cheating online players. In this paper, we conduct the first deep analysis on illegal online gambling targeting Chinese to unveil its profit chain. After successfully identifying more than 967,954 suspicious illegal gambling websites, we inspect these illegal gambling websites from five aspects, including webpage structure similarity, SEO (Search Engine Optimization) methods, the abuse of Internet infrastructure, third-party online payment, and gambling group. Then we conduct a measurement study on the profit chain of illegal online gambling, investigating the upstream and downstream of these illegal gambling websites. We mainly focus on promotion strategies, third-party online payment, the abuse of third-party live chat services, and network infrastructures. Our findings shed the light on the ecosystem of online gambling and help the security community thwart illegal online gambling.
Kun Du, Yubao Zhang, Shuang Hao 0001, Zhou Li 0001, Mingxuan Liu 0006, Haining Wang 0001, Hai-Xin Duan, Yazhou Shi, XiaoDong Su, Zhifeng Geng
ACSAC2
2019 TL;DR Hazard: A Comprehensive Study of Levelsquatting Scams
Kun Du, Zhou Li 0001, Hai-Xin Duan, Shuang Hao 0001, Baojun Liu 0002, Yuxiao Ye, Mingxuan Liu 0006, XiaoDong Su, Zhifeng Geng, Zaifeng Zhang, Jinjin Liang
SecureComm (2)1
2017 Don't Let One Rotten Apple Spoil the Whole Barrel: Towards Automated Detection of Shadowed Domains
abstract
Domain names have been exploited for illicit online activities for decades. In the past, miscreants mostly registered new domains for their attacks. However, the domains registered for malicious purposes can be deterred by existing reputation and blacklisting systems. In response to the arms race, miscreants have recently adopted a new strategy, called domain shadowing, to build their attack infrastructures. Specifically, instead of registering new domains, miscreants are beginning to compromise legitimate ones and spawn malicious subdomains under them. This has rendered almost all existing countermeasures ineffective and fragile because subdomains inherit the trust of their apex domains, and attackers can virtually spawn an infinite number of shadowed domains.
Daiping Liu, Zhou Li 0001, Kun Du, Haining Wang 0001, Baojun Liu 0002, Hai-Xin Duan
CCS3
2017 How to Learn Klingon without a Dictionary: Detection and Measurement of Black Keywords Used by the Underground Economy
abstract
Online underground economy is an important channel that connects the merchants of illegal products and their buyers, which is also constantly monitored by legal authorities. As one common way for evasion, the merchants and buyers together create a vocabulary of jargons (called "black keywords" in this paper) to disguise the transaction (e.g., "smack" is one street name for "heroin" [1]). Black keywords are often "unfriendly" to the outsiders, which are created by either distorting the original meaning of common words or tweaking other black keywords. Understanding black keywords is of great importance to track and disrupt the underground economy, but it is also prohibitively difficult: the investigators have to infiltrate the inner circle of criminals to learn their meanings, a task both risky and time-consuming. In this paper, we make the first attempt towards capturing and understanding the ever-changing black keywords. We investigated the underground business promoted through blackhat SEO (search engine optimization) and demonstrate that the black keywords targeted by the SEOers can be discovered through a fully automated approach. Our insights are two-fold: first, the pages indexed under black keywords are more likely to contain malicious or fraudulent content (e.g., SEO pages) and alarmed by off-the-shelf detectors, second, people tend to query multiple similar black keywords to find the merchandise. Therefore, we could infer whether a search keyword is "black" by inspecting the associated search results and then use the related search queries to extend our findings. To this end, we built a system called KDES (Keywords Detection and Expansion System), and applied it to the search results of Baidu, China's top search engine. So far, we have already identified 478,879 black keywords which were clustered under 1,522 core words based on text similarity. We further extracted the information like emails, mobile phone numbers and instant messenger IDs from the pages and domains relevant to the underground business. Such information helps us gain better understanding about the underground economy of China in particular. In addition, our work could help search engine vendors purify the search results and disrupt the channel of the underground market. Our co-authors from Baidu compared our results with their blacklist, found many of them (e.g., long-tail and obfuscated keywords) were not in it, and then added them to Baidu's internal blacklist.
Xiulin Ma, Kun Du, Zhou Li 0001, Hai-Xin Duan, XiaoDong Su, Zhifeng Geng
IEEE Symposium on Security and Privacy3
2016 Seeking Nonsense, Looking for Trouble: Efficient Promotional-Infection Detection through Semantic Inconsistency Search
abstract
Promotional infection is an attack in which the adversary exploits a website's weakness to inject illicit advertising content. Detection of such an infection is challenging due to its similarity to legitimate advertising activities. An interesting observation we make in our research is that such an attack almost always incurs a great semantic gap between the infected domain (e.g., a university site) and the content it promotes (e.g., selling cheap viagra). Exploiting this gap, we developed a semantic-based technique, called Semantic Inconsistency Search (SEISE), for efficient and accurate detection of the promotional injections on sponsored top-level domains (sTLD) with explicit semantic meanings. Our approach utilizes Natural Language Processing (NLP) to identify the bad terms (those related to illicit activities like fake drug selling, etc.) most irrelevant to an sTLD's semantics. These terms, which we call irrelevant bad terms (IBTs), are used to query search engines under the sTLD for suspicious domains. Through a semantic analysis on the results page returned by the search engines, SEISE is able to detect those truly infected sites and automatically collect new IBTs from the titles/URLs/snippets of their search result items for finding new infections. Running on 403 sTLDs with an initial 30 seed IBTs, SEISE analyzed 100K fully qualified domain names (FQDN), and along the way automatically gathered nearly 600 IBTs. In the end, our approach detected 11K infected FQDN with a false detection rate of 1.5% and over 90% coverage. Our study shows that by effective detection of infected sTLDs, the bar to promotion infections can be substantially raised, since other non-sTLD vulnerable domains typically have much lower Alexa ranks and are therefore much less attractive for underground advertising. Our findings further bring to light the stunning impacts of such promotional attacks, which compromise FQDNs under 3% of .edu, .gov domains and over one thousand gov.cn domains, including those of leading universities such as stanford.edu, mit.edu, princeton.edu, havard.edu and government institutes such as nsf.gov and nih.gov. We further demonstrate the potential to extend our current technique to protect generic domains such as .com and .org.
Xiaojing Liao, Kan Yuan, XiaoFeng Wang 0001, Zhongyu Pei, Jianjun Chen 0005, Hai-Xin Duan, Kun Du, Eihal Alowaisheq, Sumayah A. Alrwais, Luyi Xing, Raheem A. Beyah
IEEE Symposium on Security and Privacy8
2016 The Ever-Changing Labyrinth: A Large-Scale Analysis of Wildcard DNS Powered Blackhat SEO
Kun Du, Zhou Li 0001, Hai-Xin Duan, Kehuan Zhang
USENIX Security Symposium1
2016 Multi-band joint local sparse tracking via wavelet transforms
abstract
A novel multi‐band joint local sparse tracking algorithm via wavelet transforms is proposed in this study. The object image may contain rich information of different types; the authors use wavelet transforms to decompose the object image into some sub‐band images first. This will help extract the information in different frequency ranges for the object. Then same block operation is executed on all the sub‐band images. The l 2, 1 mixed‐norm is used to describe the multi‐band joint local sparse representation on each patch; it can effectively extract the structural information in different frequency ranges. Thus, more accurate object appearance model can be established. Second, the coefficients on the diagonal of coefficient matrix are extracted for the confidence degrees of the candidate objects in this band, and then the confidence degree results in all the bands are fused to determine the best candidate object in the current frame. This can effectively alleviate the object drifting. Finally, both qualitative and quantitative evaluation results on 15 challenging video sequences demonstrate that the proposed tracking algorithm in this study can achieve better tracking effects compared with the other state‐of‐the‐art algorithms.
Guang Han 0002, Jixin Liu 0001, Ning Sun 0005, Kun Du, Xiaofei Li 0002
IET Comput. Vis.5
2015 Colour compressed sensing imaging via sparse difference and fractal minimisation recovery
abstract
In colour compressed sensing (CS) imaging, the current two bottlenecks for application are (1) high computation cost of sparse representation (SR) with over‐complete dictionary and (2) unsatisfactory imaging quality of CS recovery with l 1 ‐norm minimisation. Thus, this study proposes a novel colour CS imaging framework. In the framework, two improvements are achieved: (1) the authors present the sparse difference to reduce the computation cost of SR in RGB colour imaging; (2) the authors use fractal dimension instead of l 1 ‐norm as the object function to actualise high quality CS recovery. The feasibility of our colour CS imaging framework is proved by sseveral experiments.
Jixin Liu 0001, Xiaofei Li 0002, Guang Han 0002, Ning Sun 0005, Kun Du, Quan-Sen Sun
IET Image Process.5
2014 Post processing for dense stereo matching by iterative local plane fitting
abstract
Disparity refinement is an essential step of local stereo matching methods to produce fine dense disparity maps. The inherent defect of local stereo methods results in erroneous disparity in occluded areas. In this paper, we present a novel post processing method which can effectively improve the accuracy of dense disparity maps by rectifying disparity errors iteratively. Invalid disparities are first detected by left-right consistency check and color-disparity consistency check. For each invalid pixel, supports from valid pixels in the neighborhood are collected to determine the plane parameters of the local window. An iterative strategy is adopted to gradually propagate disparity information from valid pixels to invalid areas. We apply the proposed method to disparity maps produced by two recent stereo matching methods, and compare the refining results with other post processing methods. Experimental results show the effectiveness of our method in improving dense disparity maps.
Hongbo Lu, Haibo Meng, Kun Du, Yuanchao Xu 0003
SNPD3