Cong Dong

dblp:249/6036 · DBLP profile ↗
← Back
18ranked-venue papers
6as first author
14since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 4 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1
YearPublicationVenuePosition
2026 F2D: Detection of resolver DNS hijacking based on filtration funnel strategy
abstract
Abstract In recent years, DNS hijacking represents a significant security threat to the infrastructure of the Domain Name System (DNS). A prevalent form of DNS hijacking involves exploiting open resolvers to manipulate DNS records. Such attacks undermine the availability and confidentiality of network services, posing serious risks to legitimate users. Current DNS hijacking detection methods tend to focus on specific domains, leveraging the unique characteristics of domain-specific hijacking to identify attacks. Consequently, these methods are often limited in applicability and may lack accuracy when dealing with diverse hijacking scenarios. Additionally, many existing approaches face challenges related to efficiency, making them less effective for long-term monitoring of hijacking activities. To address these challenges, this paper introduces an efficient detection method F2D tailored for general DNS hijacking. First, F2D uses an accurate and efficient filtration funnel strategy for targeted resolver hijacking detection. Second, two optimized detection algorithms are proposed for comprehensive filtration. Third, the method includes an efficient mechanism for identifying CDN domains, enabling the filtration of a large number of content replication servers and enhancing overall detection efficiency. During the validation phase, we monitor around 36k domains and around 600 resolvers over a one-month period. The effectiveness of our method is validated using manually labeled sample data. Experimental results demonstrate that our method can improve the F1 performance by 10% with the same false alert level, and time efficiency by 39% compared to the state-of-the-arts. Furthermore, we conduct an in-depth analysis of the captured hijacking incidents and deduce the motivation of the hijacking.
Cong Dong, Haoran Jiao, Jiahai Yang 0001, Chenglong Li 0006, Xia Yin 0001
Cybersecur.1
2026 HINHJ: Hierarchical Attention-Based Heterogeneous Graph Neural Network for DNS Hijacking Detection
abstract
The Domain Name System (DNS) is a critical internet infrastructure that translates human-readable domain names into machine-routable IP addresses. However, DNS is inherently vulnerable to manipulation, with hijacking attacks growing in both frequency and sophistication. Existing detection methods primarily rely on traffic analysis at specific network points. However, they suffer from limited coverage and low accuracy in complex environments, such as when CDN is employed. While recent approaches employ graph-based techniques, they still suffer from detection inaccuracy issues due to their failure to account for the complex interdependencies among multiple types of nodes. To address these limitations, we propose a novel heterogeneous graph-based detection framework. Based on the collected DNS records from distributed scanners, our method extracts activity and security features and constructs a heterogeneous graph to capture resolution patterns and cross-entity relationships. We further design a time-decay graph neural network TNHAN that enhances traditional Heterogeneous Graph Attention Networks (HAN) by dynamically weighting recent records. This network improves adaptability to legitimate DNS changes. For evaluation, we conduct experiments on real-world resolvers and domain datasets. Experiment results demonstrate the effectiveness of our method. Our method can achieve an F1-score of 0.96, outperforming the best baseline by 0.057 on average, and up to 0.113 under low label proportion. Moreover, we conduct several case studies on detected incidents, including cases related to geopolitical conflicts, censorship-related hijacking, and manipulation by malicious resolvers. These cases demonstrate the method’s effectiveness in identifying diverse hijacking behaviors in practice.
Haoran Jiao, Cong Dong, Chenglong Li 0006, Jiahai Yang 0001, Leyao Nie, Changzhi Zhao, Xia Yin 0001
IEEE Trans. Inf. Forensics Secur.2
2025 Post-Standardization Analysis of DoQ: Deployment, Certificates Ecosystem and Implementation
abstract
To address the security issues caused by traditional plaintext DNS transmission, encrypted protocols were introduced to protect DNS traffic. DNS over QUIC (DoQ) is the most recent DNS encryption protocol standardized in 2022. While earlier protocols like DoT and DoH have been extensively studied, research on DoQ remains limited, focusing primarily on basic deployment and performance. There is a lack of comprehensive research on the DoQ ecosystem after its standardization, and the compliance and security of its deployment remain unclear. This paper presents the first in-depth measurement of DoQ deployment across IPv4, IPv6, and authoritative servers. Our findings offer an early view of the DoQ ecosystem, covering its deployment, certificate ecology, and practical implementations. Overall, the progress of DoQ standardization is satisfactory. Since standardization, DoQ adoption has tripled, and its certificate ecosystem shows a promising trend, with fewer than 10% of certificates being invalid. However, potential security concerns persist. First, the centralization issue in DoQ is more pronounced compared to DoH and DoT. Second, about 30% of DoQ authority servers support recursive parsing, facing the risk of cache poisoning or DDoS attacks. In addition, 2% of DoQ deployments fail to meet RFC requirements, potentially enabling amplification attacks. Therefore, we highlight the need for stricter compliance with standards in future DoQ implementations to enhance security and reliability.
Chenglong Li 0006, Wenchong Dong, Cong Dong, Jiahai Yang 0001, Hui Zhang 0052
NOMS4
2025 E-DoH: elegantly detecting the depths of open DoH service on the internet
abstract
Abstract In recent years, DoE methods have been regarded as a novel trend within the realm of the DNS ecosystem. Measuring these DoE services in the wild can promote improvements in DoE methods and facilitate their widespread adoption. A primary requirement for measuring DoE methods is the discovery of these services. The discovery is relatively straightforward for DoT and DoQ, but complex for DoH since it shares port 443 with web services as suggested in RFC 8484. Although previous works primarily analyze the surface of the DoH service, they (1) result in long detection time and large traffic volume by adopting an enumeration strategy to discover the DoH service; (2) lack an in-depth analysis of the status of upper-layer DNS services. In this paper, we propose the E-DoH method for elegant, efficient, and in-depth DoH service measurement. First, we propose a measurement mechanism to enable a single DoH connection to accomplish multiple tasks including service discovery, correctness validation, and dependency construction with minimal backend configuration. Second, we propose a dynamic protocol negotiation strategy to enhance probing efficiency while significantly reducing the required traffic volume. Based on the above optimization methods, we conducted an exploration of the IPv4 space and performed an in-depth analysis of DoH based on the collected information. Through experiments, our approach demonstrates a remarkable 80% improvement in time efficiency and only requires 4–20% traffic volume to complete the detection task. In wild detection, our approach discovered 46k DoH services, which nearly doubles the number discovered by the state-of-the-art. This indicates the growing trend of DoH services. Based on the collected information, we present several intriguing conclusions about the current DoH service ecosystem.
Cong Dong, Jiahai Yang 0001, Haoran Jiao, Chenglong Li 0006, Xia Yin 0001
Cybersecur.1
2024 ContraMTD: An Unsupervised Malicious Network Traffic Detection Method based on Contrastive Learning
abstract
Malicious traffic detection has been a focal point in the field of network security, and deep learning-based approaches are emerging as a new paradigm. However, most of them are supervised methods, which highly depend on well-labeled data, and fail to handle unknown or continuously evolving attacks. Unsupervised methods alleviate the need for labeled data, but existing methods are often limited to detecting anomalies either in vertical perspective through historical comparisons or in horizontal perspective by comparing with concurrent entities. Relying on data from a single perspective is unreliable, and it limits the model's accuracy and generalizability. In this paper, we propose a novel method ContraMTD based on contrastive learning, which comprehensively considers both vertical and horizontal perspectives. ContraMTD extracts local behavior features and global interaction features from normal network traffic by proposed SEC and DE-GAT respectively, then employs contrastive learning to learn the relationship, especially consistency between them, and finally detects malicious traffic through a multi-round scoring approach. We conduct extensive experiments on three datasets, including a self-collected dataset, and the results demonstrate that our method outperforms many state-of-the-art methods in the domain of unsupervised malicious traffic detection.
Xueying Han, Susu Cui, Bo Jiang 0013, Cong Dong, Zhigang Lu 0002, Baoxu Liu
WWW6
2024 Graph-based insider threat detection: A survey
Yiru Gong, Susu Cui, Bo Jiang 0013, Cong Dong, Zhigang Lu 0002
Comput. Networks5
2024 Unveiling encrypted traffic types through hierarchical network characteristics
Susu Cui, Cong Dong, Bo Jiang 0013, Zhigang Lu 0002
Comput. Secur.4
2024 ProcSAGE: an efficient host threat detection method based on graph representation learning
abstract
Abstract Advanced Persistent Threats (APTs) achieves internal networks penetration through multiple methods, making it difficult to detect attack clues solely through boundary defense measures. To address this challenge, some research has proposed threat detection methods based on provenance graphs, which leverage entity relationships such as processes, files, and sockets found in host audit logs. However, these methods are generally inefficient, especially when faced with massive audit logs and the computational resource-intensive nature of graph algorithms. Effectively and economically extracting APT attack clues from massive system audit logs remains a significant challenge. To tackle this problem, this paper introduces the ProcSAGE method, which detects threats based on abnormal behavior patterns, offering high accuracy, low cost, and independence from expert knowledge. ProcSAGE focuses on processes or threads in host audit logs during the graph construction phase to effectively control the scale of provenance graphs and reduce performance overhead. Additionally, in the feature extraction phase, ProcSAGE considers information about the processes or threads themselves and their neighboring nodes to accurately characterize them and enhance model accuracy. In order to verify the effectiveness of the ProcSAGE method, this study conducted a comprehensive evaluation on the StreamSpot dataset. The experimental results show that the ProcSAGE method can significantly reduce the time and memory consumption in the threat detection process while improving the accuracy, and the optimization effect becomes more significant as the data size expands.
Boyuan Xu, Yiru Gong, Xiaoyu Geng, Cong Dong, Bo Jiang 0013, Zhigang Lu 0002
Cybersecur.5
2024 MVDet: Encrypted malware traffic detection via multi-view analysis
abstract
Detecting encrypted malware traffic promptly to halt the further propagation of an attack is critical. Currently, machine learning becomes a key technique for extracting encrypted malware traffic patterns. However, due to the dynamic nature of network environments and the frequent updates of malware, current methods face the challenges of detecting unknown malware traffic in open-world environment. To address the issue, we introduce MVDet, a novel method that employs machine learning to mine the behavioral features of malware traffic based on multi-view analysis. Unlike traditional methods, MVDet innovatively characterizes the behavioral features of malware traffic at 4-tuple flows from four views: statistical view, DNS view, TLS view, and business view, which is a more stable feature representation capable of handling complex network environments and malware updates. Additionally, we achieve a short-time behavioral features construction, significantly reducing the time cost for feature extraction and malware detection. As a result, we can detect malware behavior at an early stage promptly. Our evaluation demonstrates that MVDet can detect a wide variety of known malware traffic and exhibits efficient and robust detection in both open-world and unknown malware scenarios. MVDet outperforms state-of-the-art methods in closed-world known malware detection, open-world known malware detection, and open-world unknown malware detection.
Susu Cui, Xueying Han, Cong Dong, Zhigang Lu 0002
J. Comput. Secur.3
2023 C-BEDIM and S-BEDIM: Lateral movement detection in enterprise network through behavior deviation measurement
Cong Dong, Zhi Wang 0018, Zhigang Lu 0002
Comput. Secur.1
2023 HANDOM: Heterogeneous Attention Network Model for Malicious Domain Detection
Qing Wang 0041, Cong Dong, Shijie Jian, Dan Du, Zhigang Lu 0002, Yinhao Qi, Dongxu Han, Xiaobo Ma 0001, Fei Wang 0014
Comput. Secur.2
2023 CBSeq: A Channel-Level Behavior Sequence for Encrypted Malware Traffic Detection
abstract
Machine learning and neural networks have become increasingly popular solutions for encrypted malware traffic detection. They mine and learn complex traffic patterns, enabling detection by fitting boundaries between malware traffic and benign traffic. Compared with signature-based methods, they have higher scalability and flexibility. However, affected by the frequent variants and updates of malware, current methods suffer from a high false positive rate and do not work well for unknown malware traffic detection. It remains a critical task to achieve effective malware traffic detection. In this paper, we introduce CBSeq to address the above problems. CBSeq is a method that constructs a stable traffic representation, behavior sequence, to characterize attacking intent and achieve malware traffic detection. We novelly propose the channels with similar behavior as the detection object and extract side-channel content to construct behavior sequence. Unlike benign activities, the behavior sequences of malware and its variant’s traffic exhibit solid internal correlations. Moreover, we design the MSFormer, a powerful Transformer-based multi-sequence fusion classifier. It captures the internal similarity of behavior sequence, thereby distinguishing malware traffic from benign traffic. Our evaluations demonstrate that CBSeq performs effectively in various known malware traffic detection and exhibits superior performance in unknown malware traffic detection, outperforming state-of-the-art methods.
Susu Cui, Cong Dong, Meng Shen 0001, Bo Jiang 0013, Zhigang Lu 0002
IEEE Trans. Inf. Forensics Secur.2
2022 Only Header: a reliable encrypted traffic classification framework without privacy risk
Susu Cui, Cong Dong, Zhigang Lu 0002, Dan Du
Soft Comput.3
2021 MBTree: Detecting Encryption RATs Communication Using Malicious Behavior Tree
abstract
Network trace signature matching is one reliable approach to detect active Remote Control Trojan, (RAT). Compared to statistical-based detection of malicious network traces in the face of known RATs, the signature-based method can achieve more stable performance and thus more reliability. However, with the development of encrypted technologies and disguise tricks, current methods suffer inaccurate signature descriptions and inflexible matching mechanisms. In this paper, we propose to tackle above problems by presenting MBTree, an approach to detect encryption RATs Command and Control (C&C) communication based on host-level network trace behavior. MBTree first models the RAT network behaviors as the malicious set by automatically building the multiple level tree, MLTree from distinctive network traces of each sample. Then, MBTree employs a detection algorithm to detect malicious network traces that are similar to any MLTrees in the malicious set. To illustrate the effectiveness of our proposed method, we adopt theoretical analysis of MBTree from the probability perspective. In addition, we have implemented MBTree to evaluate it on five datasets which are reorganized in a sophisticated manner for comprehensive assessment. The experimental results demonstrate the accurate and robust of MBTree, especially in the face of new emerging benign applications.
Cong Dong, Zhigang Lu 0002, Zelin Cui, Baoxu Liu, Kai Chen 0012
IEEE Trans. Inf. Forensics Secur.1
2020 Optimization of RDMA-Based HDFS Data Distribution Mechanism
Junhao Zhao, Cong Dong
NPC4
2020 CSMD: a computational subtraction-based microbiome discovery pipeline for species-level characterization of clinical metagenomic samples
abstract
MOTIVATION: Microbiome analyses of clinical samples with low microbial biomass are challenging because of the very small quantities of microbial DNA relative to the human host, ubiquitous contaminating DNA in sequencing experiments and the large and rapidly growing microbial reference databases. RESULTS: We present computational subtraction-based microbiome discovery (CSMD), a bioinformatics pipeline specifically developed to generate accurate species-level microbiome profiles for clinical samples with low microbial loads. CSMD applies strategies for the maximal elimination of host sequences with minimal loss of microbial signal and effectively detects microorganisms present in the sample with minimal false positives using a stepwise convergent solution. CSMD was benchmarked in a comparative evaluation with other classic tools on previously published well-characterized datasets. It showed higher sensitivity and specificity in host sequence removal and higher specificity in microbial identification, which led to more accurate abundance estimation. All these features are integrated into a free and easy-to-use tool. Additionally, CSMD applied to cell-free plasma DNA showed that microbial diversity within these samples is substantially broader than previously believed. AVAILABILITY AND IMPLEMENTATION: CSMD is freely available at https://github.com/liuyu8721/csmd. SUPPLEMENTARY INFORMATION: Supplementary data are available at Bioinformatics online.
Paul W. Bible, Qiaoxing Liang, Cong Dong, Xiaofeng Wen, Xiaofei Ge, Xifang Li, Xiuli Deng, Shixin Guo, Juanran Liang, Wenliang Pan, Wei Chen 0074
Bioinform.5
2020 CETAnalytics: Comprehensive effective traffic information analytics for encrypted traffic classification
Cong Dong, Zhigang Lu 0002, Baoxu Liu, Bo Jiang 0013
Comput. Networks1
2019 An Approach for Scale Suspicious Network Events Detection
abstract
Detecting the real suspicious events from a large number of low-quality alerts is a severe challenge to the security operations center teams. In this paper, we present an approach to this problem by following the sequence of machine learning steps. The highlight of our approach is the method to generate two simple but effective categories of features based on group and aggregation operations, which can scale with a large number of alerts using MapReduce framework. The two generated types of features are local features and global features. The local features cover the alert aggregation information of the same group of events, while the global features cover the network aggregation information of different groups of events. Moreover, we also introduce the model stacking mechanism to enhance the robustness of the model. The proposed approach achieves AUC scores of 0.9512 on the validating dataset and 0.9303 on the test set, which is the 2ndhighest final score in the competition.
Cong Dong, YunJian Zhang, Bo Jiang 0013, Dongxu Han, Baoxu Liu
IEEE BigData1