EDBT 2026 Demo / reviewers in the wild / expert
Chenkai Wang 0001
dblp:319/0898-1
· DBLP profile ↗
6ranked-venue papers
2as first author
6since 2021 · last 2025
0009-0003-4036-2321ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Towards Continuous Integrity Attestation and Its Challenges in Practice: A Case Study of KeylimeabstractContinuous integrity attestation is vital for cloud providers to ensure the integrity of remote systems in a continuous manner. Current solutions, such as Keylime, rely on Trusted Platform Module (TPM) and Linux’s Integrity Measurement Architecture (IMA) but often struggle to balance minimizing false alerts and maintaining effective threat detection. In this paper, we examine common causes of attestation failures in Keylime through active experiments. We find that false positives often stem from unscheduled OS updates, and we propose a dynamic policy generation scheme as a solution (validated over 66 days of experiments). Our false negative experiments reveal vulnerabilities in existing designs, including five common issues across Keylime and IMA. Exploiting these issues, attackers could evade detection in all tested scenarios. Our findings offer insights into common failures of continuous integrity attestation, and our proposed solution is being integrated into Keylime with community support, enhancing cloud security. Our code will be available at https://github.com/mruffin/Dynamic-Policy-Generator. Margie Ruffin, Chenkai Wang 0001, Gheorghe Almási 0001, Abdulhamid Adebayo, Hubertus Franke, Gang Wang 0011 |
DSN | 2 |
| 2025 | Can You Walk Me Through It? Explainable SMS Phishing Detection using LLM-based Agents
Haoyu Zhai, Chenkai Wang 0001, Qingying Hao, Nick A. Cohen, Roopa Foulger, Jonathan A. Handler, Gang Wang 0011 |
SOUPS | 3 |
| 2025 | Email Spoofing with SMTP Smuggling: How the Shared Email Infrastructures Magnify this Vulnerability
Chuhan Wang 0001, Chenkai Wang 0001, Songyi Yang, Sophia Liu, Jianjun Chen 0005, Hai-Xin Duan, Gang Wang 0011 |
USENIX Security Symposium | 2 |
| 2024 | VeriSMS: A Message Verification System for Inclusive Patient Outreach against Phishing AttacksabstractPatient outreach enables timely communication between patients and healthcare providers but is vulnerable to phishing/spoofing attacks. In this paper, we work with a U.S.-based healthcare provider to design an inclusive method to address this threat. We present VeriSMS which allows patients to call a voice agent to verify whether the received (sensitive) messages are indeed sent by their healthcare provider. We design the system to be inclusive: it is accessible to patients who only have access to SMS and phone call capabilities. We perform a two-part user study to refine the system design (N=15) and confirm users can correctly understand the system and use it to identify spoofed/phishing messages (N=35). A key insight from our study is to not exclusively optimize for strong security but to tailor the designs based on user habits. Our result confirms the effectiveness and usability of VeriSMS and its ability to significantly increase adversaries’ costs. Chenkai Wang 0001, Zhuofan Jia, Hadjer Benkraouda, Cody Zevnik, Nicholas Heuermann, Roopa Foulger, Jonathan A. Handler, Gang Wang 0011 |
CHI | 1 |
| 2024 | True Attacks, Attack Attempts, or Benign Triggers? An Empirical Measurement of Network Alerts in a Security Operations Center
Zhi Chen 0028, Chenkai Wang 0001, Zhenning Zhang, Sushruth Booma, Phuong Cao, Constantin Adam, Alexander Withers, Zbigniew T. Kalbarczyk, Ravishankar K. Iyer, Gang Wang 0011 |
USENIX Security Symposium | 3 |
| 2022 | Revisiting Email Forwarding Security under the Authenticated Received Chain ProtocolabstractEmail authentication protocols such as SPF, DKIM, and DMARC are used to detect spoofing attacks, but they face key challenges when handling email forwarding scenarios. Recently in 2019, a new Authenticated Received Chain (ARC) protocol was introduced to support mail forwarding applications to preserve the authentication records. After 2 years, it is still not well understood how ARC is implemented, deployed, and configured in practice. In this paper, we perform an empirical analysis on ARC usage and examine how it affects spoofing detection decisions on popular email provides that support ARC. After analyzing an email dataset of 600K messages, we show that ARC is not yet widely adopted, but it starts to attract adoption from major email providers (e.g., Gmail, Outlook). Our controlled experiment shows that most email providers’ ARC implementations are done correctly. However, some email providers (Zoho) have misinterpreted the meaning of ARC results, which can be exploited by spoofing attacks. Finally, we empirically investigate forwarding-based “Hide My Email” services offered by iOS 15 and Firefox, and show their implementations break ARC and can be leveraged by attackers to launch more successful spoofing attacks against otherwise well-configured email receivers (e.g., Gmail). Chenkai Wang 0001, Gang Wang 0011 |
WWW | 1 |