Baojun Liu 0002

dblp:89/10754-2 · DBLP profile ↗
← Back
64ranked-venue papers
3as first author
50since 2021 · last 2026
0000-0002-9032-8063ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 50 · 3 first-author · 37 since 2021Computer networks · 10 · 9 since 2021Systems, architecture and hardware · 4 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 since 2021
YearPublicationVenuePosition
2026 CoordMail: Exploiting SMTP Timeout and Command Interaction to Coordinate Email Middleware for Convergence Amplification Attack
Ruixuan Li 0008, Chaoyi Lu, Baojun Liu 0002, Yanzhong Lin, Qingfeng Pan, Jun Shao 0001
NDSS3
2026 One Email, Many Faces: A Deep Dive into Identity Confusion in Email Aliases
Mengying Wu, Geng Hong, Jiatao Chen, Baojun Liu 0002, Mingxuan Liu 0006, Min Yang 0002
NDSS4
2026 Understanding the Status and Strategies of the Code Signing Abuse Ecosystem
Yiming Zhang 0009, Lingyun Ying, Mingming Zhang 0010, Baojun Liu 0002, Hai-Xin Duan, Zi-Quan You
NDSS5
2026 Breaking Free from Ivory Tower: Evaluating and Enhancing Real-world Chinese Underground Adversarial Jargon Detection
Zhifan Jiang, Mingxuan Liu 0006, Baojun Liu 0002
SP4
2026 Unveiling the Resilience of LLM-Enhanced Search Engines against Black-Hat SEO Manipulation
abstract
The emergence of Large Language Model-enhanced Search Engines (LLMSEs) has revolutionized information retrieval by integrating web-scale search capabilities with AI-powered summarization. While these systems demonstrate improved efficiency over traditional search engines, their security implications against well-established black-hat Search Engine Optimization (SEO) attacks remain unexplored. In this paper, we present the first systematic study of SEO attacks targeting LLMSEs. Specifically, we examine ten representative LLMSE products (e.g., ChatGPT, Gemini) and construct SEO-Bench, a benchmark comprising 1,000 real-world black-hat SEO websites, to evaluate both open- and closed-source LLMSEs. Our measurements show that LLMSEs mitigate over 99.78% of traditional SEO attacks, with the phase of retrieval serving as the primary filter, intercepting the vast majority of malicious queries. We further propose and evaluate seven LLMSEO attack strategies, demonstrating that off-the-shelf LLMSEs are vulnerable to LLMSEO attacks, i.e., rewritten-query stuffing and segmented texts double the manipulation rate compared to the baseline. This work offers the first in-depth security analysis of the LLMSE ecosystem, providing practical insights for building more resilient AI-driven search systems. We have responsibly reported the identified issues to major vendors.
Geng Hong, Mengying Wu, Mingxuan Liu 0006, Baojun Liu 0002, Mi Zhang 0001, Min Yang 0002
WWW7
2026 Characterizing Iran's Phased National Internet Shutdown in 2025: A Progressive and Distributed Action
Shibo Cui, Mingxuan Liu 0006, Baojun Liu 0002, Hai-Xin Duan, Ruixuan Li 0008, Chaoyi Lu, Jinghua Bai
WWW3
2026 Traffic Shadowing: A Global Investigation of Internet Traffic Observation and User Data Reutilization
Yunpeng Xing, Chaoyi Lu, Baojun Liu 0002, Ruixuan Li 0008, Hai-Xin Duan
IEEE Trans. Netw.3
2025 RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday Paradox
abstract
DNS cache poisoning is a persistent game of attack and defense, posing an enduring challenge for the DNS community. Significant efforts have been made to uncover, detect, and mitigate vulnerabilities that increase the risk of cache poisoning. However, no work has systematically revisited whether the original cache poisoning attack based on the Birthday Paradox remains effective. In this work, we introduce RebirthDay, a novel DNS cache poisoning attack targeting recursive resolvers and forwarders, reviving the classic DNS Birthday attack that no longer works since 2002. RebirthDay exploits newly uncovered, protocol-compliant vulnerabilities in DNS extension implementations to bypass the query aggregation mechanism intended to prevent DNS Birthday attacks that has not been well understood. We uncovered that 18 out of 22 mainstream DNS software are vulnerable due to weaknesses in the processing of a DNS extension (i.e., ECS option), specifically lacking or incorrectly implemented ECS coherence checks when handling DNS queries and responses, demonstrating the widespread susceptibility to RebirthDay. These flaws could be exploited to circumvent the query aggregation mechanism and launch RebirthDay attacks. Through comprehensive evaluation, we showed that RebirthDay attacks are highly practical and can have significant real-world impact, affecting 16 router vendors, 14 public DNS services, and 365K (15%) open DNS resolvers. We have reported the identified vulnerabilities to affected vendors and discussed mitigation solutions with them. To date, we have received acknowledgments from 8 vendors, including BIND, Unbound, PowerDNS, and Quad9, and have been assigned 50 CVE-ids. Our study emphasizes the need for greater attention to the importance of ECS verification and DNS extension implementations, revealing new security risks introduced by them.
Xiang Li 0108, Mingming Zhang 0010, Zuyao Xu, Fasheng Miao, Yuqi Qiu, Baojun Liu 0002, Jia Zhang 0004, Hai-Xin Duan, Zheli Liu, Yunhai Zhang, Dunqiu Fan
CCS6
2025 Exploring and Analyzing Cross Layer DoS Attack Against UDP-based Services on Linux
abstract
The layered architecture of the TCP/IP protocol stack enables protocol layers to be implemented independently and flexibly. However, this layered design introduces potential security risks when shared resources are not properly managed between different layers. This paper investigates a neglected cross-layer shared resource risk, termed SocketFilled, which exploits the insecure usage of the UDP send buffer at the transport layer by the link layer, resulting in the interruption of response packets from the upper application layer. To explore the root causes of cross-layer DoS vulnerabilities resulting from the implementation of the TCP/IP protocol stack, we systematically analyzed the protocol standards of address resolution and reviewed the implementation in mainstream open-source operating systems. Moreover, we conducted a comprehensive experimental evaluation of mainstream operating systems (e.g., Linux and FreeBSD) and UDP services (e.g., DNS and QUIC). The experimental results show that the latest version of Linux and UDP service software (e.g., BIND9, PowerDNS, and Nginx) are affected, causing significant packet loss and even complete service interruption. Then, we estimated the impact range of SocketFilled in the wild and demonstrated that 17.3% of open resolvers,54.3% of authoritative servers of the Tranco Top 100K domains, and 3.8% of these well-known domains' HTTP/3 servers are potentially affected, including Bing, Amazon, and Shopee, after excluding the influence of cloud servers. We have conducted responsible disclosure by reporting the vulnerability to the Linux community. Our research highlights the effectiveness of cross-layer mechanisms in DoS attacks and calls for heightened attention to the layered complexity of protocol stack implementations within the security community.
Dashuai Wu, Baojun Liu 0002, Xiang Li 0108, Eihal Alowaisheq, Hai-Xin Duan
CCS3
2025 Decoding DNS Centralization: Measuring and Identifying NS Domains Across Hosting Providers
abstract
The Domain Name System (DNS) is designed to be distributed, which aims to provide services with low latency and great reliability. However, after decades of development and changes in Internet business models, various aspects of the DNS ecosystem have begun to show signs of centralization. To investigate the centralization from the viewpoint of hosting service providers, we develop an automated method based on similarity among NS domains and co-hosting relationship to identify the hosting providers for authoritative name servers, so that we can identify hosting providers in DNS zone file to count the number of domains which a hosting provider host. This tool demonstrates greater accuracy than previous methods and our testing demonstrates the ability to identify hosting service providers for most domains in real-world measurement tasks. Using this tool, we conducted measurements on the dataset combined with .com, .net and .org TLD zones. We find that the top 10 providers collectively host over 54.19% of domains while top 100 providers host over 82.99% domains, which shows a significant level of centralization in hosting service providers within the DNS. Through an analysis of NSone’s NS domains and a statistical examination of top providers’ NS domains, we find that directly identifying the base domain as the provider is inappropriate. Furthermore, we discover relationships among hosting providers and between hosting providers and infrastructure that are more complex than previously anticipated. Finally, based on our research findings, we offer corresponding suggestions to mitigate the continued development of centralization.
Qihang Peng, Mingming Zhang 0010, Deliang Chang, Jia Zhang 0004, Baojun Liu 0002, Hai-Xin Duan
DSN5
2025 Email Cloaking: Deceiving Users and Spam Email Detectors with Invisible HTML Settings
Bingyang Guo, Mingxuan Liu 0006, Yihui Ma, Ruixuan Li 0008, Fan Shi 0003, Min Zhang 0054, Baojun Liu 0002, Chengxi Xu, Hai-Xin Duan, Geng Hong, Min Yang 0002, Qingfeng Pan
ESORICS (4)7
2025 Understanding and Characterizing Intermediate Paths of Email Delivery: The Hidden Dependencies
abstract
In the cloud era, hosting-based email services have become a common business model. Various entities can participate in the email delivery process. However, the intermediate paths of email delivery have received little attention. In particular, the vulnerabilities and centralization of email intermediate paths have already posed real-world security threats. This paper conducts the first systematic analysis of intermediate paths of email delivery, aiming to understand dependence patterns and characterize the centralization. In collaboration with a large email service provider, we collected Received headers from email reception logs spanning nine months and reconstructed the complete intermediate paths of 105M clean emails. Our results reveal that Microsoft is the dominant provider of intermediate paths, participating in 66.4% of emails. We find that 86.9M (82.7%) emails rely on third-party providers in intermediate paths, and 9.1M (8.7%) paths involve multiple providers. Email signature providers frequently appear in cross-vendor intermediate paths. In addition, we reveal significant differences in the regional dependencies and centralization of email intermediate paths across countries and continents. The centralization observed in email intermediate paths also differs from incoming and outgoing servers. We hope our work prompts more attention to email intermediate paths to enhance the security of the email ecosystem.
Ruixuan Li 0008, Chaoyi Lu, Baojun Liu 0002, Yanzhong Lin, Hai-Xin Duan, Qingfeng Pan, Jun Shao 0001
IMC3
2025 Dive into the Cloud: Unveiling the (Ab)Usage of Serverless Cloud Function in the Wild
abstract
Serverless cloud functions transfer server management responsibilities to service providers, offering scalability and cost-efficiency. This convenience not only facilitates normal activities but also raises abuse concerns. So far, public understanding of real-world cloud functions remains limited. To fill this gap, we conducted an in-depth measurement study to uncover their practical usage and abuse. Through empirical analysis of nine leading providers (e.g., AWS, Tencent), we identified 531,089 function domains from a passive DNS dataset spanning April 2022 to March 2024. We first investigated the usage status of serverless cloud functions, showing the different practices between providers. Additionally, based on active requests to these functions, we pointed out privacy risks of unauthorized access and identified four abuse types, including covert C2 communication, hosting malicious websites, promoting illicit services, and abusing egress nodes as IP proxies. Alarmingly, 4.89% of cloud functions are being abused, with over 614k invocations recorded. Only four abused functions were flagged by existing threat intelligence systems, indicating critical gaps in security monitoring for serverless environments. Our work offers insights into the serverless cloud ecosystem and provides recommendations for better management. With responsible disclosure, we hope to raise awareness and improve protective measures against abuses among cloud function providers.
Yijing Liu 0007, Mingxuan Liu 0006, Yiming Zhang 0009, Baojun Liu 0002, Jia Zhang 0004, Geng Hong, Hai-Xin Duan, Min Yang 0002
IMC4
2025 Poster: RMap: Uncovering Risky DNS Resolution Chains and Misconfigurations
abstract
In recent years, large-scale network outages caused by DNS misconfigurations have become increasingly common. The intricate inter-domain dependencies, along with emerging mechanisms (Such as DNSSEC, EDNS, and 0x20), have made DNS resolution increasingly complex and fault localization more challenging. We present RMap, a tool that rapidly probes all potential resolution chains of a domain, reveals its resolution dependency topology, and detects security risks. We experimentally demonstrate the effectiveness of RMap and its broad applicability. Our findings reveal that domain configurations in real-world environments remain concerning, with potential issues observed even in several well-known top-level domains. RMap is avaliable in https://github.com/ahlien/rmap.
Fasheng Miao, Shuying Zhuang, Xiang Li 0108, Changqing An, Deliang Chang, Baojun Liu 0002, Jia Zhang 0004, Jilong Wang 0001
IMC6
2025 Chaos in the Chain: Evaluate Deployment and Construction Compliance of Web PKI Certificate Chain
abstract
Transport Layer Security (TLS) is a cornerstone to secure Internet communications. It requires proper deployment and validation of certificate chains. During validation, clients must first construct the chain from server-provided certificates. However, existing research often integrates chain construction into the broader validation process, lacking independent analysis of this crucial step. This paper presents the first systematic assessment of certificate chain construction, covering server-side deployment compliance and client-side capabilities. On the server side, we summarized structural requirements from RFC standards and evaluated real-world website compliance. We found that approximately 3% of Tranco Top 1M domains have deployed non-compliant chains, with common issues including reversed sequences and incomplete chains. The compliance would be influenced by HTTP server and Certificate Authority checks and guidance during the configuration process. On the client side, we evaluated 9 types of chain-building capabilities across 8 mainstream TLS implementations, uncovering prevalent deficiencies like inadequate backtracking and difficulties with long chains. These deficiencies could compromise TLS security, causing a fallback to insecure HTTP or making the service unavailable. Our findings highlight critical gaps in current certificate chain practices. Based on our findings, we also propose recommendations for improving the deployment and construction of certificate chains.
Yiming Zhang 0009, Baojun Liu 0002, Mingming Zhang 0010, Hai-Xin Duan
IMC3
2025 Analyzing Compliance and Complications of Integrating Internationalized X.509 Certificates
abstract
The global PKI supports the issuance of Unicerts, which are X.509 certificates that integrate internationalized content such as IDNs and multilingual text. This integration introduces complexity in Unicert issuance and usage. Past incidents showed that poor Unicode handling can cause security risks, including spoofing and remote code execution, yet threats specific to PKI and Unicerts remain underexplored. This paper presents the first large-scale study of Unicerts, examining both issuance and parsing compliance. By analyzing 34.8 million Unicerts from CT logs and 9 mainstream TLS libraries, we found the PKI ecosystem struggles with adopting Unicode. On the issuing side, 373 issuers produced 249.3K (0.72%) noncompliant Unicerts due to weak validation on character ranges, normalization, and formatting, of which 65.3% arise from publicly trusted CAs. These issues arise from overly complex standard requirements. On the parsing side, TLS libraries like GnuTLS and PyOpenSSL exhibited issues in decoding and handling special characters, such as incompatible decoding and improper escaping, which could lead to incorrect entity extraction or subfield forgery. We further empirically identified threat surfaces, including user spoofing, CT monitor misleading, and traffic obfuscation. Finally, we analyzed root causes and proposed recommendations to enhance Unicert compliance in the global PKI ecosystem.
Mingming Zhang 0010, Jinfeng Guo, Yiming Zhang 0009, Shenglin Zhang, Baojun Liu 0002, Xiang Li 0108, Hai-Xin Duan
IMC5
2025 HADES Attack: Understanding and Evaluating Manipulation Risks of Email Blocklists
Ruixuan Li 0008, Chaoyi Lu, Baojun Liu 0002, Geng Hong, Hai-Xin Duan, Yanzhong Lin, Qingfeng Pan, Min Yang 0002, Jun Shao 0001
NDSS3
2025 Revealing the Black Box of Device Search Engine: Scanning Assets, Strategies, and Ethical Consideration
Mengying Wu, Geng Hong, Shujun Tang, Youhao Li, Baojun Liu 0002, Hai-Xin Duan, Min Yang 0002
NDSS7
2025 Beyond Exploit Scanning: A Functional Change-Driven Approach to Remote Software Version Identification
Mengying Wu, Geng Hong, Baichao An, Mingxuan Liu 0006, Lei Zhang 0096, Baojun Liu 0002, Hai-Xin Duan, Min Yang 0002
USENIX Security Symposium7
2025 NOKEScam: Understanding and Rectifying Non-Sense Keywords Spear Scam in Search Engines
Mingxuan Liu 0006, Lijie Wu, Baojun Liu 0002, Geng Hong, Yiming Zhang 0009, Jia Zhang 0004, Hai-Xin Duan, Min Zhang 0054, Fan Shi 0003, Min Yang 0002
USENIX Security Symposium4
2025 Misty Registry: An Empirical Study of Flawed Domain Registry Operation
Mingming Zhang 0010, Baojun Liu 0002, Hai-Xin Duan, Min Zhang 0054, Fan Shi 0003, Chengxi Xu
USENIX Security Symposium3
2025 You Can't Eat Your Cake and Have It Too: The Performance Degradation of LLMs with Jailbreak Defense
abstract
With the rise of generative large language models (LLMs) like LLaMA and ChatGPT, these models have significantly transformed daily life and work by providing advanced insights. However, as jailbreak attacks continue to circumvent built-in safety mechanisms, exploiting carefully crafted scenarios or tokens, the safety risks of LLMs have come into focus. While numerous defense strategies-such as prompt detection, modification, and model fine-tuning-have been proposed to counter these attacks, a critical question arises: do these defenses compromise the utility and usability of LLMs for legitimate users? Existing research predominantly focuses on the effectiveness of defense strategies without thoroughly examining their impact on performance, leaving a gap in understanding the trade-offs between LLM safety and performance.
Wuyuao Mai, Geng Hong, Xudong Pan, Baojun Liu 0002, Yuan Zhang 0009, Hai-Xin Duan, Min Yang 0002
WWW5
2024 Bounce in the Wild: A Deep Dive into Email Delivery Failures from a Large Email Service Provider
abstract
Abnormal email bounces seriously disrupt user lives and company transactions. Proliferating security protocols and protection strategies have made email delivery increasingly complex. A natural question is how and why email delivery fails in the wild. Filling this knowledge gap requires a representative global email delivery dataset, which is rarely disclosed by email service providers (ESPs).
Ruixuan Li 0008, Shaodong Xiao, Baojun Liu 0002, Yanzhong Lin, Hai-Xin Duan, Qingfeng Pan, Jianjun Chen 0005, Jia Zhang 0004, Ximeng Liu, Xiuqi Lu, Jun Shao 0001
IMC3
2024 Yesterday Once More: Global Measurement of Internet Traffic Shadowing Behaviors
abstract
We present a global, large-scale measurement of Internet traffic shadowing, a less-studied yet covert format of on-path manipulation. As part of pervasive monitoring, data within packets is silently observed, retained, and then leveraged to produce additional, unsolicited requests. To depict the landscape of such behaviors, we generate a collection of decoy traffic that lures on-path exhibitors, spread them via 4,364 vantage points recruited from commercial VPN providers, and capture unsolicited requests triggered by them. We find traffic shadowing against DNS, HTTP, and TLS protocols; DNS queries to several public resolvers are most susceptible, by being observed on a wide range of Internet paths. Through hop-by-hop tracerouting, we find observers of DNS queries associated with destinations, while HTTP messages are mostly observed on the wire. User data can be retained for long, e.g., over 10 days, and can be leveraged for more than once. While a notable portion of unsolicited requests originate from addresses labeled by blocklists, we find most of them are performing reconnaissance, and we see no evidence of exploits attempted in the collected traffic.
Yunpeng Xing, Chaoyi Lu, Baojun Liu 0002, Hai-Xin Duan, Junzhe Sun, Zhou Li 0001
IMC3
2024 Understanding the Implementation and Security Implications of Protective DNS Services
Mingxuan Liu 0006, Yiming Zhang 0009, Xiang Li 0108, Chaoyi Lu, Baojun Liu 0002, Hai-Xin Duan
NDSS5
2024 TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed Packets
abstract
DNS can be compared to a game of chess in that its rules are simple, yet the possibilities it presents are endless. While the fundamental rules of DNS are straightforward, DNS implementations can be extremely complex. In this study, we intend to explore the complexities and vulnerabilities in DNS response pre-processing by systematically analyzing DNS RFCs and DNS software implementations. We present the discovery of three new types of logic vulnerabilities, leading to the proposal of three novel attacks, namely the TuDoor attack. These attacks involve the use of malformed DNS response packets to carry out DNS cache poisoning, denial- of-service, and resource consuming attacks. By performing comprehensive experiments, we demonstrate the attack’s feasibility and significant real-world impacts of TUDOOR. In total, 24 mainstream DNS software, including BIND, PowerDNS, and Microsoft DNS, are affected by TuDoor. Attackers can instigate cache poisoning and denial-of-service attacks against vulnerable resolvers using a handful of crafted packets within 1 second or circumvent the query limit to deplete resolution resources (e.g., CPU). Besides, to determine the vulnerable resolver population in the wild, we collect and evaluate 16 popular Wi-Fi routers, 6 prevalent router OSes, 42 public DNS services, and around 1.8M open DNS resolvers. Our measurement results indicate that TUDOOR could exploit 7 routers (OSes), 18 public DNS services, and 424,652 (23.1%) open DNS resolvers. Following the best practice of responsible disclosure, we have reported these vulnerabilities to all affected vendors, and 18 of them, including BIND, Chrome, Cloudflare, and Microsoft, have acknowledged our findings and discussed mitigation solutions with us. Furthermore, 33 CVE IDs are assigned to our discovered vulnerabilities, and we provide an online detection tool as one of the mitigation measures. Our research highlights the urgent need for standardization of DNS response pre-processing logic to enhance the security of DNS.
Xiang Li 0108, Wei Xu 0064, Baojun Liu 0002, Mingming Zhang 0010, Zhou Li 0001, Jia Zhang 0004, Deliang Chang, Chuhan Wang 0001, Jianjun Chen 0005, Hai-Xin Duan, Qi Li 0002
SP3
2024 Tickets or Privacy? Understand the Ecosystem of Chinese Ticket Grabbing Apps
Yijing Liu 0007, Yiming Zhang 0009, Baojun Liu 0002, Hai-Xin Duan, Mingxuan Liu 0006, Ruixuan Li 0008
USENIX Security Symposium3
2024 Rethinking the Security Threats of Stale DNS Glue Records
Baojun Liu 0002, Hai-Xin Duan, Min Zhang 0054, Xiang Li 0108, Fan Shi 0003, Chengxi Xu, Eihal Alowaisheq
USENIX Security Symposium2
2024 Into the Dark: Unveiling Internal Site Search Abused for Black Hat SEO
Mingxuan Liu 0006, Baojun Liu 0002, Yiming Zhang 0009, Hai-Xin Duan, Min Zhang 0054, Fan Shi 0003
USENIX Security Symposium3
2024 Cross the Zone: Toward a Covert Domain Hijacking via Shared DNS Infrastructure
Mingming Zhang 0010, Baojun Liu 0002, Jia Zhang 0004, Hai-Xin Duan, Min Zhang 0054, Fan Shi 0003, Chengxi Xu
USENIX Security Symposium3
2024 A Worldwide View on the Reachability of Encrypted DNS Services
abstract
To protect user DNS privacy, four DNS over Encryption (DoE) protocols have been proposed, including DNS over TLS (DoT), DNS over HTTPS (DoH), DNS over QUIC (DoQ), and DNS over HTTP/3 (DoH3). Ensuring reachability stands as a prominent prerequisite for the proper functionality of these DoE protocols, driving considerable efforts in this domain. However, existing studies predominantly concentrate on a limited number of DoT/DoH domains or employ a restricted subset of vantage points (VPs).
Ruixuan Li 0008, Baojun Liu 0002, Chaoyi Lu, Hai-Xin Duan, Jun Shao 0001
WWW2
2024 Investigating Deployment Issues of DNS Root Server Instances From a China-Wide View
abstract
DNS root servers are the starting point of most DNS queries. To ensure their security and stability, multiple anycast instances are operated worldwide, and new root instances have been rapidly deployed in recent years. Apart from authorized instances managed by Root Server System, some networks equip unauthorized instances to hijack queries from clients. Despite various root instances handling queries within their residing networks, few studies have focused on the deployment issues of these instances. In this paper, we provide the first study to reveal the deployment issues of root instances from a nationwide view. With the support of 7,860 vantage points, we utilized a suite of methodologies to identify the deployment of unauthorized instances. 54 vantage points witnessed the evidence of unauthorized instances, and 70.4% of them further observed security issues of unauthorized instances, including DoS, unavailability of DNSSEC validation, and vulnerable DNS software. Additionally, we utilized the side-channel information of censorship mechanisms to measure the catchment area of authorized instances. We found that most authorized instances in the Chinese mainland serve with limited catchment areas due to restricted BGP policies. Through discussions with ISPs and network operators, we make recommendations to improve the deployment status of different root instances.
Fenglu Zhang, Baojun Liu 0002, Chaoyi Lu, Yunpeng Xing, Hai-Xin Duan, Ying Liu 0024, Liyuan Chang
IEEE Trans. Dependable Secur. Comput.2
2023 TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS Amplifiers
abstract
In this paper, we present a new DNS amplification attack, named TsuKing. Instead of exploiting individual DNS resolvers independently to achieve an amplification effect, TsuKing deftly coordinates numerous vulnerable DNS resolvers and crafted queries together to form potent DoS amplifiers. We demconstrate that with TsuKing, an initial small amplification factor can inrease exponentially through the internal layers of coordinated amplifiers, resulting in an extremely powerful amplification attack. TsuKing has three variants, including DNSRetry, DNSChain, and DNSLoop, all of which exploit a suite of inconsistent DNS implementations to achieve enormous amplification effect. With comprehensive measurements, we found that about 14.5% of 1.3M open DNS resolvers are potentially vulnerable to TsuKing. Real-world controlled evaluations indicated that attackers can achieve a packet amplification factor of at least 3,700X (DNSChain). We have reported vulnerabilities to affected vendors and provided them with mitigation recommendations. We have received positive responses from 6 vendors, including Unbound, MikroTik, and AliDNS, and 3 CVEs were assigned. Some of them are implementing our recommendations.
Wei Xu 0064, Xiang Li 0108, Chaoyi Lu, Baojun Liu 0002, Hai-Xin Duan, Jia Zhang 0004, Jianjun Chen 0005, Tao Wan 0004
CCS4
2023 Under the Dark: A Systematical Study of Stealthy Mining Pools (Ab)use in the Wild
abstract
Cryptocurrency mining is a crucial operation in blockchains, and miners often join mining pools to increase their chances of earning rewards. However, the energy-intensive nature of PoW cryptocurrency mining has led to its ban in New York State of the United States, China, and India. As a result, mining pools, serving as a central hub for mining activities, have become prime targets for regulatory enforcement. Furthermore, cryptojacking malware refers to self-owned stealthy mining pools to evade detection techniques and conceal profit wallet addresses. However, no systematic research has been conducted to analyze it, largely due to a lack of full understanding of the protocol implementation, usage, and port distribution of the stealth mining pool.
Zhenrui Zhang, Geng Hong, Xiang Li 0108, Zhuoqun Fu, Jia Zhang 0004, Mingxuan Liu 0006, Chuhan Wang 0001, Jianjun Chen 0005, Baojun Liu 0002, Hai-Xin Duan, Chao Zhang 0008, Min Yang 0002
CCS9
2023 Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS Servers
abstract
Authoritative nameservers are delegated to provide the final resource record. Since the security and robustness of DNS are critical to the general operation of the Internet, domain name owners are required to deploy multiple candidate nameservers for traffic load balancing. Once the load balancing mechanism is compromised, an adversary can manipulate a large number of legitimate DNS requests to a specified candidate nameserver. As a result, it may not only bypass the defense mechanisms used to filter malicious traffic that can overload the victim nameserver, but also lowers the bar for DNS traffic hijacking and cache poisoning attacks.
Fenglu Zhang, Baojun Liu 0002, Eihal Alowaisheq, Jianjun Chen 0005, Chaoyi Lu, Linjian Song, Ying Liu 0024, Hai-Xin Duan, Min Yang 0002
CCS2
2023 Wolf in Sheep's Clothing: Evaluating Security Risks of the Undelegated Record on DNS Hosting Services
abstract
Leveraging DNS for covert communications is appealing since most networks allow DNS traffic, especially the ones directed toward renowned DNS hosting services. Unfortunately, most DNS hosting services overlook domain ownership verification, enabling miscreants to host undelegated DNS records of a domain they do not own. Consequently, miscreants can conduct covert communication through such undelegated records for whitelisted domains on reputable hosting providers. In this paper, we shed light on the emerging threat posed by undelegated records and demonstrate their exploitation in the wild. To the best of our knowledge, this security risk has not been studied before.
Fenglu Zhang, Baojun Liu 0002, Eihal Alowaisheq, Lingyun Ying, Xiang Li 0108, Zaifeng Zhang, Ying Liu 0024, Hai-Xin Duan, Min Zhang 0054
IMC3
2023 Ghost Domain Reloaded: Vulnerable Links in Domain Name Delegation and Revocation
Xiang Li 0108, Baojun Liu 0002, Xuesong Bai, Mingming Zhang 0010, Qifan Zhang 0002, Zhou Li 0001, Hai-Xin Duan, Qi Li 0002
NDSS2
2023 Temporal CDN-Convex Lens: A CDN-Assisted Practical Pulsing DDoS Attack
Run Guo, Jianjun Chen 0005, Keran Mu, Baojun Liu 0002, Xiang Li 0108, Chao Zhang 0008, Hai-Xin Duan
USENIX Security Symposium5
2023 The Maginot Line: Attacking the Boundary of DNS Caching Protection
Xiang Li 0108, Chaoyi Lu, Baojun Liu 0002, Qifan Zhang 0002, Zhou Li 0001, Hai-Xin Duan, Qi Li 0002
USENIX Security Symposium3
2022 Exploring the Characteristics and Security Risks of Emerging Emoji Domain Names
Mingxuan Liu 0006, Yiming Zhang 0009, Baojun Liu 0002, Hai-Xin Duan
ESORICS (3)3
2022 Trampoline Over the Air: Breaking in IoT Devices Through MQTT Brokers
abstract
MQTT is widely adopted by IoT devices because it allows for the most efficient data transfer over a variety of communication lines. The security of MQTT has received increasing attention in recent years, and several studies have demonstrated the configurations of many MQTT brokers are insecure. Adversaries are allowed to exploit vulnerable brokers and publish malicious messages to subscribers. However, little has been done to understanding the security issues on the device side when devices handle unauthorized MQTT messages. To fill this research gap, we propose a fuzzing framework named ShadowFuzzer to find client-side vulnerabilities when processing incoming MQTT messages. To avoiding ethical issues, ShadowFuzzer redirects traffic destined for the actual broker to a shadow broker under the control to monitor vulnerabilities. We select 15 IoT devices communicating with vulnerable brokers and leverage ShadowFuzzer to find vulnerabilities when they parse MQTT messages. For these devices, ShadowFuzzer reports 34 zero-day vulnerabilities in 11 devices. We evaluated the exploitability of these vulnerabilities and received a total of 44,000 USD bug bounty rewards. And 16 CVE/CNVD/CN-NVD numbers have been assigned to us.
Huikai Xu, Qinsheng Hou, Zhenbang Ma, Hai-Xin Duan, Jianwei Zhuge, Baojun Liu 0002
EuroS&P9
2022 PMTUD is not Panacea: Revisiting IP Fragmentation Attacks against TCP
Xuewei Feng, Qi Li 0002, Kun Sun 0001, Ke Xu 0002, Baojun Liu 0002, Qiushi Yang, Hai-Xin Duan, Zhiyun Qian
NDSS5
2022 Measuring the Practical Effect of DNS Root Server Instances: A China-Wide Case Study
Fenglu Zhang, Chaoyi Lu, Baojun Liu 0002, Hai-Xin Duan, Ying Liu 0024
PAM3
2022 A Large-scale and Longitudinal Measurement Study of DKIM Deployment
Chuhan Wang 0001, Kaiwen Shen, Minglei Guo, Mingming Zhang 0010, Jianjun Chen 0005, Baojun Liu 0002, Hai-Xin Duan, Yanzhong Lin, Qingfeng Pan
USENIX Security Symposium7
2022 Building an Open, Robust, and Stable Voting-Based Domain Top List
Qinge Xie, Shujun Tang, Qingran Lin, Baojun Liu 0002, Hai-Xin Duan, Frank Li 0001
USENIX Security Symposium5
2021 Detecting and Characterizing SMS Spearphishing Attacks
abstract
Although spearphishing is a well-known security issue and has been widely researched, it is still an evolving threat with emerging forms. In recent years, Short Message Service (SMS) has been revealed as a new distribution channel for spearphishing messages, which already has caused a serious impact in the real world, but has not yet attracted enough attention from the academic community. In this paper, we report the first systemic study to spotlight this emerging threat, SMS spearphishing attack. Through cooperating with a leading security vendor, we obtain 31.96M real-world spam messages that span three months. We design and implement a novel NLP-based detection algorithm, and uncover 90,801 spearphishing messages on the entire dataset. And then, a large-scale measurement was performed on the detected messages to reveal and understand the characteristics of SMS spearphishing attack. Our findings are multi-fold. We discover that SMS spearphishing has a significant negative impact on the real-world, and a large number of victims have been affected. And the distribution of active illicit types between spearphishing message and common spam is quite inconsistent. At the micro-level, to evade detection and increase the probability of success, adversary campaigns have evolved a set of sophisticated strategies. Our research highlights the impact of SMS spearphishing attack is prominent. We call on different communities to work together to mitigate this emerging security threat.
Mingxuan Liu 0006, Yiming Zhang 0009, Baojun Liu 0002, Zhou Li 0001, Hai-Xin Duan, Donghong Sun
ACSAC3
2021 Rusted Anchors: A National Client-Side View of Hidden Root CAs in the Web PKI Ecosystem
abstract
HTTPS secures communications in the web and heavily relies on the Web PKI for authentication. In the Web PKI, Certificate Authorities (CAs) are organizations that provide trust and issue digital certificates. Web clients rely on public root stores maintained by operating systems or browsers, with hundreds of audited CAs as trust anchors. However, as reported by security incidents, hidden root CAs beyond the public root programs have been imported into local root stores, which allows adversaries to gain trust from web clients.
Yiming Zhang 0009, Baojun Liu 0002, Chaoyi Lu, Zhou Li 0001, Hai-Xin Duan, Zaifeng Zhang
CCS2
2021 Fast IPv6 Network Periphery Discovery and Security Implications
abstract
Numerous measurement researches have been performed to discover the IPv4 network security issues by leveraging the fast Internet-wide scanning techniques. However, IPv6 brings the 128-bit address space and renders brute-force network scanning impractical. Although significant efforts have been dedicated to enumerating active IPv6 hosts, limited by technique efficiency and probing accuracy, large-scale empirical measurement studies under the increasing IPv6 networks are infeasible now. To fill this research gap, by leveraging the extensively adopted IPv6 address allocation strategy, we propose a novel IPv6 network periphery discovery approach. Specifically, XMap, a fast network scanner, is developed to find the periphery, such as a home router. We evaluate it on twelve prominent Internet service providers and harvest 52M active peripheries. Grounded on these found devices, we explore IPv6 network risks of the unintended exposed security services and the flawed traffic routing strategies. First, we demonstrate the unintended exposed security services in IPv6 networks, such as DNS, and HTTP, have become emerging security risks by analyzing 4.7M peripheries. Second, by inspecting the periphery's packet routing strategies, we present the flawed implementations of IPv6 routing protocol affecting 5.8M router devices. Attackers can exploit this common vulnerability to conduct effective routing loop attacks, inducing DoS to the ISP's and home routers with an amplification factor of \gt 200. We responsibly disclose those issues to all involved vendors and ASes and discuss mitigation solutions. Our research results indicate that the security community should revisit IPv6 network strategies immediately.
Xiang Li 0108, Baojun Liu 0002, Hai-Xin Duan, Qi Li 0002, Youjun Huang
DSN2
2021 From WHOIS to WHOWAS: A Large-Scale Measurement Study of Domain Registration Privacy under the GDPR
Chaoyi Lu, Baojun Liu 0002, Yiming Zhang 0009, Zhou Li 0001, Fenglu Zhang, Hai-Xin Duan, Ying Liu 0024, Joann Qiongna Chen, Jinjin Liang, Zaifeng Zhang, Shuang Hao 0001, Min Yang 0002
NDSS2
2021 Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing Attacks
Kaiwen Shen, Chuhan Wang 0001, Minglei Guo, Chaoyi Lu, Baojun Liu 0002, Shuang Hao 0001, Hai-Xin Duan, Qingfeng Pan, Min Yang 0002
USENIX Security Symposium6
2020 Lies in the Air: Characterizing Fake-base-station Spam Ecosystem in China
abstract
Fake base station (FBS) has been exploited by criminals to attack mobile users by spamming fraudulent messages for over a decade. Despite that prior work has proposed several techniques to mitigate this issue, FBS spam is still a long-standing challenging issue in some countries, such as China, and causes billions of dollars of financial loss every year. Therefore, understanding and exploring the thematic strategies in the FBS spam ecosystem at a large scale would improve the defense mechanisms.
Yiming Zhang 0009, Baojun Liu 0002, Chaoyi Lu, Zhou Li 0001, Hai-Xin Duan, Shuang Hao 0001, Mingxuan Liu 0006, Ying Liu 0024
CCS2
2020 Talking with Familiar Strangers: An Empirical Study on HTTPS Context Confusion Attacks
abstract
HTTPS is principally designed for secure end-to-end communication, which adds confidentiality and integrity to sensitive data transmission. While several man-in-the-middle attacks (e.g., SSL Stripping) are available to break the secured connections, state-of-the-art security policies (e.g., HSTS) have significantly increased the cost of successful attacks. However, the TLS certificates shared by multiple domains make HTTPS hijacking attacks possible again.
Mingming Zhang 0010, Kaiwen Shen, Ziqiao Kong, Chaoyi Lu, Yu Wang 0288, Hai-Xin Duan, Shuang Hao 0001, Baojun Liu 0002, Min Yang 0002
CCS9
2020 CDN Backfired: Amplification Attacks Based on HTTP Range Requests
abstract
Content Delivery Networks (CDNs) aim to improve network performance and protect against web attack traffic for their hosting websites. And the HTTP range request mechanism is majorly designed to reduce unnecessary network transmission. However, we find the specifications failed to consider the security risks introduced when CDNs meet range requests. In this study, we present a novel class of HTTP amplification attack, Range-based Amplification (RangeAmp) Attacks. It allows attackers to massively exhaust not only the outgoing bandwidth of the origin servers deployed behind CDNs but also the bandwidth of CDN surrogate nodes. We examined the RangeAmp attacks on 13 popular CDNs to evaluate the feasibility and real-world impacts. Our experiment results show that all these CDNs are affected by the RangeAmp attacks. We also disclosed all security issues to affected CDN vendors and already received positive feedback from 12 vendors.
Kaiwen Shen, Run Guo, Baojun Liu 0002, Jia Zhang 0004, Hai-Xin Duan, Shuang Hao 0001, Xiarun Chen
DSN4
2020 CDN Judo: Breaking the CDN DoS Protection with Itself
Run Guo, Baojun Liu 0002, Shuang Hao 0001, Jia Zhang 0004, Hai-Xin Duan, Kaiwen Shen, Jianjun Chen 0005, Ying Liu 0024
NDSS3
2020 Poison Over Troubled Forwarders: A Cache Poisoning Attack Targeting DNS Forwarding Devices
Chaoyi Lu, Qiushi Yang, Dongjie Zhou, Baojun Liu 0002, Keyu Man, Shuang Hao 0001, Hai-Xin Duan, Zhiyun Qian
USENIX Security Symposium6
2019 TraffickStop: Detecting and Measuring Illicit Traffic Monetization Through Large-Scale DNS Analysis
abstract
Illicit traffic monetization is a type of Internet fraud that hijacks users' web requests and reroutes them to a traffic network (e.g., advertising network), in order to unethically gain monetary rewards. Despite its popularity among Internet fraudsters, our understanding of the problem is still limited. Since the behavior is highly dynamic (can happen at any place including client-side, transport-layer and server-side) and selective (could target a regional network), prior approaches like active probing can only reveal a small piece of the entire ecosystem. So far, questions including how this fraud works at a global scale and what fraudsters' preferred methods are, still remain unanswered. To fill the missing pieces, we developed TraffickStop the first system that can detect this fraud passively. Our key contribution is a novel algorithm that works on large-scale DNS logs and efficiently discovers abnormal domain correlations. TraffickStop enables the first landscape study of this fraud, and we have some interesting findings. By analyzing over 231 billion DNS logs of two weeks, we discovered 1,457 fraud sites. Regarding its scale, the fraud sites receive more than 53 billion DNS requests within one year, and a company could lose up to 53K dollars per day due to fraud traffic. We also discovered two new strategies that are leveraged by fraudsters to evade inspection. Our work provides new insights into illicit traffic monetization, raises its public awareness, and contributes to a better understanding and ultimate elimination of this threat.
Baojun Liu 0002, Zhou Li 0001, Peiyuan Zong, Chaoyi Lu, Hai-Xin Duan, Ying Liu 0024, Sumayah A. Alrwais, XiaoFeng Wang 0001, Shuang Hao 0001, Yaoqi Jia, Yiming Zhang 0009, Kai Chen 0012, Zaifeng Zhang
EuroS&P1
2019 An End-to-End, Large-Scale Measurement of DNS-over-Encryption: How Far Have We Come?
abstract
DNS packets are designed to travel in unencrypted form through the Internet based on its initial standard. Recent discoveries show that real-world adversaries are actively exploiting this design vulnerability to compromise Internet users' security and privacy. To mitigate such threats, several protocols have been proposed to encrypt DNS queries between DNS clients and servers, which we jointly term as DNS-over-Encryption. While some proposals have been standardized and are gaining strong support from the industry, little has been done to understand their status from the view of global users.
Chaoyi Lu, Baojun Liu 0002, Zhou Li 0001, Shuang Hao 0001, Hai-Xin Duan, Mingming Zhang 0010, Chunying Leng, Ying Liu 0024, Zaifeng Zhang
Internet Measurement Conference2
2019 Cracking the Wall of Confinement: Understanding and Analyzing Malicious Domain Take-downs
Eihal Alowaisheq, Peng Wang 0088, Sumayah A. Alrwais, Xiaojing Liao, XiaoFeng Wang 0001, Tasneem Alowaisheq, Xianghang Mi, Baojun Liu 0002
NDSS9
2019 TL;DR Hazard: A Comprehensive Study of Levelsquatting Scams
Kun Du, Zhou Li 0001, Hai-Xin Duan, Shuang Hao 0001, Baojun Liu 0002, Yuxiao Ye, Mingxuan Liu 0006, XiaoDong Su, Zhifeng Geng, Zaifeng Zhang, Jinjin Liang
SecureComm (2)6
2019 Resident Evil: Understanding Residential IP Proxy as a Dark Service
abstract
An emerging Internet business is residential proxy (RESIP) as a service, in which a provider utilizes the hosts within residential networks (in contrast to those running in a datacenter) to relay their customers' traffic, in an attempt to avoid server- side blocking and detection. With the prominent roles the services could play in the underground business world, little has been done to understand whether they are indeed involved in Cybercrimes and how they operate, due to the challenges in identifying their RESIPs, not to mention any in-depth analysis on them. In this paper, we report the first study on RESIPs, which sheds light on the behaviors and the ecosystem of these elusive gray services. Our research employed an infiltration framework, including our clients for RESIP services and the servers they visited, to detect 6 million RESIP IPs across 230+ countries and 52K+ ISPs. The observed addresses were analyzed and the hosts behind them were further fingerprinted using a new profiling system. Our effort led to several surprising findings about the RESIP services unknown before. Surprisingly, despite the providers' claim that the proxy hosts are willingly joined, many proxies run on likely compromised hosts including IoT devices. Through cross-matching the hosts we discovered and labeled PUP (potentially unwanted programs) logs provided by a leading IT company, we uncovered various illicit operations RESIP hosts performed, including illegal promotion, Fast fluxing, phishing, malware hosting, and others. We also reverse engi- neered RESIP services' internal infrastructures, uncovered their potential rebranding and reselling behaviors. Our research takes the first step toward understanding this new Internet service, contributing to the effective control of their security risks.
Xianghang Mi, Xuan Feng 0005, Xiaojing Liao, Baojun Liu 0002, XiaoFeng Wang 0001, Feng Qian 0001, Zhou Li 0001, Sumayah A. Alrwais, Limin Sun 0001, Ying Liu 0024
IEEE Symposium on Security and Privacy4
2018 A Reexamination of Internationalized Domain Names: The Good, the Bad and the Ugly
abstract
Internationalized Domain Names (IDNs) are domain names containing non-ASCII characters. Despite its installation in DNS for more than 15 years, little has been done to understand how this initiative was developed and its security implications. In this work, we aim to fill this gap by studying the IDN ecosystem and cyber-attacks abusing IDN. In particular, we performed by far the most comprehensive measurement study using IDNs discovered from 56 TLD zone files. Through correlating data from auxiliary sources like WHOIS, passive DNS and URL blacklists, we gained many insights. Our discoveries are multi-faceted. On one hand, 1.4 million IDNs were actively registered under over 700 registrars, and regions within east Asia have seen prominent development in IDN registration. On the other hand, most of the registrations were opportunistic: they are currently not associated with meaningful websites and they have severe configuration issues (e.g., shared SSL certificates). What is more concerning is the rising trend of IDN abuse. So far, more than 6K IDNs were determined as malicious by URL blacklists and we also identified 1,516 and 1,497 IDNs showing high visual and semantic similarity to reputable brand domains (e.g., apple.com). Meanwhile, brand owners have only registered a few of these domains. Our study suggests the development of IDN needs to be re-examined. New solutions and proposals are needed to address issues like its inadequate usage and new attack surfaces.
Baojun Liu 0002, Chaoyi Lu, Zhou Li 0001, Ying Liu 0024, Hai-Xin Duan, Shuang Hao 0001, Zaifeng Zhang
DSN1
2018 Abusing CDNs for Fun and Profit: Security Issues in CDNs' Origin Validation
abstract
Content Delivery Networks (CDNs) are critical Internet infrastructure. Besides high availability and high performance, CDNs also provide security services such as anti-DoS and Web Application Firewalls to CDN-powered websites. However, the massive resources of CDNs may also be leveraged by attackers exploiting their architectural, implementation, or operational weaknesses. In this paper, we show that today's CDN operation is overly loose in customer-controlled forwarding policy and the lack of origin validation leads to a wide range of abuse cases such as DoS attack and stealthy port scan. We systematically study these abuse cases and demonstrate their feasibility in popular CDNs. Further, we evaluate the impact of these abuses by discovering that there are millions of CDN edge servers, and a substantial fraction of them can be abused. Lastly, we propose mitigation solutions against such abuses and discuss their feasibility.
Run Guo, Jianjun Chen 0005, Baojun Liu 0002, Jia Zhang 0004, Chao Zhang 0008, Hai-Xin Duan, Tao Wan 0004, Jian Jiang 0002, Shuang Hao 0001, Yaoqi Jia
SRDS3
2018 Who Is Answering My Queries: Understanding and Characterizing Interception of the DNS Resolution Path
Baojun Liu 0002, Chaoyi Lu, Hai-Xin Duan, Ying Liu 0024, Zhou Li 0001, Shuang Hao 0001, Min Yang 0002
USENIX Security Symposium1
2017 Don't Let One Rotten Apple Spoil the Whole Barrel: Towards Automated Detection of Shadowed Domains
abstract
Domain names have been exploited for illicit online activities for decades. In the past, miscreants mostly registered new domains for their attacks. However, the domains registered for malicious purposes can be deterred by existing reputation and blacklisting systems. In response to the arms race, miscreants have recently adopted a new strategy, called domain shadowing, to build their attack infrastructures. Specifically, instead of registering new domains, miscreants are beginning to compromise legitimate ones and spawn malicious subdomains under them. This has rendered almost all existing countermeasures ineffective and fragile because subdomains inherit the trust of their apex domains, and attackers can virtually spawn an infinite number of shadowed domains.
Daiping Liu, Zhou Li 0001, Kun Du, Haining Wang 0001, Baojun Liu 0002, Hai-Xin Duan
CCS5