Zishuai Cheng

dblp:215/7279 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
3since 2021 · last 2026
0000-0002-9740-0654ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021Computer networks · 1
YearPublicationVenuePosition
2026 What-App? App Usage Detection Using Encrypted LTE/5G Traffic
abstract
Cellular traffic fingerprinting attacks, in which an unprivileged adversary passively monitors encrypted wireless channels to infer user activities, introduce significant privacy risks by giving attackers the ability to track user behaviors, infer sensitive activities, and profile victims without authorization. Although such attacks have been discussed for LTE and 5G, many existing studies rely on idealized assumptions that fall short when faced with the complexities of real-world practical scenarios. In this paper, we present the first practical traffic fingerprinting attack leveraging a Man-in-the-Middle (MITM) Relay in an operational cellular network. Implemented with open-source software, our attack allows a passive adversary to identify user applications with up to 99.02% accuracy, even under noisy conditions. We evaluate our method using 40 applications across five categories on multiple COTS user equipment (UE). Our approach further demonstrates the ability to infer fine-grained user activities such as browsing, messaging, and video streaming under practical constraints, including partial traffic knowledge and app version drift. The attack also achieves cross-device and cross-network transferability, and it remains robust in open-world scenarios where only a subset of application traffic is known to the adversary. We additionally propose a novel traffic regularization-based defense tailored specifically for cellular networks. This defense operates as an optional, backward-compatible security layer integrated seamlessly into the existing cellular protocol stack, effectively balancing security strength with practical considerations such as latency and bandwidth overhead.
Zishuai Cheng, Mihai Ordean, Baojiang Cui
Proc. Priv. Enhancing Technol.2
2023 Watching your call: Breaking VoLTE Privacy in LTE/5G Networks
abstract
Voice over LTE (VoLTE) and Voice over NR (VoNR), are two similar technologies that have been widely deployed by operators to provide a better calling experience in LTE and 5G networks, respectively. The VoLTE/NR protocols rely on the security features of the underlying LTE/5G network to protect users' privacy such that nobody can monitor calls and learn details about call times, duration, and direction. In this paper, we introduce a new privacy attack which enables adversaries to analyse encrypted LTE/5G traffic and recover any VoLTE/NR call details. We achieve this by implementing a novel mobile-relay adversary which is able to remain undetected by using an improved physical layer parameter guessing procedure. This adversary facilitates the recovery of encrypted configuration messages exchanged between victim devices and the mobile network. We further propose an identity mapping method which enables our mobile-relay adversary to link a victim's network identifiers to the phone number efficiently, requiring a single VoLTE protocol message. We evaluate the real-world performance of our attacks using four modern commercial off-the-shelf phones and two representative, commercial network carriers. We collect over 60 hours of traffic between the phones and the mobile networks and execute 160 VoLTE calls, which we use to successfully identify patterns in the physical layer parameter allocation and in VoLTE traffic, respectively. Our real-world experiments show that our mobile-relay works as expected in all test cases, and the VoLTE activity logs recovered describe the actual communication with 100% accuracy. Finally, we show that we can link network identifiers such as International Mobile Subscriber Identities (IMSI), Subscriber Concealed Identifiers (SUCI) and/or Globally Unique Temporary Identifiers (GUTI) to phone numbers while remaining undetected by the victim.
Zishuai Cheng, Mihai Ordean, Flavio D. Garcia, Baojiang Cui, Dominik Rys
Proc. Priv. Enhancing Technol.1
2021 An Improved Feature Extraction Approach for Web Anomaly Detection Based on Semantic Structure
abstract
Anomaly-based Web application firewalls (WAFs) are vital for providing early reactions to novel Web attacks. In recent years, various machine learning, deep learning, and transfer learning-based anomaly detection approaches have been developed to protect against Web attacks. Most of them directly treat the request URL as a general string that consists of letters and roughly use natural language processing (NLP) methods (i.e., Word2Vec and Doc2Vec) or domain knowledge to extract features. In this paper, we proposed an improved feature extraction approach which leveraged the advantage of the semantic structure of URLs. Semantic structure is an inherent interpretative property of the URL that identifies the function and vulnerability of each part in the URL. The evaluations on CSIC-2020 show that our feature extraction method has better performance than conventional feature extraction routine by more than average dramatic 5% improvement in accuracy, recall, and F1-score.
Zishuai Cheng, Baojiang Cui, Wenchuan Yang, Junsong Fu 0001
Secur. Commun. Networks1
2018 An Adaptive Analysis Framework for Correlating Cyber-Security-Related Data
abstract
In recent years, due to the rise of APT attacks and the failure of traditional security facilities, organizations have to collect a large amount of cyber-security-related data and try to unveil the previously unknown attacks by analyzing them. Additionally, a report from Gartner claims, "Information security is becoming a big data analytics problem, where massive amounts of data will be correlated, analyzed and mined for meaningful patterns". Generally, the research work of big data analytics for cyber security mainly includes building big data systems, designing efficient processing algorithms and exploring specific analysis methods and applications, such as detecting DDoS attacks, identifying malicious URLs, correlating IDS alert incidents and extracting threat intelligence from certain unstructured data. Of all these work, most is the extension of previous methods in the big data context, by employing big data techniques to improve the storage capacity, accelerate the calculation or carry out correlation analysis in a much longer time window. Instead, only a few cares about the real coordination of these multi-source, heterogeneous data. In this paper, we propose an adaptive analysis framework for correlating different kinds of cyber-security-related data, such as network traffic, alert incidents and external threat intelligence. This framework can help to improve the pertinence of analysis and better discover potential threats.
Xiaohui Jin, Baojiang Cui, Jun Yang 0035, Zishuai Cheng
AINA4
2018 An improved payload-based anomaly detector for web applications
Xiaohui Jin, Baojiang Cui, Zishuai Cheng, Congxian Yin
J. Netw. Comput. Appl.4