EDBT 2026 Demo / reviewers in the wild / expert
Tao Yang 0041
dblp:67/1120-41
· DBLP profile ↗
14ranked-venue papers
6as first author
14since 2021 · last 2026
0000-0003-2439-0579ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 11 · 6 first-author · 11 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | BEP: A Bayesian-Entropy Pruning Framework for Efficient IPv6 Active Network Discovery
Yuxuan Liao, Tao Yang 0041, Zhiping Cai |
IWQoS | 2 |
| 2026 | Efficient router fingerprinting in IPv6 networksabstractAbstract The pervasive interconnection of heterogeneous routing devices forms the fundamental infrastructure of modern Internet communication, making accurate router vendor identification a critical capability for multiple domains including network topology mapping, intelligent traffic engineering, and proactive cybersecurity defense. While Internet Protocol version 6 (IPv6) has achieved widespread global deployment as the next-generation Internet protocol, the opaque nature of its addressing mechanisms and protocol behaviors has created significant challenges in router attribute detection across IPv6 networks, leaving a crucial gap in network visibility and security analytics. To address this pressing challenge, we present IPv6 Router FingerPrinting (6RFP), an innovative lightweight fingerprinting methodology that establishes a new paradigm for IPv6 router vendor identification by systematically combining two complementary analytical dimensions: (i) comprehensive EUI-64 interface identifier analysis that captures vendor-specific hardware encoding patterns embedded in IPv6 addresses, and (ii) sophisticated IPv6 Identification Field characteristic profiling that reveals distinctive vendor implementations. Through extensive evaluation across diverse network environments, 6RFP demonstrates highly effective detection capabilities, achieving 85.79% accuracy—representing a remarkable 86.01% improvement over current state-of-the-art techniques—while maintaining minimal computational overhead suitable for real-time deployment. Ling Hu 0001, Tao Yang 0041, Xionglve Li, Bingnan Hou, Zhiping Cai |
Comput. J. | 3 |
| 2025 | Pruning as Scanning: Towards Internet-Wide IPv6 Network Periphery Discovery
Tao Yang 0041, Ling Hu 0001, Bingnan Hou, Zhenzhong Yang, Zhiping Cai |
INFOCOM | 1 |
| 2025 | Grey Rhino Warning: IPv6 is Becoming Fertile Ground for Reflection Amplification AttacksabstractDistributed Denial-of-Service (DDoS) attacks represent a cost-effective and potent threat to network stability. While extensively studied in IPv4 networks, DDoS implications in IPv6 remain underexplored. The vast IPv6 address space renders brute-force scanning and amplifier testing for all active addresses impractical. Innovatively, this work investigates ASlevel vulnerabilities to reflection amplification attacks in IPv6. One prerequisite for amplification presence is that it is located in a vulnerable autonomous system (AS) without inbound source address validation (ISAV) deployment. Hence, the analysis focuses on two critical aspects: global detection of ISAV deployment and identification of amplifiers within vulnerable ASes. Specifically, we develop a methodology combining ICMP Time Exceeded mechanisms for ISAV detection, employ IPv6 address scanning for amplifier identification, and utilize dual vantage points for amplification verification. Experimental results reveal that 4,460 ASes (61.36% of measured networks) lack ISAV deployment. Through scanning approximately 47 M active addresses, we have identified reflection amplifiers in 3,507 ASes. The analysis demonstrates that current IPv6 networks are fertile ground for reflection amplification attacks, alarming network security. Ling Hu 0001, Tao Yang 0041, Bingnan Hou, Zhiping Cai, Bo Yu 0008 |
IWQoS | 2 |
| 2025 | Sweeping the IPv6 Internet: High-Efficiency Router Interface Discovery With Weighted SamplingabstractAcquiring router interfaces is crucial for network measurement and security assessment. Established methods are readily available for IPv4 systems; however, efficiently pinpointing IPv6 router interfaces remains an unresolved issue, chiefly due to the vast IPv6 address space. Existing practices in this domain commonly suffer from inefficiencies. Thus, it is imperative to propose a methodology for fast enumeration of IPv6 router interfaces on a massive scale. In this study, we introduce Sweeper, a novel asynchronous IPv6 scanner that excels in discovering router interfaces from scratch, from few to many, on large-scale IPv6 networks. Unlike existing approaches, Sweeper requires merely the readily accessible IPv6 prefixes instead of seed addresses and can strategically optimize its probing direction based on a novel weighted sampling algorithm to increase the discovery rate. Real-world tests prove that Sweeper outperforms state-of-the-art works, discovering$33.2\%\sim 48.8\%$more IPv6 router interface addresses than the baselines, with same computational resources. With Sweeper, we have collected approximately 6 million IPv6 router interface addresses from a single vantage point within less than one hour. Tao Yang 0041, Bingnan Hou, Zhiping Cai |
IEEE Trans. Netw. | 1 |
| 2025 | Realizing Personalized and Adaptive Inference of AS Paths With a Generative and Measurable ProcessabstractIn the global Internet, understanding paths between autonomous systems (ASes) is valuable for improving the Internet routing system and optimizing various applications. However, due to the business and privacy concerns, only a small portion of paths are disclosed. Moreover, limited by the measurement resources, obtaining paths between any two ASes is impossible. Thus, path inference becomes necessary. Recent work proposes training individual model for each AS to infer paths, but it lacks personalization as it uses a shared approach and data for arbitrary ASes. Moreover, training models from scratch for all the ASes is time-consuming and resource-intensive. This paper introduces Personalized and Adaptive Generative Measurable Path Inference (PA-GMPI), a prefix-grained path inference process. PA-GMPI is capable of achieving superior performance and faster model training by fully leveraging the exclusive information of each AS. These improvements come from a personalized path generator, a 3-layer graph kernel based adaptive training warm-starter, and a real-world walks based AS representation learner. In evaluation, PA-GMPI significantly outperforms the state-of-the-art method, achieving a maximal accuracy improvement of 28.72% and ESR (exact same ratio) improvement of 49.95%. Furthermore, PA-GMPI achieves an average reduction of 20.21% in training resource consumption across over two thousand training sessions, using vantage ASes from five snapshots, which included 439 distinct ASes. Xionglve Li, Chengyu Wang 0008, Tao Yang 0041, Zhenyu Qiu, Bingnan Hou, Zhiping Cai |
IEEE Trans. Netw. | 3 |
| 2025 | 6Seeks: A Global IPv6 Network Periphery Scanning SystemabstractDiscovering the IPv6 network periphery, i.e., the last-hop router connecting endhosts in the IPv6 Internet, is crucial for network measurement and Internet reconnaissance. However, existing solutions commonly suffer from inefficiency when applied on a global scale due to the vast IPv6 address space. To tackle this challenge, we developed6Seeks, an innovative IPv6 scanning system designed for efficient IPv6 periphery discovery across the global IPv6 Internet without requiring seed IPv6 addresses. Specifically, we proposed to employ a heuristic method for collecting active /48 networks from the global BGP prefixes and then adopt a reinforcement learning-based dynamic probing strategy to optimize resource allocation across these networks and significantly improve efficiency. Real-world tests demonstrate that6Seeksoutperforms all existing methods in global-scale IPv6 periphery measurement experiments. In just a few hours,6Seekscan identify over 128 million IPv6 periphery devices, while using only 37% of the probing resources required by the current state-of-the-art solution. Compared to existing public datasets, the IPv6 addresses identified by6Seeksare more numerous and display unique characteristics, significantly enriching our IPv6 corpus. Tao Yang 0041, Bingnan Hou, Zhenzhong Yang, Zhiping Cai |
IEEE Trans. Netw. | 1 |
| 2024 | Efficient IPv6 Router Interface DiscoveryabstractEfficient discovery of router interfaces on the IPv6 Internet is critical for network measurement and cybersecurity. However, existing solutions commonly suffer from inefficiencies due to a lack of initial probing targets (seeds), ultimately exhibiting limitations on large-scale IPv6 networks. Therefore, it is imperative to develop a methodology that enables the efficient collection of IPv6 router interfaces with limited resources, considering the impracticality of conducting a brute-force exploration across the extensive IPv6 address space. In this paper, we introduce Treestrace, an innovative asynchronous prober specifically designed for this purpose. Without prior knowledge of the networks, this tool incrementally adjusts search directions, automatically prioritizing the survey of IPv6 address spaces with a higher concentration of IPv6 router interfaces. Furthermore, we have developed a carefully crafted architecture optimized for probing performance, allowing the tool to probe at the highest theoretically possible rate without requiring excessive computational resources. Real-world tests show that Treestrace outperforms state-of-the-art works on both seed-based and seedless tasks, achieving at least a 5.57-fold efficiency improvement on large-scale IPv6 router interface discovery. With Treestrace, we discovered approximately 8 million IPv6 router interface addresses from a single vantage point within several hours. Tao Yang 0041, Zhiping Cai |
INFOCOM | 1 |
| 2024 | DGA domain embedding with deep metric learningabstractAbstract Botnets currently use domain-generation algorithms to produce fast-flux domains that enable them to evade detection. Accurately categorizing these botnet domains is crucial to develop cybersecurity solutions against botnet threats. However, existing methods, requiring labeled data, are ineffective against new botnets. To address this issue, we propose Domain2Vec, a metric learning-based approach that can explore new botnets. Domain2Vec integrates a framework of metric learning, which uses individual domains from known botnets for categorization of unknown botnet domains. The training involves an attention-based encoder, and it includes a constraint to ensure that samples with the same labels are closer in the embedding space. The categorization uses the encoder to project domain names into appropriate representations (numerical vectors), even for domains from new botnets. Finally, Domain2Vec uses numerical vectors to explore botnets. Experiments showed that Domain2Vec performs well on domain retrieval and clustering tasks without labeled data, outperforming the state of the art by 13% and 100%, respectively. Real-world tests demonstrate that Domain2Vec can effectively identify unreported malicious domains and monitor botnet activities. Xionglve Li, Tao Yang 0041, Bingnan Hou, Lingbin Zeng, Zhiping Cai, Wenyuan Kuang |
Comput. J. | 3 |
| 2023 | Search in the Expanse: Towards Active and Global IPv6 HitlistsabstractGlobal-scale IPv6 scan, critical for network measurement and management, is still a mission to be accomplished due to its vast address space. To tackle this challenge, IPv6 scan generally leverages pre-defined seed addresses to guide search directions. Under this general principle, however, the core problem of effectively using the seeds is largely open. In this work, we propose a novel IPv6 active search strategy, namely HMap6, which significantly improves the use of seeds, w.r.t. the marginal benefit, for large-scale active address discovery in various prefixes. Using a heuristic search strategy for efficient seed collection and alias prefix detection under a wide range of BGP prefixes, HMap6 can greatly expand the scan coverage. Real-world experiments over the Internet in billion-scale scans show that HMap6 can discover 29.39M unique /80 prefixes with active addresses, an 11.88% improvement over the state-of-the-art methods. Furthermore, the IPv6 hitlists from HMap6 include all-responsive IPv6 addresses with rich information. This result sharply differs from existing public IPv6 hitlists, which contain non-responsive and filtered addresses, and pushes the IPv6 hitlists from quantity to quality. To encourage and benefit further IPv6 measurement studies, we released our tool along with our IPv6 hitlists and the detected alias prefixes. Bingnan Hou, Zhiping Cai, Kui Wu 0001, Tao Yang 0041, Tongqing Zhou |
INFOCOM | 4 |
| 2023 | 6Scan: A High-Efficiency Dynamic Internet-Wide IPv6 Scanner With Regional EncodingabstractEfficient Internet-wide scanning plays a vital role in network measurement and cybersecurity analysis. While Internet-wide IPv4 scanning is a solved problem, Internet-wide scanning for IPv6 is still a mission yet to be accomplished due to its vast address space. To tackle this challenge, IPv6 scanning generally needs to use pre-defined seed addresses to guide further IPv6 scanning directions. Under this general principle, various solutions have been developed, but all suffer from two primary pitfalls, low hit rate and low probing speed, caused by the inherent sparse distribution of active IPv6 addresses and the high computational complexity of the search algorithms, respectively. We develop 6Scan, a novel asynchronous IPv6 scanner that effectively addresses the above two problems. To increase the hit rate, 6Scan infers the promising search directions by encoding the regional identifiers of the target addresses within the probing packets and recording the regional activities from the asynchronously arrived replies. It then dynamically adjusts the search directions according to the scanning result of the previous steps. To speed up the search algorithm, 6Scan leverages the regional identifier encoding to quickly adjust search direction without excessive computation. Real-world experiments over the IPv6 Internet in a billion-scale probing budget show that compared with the state-of-the-art solutions, on average 6Scan can discover 6% more active addresses with nearly the same scanning time. Bingnan Hou, Zhiping Cai, Kui Wu 0001, Tao Yang 0041, Tongqing Zhou |
IEEE/ACM Trans. Netw. | 4 |
| 2022 | 6Forest: An Ensemble Learning-based Approach to Target Generation for Internet-wide IPv6 ScanningabstractIPv6 target generation is the critical step for fast IPv6 scanning for Internet-wide surveys. Existing techniques, however, commonly suffer from low hit rates due to inappropriate space partition caused by the outlier addresses and short-sighted splitting indicators. To address the problem, we propose 6Forest, an ensemble learning-based approach for IPv6 target generation that is from a global perspective and resilient to outlier addresses. Given a set of known addresses, 6Forest first considers it as an initial address region and then iteratively divides the IPv6 address space into smaller regions using a maximum-covering splitting indicator. Before a round of space partition, it builds a forest structure for each region and exploits an enhanced isolation forest algorithm to remove the outlier addresses. Finally, it pre-scans samples from the divided address regions and based on the results generates IPv6 addresses. Experiments on eight large-scale candidate datasets indicate that, compared with the state-of-the-art methods in IPv6 worldwide scanning, 6Forest can achieve up to 116.5% improvement for low-budget scanning and 15× improvement for high-budget scanning. Tao Yang 0041, Zhiping Cai, Bingnan Hou, Tongqing Zhou |
INFOCOM | 1 |
| 2022 | 6Graph: A graph-theoretic approach to address pattern mining for Internet-wide IPv6 scanning
Tao Yang 0041, Bingnan Hou, Zhiping Cai, Kui Wu 0001, Tongqing Zhou, Chengyu Wang 0008 |
Comput. Networks | 1 |
| 2021 | TSAEns: Ensemble Learning for KPI Anomaly Detection
Chengyu Wang 0008, Tao Yang 0041, Jinhua Cui 0002, Tongqing Zhou, Zhiping Cai |
ICA3PP (1) | 2 |