Jian Qu

dblp:67/10326 · DBLP profile ↗
← Back
13ranked-venue papers
6as first author
9since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 2 first-author · 7 since 2021Artificial intelligence and machine learning · 3 · 3 first-author · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 NEST: A Node-Interactive Generative Emulation Framework for Synthetic Traffic Generation
Jianfeng Li 0006, Jian Qu, Xiaobo Ma 0001
INFOCOM3
2024 DNSScope: Fine-Grained DNS Cache Probing for Remote Network Activity Characterization
abstract
The domain name system (DNS) is indispensable to nearly every Internet service. It has been extensively utilized for network activity characterization in passive and active approaches. Compared to the passive approach, active DNS cache probing is privacy-preserving and low-cost, enabling worldwide characterization of remote network activities in different networks. Unfortunately, existing probing-based methods are too coarse-grained to characterize the time-varying features of network activities, substantially limiting their applications in time-sensitive tasks. In this paper, we advance DNSScope, a fine-grained DNS cache probing framework by tackling three challenges: sample sparsity, observational distortion, and cache entanglement. DNSScope synthesizes statistical learning and self-supervised transfer learning to achieve time-varying characterization. Extensive evaluations demonstrate that it can accurately estimate the time-varying DNS query arrival rates on recursive DNS resolvers. Its average mean absolute error is 0.124, as low as one-sixth that of the baseline methods.
Jianfeng Li 0006, Xiaobo Ma 0001, Jian Qu, Xiapu Luo, Xiaohong Guan
INFOCOM5
2024 Robust App Fingerprinting Over the Air
abstract
Mobile apps have significantly transformed various aspects of modern life, leading to growing concerns about privacy risks. Despite widespread encrypted communication, app fingerprinting (AF) attacks threaten user privacy substantially. However, existing AF attacks, when targeted at wireless traffic, face four fundamental challenges, namely 1) sample inseparability; 2) app multiplexing; 3) signal attenuation; and 4) open-world recognition. In this paper, we advance a novel AF attack, dubbed PacketPrint, to recognize app user activities over the air in an open-world setting. We introduce two novel models, i.e., sequential XGBoost and hierarchical bag-of-words model, to tackle sample inseparability and enhance robustness against noise packets arising from app multiplexing. We also propose the environment-aware model enhancement to bolster PacketPrint’s robustness in handling packet loss at the sniffer caused by signal attenuation. We conduct extensive experiments to evaluate the proposed attack in a series of challenging scenarios, including 1) open-world setting; 2) simultaneous use of different apps; 3) severe packet loss at the sniffer; and 4) cross-dataset recognition. The experimental results show that PacketPrint can accurately recognize app user activities. It achieves the average F1-score 0.947 for open-world app recognition and the average F1-score 0.959 for in-app user action recognition.
Jianfeng Li 0006, Jian Qu, Shuohan Wu, Hao Zhou 0043, Xiaobo Ma 0001, Ting Wang 0006, Xiapu Luo, Xiaohong Guan
IEEE/ACM Trans. Netw.3
2024 Website Fingerprinting on Encrypted Proxies: A Flow-Context-Aware Approach and Countermeasures
abstract
Website fingerprinting (WFP) could infer which websites a user is accessing via an encrypted proxy by passively inspecting the traffic characteristics of accessing different websites between the user and the proxy. Designing WFP attacks is crucial for understanding potential vulnerabilities of encrypted proxies, which guides the design of defensive measures against WFP. In this paper, we design a novel WFP attack against (popular) encrypted proxies that relay connections between the user and the proxy individually (e.g., Shadowsocks, V2Ray), and accordingly implement lightweight countermeasures to effectively defend against the attack. The attack features flow-context-aware and is both accurate and immediately deployable, because it fully considers the obstacle (dubbed training-testing asymmetry) that fundamentally limits the practicability of WFP and addresses the obstacle with built-in spatial-temporal flow correlation mechanism. We implement the countermeasure as middleboxes installed on both the client and server sides of encrypted proxies, without altering any existing infrastructures for compatibility. The middleboxes can obfuscate a website’s flow regularities across different visits. Large-scale experiments in real-world scenarios demonstrate that the WFP attack can generally achieve a detection rate above 98.8% with a false positive rate below 0.2%. The countermeasure forces the attack’s false positive rate to be above 0.2 and true positive rate to be below 0.9 with just five persistent TCP connections while introducing very limited bandwidth overhead (e.g., 0.49%) and almost-zero additional network latency.
Xiaobo Ma 0001, Jian Qu, Mawei Shi, Bingyu An, Jianfeng Li 0006, Xiapu Luo, Junjie Zhang 0004, Zhenhua Li 0001, Xiaohong Guan
IEEE/ACM Trans. Netw.2
2024 On Smartly Scanning of the Internet of Things
abstract
Cyber search engines, such as Shodan and Censys, have gained popularity due to their strong capability of indexing the Internet of Things (IoT). They actively scan and fingerprint IoT devices for unearthing IP-device mapping. Because of the large address space of the Internet and the mapping’s mutative nature, efficiently tracking the evolution of IP-device mapping with a limited budget of scans is essential for building timely cyber search engines. An intuitive solution is to use reinforcement learning to schedule more scans to networks with high churn rates of IP-device mapping. However, such an intuitive solution has never been systematically studied. In this paper, we take the first step toward demystifying this problem based on our experiences in maintaining a global IoT scanning platform. Inspired by the measurement study of large-scale real-world IoT scan records, we land reinforcement learning onto a system capable of smartly scanning IoT devices in a principled way. We disclose key parameters affecting the effectiveness of different scanning strategies, and real-world experiments demonstrate that our system can scan up to around 40 times as many IP-device mapping mutations as random/sequential scanning.
Jian Qu, Xiaobo Ma 0001, Wenmao Liu, Hongqing Sang, Jianfeng Li 0006, Lei Xue 0001, Xiapu Luo, Zhenhua Li 0001, Xiaohong Guan
IEEE/ACM Trans. Netw.1
2023 An Input-Agnostic Hierarchical Deep Learning Framework for Traffic Fingerprinting
Jian Qu, Xiaobo Ma 0001, Jianfeng Li 0006, Xiapu Luo, Lei Xue 0001, Junjie Zhang 0004, Zhenhua Li 0001, Xiaohong Guan
USENIX Security Symposium1
2023 Who is DNS serving for? A human-software perspective of modeling DNS services
Jian Qu, Xiaobo Ma 0001, Wenmao Liu
Knowl. Based Syst.1
2022 Landing Reinforcement Learning onto Smart Scanning of The Internet of Things
abstract
Cyber search engines, such as Shodan and Censys, have gained popularity due to their strong capability of indexing the Internet of Things (IoT). They actively scan and fingerprint IoT devices for unearthing IP-device mapping. Because of the large address space of the Internet and the mapping’s mutative nature, efficiently tracking the evolution of IP-device mapping with a limited budget of scans is essential for building timely cyber search engines. An intuitive solution is to use reinforcement learning to schedule more scans to networks with high churn rates of IP-device mapping. However, such an intuitive solution has never been systematically studied. In this paper, we take the first step toward demystifying this problem based on our experiences in maintaining a global IoT scanning platform. Inspired by the measurement study of large-scale real-world IoT scan records, we land reinforcement learning onto a system capable of smartly scanning IoT devices in a principled way. We disclose key parameters affecting the effectiveness of different scanning strategies, and find that our system would achieve growing advantages with the proliferation of IoT devices.
Jian Qu, Xiaobo Ma 0001, Wenmao Liu, Hongqing Sang, Jianfeng Li 0006, Lei Xue 0001, Xiapu Luo, Zhenhua Li 0001, Xiaohong Guan
INFOCOM1
2022 Inferring Hidden IoT Devices and User Interactions via Spatial-Temporal Traffic Fingerprinting
abstract
With the popularization of Internet of Things (IoT) devices in smart home and industry fields, a huge number of IoT devices are connected to the Internet. However, what devices are connected to a network may not be known by the Internet Service Provider (ISP), since many IoT devices are placed within small networks (e.g., home networks) and are hidden behind network address translation (NAT). Without pinpointing IoT devices in a network, it is unlikely for the ISP to appropriately configure security policies and effectively manage the network. Additionally, inferring fine-grained user interactions of IoT devices is also an interesting yet unresolved problem. In this paper, we design an efficient and scalable system via spatial-temporal traffic fingerprinting from an ISP’s perspective in consideration of practical issues like learning-testing asymmetry. Our system can accurately identify typical IoT devices in a network, with the additional capability of identifying what devices are hidden behind NAT and the number of each type of device that share the same IP address. Our system can also detect user interactions and meanwhile identify their (concurrent) number through a multi-output regression model. Through extensive evaluation, we demonstrate that the system can generally identify IoT devices with an F1-Score above 0.999, and estimate the number of the same type of IoT device behind NAT with an average error below 5%. By studying 29 user interactions of 7 devices, we show that our system is promising in detecting user interactions.
Xiaobo Ma 0001, Jian Qu, Jianfeng Li 0006, John C. S. Lui, Zhenhua Li 0001, Wenmao Liu, Xiaohong Guan
IEEE/ACM Trans. Netw.2
2020 Pinpointing Hidden IoT Devices via Spatial-temporal Traffic Fingerprinting
abstract
With the popularization of Internet of Things (IoT) devices in smart home and industry fields, a huge number of IoT devices are connected to the Internet. However, what devices are connected to a network may not be known by the Internet Service Provider (ISP), since many IoT devices are placed within small networks (e.g., home networks) and are hidden behind network address translation (NAT). Without pinpointing IoT devices in a network, it is unlikely for the ISP to appropriately configure security policies and effectively manage the network. In this paper, we design an efficient and scalable system via spatial-temporal traffic fingerprinting. Our system can accurately identify typical IoT devices in a network, with the additional capability of identifying what devices are hidden behind NAT and how many they are. Through extensive evaluation, we demonstrate that the system can generally identify IoT devices with an F-Score above 0.999, and estimate the number of the same type of IoT device behind NAT with an average error below 5%. We also perform small-scale (labor-intensive) experiments to show that our system is promising in detecting user-IoT interactions.
Xiaobo Ma 0001, Jian Qu, Jianfeng Li 0006, John C. S. Lui, Zhenhua Li 0001, Xiaohong Guan
INFOCOM2
2012 An LSSVR-based algorithm for online system condition prognostics
Jian Qu, Mingjian Zuo
Expert Syst. Appl.1
2011 Web based English-Chinese OOV term translation using Adaptive rules and Recursive feature selection
Jian Qu
PACLIC1
2011 Reliability and Availability Analysis of a Repairable k-out-of-n: G System With R Repairmen Subject to Shut-Off Rules
abstract
Thek-out-of-n:Gsystem is widely used in reliability and maintenance engineering. We consider a generalk-out-of-n:Gsystem which has identical components with identical repair time and lifetime distributions. There areRidentical repairmen in the system. The shut-off rules of suspended animation, continuous operation, and a mixture of these two are studied. Repair times and lifetimes are assumed to be statistically independent and exponentially distributed (within, and between). We derive new closed form solutions for important performance measures including steady state availability, mean time to system failure, and mean time to first system failure.
Ramin Moghaddass, Mingjian Zuo, Jian Qu
IEEE Trans. Reliab.3