EDBT 2026 Demo / reviewers in the wild / expert
Shuai Hao 0001
dblp:73/5618-1
· DBLP profile ↗
30ranked-venue papers
2as first author
22since 2021 · last 2026
0000-0001-7483-5252ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 1 first-author · 11 since 2021Computer networks · 10 · 1 first-author · 7 since 2021Systems, architecture and hardware · 4 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The Privacy Paradox of LLMs: User Perceptions and the Reality of PII LeakageabstractLarge language models (LLMs) are increasingly deployed, yet they introduce significant privacy risks by disclosing personally identifiable information (PII) during interactions. Although prior work has demonstrated the feasibility of extracting PII from LLMs, no comprehensive study has evaluated the actual extent of PII leakage across mainstream LLMs or investigated user perceptions, literacy, and behavioral responses to these risks. To address these gaps, we conduct a large-scale evaluation of PII leakage in popular LLMs, demonstrating that attackers can extract email addresses and phone numbers with high success rates. Through a mixed-methods study involving 20 interviews and 204 survey participants, we identify significant discrepancies between user concerns and behavior: despite strong concerns about PII leakage and limited understanding of training data provenance, users continue to use LLMs due to perceived utility, often exhibiting privacy cynicism. Based on these findings, we propose design implications for enhancing the privacy-utility balance in future LLM deployments. Haitao Xu 0002, Shu Meng, Shuai Hao 0001, Chuan Yue, Zhao Li 0007 |
CHI | 4 |
| 2026 | LLM-Empowered Discovery of Windows APIs Exploitable for Persistent Storage in Fileless Attacks
Shu Meng, Haitao Xu 0002, Shuai Hao 0001, Yixin Jiang |
DSN | 4 |
| 2026 | Too Open to be Secure: An Evaluation of OpenNIC DNS Services and Domains
Dianshi Yang, Xiaoqin Liang, Daiping Liu, Guannan Liu 0003, Shuai Hao 0001, Xing Gao 0001 |
DSN | 5 |
| 2026 | ReOpt: Near-Optimal Region Division for Low-Latency Regional Anycast
Minyuan Zhou, Congying Wang, Jiaqi Zheng 0001, Shuai Hao 0001, Guihai Chen, Jie Wu 0001 |
INFOCOM | 5 |
| 2026 | CHAMELEOSCAN: Demystifying and Detecting iOS Chameleon Apps via LLM-Powered UI Exploration
Haitao Xu 0002, Yanchen Lu, Mengxia Ren, Shuai Hao 0001, Chuan Yue, Zhao Li 0007, Fan Zhang 0010, Yixin Jiang |
NDSS | 6 |
| 2025 | Pathfinder: Exploring Path Diversity for Assessing Internet Censorship InconsistencyabstractInternet censorship is commonly enabled by authorities to enforce information control. So far, existing censorship studies have largely focused on country-level characterization, primarily because (1) censorship enforcement is often mandated through nationwide policies and (2) it is difficult to control the routing of probing packets to trigger censorship across different networks within a country. However, censorship mechanisms can vary significantly at the ISP level, revealing a more diverse landscape than previously assumed. In this paper, we investigate Internet censorship from a new perspective by scrutinizing diverse censorship deployments within a country. We design and deploy a measurement framework that utilizes multiple geo-distributed backend servers to probe various network paths from a single vantage point. By generating traffic targeting the same domain but different backend server IPs, we induce path diversity that exposes the traffic to distinct transit networks, and potentially, different censorship devices, thereby enabling a more granular analysis of censorship practices. Through our large-scale experiments and in-depth analysis, we reveal that diverse censorship resulting from varying routing paths within a country is widespread, implying that (1) the implementations of centralized censorship are commonly incomplete or flawed and (2) decentralized censorship is also prevalent. Moreover, we find that different hosting platforms also contribute to inconsistent censorship behavior due to their varying peering relationships with ISPs within a country. Finally, we present detailed case studies to illustrate the configurations that lead to such inconsistencies and to explore their underlying causes. Xiaoqin Liang, Guannan Liu 0003, Lin Jin, Shuai Hao 0001, Haining Wang 0001 |
ACSAC | 4 |
| 2025 | TacDroid: Detection of Illicit Apps Through Hybrid Analysis of UI-Based Transition GraphsabstractIllicit apps have emerged as a thriving underground industry, driven by their substantial profitability. These apps either offer users restricted services (e.g., porn and gambling) or engage in fraudulent activities like scams. Despite the widespread presence of illicit apps, scant attention has been directed towards this issue, with several existing detection methods predominantly relying on static analysis alone. However, given the burgeoning trend wherein an increasing number of mobile apps achieve their core functionality through dynamic resource loading, depending solely on static analysis proves inadequate. To address this challenge, in this paper, we introduce Tac-droid,a novel approach that integrates dynamic analysis for dynamic content retrieval with static analysis to mitigate the limitations inherent in both methods, i.e., the low coverage of dynamic analysis and the low accuracy of static analysis. Specifically, Tacdroid conducts both dynamic and static analyses on an Android app to construct dynamic and static User Interface Transition Graphs (UTGs), respectively. These two UTGs are then correlated to create an intermediate UTG. Subsequently, Tacdroid embeds graph structure and utilizes an enhanced Graph Autoencoder (GAE) model to predict transitions between nodes. Through link prediction, Tacdroid effectively eliminates false positive transition edges stemming from misjudgments in static analysis and supplements false negative transition edges overlooked in the intermediate UTG, thereby generating a comprehensive and accurate UTG. Finally, Tacdroid determines the legitimacy of an app and identifies its category based on the app's UTG. Our evaluation results highlight the outstanding accuracy of Tacdroid in detecting illicit apps. It significantly surpasses the state-of-the-art work, achieving an F1-score of 96.73%. This work represents a notable advancement in the identification and categorization of illicit apps. Yanchen Lu, Zehua He, Haitao Xu 0002, Zhao Li 0007, Shuai Hao 0001, Liu Wang 0002, Haoyu Wang 0001, Kui Ren 0001 |
ICSE | 6 |
| 2025 | Understanding PII Leakage in Large Language Models: A Systematic SurveyabstractLarge Language Models (LLMs) have demonstrated exceptional success across a variety of tasks, particularly in natural language processing, leading to their growing integration into numerous facets of daily life. However, this widespread deployment has raised substantial privacy concerns, especially regarding personally identifiable information (PII), which can be directly associated with specific individuals. The leakage of such information presents significant real-world privacy threats. In this paper, we conduct a systematic investigation into existing research on PII leakage in LLMs, encompassing commonly utilized PII datasets, evaluation metrics, and current studies on both PII leakage attacks and defensive strategies. Finally, we identify unresolved challenges in the current research landscape and suggest future research directions. Zhao Li 0007, Shu Meng, Mengxia Ren, Haitao Xu 0002, Shuai Hao 0001, Chuan Yue, Fan Zhang 0010 |
IJCAI | 6 |
| 2025 | Understanding the Business of Online Affiliate Marketing: An Empirical StudyabstractAffiliate marketing is a revenue-sharing marketing scheme by which an affiliate, such as a blogger or YouTuber, garners commissions for promoting a merchant's goods or services, thereby aiming to foster a mutually beneficial relationship between affiliates and merchants. Despite being a multi-billion-dollar global industry, affiliate marketing remains inadequately explored, and the research community lacks a comprehensive understanding of its intricate ecosystem. In this paper, we present the first comprehensive empirical study of the affiliate marketing ecosystem. We conduct thorough measurements to assess the prevalence of affiliate marketing, estimate the market size, and elucidate the characteristics of affiliates, merchants, and intermediary affiliate networks. Over a continuous span of 13 months, we monitored four of the most prominent affiliate aggregation platforms, yielding a substantial dataset. We observed 467,219 unique offers - tasks to be undertaken by affiliates - involving 37,109 merchants and 556 affiliate networks across the four platforms. Notably, these offers would cost the merchants more than 19 million USD for the completion of all the actions pre-defined in these offers, such as signing up or making a transaction. Additionally, we compiled a large-scale dataset comprising 124,462 affiliate links, enabling us to conduct a comprehensive investigation. Finally, we propose machine learning models incorporating the characteristics of affiliate links to detect real-world affiliate marketing campaigns. Haitao Xu 0002, Kaleem Ullah Qasim, Shuai Hao 0001, Wenrui Ma, Zhenyuan Li, Fan Zhang 0010, Zhao Li 0007 |
INFOCOM | 4 |
| 2025 | Effective PII Extraction from LLMs through Augmented Few-Shot Learning
Shu Meng, Haitao Xu 0002, Shuai Hao 0001, Chuan Yue, Wenrui Ma, Fan Zhang 0010, Zhao Li 0007 |
USENIX Security Symposium | 5 |
| 2024 | Silent Observers Make a Difference: A Large-scale Analysis of Transparent Proxies on the InternetabstractTransparent web proxies have been widely deployed on the Internet, bridging the communications between clients and servers and providing desirable benefits to both sides, such as load balancing, security monitoring, and privacy enhancement. Meanwhile, they work silently as clients and servers may not be aware of their existence. However, due to their invisibility and stealthiness, transparent proxies remain understudied for their behaviors, suspicious activities, and potential vulnerabilities that could be exploited by attackers. To better understand transparent proxies, we design and develop a framework to systematically investigate them in the wild. We identify two major types of transparent web proxies, named FDR and CPV, respectively. FDR is a type of transparent proxy that independently performs Forced DNS Resolution during interception. CPV is a type of transparent proxy that presents Cache Poisoning Vulnerability. We perform a large-scale measurement to detect each type of transparent web proxy and scrutinize their security implications. In total, we observe 32,246 FDR and 11,286 CPV cases through our acquired vantage points. We confirm that these two types of transparent proxies are distributed globally — FDRs are observed in 98 countries and CPVs are observed in 51 countries. Our work highlights the issues of vulnerable transparent proxies and provides insights for mitigating such problems. Rui Bian, Lin Jin, Shuai Hao 0001, Haining Wang 0001, Chase Cotton |
INFOCOM | 3 |
| 2023 | Dial "N" for NXDomain: The Scale, Origin, and Security Implications of DNS Queries to Non-Existent DomainsabstractNon-Existent Domain (NXDomain) is one type of the Domain Name System (DNS) error responses, indicating that the queried domain name does not exist and cannot be resolved. Unfortunately, little research has focused on understanding why and how NXDomain responses are generated, utilized, and exploited. In this paper, we conduct the first comprehensive and systematic study on NXDomain by investigating its scale, origin, and security implications. Utilizing a large-scale passive DNS database, we identify 146,363,745,785 NXDomains queried by DNS users between 2014 and 2022. Within these 146 billion NXDomains, 91 million of them hold historic WHOIS records, of which 5.3 million are identified as malicious domains including about 2.4 million blocklisted domains, 2.8 million DGA (Domain Generation Algorithms) based domains, and 90 thousand squatting domains targeting popular domains. To gain more insights into the usage patterns and security risks of NXDomains, we register 19 carefully selected NXDomains in the DNS database, each of which received more than ten thousand DNS queries per month. We then deploy a honeypot for our registered domains and collect 5,925,311 incoming queries for 6 months, from which we discover that 5,186,858 and 505,238 queries are generated from automated processes and web crawlers, respectively. Finally, we perform extensive traffic analysis on our collected data and reveal that NXDomains can be misused for various purposes, including botnet takeover, malicious file injection, and residue trust exploitation. Guannan Liu 0003, Lin Jin, Shuai Hao 0001, Yubao Zhang, Daiping Liu, Angelos Stavrou, Haining Wang 0001 |
IMC | 3 |
| 2023 | Regional IP Anycast: Deployments, Performance, and PotentialsabstractRecent studies show that an end system's traffic may reach a distant anycast site within a global IP anycast system, resulting in high latency. To address this issue, some private and public CDNs have implemented regional IP anycast, a technique that involves dividing content-hosting sites into geographic regions, announcing a unique IP anycast prefix for each region, and utilizing DNS and IP-geolocation to direct clients to CDN sites in their corresponding geographic regions. In this work, we aim to understand how a regional anycast CDN partitions its sites and maps its customers' clients to its sites, and how a regional anycast CDN performs compared to its global anycast counterpart. We study the deployment strategies and the performance of two CDNs (Edgio and Imperva) that currently deploy regional IP anycast. We find that both Edgio and Imperva partition their sites and clients following continent or country borders. Furthermore, we compare the client latency distribution in Imperva's regional anycast CDN with its similar-scale DNS global anycast network, while accounting for and mitigating the relevant deployment differences between the two networks. We find that regional anycast can effectively alleviate the pathology in global IP anycast where BGP routes clients' traffic to distant CDN sites. However, DNS mapping inefficiencies, where DNS returns a sub-optimal regional IP anycast address that does not cover a client's low-latency CDN sites, can harm regional anycast's performance. Finally, we show what performance benefits regional IP anycast can achieve with a latency-based region partition method using the Tangled testbed. When compared to global anycast, regional anycast significantly reduces the 90th percentile client latency by 58.7% to 78.6% for clients across different geographic areas. Minyuan Zhou, Shuai Hao 0001, Xiaowei Yang 0001, Jiaqi Zheng 0001, Guihai Chen, Wan-Chun Dou |
SIGCOMM | 3 |
| 2022 | Ready Raider One: Exploring the Misuse of Cloud Gaming ServicesabstractCloud gaming has become an emerging computing paradigm in recent years, allowing computer games to offload complex graphics and logic computation to the cloud. To deliver a smooth and high-quality gaming experience, cloud gaming services have invested abundant computing resources in the cloud, including adequate CPUs, top-tier GPUs, and high-bandwidth Internet connections. Unfortunately, the abundant computing resources offered by cloud gaming are vulnerable to misuse and exploitation for malicious purposes. In this paper, we present an in-depth study on security vulnerabilities in cloud gaming services. Specifically, we reveal that adversaries can purposely inject malicious programs/URLs into the cloud gaming services via game mods. Using the provided features such as in-game subroutines, game launch options, and built-in browsers, adversaries are able to execute the injected malicious programs/URLs in cloud gaming services. To demonstrate that such vulnerabilities pose a serious threat, we conduct four proof-of-concept attacks on cloud gaming services. Two of them are to abuse the CPUs and GPUs in cloud gaming services to mine cryptocurrencies with attractive profits and train machine learning models at a trivial cost. The other two are to exploit the high-bandwidth connections provided by cloud gaming for malicious Command & Control and censorship circumvention. Finally, we present several countermeasures for cloud gaming services to protect their valuable assets from malicious exploitation. Guannan Liu 0003, Daiping Liu, Shuai Hao 0001, Xing Gao 0001, Kun Sun 0001, Haining Wang 0001 |
CCS | 3 |
| 2022 | A Comprehensive, Longitudinal Study of Government DNS Deployment at Global ScaleabstractWithin the Domain Name System (DNS), government domains form a particularly valuable part of the names-pace, representing trusted sources of information, vital services, and gateways for government personnel to engage in their duties. As the COVID-19 pandemic has unfolded, governments’ digital resources have become increasingly important to provide support to populations largely in isolation. The accessibility of these resources relies largely on the trustworthiness of the domains that represent them. In this paper, we conduct an extensive measurement study focused on the availability and legitimacy of DNS records in the authoritative nameservers of government domains for over 190 countries. Our measurements reveal that thousands of domains do not use replicated authoritative name-servers, as well as a substantial increase in the trend of more domains relying on a single third-party DNS services provider. We also find more than 1,000 domains vulnerable to hijacking due to defective delegations. Our work shows that although robust overall, the deployments of authoritative nameservers in government domains still contain a non-trivial number of configurations that do not meet RFC requirements, leading to poor performance and reduced reliability that may leave domains vulnerable to hijacking. Rebekah Houser, Shuai Hao 0001, Chase Cotton, Haining Wang 0001 |
DSN | 2 |
| 2022 | Quantifying Nations' Exposure to Traffic Observation and Selective Tampering
Alexander Gamero-Garrido, Esteban Carisimo, Shuai Hao 0001, Bradley Huffaker, Alex C. Snoeren, Alberto Dainotti |
PAM | 3 |
| 2022 | Shining a light on dark places: A comprehensive analysis of open proxy ecosystem
Rui Bian, Shuai Hao 0001, Haining Wang 0001, Chase Cotton |
Comput. Networks | 2 |
| 2021 | Mingling of Clear and Muddy Water: Understanding and Detecting Semantic Confusion in Blackhat SEO
Kun Du, Yubao Zhang, Shuai Hao 0001, Haining Wang 0001, Jia Zhang 0004, Hai-Xin Duan |
ESORICS (1) | 4 |
| 2021 | DNSonChain: Delegating Privacy-Preserved DNS Resolution to BlockchainabstractDomain Name System (DNS) is known to present privacy concerns. To this end, decentralized blockchains have been used to host DNS records, so that users can synchronize with the blockchain to maintain a local DNS database and resolve domain names locally. However, existing blockchain-based solutions either do not guarantee a domain name is controlled by its "true" owner; or have to resort to DNSSEC, a not yet widely adopted protocol, for verifying ownership. In this paper, we present DNSonChain, a new blockchain-based naming service compatible with DNS. It allows domain owners to claim their domain ownership on the blockchain where DNS records are hosted. The core function of DNSonChain is to validate the domain ownership in a decentralized manner. We propose a majority vote mechanism that randomly selects multiple participants (i.e., voters) in the system to vote for the authority of domain ownership. To provide resistance to attacks from fraudulent voters, DNSonChain requires two rounds of voting processes. Our security analysis shows that DNSonChain is robust against several types of security failures, able to recover from various attacks. We implemented a prototype of DNSonChain as an Ethereum decentralized application and evaluate it on an Ethereum Testnet. Lin Jin, Shuai Hao 0001, Yan Huang 0001, Haining Wang 0001, Chase Cotton |
ICNP | 2 |
| 2021 | A Comprehensive Measurement-based Investigation of DNS HijackingabstractAttacks against the domain name system (DNS) have long plagued the Internet, requiring continual investigation and vigilance to prevent the abuse of this critical infrastructure. Among these attacks, DNS hijacking has repeatedly asserted itself as one of the most serious threats. In recent years, the severity of DNS hijacking has motivated renewed interest in developing more robust defenses. The size, dynamism, and diversity of the DNS ecosystem present nontrivial challenges to crafting an effective and scalable defense. Further, the relative rarity of documented DNS hijacking attacks makes them difficult to study in-depth. In this paper, we attempt to address the challenges in two thrusts. We first conduct an analysis based on the reports of confirmed DNS hijacking attacks and passive DNS records to characterize known DNS hijacking attacks and identify features for building defense mechanisms. Then we explore the extent to which the characteristic features can be used to build a DNS hijacking detection mechanism and evaluate its effectiveness from the perspective of a network gateway. Rebekah Houser, Shuai Hao 0001, Zhou Li 0001, Daiping Liu, Chase Cotton, Haining Wang 0001 |
SRDS | 2 |
| 2021 | Understanding the Impact of Encrypted DNS on Internet CensorshipabstractDNS traffic is transmitted in plaintext, resulting in privacy leakage. To combat this problem, secure protocols have been used to encrypt DNS messages. Existing studies have investigated the performance overhead and privacy benefits of encrypted DNS communications, yet little has been done from the perspective of censorship. In this paper, we study the impact of the encrypted DNS on Internet censorship in two aspects. On one hand, we explore the severity of DNS manipulation, which could be leveraged for Internet censorship, given the use of encrypted DNS resolvers. In particular, we perform 7.4 million DNS lookup measurements on 3,813 DoT and 75 DoH resolvers and identify that 1.66% of DoT responses and 1.42% of DoH responses undergo DNS manipulation. More importantly, we observe that more than two-thirds of the DoT and DoH resolvers manipulate DNS responses from at least one domain, indicating that the DNS manipulation is prevalent in encrypted DNS, which can be further exploited for enhancing Internet censorship. On the other hand, we evaluate the effectiveness of using encrypted DNS resolvers for censorship circumvention. Specifically, we first discover those vantage points that involve DNS manipulation through on-path devices, and then we apply encrypted DNS resolvers at these vantage points to access the censored domains. We reveal that 37% of the domains are accessible from the vantage points in China, but none of the domains is accessible from the vantage points in Iran, indicating that the censorship circumvention of using encrypted DNS resolvers varies from country to country. Moreover, for a vantage point, using a different encrypted DNS resolver does not lead to a noticeable difference in accessing the censored domains. Lin Jin, Shuai Hao 0001, Haining Wang 0001, Chase Cotton |
WWW | 2 |
| 2021 | Detecting incentivized review groups with co-review graphabstractOnline reviews play a crucial role in the ecosystem of nowadays business (especially e-commerce platforms), and have become the primary source of consumer opinions. To manipulate consumers’ opinions, some sellers of e-commerce platforms outsource opinion spamming with incentives (e.g., free products) in exchange for incentivized reviews. As incentives, by nature, are likely to drive more biased reviews or even fake reviews. Despite e-commerce platforms such as Amazon have taken initiatives to squash the incentivized review practice, sellers turn to various social networking platforms (e.g., Facebook) to outsource the incentivized reviews. The aggregation of sellers who request incentivized reviews and reviewers who seek incentives forms incentivized review groups. In this paper, we focus on the incentivized review groups in e-commerce platforms. We perform the data collections from various social networking platforms, including Facebook, WeChat, and Douban. A measurement study of incentivized review groups is conducted with regards to group members, group activities, and products. To identify the incentivized review groups, we propose a new detection approach based on co-review graphs. Specifically, we employ the community detection method to find the suspicious communities from co-review graphs. We also build a “gold standard” dataset from the data we collected, which contains the information of reviewers who belong to incentivized review groups. We utilize the “gold standard” dataset to evaluate the effectiveness of our detection approach. Yubao Zhang, Shuai Hao 0001, Haining Wang 0001 |
High Confid. Comput. | 2 |
| 2020 | Review Trade: Everything Is Free in Incentivized Review Groups
Yubao Zhang, Shuai Hao 0001, Haining Wang 0001 |
SecureComm (1) | 2 |
| 2020 | Understanding the Manipulation on Recommender Systems through Web InjectionabstractRecommender systems have been increasingly used in a variety of web services, providing a list of recommended items in which a user may have an interest. While important, recommender systems are vulnerable to various malicious attacks. In this paper, we study a new security vulnerability in recommender systems caused byweb injection, through which malicious actors stealthily tamper any unprotected in-transit HTTP webpage content and force victims to visit specific items in some web services (even running HTTPS),e.g., YouTube. By doing so, malicious actors can promote their targeted items in those web services. To obtain a deeper understanding on the recommender systems of our interest (including YouTube, Yelp, Taobao, and 360 App market), we first conduct a measurement-based analysis on several real-world recommender systems by leveraging machine learning algorithms. Then, web injection is implemented in three different types of devices (i.e., computer, router, and proxy server) to investigate the scenarios where web injection could occur. Based on the implementation of web injection, we demonstrate that it is feasible and sometimes effective to manipulate the real-world recommender systems through web injection. We also present several countermeasures against such manipulations. Yubao Zhang, Jidong Xiao, Shuai Hao 0001, Haining Wang 0001, Sencun Zhu, Sushil Jajodia |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2019 | Unveil the Hidden Presence: Characterizing the Backend Interface of Content Delivery NetworksabstractContent Delivery Networks (CDNs) are critical to today’s Internet ecosystem for delivering rich content to end-users. CDNs augment the Internet infrastructure by deploying geographically distributed edge servers, which play a dual role in CDNs: one as frontend interface to facilitate end-user’s proximal access and the other as backend interface to fetch content from origin servers. Previous research has well studied the frontend interface of CDNs, but no active approach has yet been provided to investigate the backend interface. In this paper, we first propose an active approach to measuring the backend interface of CDNs. Then, we present a large-scale measurement study to characterize the backend interface for three CDN platforms, so as to understand the CDN’s globally distributed infrastructure, which is essential to its performance and security. In particular, we discover the address space and operation patterns of the backend interface of CDNs. Then, by analyzing the backend addresses and their associated frontend addresses, we study their geolocation association. Furthermore, we issue traceroutes from origin servers to the backend addresses of the CDNs to analyze their performance implications, and perform port scanning on the backend addresses to investigate their security implications. Lin Jin, Shuai Hao 0001, Haining Wang 0001, Chase Cotton |
ICNP | 2 |
| 2018 | Your Remnant Tells Secret: Residual Resolution in DDoS Protection ServicesabstractThe increasing prevalence of Distributed Denial of Service (DDoS) attacks on the Internet has led to the wide adoption of DDoS Protection Service (DPS), which is typically provided by Content Delivery Networks (CDNs) and is integrated with CDN's security extensions. The effectiveness of DPS mainly relies on hiding the IP address of an origin server and rerouting the traffic to the DPS provider's distributed infrastructure, where malicious traffic can be blocked. In this paper, we perform a measurement study on the usage dynamics of DPS customers and reveal a new vulnerability in DPS platforms, called residual resolution, by which a DPS provider may leak origin IP addresses when its customers terminate the service or switch to other platforms, resulting in the failure of protection from future DPS providers as adversaries are able to discover the origin IP addresses and launch the DDoS attack directly to the origin servers. We identify that two major DPS/CDN providers, Cloudflare and Incapsula, are vulnerable to such residual resolution exposure, and we then assess the magnitude of the problem in the wild. Finally, we discuss the root causes of residual resolution and the practical countermeasures to address this security vulnerability. Lin Jin, Shuai Hao 0001, Haining Wang 0001, Chase Cotton |
DSN | 2 |
| 2018 | Privacy Risk Assessment on Email TrackingabstractToday's online marketing industry has widely employed email tracking techniques, such as embedding a tiny tracking pixel, to track email opens of potential customers and measure marketing effectiveness. However, email tracking could allow miscreants to collect metadata information associated with email reading without user awareness and then leverage the information for stealthy surveillance, which has raised serious privacy concerns. In this paper, we present an in-depth and comprehensive study on the privacy implications of email tracking. First, we develop an email tracking system and perform realworld tracking on hundreds of solicited crowdsourcing participants. We estimate the amount of privacy-sensitive information available from email reading, assess privacy risks of information leakage, and demonstrate how easy it is to launch a long-term targeted surveillance attack in real scenarios by simply sending an email with tracking capability. Second, we investigate the prevalence of email tracking through a large-scale measurement, which includes more than 44,000 email samples obtained over a period of seven years. Third, we conduct a user study to understand users' perception of privacy infringement caused by email tracking. Finally, we evaluate existing countermeasures against email tracking and propose guidelines for developing more comprehensive and fine-grained prevention solutions. Haitao Xu 0002, Shuai Hao 0001, Alparslan Sari, Haining Wang 0001 |
INFOCOM | 2 |
| 2018 | End-Users Get Maneuvered: Empirical Analysis of Redirection Hijacking in Content Delivery Networks
Shuai Hao 0001, Yubao Zhang, Haining Wang 0001, Angelos Stavrou |
USENIX Security Symposium | 1 |
| 2016 | All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS RecordsabstractIn a dangling DNS record (Dare), the resources pointed to by the DNS record are invalid, but the record itself has not yet been purged from DNS. In this paper, we shed light on a largely overlooked threat in DNS posed by dangling DNS records. Our work reveals that Dare can be easily manipulated by adversaries for domain hijacking. In particular, we identify three attack vectors that an adversary can harness to exploit Dares. In a large-scale measurement study, we uncover 467 exploitable Dares in 277 Alexa top 10,000 domains and 52 edu zones, showing that Dare is a real, prevalent threat. By exploiting these Dares, an adversary can take full control of the (sub)domains and can even have them signed with a Certificate Authority (CA). It is evident that the underlying cause of exploitable Dares is the lack of authenticity checking for the resources to which that DNS record points. We then propose three defense mechanisms to effectively mitigate Dares with little human effort. Daiping Liu, Shuai Hao 0001, Haining Wang 0001 |
CCS | 2 |
| 2015 | On the DNS Deployment of Modern Web ServicesabstractAccessing Internet services relies on the Domain Name System (DNS) for translating human-readable names to routable network addresses. At the bottom level of the DNS hierarchy, the authoritative DNS (ADNS) servers maintain the actual mapping records and answer the DNS queries. Today, the increasing use of upstream ADNS services (i.e., third-party ADNS-hosting services) and Infrastructure-as-a-Service (IaaS) clouds facilitates the establishment of web services, and has been fostering the evolution of the deployment of ADNS servers. To shed light on this trend, in this paper we present a large-scale measurement to study the ADNS deployment patterns of modern web services and examine the characteristics of different deployment styles, such as performance, life-cycle of servers, and availability. Furthermore, we focus specifically on the DNS deployment for subdomains hosted in IaaS clouds. Shuai Hao 0001, Haining Wang 0001, Angelos Stavrou, Evgenia Smirni |
ICNP | 1 |