Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Shukun Yang

dblp:172/8803 · DBLP profile ↗
← Back
6ranked-venue papers
1as first author
1since 2021 · last 2025
0000-0002-1272-9275ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 1 since 2021Security and privacy · 3 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
4 papers
Authentication and access control · 87% Privacy and data protection · 10% Usable security · 3%

Topics — the 8 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Authentication and access control
password security
0.622018
DPPG: A Dynamic Password Policy Generation System · IEEE Trans. Inf. Forensics Secur. 2018
Zero-Sum Password Cracking Game: A Large-Scale Empirical Study on the Crackability, Correlation, and Security of Passwords · IEEE Trans. Dependable Secur. Comput. 2017
Authentication and access control › password security
password policy
0.312018
DPPG: A Dynamic Password Policy Generation System · IEEE Trans. Inf. Forensics Secur. 2018
Authentication and access control › password security
password strength estimation
0.312018
DPPG: A Dynamic Password Policy Generation System · IEEE Trans. Inf. Forensics Secur. 2018
Authentication and access control › knowledge-based authentication
password
0.312017
Password correlation: Quantification, evaluation and application · INFOCOM 2017
Authentication and access control
password guessing
0.312017
Zero-Sum Password Cracking Game: A Large-Scale Empirical Study on the Crackability, Correlation, and Security of Passwords · IEEE Trans. Dependable Secur. Comput. 2017
Authentication and access control › password security
password strength
0.312017
Password correlation: Quantification, evaluation and application · INFOCOM 2017
Privacy and data protection
anonymization
0.212016
On the relative de-anonymizability of graph data: Quantification and evaluation · INFOCOM 2016
Authentication and access control › password security
password strength meter
0.112017
Password correlation: Quantification, evaluation and application · INFOCOM 2017

Methods — techniques the papers use, named apart from their topics

offline cracking simulation · 0.3diversity-based security metric · 0.3training-based cracking · 0.3statistical correlation analysis · 0.3empirical study · 0.3cracking algorithm comparison · 0.3structural importance analysis · 0.2
YearPublicationVenuePosition
2025 Multidiffusion Information Centrality for the Identification of Influential Spreaders in Temporal Social Networks
abstract
Identifying influential spreaders in a temporal social network, which has potential applications including network immunization, epidemic control, and viral marketing, is a fundamental class of problems. In this context, various centrality algorithms have been introduced to quantify influential spreaders, focusing on three categories: topology-based methods, dynamics-based methods, and machine learning-based methods. However, topology-based methods tend to consider single temporal features, while the consideration of multi-temporal features is subject to the same challenges of high temporal complexity as dynamics-based methods, and machine learning-based methods face challenges related to dependency on the training dataset. In this paper, we propose a novel centrality algorithm based on multiple diffusion information (RPT: Multi-diffusion information centrality based on R-path trees) to identify the influential node in a temporal social network. This algorithm considers three different temporal features and has lower temporal complexity using a newly proposed representation structure known as an R-path tree (a distinctive inverted tree that encompasses the earliest arrival paths from other nodes to the root node). Through experiments carried out on 12 empirical social networks, the results show that the effectiveness of RPT in identifying influential spreaders generally exceeds that of other baseline measures.
Xuelong Yu, Shukun Yang, Hai Zhao 0002, Kuan Zhang 0001, Chong Yu 0002
IEEE Internet Things J.2
2018 DPPG: A Dynamic Password Policy Generation System
abstract
To keep password users from creating simple and common passwords, major websites and applications provide a password-strength measure, namely a password checker. While critical requirements for a password checker to be stringent have prevailed in the study of password security, we show that regardless of the stringency, such static checkers can leak information and actually help the adversary enhance the performance of their attacks. To address this weakness, we propose and devise the Dynamic Password Policy Generator, namely DPPG, to be an effective and usable alternative to the existing password strength checker. DPPG aims to enforce an evenly-distributed password space and generate dynamic policies for users to create passwords that are diverse and that contribute to the overall security of the password database. Since DPPG is modular and can function with different underlying metrics for policy generation, we further introduce a diversity-based password security metric that evaluates the security of a password database in terms of password space and distribution. The metric is useful as a countermeasure to well-crafted offline cracking algorithms and theoretically illustrates why DPPG works well.
Shukun Yang, Shouling Ji, Raheem A. Beyah
IEEE Trans. Inf. Forensics Secur.1
2017 Password correlation: Quantification, evaluation and application
abstract
In this paper, we study the correlation between passwords across different datasets which quantitatively explains the success of existing training-based password cracking techniques. We also study the correlation between a user's password and his/her social profile. This enabled us to develop the first social profile-aware password strength meter, namely SociaLShield. Our quantification techniques and SocialShield have meaningful implications to system administrators, users, and researchers, e.g., helping them quantitatively understand the threats posed by a password leakage incident, defending against emerging profile-based password attacks, and facilitating the research of countermeasures against existing and newly developed training-based password attacks. We validate our proposed quantification techniques and SocialShield through extensive experiments by leveraging real-world leaked passwords. Experimental results demonstrate that our quantification techniques are accurate in measuring correlation among different leaked datasets and that although SocialShield is light-weight, it is effective in defending against profile-based password attacks.
Shouling Ji, Shukun Yang, Anupam Das 0001, Xin Hu 0001, Raheem A. Beyah
INFOCOM2
2017 Zero-Sum Password Cracking Game: A Large-Scale Empirical Study on the Crackability, Correlation, and Security of Passwords
abstract
In this paper, we conduct a large-scale study on the crackability, correlation, and security of 145 million real world passwords, which were leaked from several popular Internet services and applications. To the best of our knowledge, this is the largest empirical study that has been conducted. Specifically, we first evaluate the crackability of 145 million real world passwords against 6+ state-of-the-art password cracking algorithms in multiple scenarios. Second, we examine the effectiveness and soundness of popular commercial password strength meters (e.g., Google, QQ) and the security impacts of username/email leakage on passwords. Finally, we discuss the implications of our results, analysis, and findings, which are expected to help both password users and system administrators to gain a deeper understanding of the vulnerability of real passwords against state-of-the-art password cracking algorithms, as well as to shed light on future password security research topics.
Shouling Ji, Shukun Yang, Xin Hu 0001, Weili Han, Zhigong Li, Raheem A. Beyah
IEEE Trans. Dependable Secur. Comput.2
2016 On the relative de-anonymizability of graph data: Quantification and evaluation
abstract
In this paper, we propose a structural importance-aware approach to quantify the vulnerability/de-anonymizability of graph data to structure-based De-Anonymization (DA) attacks [1][2][3][4]. Specifically, we quantify both the seed-based and the seed-free Relative De-anonymizability (RD) of graph data for both perfect DA (successfully de-anonymizing all the target users) and partial DA (where some DA error is tolerated) under a general data model. In our relative quantification, instead of treating all the users in graph data as structurally equivalent, we adaptively quantify their RD in terms of their structural importance. Leveraging 15 real world graph datasets, we validate the accuracy of our relative quantifications and compare them with state-of-the-art seed-based and seed-free quantification techniques. The results demonstrate that our structural importance-aware relative quantifications are more sound and precise when measuring graph data's real vulnerability/de-anonymizability.
Shouling Ji, Shukun Yang, Prateek Mittal, Raheem A. Beyah
INFOCOM3
2015 PARS: A Uniform and Open-source Password Analysis and Research System
abstract
In this paper, we introduce an open-source and modular password analysis and research system, PARS, which provides a uniform, comprehensive and scalable research platform for password security. To the best of our knowledge, PARS is the first such system that enables researchers to conduct fair and comparable password security research. PARS contains 12 state-of-the-art cracking algorithms, 15 intra-site and cross-site password strength metrics, 8 academic password meters, and 15 of the 24 commercial password meters from the top-150 websites ranked by Alexa. Also, detailed taxonomies and large-scale evaluations of the PARS modules are presented in the paper.
Shouling Ji, Shukun Yang, Ting Wang 0006, Changchang Liu, Wei-Han Lee, Raheem A. Beyah
ACSAC2