Diwen Xue

dblp:259/6190 · DBLP profile ↗
← Back
11ranked-venue papers
8as first author
10since 2021 · last 2025
0000-0002-0616-4765ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 5 first-author · 8 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 Fingerprinting Deep Packet Inspection Devices by their Ambiguities
abstract
Users around the world face escalating network interference such as censorship, throttling, and interception, largely driven by the commoditization and growing availability of Deep Packet Inspection (DPI) devices. Once reserved for a few well-resourced nation-state actors, the ability to interfere with traffic at scale is now within reach of nearly any network operator. Despite this proliferation, our understanding of DPIs and their deployments on the Internet remains limited---being network intermediary leaves DPI unresponsive to conventional host-based scanning tools, and DPI vendors actively obscuring their products further complicates measurement efforts.
Diwen Xue, Armin Huremagic, Wayne Wang, Ram Sundara Raman, Roya Ensafi
CCS1
2025 The Discriminative Power of Cross-layer RTTs in Fingerprinting Proxy Traffic
Diwen Xue, Robert Stanley, Roya Ensafi
NDSS1
2025 CenPush: Blocking-Resistant Control Channel Using Push Notifications
abstract
The rapid increase in global censorship events has stimulated a substantial growth in users relying on circumvention tools. Fighting against censors requires tool maintainers to frequently update client-side configurations and proxy IPs. However, existing methods for doing so require clients to explicitly query for updates. Further, this client-initiated communication relies mostly on ad-hoc and out-of-band channels. This work demonstrates the utility of push notification services as an efficient and sustainable communication channel between tool maintainers and their clients. A push notification channel allows tool maintainers to update client configurations automatically without the need for clients to initiate a query themselves. We develop a general-purpose design for integrating push notifications as a control channel in circumvention tools. We utilize the design to integrate and implement push notifications for use in the popular circumvention tool Tor and demonstrate their utility to push bridge line updates to Tor clients.
Piyush Kumar Sharma, Diwen Xue, Aaron Ortwein, Cecylia Bocovich, Harry, Roya Ensafi
Proc. Priv. Enhancing Technol.2
2024 Fingerprinting Obfuscated Proxy Traffic with Encapsulated TLS Handshakes
Diwen Xue, Michael G. Kallitsis, Amir Houmansadr, Roya Ensafi
USENIX Security Symposium1
2024 Bridging Barriers: A Survey of Challenges and Priorities in the Censorship Circumvention Landscape
Diwen Xue, Anna Ablove, Reethika Ramesh, Grace Kwak Danciu, Roya Ensafi
USENIX Security Symposium1
2024 Attacking Connection Tracking Frameworks as used by Virtual Private Networks
abstract
VPNs (Virtual Private Networks) have become an essential privacy-enhancing technology, particularly for at-risk users like dissidents, journalists, NGOs, and others vulnerable to targeted threats. While previous research investigating VPN security has focused on cryptographic strength or traffic leakages, there remains a gap in understanding how lower-level primitives fundamental to VPN operations, like connection tracking, might undermine the security and privacy that VPNs are intended to provide. In this paper, we examine the connection tracking frameworks used in common operating systems, identifying a novel exploit primitive that we refer to as the port shadow. We use the port shadow to build four attacks against VPNs that allow an attacker to intercept and redirect encrypted traffic, de-anonymize a VPN peer, or even portscan a VPN peer behind the VPN server. We build a formal model of modern connection tracking frameworks and identify that the root cause of the port shadow lies in five shared, limited resources. Through bounded model checking, we propose and verify six mitigations in terms of enforcing process isolation. We hope our work leads to more attention on the security aspects of lower-level systems and the implications of integrating them into security-critical applications.
Benjamin Mixon-Baca, Jeffrey Knockel, Diwen Xue, Tarun Ayyagari, Deepak Kapur, Roya Ensafi, Jedidiah R. Crandall
Proc. Priv. Enhancing Technol.3
2022 TSPU: Russia's decentralized censorship system
abstract
Russia's Sovereign RuNet was designed to build a Russian national firewall. Previous anecdotes and isolated events in the past two years reflected centrally coordinated censorship behaviors across multiple ISPs, suggesting the deployment of "special equipment" in networks, colloquially known as "TSPU". Despite the TSPU comprising a critical part of the technical stack of RuNet, very little is known about its design, its capabilities, or the extent of its deployment.
Diwen Xue, Benjamin Mixon-Baca, ValdikSS, Anna Ablove, Beau Kujath, Jedidiah R. Crandall, Roya Ensafi
IMC1
2022 VPNInspector: Systematic Investigation of the VPN Ecosystem
Reethika Ramesh, Leonid Evdokimov, Diwen Xue, Roya Ensafi
NDSS3
2022 OpenVPN is Open to VPN Fingerprinting
Diwen Xue, Reethika Ramesh, Arham Jain, Michael G. Kallitsis, J. Alex Halderman, Jedidiah R. Crandall, Roya Ensafi
USENIX Security Symposium1
2021 Throttling Twitter: an emerging censorship technique in Russia
abstract
In March 2021, the Russian government started to throttle Twitter on a national level, marking the first ever use of large-scale, targeted throttling for censorship purposes. The slowdown was intended to pressure Twitter to comply with content removal requests from the Russian government.
Diwen Xue, Reethika Ramesh, Valdik S. S, Leonid Evdokimov, Andrey Viktorov, Arham Jain, Eric Wustrow, Simone Basso, Roya Ensafi
Internet Measurement Conference1
2019 Implementing a Domain-Independent Framework to Detect Suspicious Review Patterns
abstract
Nowadays detecting opinion spam has attracted a lot of attention. Different approaches have been taken to tackle this problem. However, most of these approaches are neither domain-independent nor scalable. In this paper, we focus on the similar but more general problem on how to detect abnormal patterns in reviews. These abnormal patterns can indicate potential spam activities. We will implement a scalable, domain-independent framework with the help of the Hadoop ecosystem tools. We will extract certain relationships between different fields in our data and the rating that a review gave a product or service, and in turn determine how “abnormal” these relationships are based on statistics acquired from the entire dataset. We applied this technique to three datasets in different domains and found such abnormal patterns, which indicate potential spammers and/or spam activities.
Diwen Xue, Willie Yee, Yueping Wang, Suzanne McIntosh
IEEE BigData1