EDBT 2026 Demo / reviewers in the wild / expert
Xigao Li
dblp:199/5197
· DBLP profile ↗
6ranked-venue papers
5as first author
5since 2021 · last 2025
0000-0003-4760-308XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | The Poorest Man in Babylon: A Longitudinal Study of Cryptocurrency Investment ScamsabstractGovernments and regulatory bodies have recognized investment scams as a prevalent form of cryptocurrency fraud. These scams typically use professional-looking websites to lure unsuspecting victims with promises of unrealistically high returns. In this paper, we introduce Crimson, a distributed system designed to continuously detect cryptocurrency investment scam websites as they are created in the wild. During the first 8 months of 2024, Crimson processed approximately 6 billion domain names and classified 43,572 unique cryptocurrency investment scam websites in real-time. Beyond detection, we provide insights into the design and infrastructure of these websites that can help users recognize scam patterns and assist hosting providers in detecting and blocking such sites. Furthermore, we investigate the inclusion of our detected scam websites in block-lists used by popular web browsers and applications, finding that the vast majority of these websites were absent. On the financial side, by analyzing the transactions incoming to scammer wallets on 6.7% of the sites detected by Crimson, we observe an estimated lower bound of 2.04M USD in losses due to cryptocurrency investment scams. Abisheka Pitumpe, Xigao Li, Amir Rahmati, Nick Nikiforakis |
WWW | 3 |
| 2024 | Like, Comment, Get Scammed: Characterizing Comment Scams on Media Platforms
Xigao Li, Amir Rahmati, Nick Nikiforakis |
NDSS | 1 |
| 2023 | Double and Nothing: Understanding and Detecting Cryptocurrency Giveaway Scams
Xigao Li, Anurag Yepuri, Nick Nikiforakis |
NDSS | 1 |
| 2023 | Scan Me If You Can: Understanding and Detecting Unwanted Vulnerability ScanningabstractWeb vulnerability scanners (WVS) are an indispensable tool for penetration testers and developers of web applications, allowing them to identify and fix low-hanging vulnerabilities before they are discovered by attackers. Unfortunately, malicious actors leverage the very same tools to identify and exploit vulnerabilities in third-party websites. Existing research in the WVS space is largely concerned with how many vulnerabilities these tools can discover, as opposed to trying to identify the tools themselves when they are used illicitly. Xigao Li, Babak Amin Azad, Amir Rahmati, Nick Nikiforakis |
WWW | 1 |
| 2021 | Good Bot, Bad Bot: Characterizing Automated Browsing ActivityabstractAs the web keeps increasing in size, the number of vulnerable and poorly-managed websites increases commensurately. Attackers rely on armies of malicious bots to discover these vulnerable websites, compromising their servers, and exfiltrating sensitive user data. It is, therefore, crucial for the security of the web to understand the population and behavior of malicious bots.In this paper, we report on the design, implementation, and results of Aristaeus, a system for deploying large numbers of "honeysites", i.e., websites that exist for the sole purpose of attracting and recording bot traffic. Through a seven-month-long experiment with 100 dedicated honeysites, Aristaeus recorded 26.4 million requests sent by more than 287K unique IP addresses, with 76,396 of them belonging to clearly malicious bots. By analyzing the type of requests and payloads that these bots send, we discover that the average honeysite received more than 37K requests each month, with more than 50% of these requests attempting to brute-force credentials, fingerprint the deployed web applications, and exploit large numbers of different vulnerabilities. By comparing the declared identity of these bots with their TLS handshakes and HTTP headers, we uncover that more than 86.2% of bots are claiming to be Mozilla Firefox and Google Chrome, yet are built on simple HTTP libraries and command-line tools. Xigao Li, Babak Amin Azad, Amir Rahmati, Nick Nikiforakis |
SP | 1 |
| 2017 | A hybrid disaster-tolerant model with DDF technology for MooseFS open-source distributed file system
Xigao Li, Lin Qian |
J. Supercomput. | 1 |