Dongbin Wang

dblp:53/5185 · DBLP profile ↗
← Back
14ranked-venue papers
1as first author
6since 2021 · last 2026
0000-0002-8290-1376ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 2 since 2021Security and privacy · 4 · 4 since 2021Human-computer interaction and ubiquitous computing · 3Systems, architecture and hardware · 2Databases, data management, data science and information retrieval · 1 · 1 first-author
YearPublicationVenuePosition
2026 DoSMitigation: Mitigating DoS Attacks in Software Defined Networking
Dongzhe Wu, Dongbin Wang, Dongchao Zhou, Yongfeng Tan, Zhuowei Shen
ICC2
2026 From Obfuscated to Obvious: A Comprehensive JavaScript Deobfuscation Tool for Security Analysis
Dongchao Zhou, Lingyun Ying, Huajun Chai, Dongbin Wang
NDSS4
2024 CPCED: a container escape detection system based on CNI plugin
abstract
Container escape detection is a critical research topic in the field of cloud security. Among the challenges faced in modern cloud security, the issue of container escape poses a significant threat due to its direct impact on the security of the host machine. Although recent research has proposed various methods to address such issue, they have shortcomings in terms of real-time capabilities and deployment in multinode environments. Meanwhile, container network interface (CNI) plugins provide network functionality for container management systems such as Kubernetes, offering ease of use and scalability. Therefore, we propose CPCED, a real-time container escape detection system running on a generic CNI plugin, and implement the prototype. The system defines the container namespace event that is used to detect insecure interactions by monitoring its changes in the permissions of the process namespace. To detect the events, an algorithm is proposed to extract suspicious process paths and command context in Kubernetes and Docker environments. The experimental results show that this system detects nine container escape vulnerabilities successfully. Compared to PACED, one of the real-time container escape attack detection systems, the memory usage of CPCED is reduced by 7.6% on average, and the average detection time of single vulnerability is 18.6% of PACED’s.
Dongbin Wang
TrustCom3
2024 A Revocable Pairing-Free Certificateless Signature Scheme Based on RSA Accumulator
abstract
Certificateless public key cryptography (CL-PKC) has garnered significant attention in recent years due to its ability to address the complex certificate management requirements inherent in public key infrastructure (PKI) systems and the key escrow issue associated with identity-based cryptography (IBC). However, the efficient revocation of illegitimate users in authentication schemes based on CL-PKC remains a challenge. Moreover, certain schemes still exhibit security vulnerabilities, such as susceptibility to key replacement attacks, and also require performance enhancements. In this article, we propose a novel certificateless signature scheme that incorporates the RSA accumulator. By leveraging the witness in the RSA accumulator to produce the public keys of users, the authenticity of the public key can be efficiently verified, thereby eliminating key replacement attacks. Additionally, by removing specific elements from the RSA accumulator and broadcasting the update credential to legitimate users via a public channel, our proposed scheme allows the effective revocation of malicious users. Security analysis and performance evaluations indicate that our scheme provides comprehensive security and achieves high performance in terms of computational and communication costs in both signingverification and revocation processes.
Zhuowei Shen, Xiao Kou, Taiyao Yang, Haoqin Xu, Dongbin Wang, Shaobo Niu
TrustCom5
2023 Evicting and filling attack for linking multiple network addresses of Bitcoin nodes
abstract
Abstract Bitcoin is a decentralized P2P cryptocurrency. It supports users to use pseudonyms instead of network addresses to send and receive transactions at the data layer, hiding users’ real network identities. Traditional transaction tracing attack cuts through the network layer to directly associate each transaction with the network address that issued it, thus revealing the sender’s network identity. But this attack can be mitigated by Bitcoin’s network layer privacy protections. Since Bitcoin protects the unlinkability of Bitcoin addresses and there may be a many-to-one relationship between addresses and nodes, transactions sent from the same node via different addresses are seen as coming from different nodes because attackers can only use addresses as node identifiers. In this paper, we proposed the evicting and filling attack to expose the correlations between addresses and cluster transactions sent from different addresses of the same node. The attack exploited the unisolation of Bitcoin’s incoming connection processing mechanism. In particular, an attacker can utilize the shared connection pool and deterministic connection eviction strategy to infer the correlation between incoming and evicting connections, as well as the correlation between releasing and filling connections. Based on inferred results, different addresses of the same node with these connections can be linked together, whether they are of the same or different network types. We designed a multi-step attack procedure, and set reasonable attack parameters through analyzing the factors that affect the attack efficiency and accuracy. We mounted this attack on both our self-run nodes and multi-address nodes in real Bitcoin network, achieving an average accuracy of 96.9% and 82%, respectively. Furthermore, we found that the attack is also applicable to Zcash, Litecoin, Dogecoin, Bitcoin Cash, and Dash. We analyzed the cost of network-wide attacks, the application scenario, and proposed countermeasures of this attack.
Huashuang Yang, Jinqiao Shi, Yue Gao 0003, Ruisheng Shi, Dongbin Wang
Cybersecur.7
2022 Privacy-preserving Trajectory Generation Algorithm Considering Utility based on Semantic Similarity Awareness
abstract
Location-based service recommendations usually need to collect and analyze the location information of trajectories generated by users with smart phones or wearable devices. It is easy to cause the location privacy leaks. The current location privacy protection methods usually confuse the adversary by adding fake locations into real trajectories to achieve the goal of privacy protection. However, these methods fail to consider the utility of user trajectories in service recommendations. In this paper, we propose a privacy-preserving trajectory generation algorithm based on service semantic similarity. To improve the utility of privacy-preserving trajectories for service recommendations, the algorithm constructs a series of service semantic grid maps and generates fake individuals with privacy-preserving trajectories considering both utility and privacy. Simulation results show that the proposed algorithm can effectively hide the locations in real trajectories of individuals and obtain higher effectiveness for service recommendations.
Kun Guo 0007, Dongbin Wang, Yibo Gao, Yueming Lu
ICC2
2019 Towards Multi-Controller Placement for SDN Based on Density Peaks Clustering
abstract
As a novel network architecture, softwaredefined networking (SDN) decouples control and data planes, which brings a lot of flexibility to the network. But the separation arises some problems, such as controller placement problem(CPP). Controller placement problem is an important task especially in wide area networks, which would directly affect latency and performance of entire network. In this paper, we propose a method based on modified density peaks clustering(MDPC) algorithm to solve controller placement problem, aiming to minimize the average propagation latency between switches and controllers. The entire network is divided into several sub-networks, each of sub-networks is managed by a controller. We conduct the experiments on the Internet2 OS3E topology to evaluate the performance of our method. The experimental results show that our controller placement strategy can significantly reduce latency. Specifically, the average latency can be reduced by 35% compared to K-means and 10% compared to optimized Kmeans.
Yuezhen Qi, Dongbin Wang, Wenbin Yao, Yuhua Cao
ICC2
2017 Ranking the Influence of Micro-blog Users Based on Activation Forwarding Relationship
Yiwei Yang 0005, Wenbin Yao, Dongbin Wang
CollaborateCom3
2017 UR Rank: Micro-blog User Influence Ranking Algorithm Based on User Relationship
Wenbin Yao, Yiwei Yang 0005, Dongbin Wang
CollaborateCom3
2017 Cloud Multimedia Files Assured Deletion Based on Bit Stream Transformation with Chaos Sequence
Wenbin Yao, Dongbin Wang
ICA3PP3
2017 A Virtual Machine Migration Algorithm Based on Group Selection in Cloud Data Center
Wenbin Yao, Dongbin Wang
NPC3
2016 An Effective Buffer Management Policy for Opportunistic Networks
Wenbin Yao, Ming Zong, Dongbin Wang
CollaborateCom4
2016 An Optimal Controller Design for CPS with Stochastic Time Delay
abstract
Since Cyber-Physical System (CPS) is defined as integrations of computation, communication and control to physical processes, the communication plays an important role in such system. Compared with the traditional control system, the control in CPS is very difficult because the communication networks inevitably introduce variable time delays and possible lost of samples. In Networked Control System (NCS), there are some related works to discuss the problem of time delay. However it still needs to evaluate and improve those existing schemes in CPS. In this paper, a novel dynamic timeout scheme and actuator compensation by using a hidden Markov model for the time delay to reduce the influence of random time delays has been proposed. Simulation results on TrueTime 2.0 demonstrate the feasibility and effectiveness of this networked real-time control strategy.
Leilei Lou, Dongbin Wang
MSN3
2008 A Survey of Secure Routing in Ad Hoc Networks
abstract
Mobile ad hoc network (MANET) is a self-configuring network that is formed automatically via wireless links by a collection of mobile nodes without the help of a fixed infrastructure or centralized management. The mobile nodes forward packets for each other, allowing communication among nodes outside wireless transmission range hop by hop. Due to dynamic infrastructure-less nature and lack of centralized monitoring points, the ad hoc networks are vulnerable to attacks. Attacks on ad hoc network routing protocols disrupt network performance and reliability. This paper attempts to provide a comprehensive overview of attacks and secure routing. It first analyzes the reason that ad hoc network is vulnerable to attacks. Then it presents the well known attacks and the popular secure protocols.
Dongbin Wang, Mingzeng Hu
WAIM1