Xuanbo Huang

dblp:286/8388 · DBLP profile ↗
← Back
17ranked-venue papers
5as first author
16since 2021 · last 2026
0009-0006-3817-5756ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 10 · 2 first-author · 9 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 BLAS: A Blockchain-Enabled Efficient and Verifiable Log Audit System With Hybrid Storage
abstract
A reliable log audit system is a fundamental tool for efficient security management and attack detection. Blockchain has emerged as a prominent technology for building log audit systems, thanks to its non-repudiation and immutability properties. However, current blockchain-based solutions are computationally intensive and typically rely on coarse-grained queries, making them impractical for real-world systems. Therefore, we propose a blockchain-based verifiable log audit system, BLAS, which adopts three novel techniques. Firstly, we propose a novel data structure called the Index-Object Merkle Forest (IOMF), which combines modified Merkle Tree data structures and keyword-range bitmap indexes to support efficient log auditing. Secondly, we propose a hierarchical extension of IOMF to create an Authenticated Layered Index Structure (ALIS). ALIS enables fine-grained auditing at the entry level. Finally, we propose two optimization techniques in ALIS to reduce computational and communication costs. The performance evaluation confirms that BLAS is consistently faster than the baseline solutions with similar settings in various experiments, achieving speedups of hundreds to over ten thousand times for the most challenging workloads.
Xuanbo Huang, Mingrui Ai, Kaiping Xue, Yingjie Xue, Hyundong Shin
IEEE Trans. Dependable Secur. Comput.1
2025 Seeing Through NAT: A Frequency Domain Approach to Enterprise Device Detection via Adaptive Fingerprint Fusion
abstract
Network asset auditing constitutes a systematic assessment of organizational IT infrastructures, encompassing comprehensive identification of active hosts, operating systems, and service configurations. This foundational process plays a pivotal role in discovering and managing potential vulnerabilities that adversaries may exploit. While various existing network scanning tools (e.g., Nmap, Masscan, ZMap) provide elementary auditing capabilities, their efficacy is fundamentally constrained in detecting devices/services concealed behind Network Address Translation (NAT) gateways. To address this critical limitation, we propose DMIF (Detection framework based on Multiple Inherent Fingerprints), which introduces two methodological innovations: (1) a frequency domain analytical approach for extracting inherent traffic characteristics, and (2) an adaptive multi-fingerprint aggregation mechanism. Our DMIF builds upon the key observation that different hosts and different operating systems exhibit distinctive traffic fingerprints stemming from their hardware architectures and protocol implementations. The framework’s feature extraction module employs spectral analysis to capture these device-specific patterns, while the fingerprint aggregation module dynamically optimizes weight assignments across multiple fingerprint dimensions through machine learning techniques. We evaluate DMIF in two scenarios and consider the effects of network fluctuations and user behaviors. Experimental results demonstrate that DMIF’s detection F1 score exceeds 0.91 for a wide range of device types, including personal computers, mobile phones, and IoT devices.
Dengfeng Fu, Lutong Chen, Xuanbo Huang, Zixu Huang, Kaiping Xue
GLOBECOM4
2025 A Shared Infrastructure Verification Framework with Transient Perturbation Probing for SDN Topology Poisoning Defense
Xuanbo Huang, Lutong Chen, Zixu Huang, Kaiping Xue
GLOBECOM2
2025 Unveiling Stealthy DGA Traffic: A Hybrid Threshold-Behavior Analysis Framework for Detecting Botnet Domains
abstract
In recent years, most botnets have utilized Domain Generation Algorithms (DGAs) to dynamically generate domains to establish communication with Command and Control (C&C) servers, enabling malicious activities. However, recent research mainly proposes methods based on labeled DGA domain datasets that already yield high detection rates, but cannot be applied directly to realistic network environments. In this paper, we propose a novel hybrid threshold-behavior analysis system that examines and processes network traffic in several layers to detect DGA domains precisely. Our system incorporates a multi-level filtering approach that dramatically increases the precision of domain identification. At the system’s center lies its innovative hybrid threshold-behavior analysis framework, which employs a cascaded filtering process to enhance malicious domain identification while efficiently preserving computational resources. To address the issue of separating highly random DGA domains from their legitimate ones, we utilize adaptive thresholding combined with contextual analysis of domain query patterns to enable stealthy DGA domain detection. We test on realistic network traffic datasets to verify the performance of our system. The experiments show that our system has a 97.88% recall rate for labeled DGA domains and can correctly identify a huge number of previously unlabeled DGA domains, demonstrating its effectiveness and feasibility.
Jiankang Sun, Lutong Chen, Xuanbo Huang, Xuanchao Xie, Zixu Huang, Kaiping Xue
GLOBECOM3
2025 Fuzzydetect: Sliding Window-Driven Fuzzy Hashing with SVM Classification for Resilient Web Fuzzing Attack Detection
abstract
With the continuous evolution of web application attack techniques, attackers have widely adopted fuzzing-based penetration testing. However, traditional rule-based feature-matching detection mechanisms and machine learning-based detection systems face challenges including ineffective malicious traffic with local mutations, complex and time-consuming model training, and excessive server load. This paper introduces Fuzzydetect, a novel detection framework for identifying malicious HTTP fuzzing traffic. It applies a sliding window mechanism to segment network traffic and uses fuzzy hashing to capture similarity patterns in consecutive packets and compute similarity scores, utilizing Support Vector Machine (SVM) to distinguish malicious activity from benign traffic. We conduct comprehensive experiments using mainstream datasets to evaluate our system with existing solutions. Experimental results demonstrate that the proposed system achieves a True Positive Rate of 99.64%, accuracy of 98.2%, and F1-score of 0.9867, with a faster processing speed that satisfies real-time detection requirements.
Xuanbo Huang, Lutong Chen, Zixuan Huang 0006, Kaiping Xue
GLOBECOM2
2025 A NAT Network Host Probing Method Through NTP Traffic Analysis
abstract
Network probing serves as a potent technique in network security protection, enabling the effective identification of dangerous devices and potential threats. This paper focuses on network probing against Network Address Translation (NAT) hidden networks, especially for campus or public networks. However, it is noted that the traditional active probing techniques usually need to inject probes into the network, posing a challenge in public network scenarios. Moreover, current passive techniques cannot achieve high accuracy, low computational resources, and real-time requirements simultaneously. To this end, we design a host probing system named Hostprober for NAT networks based on Network Time Protocol (NTP) traffic analysis. Leveraging the widely used and featured NTP traffic, the Hostprober can identify the NTP traffic fingerprints by normalizing polling intervals and dynamically adjusting the time window. Based on the captured fingerprints, the Hostprober can reorganize the NTP traffic into traffic sets corresponding to different hosts, and match the NTP traffic to the models to achieve the purpose of host detection and network probing. Furthermore, we evaluate our proposed internal network probing method in both a controlled virtual environment and a real network environment, comparing it with other baselines. The evaluation results show that our approach demonstrates good accuracy and outperforms other comparison methods.
Dengfeng Fu, Lutong Chen, Xuanbo Huang, Huanjie Zhang, Kaiping Xue
ICC4
2025 User Behavior-Based Dynamic Authentication Design for Enhanced Identity Security
abstract
Multi-factor authentication (MFA) has become an essential method for enhancing security in authentication procedures by leveraging multi-dimensional authentication anchors, such as Biometrics-Based Authentication and One-time Password (OTP). However, MFA usually triggers for each login attempt and significantly impacts user usability. To this end, Risk-Based Authentication (RBA) is developed to achieve a better balance between user usability and security by dynamically checking the user authentication information. Opposite to the previous RBA designs that leverage static rules, this paper introduces Dynamic User Behavior Authentication (DUBA), an enhanced RBA design proposed to further improve both security and user experience. Our design uses probabilistic statistical methods to evaluate and score user behaviors. In this, authentication procedures can be dynamically adjusted in response to real-time user patterns and potential threats. Besides, DUBA introduces the weight adjust scheme that can efficiently defend against malicious behavior while improving usability, utilizing multi-dimensional behavioral data, such as login frequency, device information, and geographic location. We implement DUBA and evaluate its effectiveness by integrating it into the actual Single Sign-On (SSO) system in use on our campus. The results show that DUBA significantly reduces false positives and strengthens defenses against identity impersonation attacks.
Jianbin Zeng, Lutong Chen, Xuanbo Huang, Zhonghui Li, Kaiping Xue
ICC5
2025 Boosting Malicious Traffic Detection Accuracy with Stacked Feature Fusion and Attention Mechanism
abstract
Malicious traffic detection has gained increasing importance in network security research due to its potential for detecting network attacks in real time. Currently, malicious traffic detection methods primarily rely on either a single feature or a single model architecture. This limitation often leads to high false positive rates when deployed in complex open environments and constrains their capability to handle diverse types of malicious traffic effectively. To address these challenges, in this paper, we propose a novel hybrid model that leverages feature fusion and attention mechanisms to enhance the accuracy of malicious traffic detection. Specifically, we first employ both Decision Tree (DT) and Random Forest (RF) models to extract traffic features. Their predictions are then fused using a stacking method to enrich the feature representation. Subsequently, a Multilayer Perceptron (MLP) is introduced as the meta-learner, with a self-attention mechanism incorporated into its hidden layer to dynamically optimize feature weight allocation, thereby enabling the model to focus more accurately on key traffic features. Extensive experiments were conducted using the CICIDS2017 and CICIDS2018 datasets. The experimental results demonstrate that our proposed model, which combines feature fusion and attention mechanisms, achieves significantly superior detection performance compared to traditional singlemodel approaches, particularly in terms of precision, recall, and F1-score.
Menghui Wu, Xuanbo Huang, Zhongxiang Cai, Lutong Chen, Kaiping Xue
ICPADS2
2025 Defending Against Link-Flooding Attacks With Adversary Interest Prediction and Grouped Online Load Balancing
abstract
A Link Flooding Attack (LFA) is a type of link-aimed Distributed Denial of Service (DDoS) attack that can overwhelm the Internet critical links to cut off connections with lots of low-rate, seemingly benign traffic. To defend against such threats, a promising solution involves mitigating the attack through load balancing. However, adaptive attacks employ two effective means to circumvent existing load balancing strategies. The first is the frequent changing of targets, known as rolling attacks. Rolling attacks exploit the delay between attack detection feedback and the mitigation of load balancing, depleting the defender’s resources. The second is the strategical selection of target links to create the worst-case scenario for load balancing algorithms. To address these challenges, we propose LinkDam. Specifically, LinkDam adopts a proactive approach by tracking and predicting potential victim links, providing defense against all targets of rolling attacks. Subsequently, we introduce a robust load balancing strategy to prevent the exploitation of selected link combinations. Additionally, LinkDam introduces a partial deployment approach, demanding a mere 40% of nodes be programmable (i.e., SDN nodes) while maintaining an acceptable 10% performance reduction from the maximum achievable. The experimental results indicate that LinkDam surpasses an 80% accuracy threshold, and exhibits a 57% higher tolerance to attack budgets compared to state-of-the-art solutions.
Zixu Huang, Xuanbo Huang, Kaiping Xue, Jiangping Han, Lutong Chen, Qibin Sun, Jun Lu 0001
IEEE Trans. Netw.2
2025 SpiderNet: Enabling Bot Identification in Network Topology Obfuscation Against Link Flooding Attacks
abstract
Link-flooding attacks (LFAs) pose a significant challenge to Internet availability by attacking critical network links with high volumes of seemingly legitimate traffic. In response, researchers have developed network topology obfuscation (NTO) to safeguard critical links. However, state-of-the-art NTO defenses are coarse-grained, leading to less efficient security and usability. In addition, once under attack, NTO schemes cannot identify the attacker’s bot and launch counter-defensive measures. To address these issues, this paper introduces SpiderNet, which employs advanced obfuscation techniques to secure critical links while using strategically created honeypot links for effective bot identification. When adversaries probe the network, SpiderNet captures their probing behavior and deliberately feeds back misinformation about honeypot links. By analyzing the attack patterns directed at these decoy targets, SpiderNet correlates them with adversarial probing activities to effectively identify the bots. Our experiments demonstrate that SpiderNet is more robust than state-of-the-art NTO schemes in terms of security and usability, while also being capable of identifying LFA bots.
Xuanbo Huang, Kaiping Xue, Zixu Huang, Jiangping Han, Lutong Chen, David S. L. Wei, Qibin Sun, Jun Lu 0001
IEEE Trans. Netw.1
2024 You Can Obfuscate, but You Cannot Hide: CrossPoint Attacks against Network Topology Obfuscation
Xuanbo Huang, Kaiping Xue, Lutong Chen, Mingrui Ai, Huancheng Zhou, Bo Luo, Guofei Gu, Qibin Sun
USENIX Security Symposium1
2024 FakeBehalf: Imperceptible Email Spoofing Attacks against the Delegation Mechanism in Email Systems
Jinrui Ma, Lutong Chen, Kaiping Xue, Bo Luo, Xuanbo Huang, Mingrui Ai, Huanjie Zhang, David S. L. Wei
USENIX Security Symposium5
2023 PLR: An In-Network Proactive Loss Recovery Scheme for Named Data Networking
abstract
With potential advantages over TCP/IP for content delivery, mobility, and security, Named Data Networking (NDN) has become a promising architecture for the next-generation network. However, its poor performance in reliable transmission is still an unsolved problem. Many existing schemes in NDN employ inaccurate retransmission timeouts calculated with RTTs from diverse content sources to detect packet loss, which is lagging and may deteriorate transmission performance. Besides, after identifying the loss, the consumer costly resends the request to recover it, further increasing recovery time. In this paper, we propose an in-network Proactive Loss Recovery (PLR) scheme, which provides an efficient in-network method for timely detection and proactive recovery of lost packets. Deployed on each router, PLR detects the loss by monitoring queue status and sends high-priority explicit feedback to notify consumers of loss events timely. Meanwhile, lost packets are stored in each router's cache and will be retransmitted at an adaptive rate based on the detected remaining bandwidth. The simulation shows that PLR can vastly reduce the number of retransmissions on consumers, and the content completion time can be decreased by up to 21.8% compared with the baseline.
Xuanbo Huang, Jiangping Han, Bobo Wang, Jian Li 0031, Kaiping Xue
ICCCN3
2022 LLDM: Low-Latency DoS Attack Detection and Mitigation in SDN
abstract
Software-Defined Networking (SDN) is a new and highly flexible network architecture, but the bottleneck between the control plane and the data plane makes it vulnerable to the control plane saturation DoS attacks. When the attack happens, traditional schemes in DoS scrubbing agent use a binary classification and a First In First Out (FIFO) queue to filter attack flows. However, this scheme is inimical to the end-to-end latency of benign traffic. To tackle this issue, we propose LLDM, leveraging a dynamic priority scheme and a priority queue to detect, mitigate the attacks while ensuring low latency for benign traffic. After detecting the attack, LLDM leverages a two-phase scheme for mitigation. First, LLDM marks packets from the ports under attack as suspicious and migrates them to the mitigation agent. Then, the dynamic priority manager assigns each packet a priority corresponding to its legality, which is used in the priority queue for DoS scrubbing. We evaluate LLDM in a simulation SDN environment. The experimental results show that LLDM can reduce 90.4% of the queuing delay compared with the traditional scheme under a 5000 Packets Per Second (PPS) attack, and it is also resistant to more sophisticated attacks. Under the high rate attack of 50000 PPS, LLDM installs a flow rule for legitimate traffic in 0.2 seconds. Moreover, for benign HTTP requests, LLDM can keep the request time at 1.39 seconds.
Zixu Huang, Xuanbo Huang, Jian Li 0031, Kaiping Xue, Qibin Sun, Jun Lu 0001
HPSR2
2022 A Dynamic Flow Table Management Method Based on Real-time Traffic Monitoring
abstract
In Software-Defined Networking (SDN), the controllers implement flexible and scalability networking policies by installing different flow rules. Each rule matches a specific class of flows, instructs the switches to execute actions, and then expires when they finish their tasks. OpenFlow introduces the timeout mechanism to manage these flow rules. However, finding a reasonable timeout value becomes a difficult problem for the network managers. When a relatively small timeout value is given to an elephant flow, the rule expires early, introducing extra cost for the controller and long latency for the matching flow, respectively. On the contrary, a large timeout value for a mice flow makes a rule occupy the switch memory too long, wasting the caching memory and causing the flow table prone to overflow. Therefore, it is necessary to allocate appropriate timeouts for different flows dynamically. In this paper, we achieve this goal with real-time traffic monitoring and heuristic algorithms. By considering different network loads and designing corresponding dynamic timeout algorithms for different scenarios, we make full use of the advantages of SDN to improve the utilization rate of the switch memory and save the controller resources. Further, we implement our scheme in a simulation SDN platform and evaluate the algorithms with the public datasets. Experiments show that our scheme has low control overhead and is memory efficient compared with current mechanisms.
Xuanbo Huang, Jian Li 0031, Kaiping Xue, Qibin Sun, Jun Lu 0001
HPSR2
2022 An Efficient Scheme to Defend Data-to-Control-Plane Saturation Attacks in Software-Defined Networking
Xuanbo Huang, Kaiping Xue, Yitao Xing, Dingwen Hu, Ruidong Li 0001, Qibin Sun
J. Comput. Sci. Technol.1
2020 FSDM: Fast Recovery Saturation Attack Detection and Mitigation Framework in SDN
abstract
The whole Software-Defined Networking (SDN) system might be out of service when the control plane is overloaded by control plane saturation attacks. In this attack, a malicious host can manipulate massive table-miss packets to exhaust the control plane resources. Even though many studies have focused on this problem, systems still suffer from more influenced switches because of centralized mitigation policies, and long recovery delay because of the remaining attack flows. To solve these problems, we propose FSDM, a Fast recovery Saturation attack Detection and Mitigation framework. For detection, FSDM extracts the distribution of Control Channel Occupation Rate (CCOR) to detect the attack and locates the port that attackers come from. For mitigation, with the attacker's location and distributed Mitigation Agents, FSDM adopts different policies to migrate or block attack flows, which influences fewer switches and protects the control plane from resource exhaustion. Besides, to reduce the system recovery delay, FSDM equips a novel functional module called Force_Checking, which enables the whole system to quickly clean up the remaining attack flows and recovery faster. Finally, we conducted extensive experiments, which show that, with the increasing of attack PPS (Packets Per Second), FSDM only suffers a minor recovery delay increase. Compared with traditional methods without cleaning up remaining flows, FSDM saves more than 81% of ping RTT under attack rate ranged from 1000 to 4000 PPS, and successfully reduced the delay of 87% of HTTP requests time under large attack rate ranged from 5000 to 30000 PPS.
Xuanbo Huang, Kaiping Xue, Yitao Xing, Dingwen Hu, Ruidong Li 0001, Qibin Sun
MASS1