Shan Wang 0008

dblp:55/1254-8 · DBLP profile ↗
← Back
13ranked-venue papers
7as first author
12since 2021 · last 2026
0000-0001-7742-8679ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 5 · 4 first-author · 4 since 2021Computer networks · 5 · 2 first-author · 5 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2026 Your Outer Appearance Mirrors Your Inner Self: Exploiting Unobservable Node Internals to Deanonymize Uploaders in Freenet
Yonghuan Xu, Ming Yang 0001, Shan Wang 0008, Xiaodan Gu, Zixia Liu, Zhen Ling 0001
INFOCOM3
2026 Descriptors of Exposure: Undermining Tor Anonymity Through Exploiting Descriptor Flood
Chunmian Wang, Junzhou Luo, Zhen Ling 0001, Yue Zhang 0025, Shan Wang 0008, Ming Yang 0001, Guangchi Liu, Xinwen Fu
SP5
2026 A Tor-Based Anonymous Network Covert Channel
abstract
Network Covert Channels (NCC) enhance covertness by concealing the existence of information transmission. However, traditional NCCs remain vulnerable to traffic analysis. Once NCC is detected, adversaries can breach anonymity by uncovering users' network identities and even communication relationships. While certain indirect NCCs offer limited anonymity to protect the identity of at most one party and the relationship, this level proves insufficient. This paper proposes ANCC, an innovative Anonymous Network Covert Channel that is the first to achieve comprehensive anonymity for the sender, the receiver and the communication relationship. By leveraging the Tor network's Hidden Service Directories (HSDirs) as intermediate nodes, Tor-based ANCC modulates covert information through the publication and retrieval statuses of hidden services distributed on multiple HSDirs. This mechanism allows ANCC traffic to blend seamlessly into legitimate Tor traffic, ensuring both robust covertness and high-level anonymity. Theoretical analysis demonstrates that even against a powerful adversary compromising fifty intermediate nodes, the detection probability remains below 0.25%, with the risk of identity or relationship exposure staying negligible (under 0.0021% and 0.00002% respectively). Additionally, the multiple HSDirs supporting parallel transmission enhance the channel capacity and error correction encoding strengthens the robustness. Extensive evaluation within the real-world Tor network demonstrates a transmission accuracy exceeding 99.6% and a channel capacity of around 3 Kbps, proving its effectiveness for practical applications.
Ming Yang 0001, Zhen Ling 0001, Zixia Liu, Changwei Cao, Shan Wang 0008, Xinwen Fu
IEEE Trans. Dependable Secur. Comput.7
2025 Time Tells All: Deanonymization of Blockchain RPC Users with Zero Transaction Fee
abstract
Remote Procedure Call (RPC) services have become a primary gateway for users to access public blockchains. While they offer significant convenience, RPC services also introduce critical privacy challenges that remain insufficiently examined. Existing deanonymization attacks either do not apply to blockchain RPC users or incur costs like transaction fees assuming an active network eavesdropper. In this paper, we propose a novel deanonymization attack that can link an IP address of a RPC user to this user's blockchain pseudonym. Our analysis reveals a temporal correlation between the timestamps of transaction confirmations recorded on the public ledger and those of TCP packets sent by the victim when querying transaction status. We assume a strong passive adversary with access to network infrastructure, capable of monitoring traffic at network border routers or Internet exchange points. By monitoring network traffic and analyzing public ledgers, the attacker can link the IP address of the TCP packet to the pseudonym of the transaction initiator by exploiting the temporal correlation. This deanonymization attack incurs zero transaction fee. We mathematically model and analyze the attack method, perform large-scale measurements of blockchain ledgers, and conduct real-world attacks to validate the attack. Our attack achieves a high success rate of over 95% against normal RPC users on various blockchain networks, including Ethereum, Bitcoin and Solana.
Shan Wang 0008, Ming Yang 0001, Yu Liu 0168, Yue Zhang 0025, Shuaiqing Zhang, Zhen Ling 0001, Jiannong Cao 0001, Xinwen Fu
CCS1
2024 CORE: Transaction Commit-Controlled Release of Private Data Over Blockchains
abstract
In blockchain applications such as digital goods exchange, private data may be transmitted from a data owner to a recipient through a transfer transaction. However, these blockchain applications often assume the underlying blockchain system is secure and reliable, and thus do not consider transaction failures. We find that a failed transfer transaction may disclose the private data to the recipient, but the data owner may not receive tokens as payments or the ledger may not correctly record the data trail. To handle transaction failures and protect private data, we propose a novel transaction commit-controlled release (CORE) protocol. With CORE, the private data can only be obtained by an intended recipient after the transfer transaction is committed, the data owner receives tokens, and the ledger correctly records the data trail. We perform security analysis of CORE, implement CORE and evaluate its performance over representative public and permissioned blockchains. The results of our extensive experiments show CORE introduces minor overhead in terms of transaction latency and transaction fees. We are the first to identify and address the generic private data disclosure issues in both public and permissioned blockchains.
Shan Wang 0008, Ming Yang 0001, Jiannong Cao 0001, Zhen Ling 0001, Qiang Tang 0005, Xinwen Fu
ICDCS1
2024 Sharon: Secure and Efficient Cross-shard Transaction Processing via Shard Rotation
abstract
Recently, sharding has become a popular direction to scale out blockchain systems by dividing the network into shards that process transactions in parallel. However, secure and efficient cross-shard transaction processing remains a vital and unaddressed challenge. Existing work handles a cross-shard transaction via transaction division: dividing it into sub-transactions, processing them separately, and combing the processing results. Such an approach is unfavorable for decentralized blockchain due to its reliance on trustworthy parties, e.g., the client or a reference node, to perform the transaction division and result combination. Furthermore, the processing result of one transaction can affect another, violating the important property of transaction isolation. In this work, we propose Sharon, a novel sharding protocol that processes cross-shard transactions via shard rotation rather than transaction division. In Sharon, shards rotate to merge pairwisely and process cross-shard transactions when merged. Sharon eliminates reliance on trustworthy parties and provides transaction isolation in nature because transactions are no longer divided. Nevertheless, it poses a scientific question of when and how to merge the shards to improve system performance. To answer the question, we formally define the shard scheduling problem to minimize transaction confirmation latency and propose a novel construction algorithm. The proposed algorithm is proven optimal and runs in polynomial time. We conduct extensive experiments on Amazon EC2 instances using Bitcoin and Ethereum data. The results indicate that Sharon achieves nearly linear scalability, improves the system throughput by 139%, and saves the transaction processing latency by 72.4% compared with state-of-the-art approaches.
Shan Jiang 0005, Jiannong Cao 0001, Cheung Leong Tung, Shan Wang 0008
INFOCOM5
2024 Deanonymizing Ethereum Users behind Third-Party RPC Services
abstract
Third-party RPC services have become the mainstream way for users to access Ethereum. In this paper, we present a novel deanonymization attack that can link an Ethereum address to a real-world identity such as IP address of a user who accesses Ethereum via a third-party RPC service. We find that RPC API calls result in distinguishable sizes of encrypted TCP packets. An attacker can then find when a user sends a transaction to an RPC provider and immediately send a beacon transaction after the user transaction. By exploiting the differences in the distributions of inter-arrival time intervals of normal transactions and two simultaneously initiated transactions, the attacker can identify the victim transaction in the Ethereum network. This enables the attacker to correlate the Ethereum address of the victim transaction’s initiator with the source IP address of TCP packets from a victim user. We model the attack through empirical measurements and conduct extensive real-world experiments to validate the effectiveness of our attack. With three optimization strategies, the correlation accuracy can reach to 98.70% and 96.60% respectively in Ethereum testnet and mainnet. We are the first to study the deanonymization of Ethereum users behind third-party RPC services.
Shan Wang 0008, Ming Yang 0001, Wenxuan Dai, Yu Liu 0168, Yue Zhang 0025, Xinwen Fu
INFOCOM1
2024 BBS: A secure and autonomous blockchain-based big-data sharing system
Shan Wang 0008, Ming Yang 0001, Shan Jiang 0005, Fei Chen 0003, Yue Zhang 0025, Xinwen Fu
J. Syst. Archit.1
2022 BBS: A Blockchain Big-Data Sharing System
abstract
Chain of custody is needed to document the sequence of custody of sensitive big data. In this paper, we design a blockchain big-data sharing system (BBS) based on Hyperledger Fabric. We denote the data stored outside of a ledger for sharing as "off-state" and "big data" (referring to extremely large data) is in this category. In our off-state sharing protocol, a sender registers a file with BBS for sharing. To acquire the file, an authenticated and authorized receiver has to use transactions and interacts with BBS in four phases, including the file transfer request, encrypted file transfer, key retrieval, and file decryption. The corresponding transactions are recorded in the ledger and serve as chain of custody to document the trail of the data. Compared with related work, BBS can perform the four phases autonomously. It utilizes the permissioned blockchain, i.e. Hyperledger Fabric, for access control and can defeat dishonest receivers. We design and implement a prototype of BBS for big file sharing. Extensive experiments were performed to validate its feasibility and performance.
Shan Wang 0008, Ming Yang 0001, Tingjian Ge, Yan Luo 0001, Xinwen Fu
ICC1
2022 Implication of Animation on Android Security
abstract
We find that seemingly innocuous animations widely used in Android can pose great threats to user security and privacy. Both entrance and exit animations can be exploited. In our draw-and-destroy overlay attack, a malicious app periodically draws and destroys transparent UI-intercepting overlays, which can be put over victim apps to intercept user inputs stealthily. Although Android is patched to show alerts if there is an overlay over an app, quickly drawing and destroying malicious overlays can exploit the slow-in animation of the notification alert view and suppress the alert. In our draw-and-destroy toast attack, a malicious app periodically creates a new customized toast over a victim app before the previously customized toast disappears. This attack exploits the fade-out animation of the toast so that transition between two successive toasts cannot be observed. The two draw-and-destroy attacks can be building blocks of other attacks. We particularly study the password-stealing attack given its severe consequence, in which the draw-and-destroy toast attack displays a fake keyboard over the original keyboard and the draw-and-destroy overlay attack places transparent overlays over the fake keyboard to intercept user inputs. Extensive real-world experiments are conducted to validate the feasibility and effectiveness of the attacks. We also discuss defense measures mitigating the attacks. We are the first to discover the security implications of animation on Android security.
Shan Wang 0008, Zhen Ling 0001, Yue Zhang 0025, Ruizhao Liu, Joshua Kraunelis, Kang Jia, Bryan Pearson, Xinwen Fu
ICDCS1
2021 On Automating BACnet Device Discovery and Property Identification
abstract
BACnet is the most popular inter-communication protocol in building automation systems (BAS) and has been deployed in a large scale. It is critical to scan and perform risk analysis of a BAS. Existing work identifies BACnet devices in a manual way and does not further discover their properties. In this paper, we design and implement an automatic tool to identify a BACnet device at a given IP and enumerate both standard and vendor-defined BACnet objects and properties. We applied our tool to a testbed real-world BAS system on a university campus and successfully validated the tool’s effectiveness. Our tool is the first of its kind for risk assessment of the BAS, e.g., automatically scanning open smart buildings on the Internet. The video at https://youtu.be/YUfO8GQILxQ demonstrates that our toolkit may be used to remotely move a damper controlling a building’s Heating, ventilation, and air conditioning (HVAC) system from the Internet and justifies the importance of using our tool for penetration testing of a BAS.
Michael Cash, Shan Wang 0008, Bryan Pearson, Qun Zhou 0002, Xinwen Fu
ICC2
2021 On Private Data Collection of Hyperledger Fabric
abstract
Hyperledger Fabric is a popular permissioned Blockchain framework for a consortium of organizations to develop Blockchain based applications and transact within the consortium. Hyperledger Fabric introduces a fine-grained access control mechanism called the private data collection (PDC), which allows private data to be shared by only a subset of participants. In this paper, we analyze PDC and show three classes of use cases in which misuse of Hyperledger Fabric features may endanger implemented Hyperledger Fabric systems. We present two groups of potential attacks including fake PDC results injection and PDC leakage against the misuse of the policy based consensus protocol. We use prototype systems to validate the discovered attacks. We also collected 6392 Hyprledger Fabric projects on GitHub and built a tool to statically analyse them. We find that 86.51% of the PDC related projects are potentially vulnerable to the fake PDC results injection attacks, and 91.67% have PDC leakage issues. We design new features for the Hyper-ledger Fabric framework to mitigate the attacks and show that the new features have minor impact on the system performance.
Shan Wang 0008, Ming Yang 0001, Yue Zhang 0025, Yan Luo 0001, Tingjian Ge, Xinwen Fu, Wei Zhao 0001
ICDCS1
2017 Detection of malicious behavior in android apps through API calls and permission uses analysis
abstract
Summary In recent years, with the prevalence of smartphones, the number of Android malware shows explosive growth. As malicious apps may steal users' sensitive data and even money from mobile and bank accounts, it is important to detect potential malicious behaviors so as to block them. To achieve this goal, we propose a dynamic behavior inspection and analysis framework for malicious behavior detection. A customized Android system is built to record apps' API calls, permission uses, and some other runtime features. We also develop an automated app behavior inspection platform to install and inspect massive samples so as to collect apps' dynamic behavior records. Then these records are exploited to train a string subsequence kernel–based Support Vector Machine (SVM) model, which can be used to classify benign and malicious behaviors offline. To realize online detection, we further extract apps' runtime features including sensitive permission combination uses, sensitive behavior sequences, and user interactions for behavior classification. The classification results can reach an accuracy of 84.9% in offline phase and 99.0% in online phase. Besides, we verify our scheme for identifying malicious apps, and the results show that 71.8% instances of malware samples are identified by running each app for only 18 minutes.
Ming Yang 0001, Shan Wang 0008, Zhen Ling 0001, Yaowen Liu, Zhenyu Ni
Concurr. Comput. Pract. Exp.2