EDBT 2026 Demo / reviewers in the wild / expert
Chaochao Luo
dblp:229/1207
· DBLP profile ↗
4ranked-venue papers
2as first author
3since 2021 · last 2025
0000-0001-8674-6716ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Malware analysis · 40% Network security · 40% Systems and software security · 20% | |
| Interdisciplinary, comprehensive, and emerging computing
1 paper |
Computational social science and digital humanities · 100% |
Topics — the 4 heaviest of 6, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Malware analysis
botnet |
0.9 | 1 | 2025 | Your Botnet Is His Botnet? A Deep Dive Into the Supply Chain Attack Against Cyber-Arm Industry · IEEE Trans. Netw. 2025 |
Malware analysis
cybercrime market |
0.9 | 1 | 2025 | Your Botnet Is His Botnet? A Deep Dive Into the Supply Chain Attack Against Cyber-Arm Industry · IEEE Trans. Netw. 2025 |
Network security
malware propagation |
0.9 | 1 | 2025 | An Attack Exploiting Cyber-Arm Industry · IEEE Trans. Dependable Secur. Comput. 2025 |
Systems and software security › software supply chain security
supply chain attacks |
0.9 | 1 | 2025 | Your Botnet Is His Botnet? A Deep Dive Into the Supply Chain Attack Against Cyber-Arm Industry · IEEE Trans. Netw. 2025 |
Methods — techniques the papers use, named apart from their topics
mathematical modeling · 1.7attack model analysis · 1.7threat prediction · 0.9propagation model · 0.9
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | An Attack Exploiting Cyber-Arm IndustryabstractThe landscape of cyberattacks has transcended from mere hobbyist pursuits of cybercriminals to a lucrative business model, facilitating their sustenance. Concurrently, the cybercrime market has evolved into a complex ecosystem. Empowered by this environment, cybercriminal tactics have evolved from simple, isolated activities to intricate and coordinated cyberattacks. In this article, we reveal a new type of cyberattack paradigm termed Attack Exploiting Cyber-arms Industry (AECI), which, despite its potential for severe impact, requires less investment and entails fewer obstacles and risks compared to traditional methods. However, this type of attack is still neglected by security researchers and communities and this is the first work focusing on this type of attack. To elucidate AECI, we provide an overview of the cyber-arms industry and introduces an attack model. The model dissects each phase of AECI to illuminate its operational mechanics and strategic imperatives. Furthermore, to assess its potential impact, a mathematical model is proposed to estimate the scale of infection attributable to AECI. Through analysis of a specific attack case, our findings demonstrate that AECI can generate significant impacts within a brief timeframe, akin to the magnitude observed with the Mirai botnet. The proposed model is demonstrated to prove instrumental in effectively analyzing AECI and providing accurate estimations of its infection scale. Chaochao Luo, Wei Shi 0001, Yuan Liu 0002, Ximeng Liu, Zhihong Tian 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Your Botnet Is His Botnet? A Deep Dive Into the Supply Chain Attack Against Cyber-Arm IndustryabstractIn recent years, supply chain attacks have garnered significant attention from both enterprises and the security community due to their profound impact. Numerous studies have begun to focus on supply chain attacks targeting legitimate software. However, it is noteworthy that supply chain attacks also occur within cybercrime markets, which differ substantially from those observed in lawful markets. These attacks not only facilitate widespread infections but also enable the rapid formation of substantial botnets. Regrettably, supply chain attacks within cybercrime markets have largely been overlooked by the security community, resulting in a notable deficiency in systematic methodologies for comprehending such assaults. This work concentrates on a specific supply chain attack observed in cybercrime markets, denoted as the “Nigrita Attack.” To facilitate a systematic understanding of this attack, we introduce a model designed to delineate its propagation dynamics. Additionally, we propose an approach for forecasting its future threat potential. To assess the efficacy of the proposed propagation model and the accuracy of the method for predicting the scale of infections, we assembled a dataset comprising more than 40,342 distinct malware samples and conducted a comprehensive series of analyses. Empirical results substantiate both the effectiveness of the proposed propagation model and the precision of the approach in estimating the magnitude of potential infections. Chaochao Luo, Xinli Li, Zhuting Pan, Jian Tang 0008, Zhihong Tian 0001 |
IEEE Trans. Netw. | 1 |
| 2021 | A Novel Web Attack Detection System for Internet of Things via Ensemble ClassificationabstractInternet of Things (IoT) has become one of the fastest-growing technologies and has been broadly applied in various fields. IoT networks contain millions of devices with the capability of interacting with each other and providing functionalities that were never available to us before. These IoT networks are designed to provide friendly and intelligent operations through big data analysis of information generated or collected from an abundance of devices in real time. However, the diversity of IoT devices makes the IoT networks’ environments more complex and more vulnerable to various web attacks compared to traditional computer networks. In this article, we propose a novel ensemble deep learning based web attack detection system (EDL-WADS) to alleviate the serious issues that IoT networks faces. Specifically, we have designed three deep learning models to first detect web attacks separately. We then use an ensemble classifier to make the final decision according to the results obtained from the three deep learning models. In order to evaluate the proposed WADS, we have performed experiments on a public dataset as well as a real-word dataset running in a distributed environment. Experimental results show that the proposed system can detect web attacks accurately with low false positive and negative rates. Chaochao Luo, Zhiyuan Tan 0001, Geyong Min, Wei Shi 0001, Zhihong Tian 0001 |
IEEE Trans. Ind. Informatics | 1 |
| 2020 | A Distributed Deep Learning System for Web Attack Detection on Edge DevicesabstractWith the development of Internet of Things (IoT) and cloud technologies, numerous IoT devices and sensors transmit huge amounts of data to cloud data centers for further processing. While providing us considerable convenience, cloud-based computing and storage also bring us many security problems, such as the abuse of information collection and concentrated web servers in the cloud. Traditional intrusion detection systems and web application firewalls are becoming incompatible with the new network environment, and related systems with machine learning or deep learning are emerging. However, cloud-IoT systems increase attacks against web servers, since data centralization carries a more attractive reward. In this article, based on distributed deep learning, we propose a web attack detection system that takes advantage of analyzing URLs. The system is designed to detect web attacks and is deployed on edge devices. The cloud handles the above challenges in the paradigm of the Edge of Things. Multiple concurrent deep models are used to enhance the stability of the system and the convenience in updating. We implemented experiments on the system with two concurrent deep models and compared the system with existing systems by using several datasets. The experimental results with 99.410% in accuracy, 98.91% in true positive rate (TPR), and 99.55% in detection rate of normal requests (DRN) demonstrate the system is competitive in detecting web attacks. Zhihong Tian 0001, Chaochao Luo, Jing Qiu 0002, Xiaojiang Du, Mohsen Guizani |
IEEE Trans. Ind. Informatics | 2 |