EDBT 2026 Demo / reviewers in the wild / expert
Jiawen Diao
dblp:205/7539
· DBLP profile ↗
3ranked-venue papers
2as first author
3since 2021 · last 2024
0009-0008-7603-1387ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Poster: DoHunter: A feature fusion-based LLM for DoH tunnel detectionabstractDNS over HTTPS (DoH) reduces the risk of privacy leakage of DNS queries, but it also provides a covert communication channel for malicious activities. In this paper, we propose a method for malicious encrypted traffic identification, which harnesses the advanced context comprehension of Large Language Model (LLM) and incorporates expert features to detect anomalies. The evaluation results show that the method proposed in this paper can not only identify common and emerging malicious DoH tunnel tools such as dns2tcp, iodine, and dnstt, but also identify weaponized DoH traffic within a real APT attack, with a recall of 0.9995. Jiawen Diao, Shengmin Zhao, Jianguo Xie, Rongna Xie, Guozhen Shi |
CCS | 1 |
| 2022 | From Passive to Active: Near-optimal DNS-based Data Exfiltration Defense Method Based on Sticky MechanismabstractDNS-based data exfiltration has become increasingly popular among advanced persistent threat (APT) attackers owing to the ubiquity and penetrability of the DNS protocol. AI-powered methods solve the defect that attackers can easily bypass because of the fixed threshold and weight in rule matching while still suffer from several issues. Such as the lack of malware samples for training, the amplified impact of even low FPR present enormous obstacles to applying the model in real-world detection.We present a method to generate malicious traffic covering an extensive sample space based on Tactics, Techniques, and Procedures (TTPs). We then propose a sticky mechanism, which transforms certain decision-making into dynamic human-computer interaction decision-making, to verify the suspicious hosts recognized by the AI model. The experimental results demonstrate the superiority of our model by identifying eight kinds of real attacks precisely. The good performance on real-world traffic shows our method is a solid foothold for applying AI-powered detection to practical applications. Jiawen Diao, Binxing Fang, Xiang Cui, Zhongru Wang, Shouyou Song |
TrustCom | 1 |
| 2022 | DCC-Find: DNS Covert Channel Detection by Features Concatenation-Based LSTMabstractDNS (Domain Name System) plays an important role in network communication and it is rarely blocked by firewalls and intrusion detection systems (IDS). It is a suitable way for attackers to build DCC (DNS Covert Channel), which is used for data exfiltration. In recent years, some DCC detection methods have been proposed based on deep learning and there is no need for manual feature extraction. However, some expert knowledge is helpful to express the DNS characteristic. In this paper, we propose a FC-LSTM (Features Concatenation-based LSTM) model to detect DCC. The statistical features are concatenated with the output features of the LSTM model. This method makes the expression of DNS domain names more abundant. The experimental results have shown that the DCC traffic can be identified from normal traffic via this model, and the recognition rate is significantly improved compared with the traditional LSTM model and CNN model. In addition, we implement multi-classification in terms of the DCC tools (some of them are used in APT32). We also add generalization DNS packets (simulating APT34 traffic using DCC for stealing and attacking) to verify the robustness of our model. The FC-LSTM model has a good detection performance as well. Dongxu Han, Pu Dong, Xiang Cui, Jiawen Diao, Qing Wang 0041, Dan Du |
TrustCom | 5 |