EDBT 2026 Demo / reviewers in the wild / expert
Qing Wang 0041
dblp:97/6505-41
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2023
0000-0002-4044-0583ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | HANDOM: Heterogeneous Attention Network Model for Malicious Domain Detection
Qing Wang 0041, Cong Dong, Shijie Jian, Dan Du, Zhigang Lu 0002, Yinhao Qi, Dongxu Han, Xiaobo Ma 0001, Fei Wang 0014 |
Comput. Secur. | 1 |
| 2022 | DGGCN: Dictionary based DGA detection method based on DomainGraph and GCNabstractNowadays, malware uses Algorithmically Generated Domains (AGDs) to establish communication with Command and Control (C&C) servers. Dictionary based Domain Generation Algorithm (DGA) selects words from the frequently changed dictionaries to generate AGDs similar to benign domains, which degrades the accuracy of string based detection method. To combat this, we propose a DGA detection method based on DomainGraph and GCN (Graph Convolutional Network) which detects cross-dictionary AGDs based on the association relation between domains instead of lexical features. Starting from the association relation between domains rather than the lexical features of the domain itself, we can detect the unknown AGDs from a known AGD, regardless of the DGA dictionary they use. The proposed method exploits the fact that string association of benign domains is weak, while AGDs' association is strong. DGGCN composes a domain segmentation method, constructs a graph composed of domains (DomainGraph) based on segmentations and adopts GCN to detect AGDs. We conduct the experiments on public datasets under three settings: detecting AGDs generated by familiar dictionaries, unfamiliar dictionaries and confusing dictionaries. The results reveal that DGGCN can detect cross-dictionary AGDs similar to benign domains more accurately and robustly. Haoran Jiao, Qing Wang 0041, Zhaoshan Fan, Dan Du |
ICCCN | 2 |
| 2022 | DCC-Find: DNS Covert Channel Detection by Features Concatenation-Based LSTMabstractDNS (Domain Name System) plays an important role in network communication and it is rarely blocked by firewalls and intrusion detection systems (IDS). It is a suitable way for attackers to build DCC (DNS Covert Channel), which is used for data exfiltration. In recent years, some DCC detection methods have been proposed based on deep learning and there is no need for manual feature extraction. However, some expert knowledge is helpful to express the DNS characteristic. In this paper, we propose a FC-LSTM (Features Concatenation-based LSTM) model to detect DCC. The statistical features are concatenated with the output features of the LSTM model. This method makes the expression of DNS domain names more abundant. The experimental results have shown that the DCC traffic can be identified from normal traffic via this model, and the recognition rate is significantly improved compared with the traditional LSTM model and CNN model. In addition, we implement multi-classification in terms of the DCC tools (some of them are used in APT32). We also add generalization DNS packets (simulating APT34 traffic using DCC for stealing and attacking) to verify the robustness of our model. The FC-LSTM model has a good detection performance as well. Dongxu Han, Pu Dong, Xiang Cui, Jiawen Diao, Qing Wang 0041, Dan Du |
TrustCom | 6 |
| 2022 | PUMD: a PU learning-based malicious domain detection frameworkabstractAbstract Domain name system (DNS), as one of the most critical internet infrastructure, has been abused by various cyber attacks. Current malicious domain detection capabilities are limited by insufficient credible label information, severe class imbalance, and incompact distribution of domain samples in different malicious activities. This paper proposes a malicious domain detection framework named PUMD, which innovatively introduces Positive and Unlabeled (PU) learning solution to solve the problem of insufficient label information, adopts customized sample weight to improve the impact of class imbalance, and effectively constructs evidence features based on resource overlapping to reduce the intra-class distance of malicious samples. Besides, a feature selection strategy based on permutation importance and binning is proposed to screen the most informative detection features. Finally, we conduct experiments on the open source real DNS traffic dataset provided by QI-ANXIN Technology Group to evaluate the PUMD framework’s ability to capture potential command and control (C&C) domains for malicious activities. The experimental results prove that PUMD can achieve the best detection performance under different label frequencies and class imbalance ratios. Zhaoshan Fan, Qing Wang 0041, Haoran Jiao, Zelin Cui |
Cybersecur. | 2 |