Prof. Haixin Duan

Haixin Duan 段海新

Professor & Doctoral Supervisor

Institute for Network Sciences and Cyberspace (INSC), Tsinghua University
Network and Information Security Lab (NISL)  ·  FIT Building 3-211

Network Protocol Security Analysis Network Measurement Intrusion Detection & Underground Economy AI System Security

👤About

Haixin Duan is a Professor and Doctoral Supervisor at the Institute for Network Sciences and Cyberspace (INSC), Tsinghua University. He received his Ph.D. in Computer Science from Tsinghua University in 2001, and was a Visiting Scholar at UC Berkeley (2011–2012) and Senior Scientist at ICSI (2012–2013).

His research focuses on Internet infrastructure security, including DNS security and vulnerability analysis, Web security and Web PKI, HTTP/HTTPS and CDN security, network measurement, intrusion detection, and AI system security. He has published over 100 papers at top-tier security venues including IEEE S&P, USENIX Security, ACM CCS, and NDSS.

He received the ACM CCS Best Paper Award (2020), IEEE/IFIP DSN Best Paper Award (2020), NDSS Distinguished Paper Award (2016), and was named an Outstanding Talent in China's Cyberspace Security by the Cyberspace Administration of China. He serves as a member of the Academic Degrees Committee of the State Council (since 2020), and is co-founder of InForSec, XCTF, and DataCon.


Research Interests

DNS Security & Vulnerability Analysis Web Security & Web PKI HTTP/HTTPS & CDN Security Network Measurement Intrusion Detection & Underground Economy Email Security IoT Security Protocol Security Analysis AI System Security

💼Experience

Professional Experience

2009 — Present Professor & Doctoral Supervisor
Institute for Network Sciences and Cyberspace (INSC), Tsinghua University
Leading the NISL research group; teaching undergraduate and graduate courses; directing multiple national research projects.
2012 — 2013 Senior Scientist
International Computer Science Institute (ICSI), Berkeley, USA
2011 — 2012 Visiting Scholar
University of California, Berkeley, USA
2003 — 2009 Associate Professor
Network Engineering Research Center, Tsinghua University
2001 — 2003 Assistant Professor
Network Engineering Research Center, Tsinghua University

Education

1996 — 2000 Ph.D. in Computer Science
Tsinghua University, Beijing, China
1994 — 1996 M.Eng. in Computer Science
Harbin Institute of Technology, Harbin, China
1990 — 1994 B.Eng. in Computer Science
Harbin Institute of Technology, Harbin, China

Awards & Honors

2025 USENIX Security Distinguished Paper Award
"My ZIP isn't your ZIP: Identifying and Exploiting Semantic Gaps Between ZIP Parsers" Link
2023 ACM CCS Distinguished Paper Award
"Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS Servers" Link
2022 IEEE/IFIP DSN Best Paper Runner-Up
"HDiff: Hiding Differences to Identify Semantic Gaps in Vulnerability Signatures" Link
2020 ACM CCS Best Paper Award
"DNS cache poisoning attack reloaded: Revolutions with side channels" Link
2020 IEEE/IFIP DSN Best Paper Award
"CDN Backfired: Amplification Attacks Based on HTTP Range Requests" Link
2020 Applied Networking Research Award (IRTF)
"An End-to-End, Large-Scale Measurement of DNS-over-Encryption: How Far Have We Come?" Link
2016 NDSS Distinguished Paper Award
"Forwarding-Loop Attacks in Content Delivery Networks" — first Chinese researcher to receive this award Link
2016 Outstanding Cybersecurity Talent Award (Cyberspace Administration of China)
Awarded by the Cyberspace Administration of China (inaugural cohort) Link

📚Teaching

Undergraduate
Network Security Engineering and Practice
Core undergraduate course covering cryptography fundamentals, network protocol security, Web security, and intrusion detection, with hands-on lab sessions. Taught continuously since 2003.
📅 Every semester 🕐 2003 — Present
Graduate
Network Protocol Security Analysis
Advanced graduate course covering security design and real-world vulnerabilities in Internet protocols including DNS, HTTP, TLS, and BGP, integrating latest research findings from the lab.
📅 Every semester 🕐 2019 — Present
Graduate
Network and System Security
Graduate course covering OS security, offensive and defensive techniques, vulnerability analysis, and security measurement methodology.
📅 Concluded 🕐 2005 — 2019

📄Publications

192 publications (conference & journal papers). Source: DBLP · Google Scholar

LLMThief: Evaluating Configuration Leaking Risks in Commercial LLM App Stores
Pinji Chen, Jinlong Jiang, Jianjun Chen 0005, Feiran Qin, Minghao Zhang, Jiahe Zhang, Haixin Duan, Kaiwen Shen, Hui Jiang
IEEE Symposium on Security and Privacy (S&P) 2026
Identifying Logical Vulnerabilities in QUIC Implementations
Kaihua Wang, Jianjun Chen 0005, Pinji Chen, Jianwei Zhuge, Jiaju Bai, Haixin Duan
Network and Distributed System Security Symposium (NDSS) 2026
SIPConfusion: Exploiting SIP Semantic Ambiguities for Caller ID and SMS Spoofing
Qi Wang 0094, Jianjun Chen 0005, Jingcheng Yang, Jiahe Zhang, Yaru Yang, Haixin Duan
Network and Distributed System Security Symposium (NDSS) 2026
Token Time Bomb: Evaluating JWT Implementations for Vulnerability Discovery
Jingcheng Yang, Enze Wang, Jianjun Chen 0005, Qi Wang 0094, Yuheng Zhang, Haixin Duan, Wei Xie 0007, Baosheng Wang
Network and Distributed System Security Symposium (NDSS) 2026
Small Cell, Big Risk: A Security Assessment of 4G LTE Femtocells in the Wild
Yaru Yang, Yiming Zhang 0009, Tao Wan 0004, Haixin Duan, Deliang Chang, Yishen Li, Shujun Tang
Network and Distributed System Security Symposium (NDSS) 2026
Understanding the Status and Strategies of the Code Signing Abuse Ecosystem
Hanqing Zhao, Yiming Zhang 0009, Lingyun Ying, Mingming Zhang 0010, Baojun Liu 0002, Haixin Duan, Zi-Quan You, Shuhao Zhang
Network and Distributed System Security Symposium (NDSS) 2026
Characterizing Iran's Phased National Internet Shutdown in 2025: A Progressive and Distributed Action
Shibo Cui, Mingxuan Liu 0006, Baojun Liu 0002, Haixin Duan, Ruixuan Li 0008, Chaoyi Lu, Jin Zhang, Zhicheng Wang, Jinghua Bai
The Web Conference (WWW) 2026
Explore-on-Graph: Incentivizing Autonomous Exploration of Large Language Models on Knowledge Graphs with Path-refined Reward Modeling
Shiqi Yan, Yubo Chen 0002, Ruiqi Zhou, Zhengxi Yao, Shuai Chen, Tianyi Zhang, Shijie Zhang, Wei Qiang Zhang, Yongfeng Huang 0001, Haixin Duan, Yunqi Zhang
arXiv preprint (CoRR) 2026
RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday Paradox
Xiang Li 0108, Mingming Zhang 0010, Zuyao Xu, Fasheng Miao, Yuqi Qiu, Baojun Liu 0002, Jia Zhang 0004, Xiaofeng Zheng, Haixin Duan, Zheli Liu, Yunhai Zhang, Dunqiu Fan
ACM Conference on Computer and Communications Security (CCS) 2025
Exploring and Analyzing Cross Layer DoS Attack Against UDP-based Services on Linux
Dashuai Wu, Yunyi Zhang, Baojun Liu 0002, Xiang Li 0108, Eihal Alowaisheq, Haixin Duan
ACM Conference on Computer and Communications Security (CCS) 2025
Decoding DNS Centralization: Measuring and Identifying NS Domains Across Hosting Providers
Qihang Peng, Mingming Zhang 0010, Deliang Chang, Jia Zhang 0004, Baojun Liu 0002, Haixin Duan
IEEE/IFIP International Conference on Dependable Systems and Networks (DSN) 2025
Email Cloaking: Deceiving Users and Spam Email Detectors with Invisible HTML Settings
Bingyang Guo, Mingxuan Liu 0006, Yihui Ma, Ruixuan Li 0008, Fan Shi 0003, Min Zhang 0054, Baojun Liu 0002, Chengxi Xu, Haixin Duan, Geng Hong, Min Yang 0002, Qingfeng Pan
European Symposium on Research in Computer Security (ESORICS) 2025
The Danger of Packet Length Leakage: Off-path TCP/IP Hijacking Attacks Against Wireless and Mobile Networks
Guancheng Li, Minghao Zhang, Jianjun Chen 0005, Ge Dai, Pinji Chen, Huiming Liu, Yang Yu, Haixin Duan, Zhiyun Qian
IEEE European Symposium on Security and Privacy (EuroS&P) 2025
Exposing the Hidden Layer: Software Repositories in the Service of Seo Manipulation
Mengying Wu, Geng Hong, Wuyuao Mai, Xinyi Wu, Lei Zhang 0096, Yingyuan Pu, Huajun Chai, Lingyun Ying, Haixin Duan, Min Yang 0002
IEEE/ACM International Conference on Software Engineering (ICSE) 2025
Dive into the Cloud: Unveiling the (Ab)Usage of Serverless Cloud Function in the Wild
Yijing Liu, Mingxuan Liu 0006, Yiming Zhang 0009, Baojun Liu 0002, Jia Zhang 0004, Geng Hong, Haixin Duan, Min Yang 0002
ACM Internet Measurement Conference (IMC) 2025
Chaos in the Chain: Evaluate Deployment and Construction Compliance of Web PKI Certificate Chain
Jia Yao, Yiming Zhang 0009, Baojun Liu 0002, Zhan Liu, Mingming Zhang 0010, Haixin Duan
ACM Internet Measurement Conference (IMC) 2025
Understanding and Characterizing Intermediate Paths of Email Delivery: The Hidden Dependencies
Ruixuan Li 0008, Chaoyi Lu, Baojun Liu 0002, Yanzhong Lin, Haixin Duan, Qingfeng Pan, Jun Shao 0001
ACM Internet Measurement Conference (IMC) 2025
Analyzing Compliance and Complications of Integrating Internationalized X.509 Certificates
Mingming Zhang 0010, Jinfeng Guo, Yiming Zhang 0009, Shenglin Zhang, Baojun Liu 0002, Hanqing Zhao, Xiang Li 0108, Haixin Duan
ACM Internet Measurement Conference (IMC) 2025
HADES Attack: Understanding and Evaluating Manipulation Risks of Email Blocklists
Ruixuan Li 0008, Chaoyi Lu, Baojun Liu 0002, Yunyi Zhang, Geng Hong, Haixin Duan, Yanzhong Lin, Qingfeng Pan, Min Yang 0002, Jun Shao 0001
Network and Distributed System Security Symposium (NDSS) 2025
Cross-Origin Web Attacks via HTTP/2 Server Push and Signed HTTP Exchange
Pinji Chen, Jianjun Chen 0005, Mingming Zhang 0010, Qi Wang 0094, Yiming Zhang 0009, Mingwei Xu, Haixin Duan
Network and Distributed System Security Symposium (NDSS) 2025
Automatic Insecurity: Exploring Email Auto-configuration in the Wild
Shushang Wen, Yiming Zhang 0009, Yuxiang Shen, Bingyu Li, Haixin Duan, Jingqiang Lin 0001
Network and Distributed System Security Symposium (NDSS) 2025
Revealing the Black Box of Device Search Engine: Scanning Assets, Strategies, and Ethical Consideration
Mengying Wu, Geng Hong, Jinsong Chen, Qi Liu, Shujun Tang, Youhao Li, Baojun Liu 0002, Haixin Duan, Min Yang 0002
Network and Distributed System Security Symposium (NDSS) 2025
Hey, Your Secrets Leaked! Detecting and Characterizing Secret Leakage in the Wild
Jiawei Zhou, Zidong Zhang, Lingyun Ying, Huajun Chai, Jiuxin Cao, Haixin Duan
IEEE Symposium on Security and Privacy (S&P) 2025
Invade the Walled Garden: Evaluating GTP Security in Cellular Networks
Yiming Zhang 0009, Tao Wan 0004, Yaru Yang, Haixin Duan, Yichen Wang, Jianjun Chen 0005, Zixiang Wei, Xiang Li 0108
IEEE Symposium on Security and Privacy (S&P) 2025
Detection and Mitigation of Unknown Threats in IPv6 Networks via Layered Data Adaptation
Youjun Huang, Xiang Li 0108, Jia Zhang 0004, Haixin Duan
IEEE International Conference on Trust, Security and Privacy in Computing (TrustCom) 2025
My ZIP isn't your ZIP: Identifying and Exploiting Semantic Gaps Between ZIP Parsers
Yufan You, Jianjun Chen 0005, Qi Wang 0094, Haixin Duan
USENIX Security Symposium 2025
Email Spoofing with SMTP Smuggling: How the Shared Email Infrastructures Magnify this Vulnerability
Chuhan Wang 0001, Chenkai Wang 0001, Songyi Yang, Sophia Liu, Jianjun Chen 0005, Haixin Duan, Gang Wang 0011
USENIX Security Symposium 2025
The Silent Danger in HTTP: Identifying HTTP Desync Vulnerabilities with Gray-box Testing
Keran Mu, Jianjun Chen 0005, Jianwei Zhuge, Qi Li 0002, Haixin Duan, Nick Feamster
USENIX Security Symposium 2025
Beyond Exploit Scanning: A Functional Change-Driven Approach to Remote Software Version Identification
Jinsong Chen, Mengying Wu, Geng Hong, Baichao An, Mingxuan Liu 0006, Lei Zhang 0096, Baojun Liu 0002, Haixin Duan, Min Yang 0002
USENIX Security Symposium 2025
NOKEScam: Understanding and Rectifying Non-Sense Keywords Spear Scam in Search Engines
Mingxuan Liu 0006, Yunyi Zhang, Lijie Wu, Baojun Liu 0002, Geng Hong, Yiming Zhang 0009, Hui Jiang, Jia Zhang 0004, Haixin Duan, Min Zhang 0054, Wei Guan, Fan Shi 0003, Min Yang 0002
USENIX Security Symposium 2025
Misty Registry: An Empirical Study of Flawed Domain Registry Operation
Mingming Zhang 0010, Yunyi Zhang, Baojun Liu 0002, Haixin Duan, Min Zhang 0054, Fan Shi 0003, Chengxi Xu
USENIX Security Symposium 2025
You Can't Eat Your Cake and Have It Too: The Performance Degradation of LLMs with Jailbreak Defense
Wuyuao Mai, Geng Hong, Pei Chen, Xudong Pan, Baojun Liu 0002, Yuan Zhang 0009, Haixin Duan, Min Yang 0002
The Web Conference (WWW) 2025
Dr. Docker: A Large-Scale Security Measurement of Docker Image Ecosystem
Hequan Shi, Lingyun Ying, Libo Chen 0001, Haixin Duan, Ming Liu, Zhi Xue
The Web Conference (WWW) 2025
You Can't Eat Your Cake and Have It Too: The Performance Degradation of LLMs with Jailbreak Defense
Wuyuao Mai, Geng Hong, Pei Chen, Xudong Pan, Baojun Liu 0002, Yuan Zhang 0009, Haixin Duan, Min Yang 0002
arXiv preprint (CoRR) 2025
Underground Application Collection Method Based on Spiking Traffic Analysis
Pei Chen, Geng Hong, Mengying Wu, Jinsong Chen, Haixin Duan, Min Yang 0002
International Journal of Software and Informatics 2024
Investigating Deployment Issues of DNS Root Server Instances From a China-Wide View
Fenglu Zhang, Baojun Liu 0002, Chaoyi Lu, Yunpeng Xing, Haixin Duan, Ying Liu 0024, Liyuan Chang
IEEE Transactions on Dependable and Secure Computing 2024
Dissecting Open Edge Computing Platforms: Ecosystem, Usage, and Security Risks
Yu Bi, Mingshuo Yang, Yong Fang, Xianghang Mi, Shanqing Guo, Shujun Tang, Haixin Duan
Annual Computer Security Applications Conference (ACSAC) 2024
Internet's Invisible Enemy: Detecting and Measuring Web Cache Poisoning in the Wild
Yuejia Liang, Jianjun Chen 0005, Run Guo, Kaiwen Shen, Hui Jiang, Man Hou, Yue Yu, Haixin Duan
ACM Conference on Computer and Communications Security (CCS) 2024
Inbox Invasion: Exploiting MIME Ambiguities to Evade Email Attachment Detectors
Jiahe Zhang, Jianjun Chen 0005, Qi Wang 0094, Hangyu Zhang, Chuhan Wang 0001, Jianwei Zhuge, Haixin Duan
ACM Conference on Computer and Communications Security (CCS) 2024
Toward Understanding the Security of Plugins in Continuous Integration Services
Xiaofan Li 0009, Yacong Gu, Chu Qiao, Zhenkai Zhang 0002, Daiping Liu, Lingyun Ying, Haixin Duan, Xing Gao 0001
ACM Conference on Computer and Communications Security (CCS) 2024
MiniCAT: Understanding and Detecting Cross-Page Request Forgery Vulnerabilities in Mini-Programs
Zidong Zhang, Qinsheng Hou, Lingyun Ying, Wenrui Diao, Yacong Gu, Rui Li 0102, Shanqing Guo, Haixin Duan
ACM Conference on Computer and Communications Security (CCS) 2024
PowerPeeler: A Precise and General Dynamic Deobfuscation Method for PowerShell Scripts
Ruijie Li, Chenyang Zhang, Huajun Chai, Lingyun Ying, Haixin Duan, Jun Tao 0003
ACM Conference on Computer and Communications Security (CCS) 2024
ChatScam: Unveiling the Rising Impact of ChatGPT on Domain Name Abuse
Mingxuan Liu 0006, Zhenglong Jin, Jiahai Yang 0001, Baoiun Liu, Haixin Duan, Ying Liu 0024, Ximeng Liu, Shujun Tang
IEEE/IFIP International Conference on Dependable Systems and Networks (DSN) 2024
Yesterday Once More: Global Measurement of Internet Traffic Shadowing Behaviors
Yunpeng Xing, Chaoyi Lu, Baojun Liu 0002, Haixin Duan, Junzhe Sun, Zhou Li 0001
ACM Internet Measurement Conference (IMC) 2024
Bounce in the Wild: A Deep Dive into Email Delivery Failures from a Large Email Service Provider
Ruixuan Li 0008, Shaodong Xiao, Baojun Liu 0002, Yanzhong Lin, Haixin Duan, Qingfeng Pan, Jianjun Chen 0005, Jia Zhang 0004, Ximeng Liu, Xiuqi Lu, Jun Shao 0001
ACM Internet Measurement Conference (IMC) 2024
Understanding the Implementation and Security Implications of Protective DNS Services
Mingxuan Liu 0006, Yiming Zhang 0009, Xiang Li 0108, Chaoyi Lu, Baojun Liu 0002, Haixin Duan, Xiaofeng Zheng
Network and Distributed System Security Symposium (NDSS) 2024
BreakSPF: How Shared Infrastructures Magnify SPF Vulnerabilities Across the Internet
Chuhan Wang 0001, Yasuhiro Kuranaga, Yihang Wang, Mingming Zhang 0010, Linkai Zheng, Xiang Li 0108, Jianjun Chen 0005, Haixin Duan, Yanzhong Lin, Qingfeng Pan
Network and Distributed System Security Symposium (NDSS) 2024
ReqsMiner: Automated Discovery of CDN Forwarding Request Inconsistencies and DoS Attacks with Grammar-based Fuzzing
Linkai Zheng, Xiang Li 0108, Chuhan Wang 0001, Run Guo, Haixin Duan, Jianjun Chen 0005, Chao Zhang 0008, Kaiwen Shen
Network and Distributed System Security Symposium (NDSS) 2024
CrypTody: Cryptographic Misuse Analysis of IoT Firmware via Data-flow Reasoning
Jianing Wang, Shanqing Guo, Wenrui Diao, Yue Liu, Haixin Duan, Yichen Liu, Zhenkai Liang
International Symposium on Research in Attacks, Intrusions and Defenses (RAID) 2024
Break the Wall from Bottom: Automated Discovery of Protocol-Level Evasion Vulnerabilities in Web Application Firewalls
Qi Wang 0094, Jianjun Chen 0005, Zheyu Jiang, Run Guo, Ximeng Liu, Chao Zhang 0008, Haixin Duan
IEEE Symposium on Security and Privacy (S&P) 2024
Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web Applications
Enze Wang, Jianjun Chen 0005, Wei Xie 0007, Chuhan Wang 0001, Yifei Gao, Zhenhua Wang, Haixin Duan, Yang Liu 0003, Baosheng Wang
IEEE Symposium on Security and Privacy (S&P) 2024
More Haste, Less Speed: Cache Related Security Threats in Continuous Integration Services
Yacong Gu, Lingyun Ying, Huajun Chai, Yingyuan Pu, Haixin Duan, Xing Gao 0001
IEEE Symposium on Security and Privacy (S&P) 2024
TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed Packets
Xiang Li 0108, Wei Xu, Baojun Liu 0002, Mingming Zhang 0010, Zhou Li 0001, Jia Zhang 0004, Deliang Chang, Xiaofeng Zheng, Chuhan Wang 0001, Jianjun Chen 0005, Haixin Duan, Qi Li 0002
IEEE Symposium on Security and Privacy (S&P) 2024
DNSBomb: A New Practical-and-Powerful Pulsing DoS Attack Exploiting DNS Queries-and-Responses
Xiang Li 0108, Dashuai Wu, Haixin Duan, Qi Li 0002
IEEE Symposium on Security and Privacy (S&P) 2024
Tickets or Privacy? Understand the Ecosystem of Chinese Ticket Grabbing Apps
Yijing Liu, Yiming Zhang 0009, Baojun Liu 0002, Haixin Duan, Qiang Li, Mingxuan Liu 0006, Ruixuan Li 0008, Jia Yao
USENIX Security Symposium 2024
ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
Qifan Zhang 0002, Xuesong Bai, Xiang Li 0108, Haixin Duan, Qi Li 0002, Zhou Li 0001
USENIX Security Symposium 2024
Rethinking the Security Threats of Stale DNS Glue Records
Yunyi Zhang, Baojun Liu 0002, Haixin Duan, Min Zhang 0054, Xiang Li 0108, Fan Shi 0003, Chengxi Xu, Eihal Alowaisheq
USENIX Security Symposium 2024
Into the Dark: Unveiling Internal Site Search Abused for Black Hat SEO
Yunyi Zhang, Mingxuan Liu 0006, Baojun Liu 0002, Yiming Zhang 0009, Haixin Duan, Min Zhang 0054, Hui Jiang, Yanzhe Li, Fan Shi 0003
USENIX Security Symposium 2024
Cross the Zone: Toward a Covert Domain Hijacking via Shared DNS Infrastructure
Yunyi Zhang, Mingming Zhang 0010, Baojun Liu 0002, Zhan Liu, Jia Zhang 0004, Haixin Duan, Min Zhang 0054, Fan Shi 0003, Chengxi Xu
USENIX Security Symposium 2024
Uncovering Security Vulnerabilities in Real-world Implementation and Deployment of 5G Messaging Services
Yaru Yang, Yiming Zhang 0009, Tao Wan 0004, Chuhan Wang 0001, Haixin Duan, Jianjun Chen 0005, Yishen Li
ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec) 2024
A Worldwide View on the Reachability of Encrypted DNS Services
Ruixuan Li 0008, Baojun Liu 0002, Chaoyi Lu, Haixin Duan, Jun Shao 0001
The Web Conference (WWW) 2024
From Promises to Practice: Evaluating the Private Browsing Modes of Android Browser Apps
Xiaoyin Liu, Wenzhi Li, Qinsheng Hou, Shishuai Yang, Lingyun Ying, Wenrui Diao, Yanan Li, Shanqing Guo, Haixin Duan
The Web Conference (WWW) 2024
An Empirical Study of Open Edge Computing Platforms: Ecosystem, Usage, and Security Risks
Yu Bi, Mingshuo Yang, Yong Fang, Xianghang Mi, Shanqing Guo, Shujun Tang, Haixin Duan
arXiv preprint (CoRR) 2024
PowerPeeler: A Precise and General Dynamic Deobfuscation Method for PowerShell Scripts
Ruijie Li, Chenyang Zhang, Huajun Chai, Lingyun Ying, Haixin Duan, Jun Tao 0003
arXiv preprint (CoRR) 2024
Revealing the Black Box of Device Search Engine: Scanning Assets, Strategies, and Ethical Consideration
Mengying Wu, Geng Hong, Jinsong Chen, Qi Liu, Shujun Tang, Youhao Li, Baojun Liu 0002, Haixin Duan, Min Yang 0002
arXiv preprint (CoRR) 2024
Detecting and Measuring Security Risks of Hosting-Based Dangling Domains
Mingming Zhang 0010, Xiang Li 0108, Baojun Liu 0002, Jianyu Lu, Yiming Zhang 0009, Jianjun Chen 0005, Haixin Duan, Shuang Hao 0001, Xiaofeng Zheng
Proceedings of the ACM on Measurement and Analysis of Computing Systems (SIGMETRICS/IMC) 2023
Automatic Generation of Adversarial Readable Chinese Texts
Mingxuan Liu 0006, Zihan Zhang, Yiming Zhang 0009, Chao Zhang 0008, Zhou Li 0001, Qi Li 0002, Haixin Duan, Donghong Sun
IEEE Transactions on Dependable and Secure Computing 2023
TAICHI: Transform Your Secret Exploits Into Mine From a Victim's Perspective
Zhongyu Pei, Xingman Chen, Songtao Yang, Haixin Duan, Chao Zhang 0008
IEEE Transactions on Dependable and Secure Computing 2023
Can We Trust the Phone Vendors? Comprehensive Security Measurements on the Android Firmware Ecosystem
Qinsheng Hou, Wenrui Diao, Yanhao Wang, Chenglin Mao, Lingyun Ying, Song Liu, Xiaofeng Liu 0013, Yuanzhi Li, Shanqing Guo, Meining Nie, Haixin Duan
IEEE Transactions on Software Engineering 2023
Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS Servers
Fenglu Zhang, Baojun Liu 0002, Eihal Alowaisheq, Jianjun Chen 0005, Chaoyi Lu, Linjian Song, Yong Ma, Ying Liu 0024, Haixin Duan, Min Yang 0002
ACM Turing Celebration Conference - China (ACM TUR-C) 2023
Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS Servers
Fenglu Zhang, Baojun Liu 0002, Eihal Alowaisheq, Jianjun Chen 0005, Chaoyi Lu, Linjian Song, Yong Ma, Ying Liu 0024, Haixin Duan, Min Yang 0002
ACM Conference on Computer and Communications Security (CCS) 2023
TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS Amplifiers
Wei Xu, Xiang Li 0108, Chaoyi Lu, Baojun Liu 0002, Haixin Duan, Jia Zhang 0004, Jianjun Chen 0005, Tao Wan 0004
ACM Conference on Computer and Communications Security (CCS) 2023
Under the Dark: A Systematical Study of Stealthy Mining Pools (Ab)use in the Wild
Zhenrui Zhang, Geng Hong, Xiang Li 0108, Zhuoqun Fu, Jia Zhang 0004, Mingxuan Liu 0006, Chuhan Wang 0001, Jianjun Chen 0005, Baojun Liu 0002, Haixin Duan, Chao Zhang 0008, Min Yang 0002
ACM Conference on Computer and Communications Security (CCS) 2023
Stolen Risks of Models with Security Properties
Yue Qin, Zhuoqun Fu, Chuyun Deng, Xiaojing Liao, Jia Zhang 0004, Haixin Duan
ACM Conference on Computer and Communications Security (CCS) 2023
Wolf in Sheep's Clothing: Evaluating Security Risks of the Undelegated Record on DNS Hosting Services
Fenglu Zhang, Yunyi Zhang, Baojun Liu 0002, Eihal Alowaisheq, Lingyun Ying, Xiang Li 0108, Zaifeng Zhang, Ying Liu 0024, Haixin Duan, Min Zhang 0054
ACM Internet Measurement Conference (IMC) 2023
A Security Study about Electron Applications and a Programming Methodology to Tame DOM Functionalities
Zihao Jin, Shuo Chen 0001, Yang Chen, Haixin Duan, Jianjun Chen 0005, Jianping Wu
Network and Distributed System Security Symposium (NDSS) 2023
Ghost Domain Reloaded: Vulnerable Links in Domain Name Delegation and Revocation
Xiang Li 0108, Baojun Liu 0002, Xuesong Bai, Mingming Zhang 0010, Qifan Zhang 0002, Zhou Li 0001, Haixin Duan, Qi Li 0002
Network and Distributed System Security Symposium (NDSS) 2023
Detecting and Measuring Security Risks of Hosting-Based Dangling Domains
Mingming Zhang 0010, Xiang Li 0108, Baojun Liu 0002, Jianyu Lu, Yiming Zhang 0009, Jianjun Chen 0005, Haixin Duan, Shuang Hao 0001, Xiaofeng Zheng
ACM SIGMETRICS Conference 2023
Continuous Intrusion: Characterizing the Security of Continuous Integration Services
Yacong Gu, Lingyun Ying, Huajun Chai, Chu Qiao, Haixin Duan, Xing Gao 0001
IEEE Symposium on Security and Privacy (S&P) 2023
Investigating Package Related Security Threats in Software Registries
Yacong Gu, Lingyun Ying, Yingyuan Pu, Xiao Hu, Huajun Chai, Ruimin Wang, Xing Gao 0001, Haixin Duan
IEEE Symposium on Security and Privacy (S&P) 2023
MTSan: A Feasible and Practical Memory Sanitizer for Fuzzing COTS Binaries
Xingman Chen, Yinghao Shi, Zheyu Jiang, Yuan Li 0061, Ruoyu Wang 0001, Haixin Duan, Haoyu Wang 0001, Chao Zhang 0008
USENIX Security Symposium 2023
The Maginot Line: Attacking the Boundary of DNS Caching Protection
Xiang Li 0108, Chaoyi Lu, Baojun Liu 0002, Qifan Zhang 0002, Zhou Li 0001, Haixin Duan, Qi Li 0002
USENIX Security Symposium 2023
Temporal CDN-Convex Lens: A CDN-Assisted Practical Pulsing DDoS Attack
Run Guo, Jianjun Chen 0005, Yihang Wang, Keran Mu, Baojun Liu 0002, Xiang Li 0108, Chao Zhang 0008, Haixin Duan, Jianping Wu
USENIX Security Symposium 2023
ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
Qifan Zhang 0002, Xuesong Bai, Xiang Li 0108, Haixin Duan, Qi Li 0002, Zhou Li 0001
arXiv preprint (CoRR) 2023
SFuzz: Slice-based Fuzzing for Real-Time Operating Systems
Libo Chen 0001, Quanpu Cai, Zhenbang Ma, Yanhao Wang, Hong Hu 0004, Minghang Shen, Yue Liu, Shanqing Guo, Haixin Duan, Kaida Jiang, Zhi Xue
ACM Conference on Computer and Communications Security (CCS) 2022
An Extensive Study of Residential Proxies in China
Mingshuo Yang, Yunnan Yu, Xianghang Mi, Shujun Tang, Shanqing Guo, Yilin Li, Xiaofeng Zheng, Haixin Duan
ACM Conference on Computer and Communications Security (CCS) 2022
HDiff: A Semi-automatic Framework for Discovering Semantic Gap Attack in HTTP Implementations
Kaiwen Shen, Jianyu Lu, Yaru Yang, Jianjun Chen 0005, Mingming Zhang 0010, Haixin Duan, Jia Zhang 0004, Xiaofeng Zheng
IEEE/IFIP International Conference on Dependable Systems and Networks (DSN) 2022
Invoke-Deobfuscation: AST-Based and Semantics-Preserving Deobfuscation for PowerShell Scripts
Huajun Chai, Lingyun Ying, Haixin Duan, Daren Zha
IEEE/IFIP International Conference on Dependable Systems and Networks (DSN) 2022
Exploring the Characteristics and Security Risks of Emerging Emoji Domain Names
Mingxuan Liu 0006, Yiming Zhang 0009, Baojun Liu 0002, Haixin Duan
European Symposium on Research in Computer Security (ESORICS) 2022
Trampoline Over the Air: Breaking in IoT Devices Through MQTT Brokers
Huikai Xu, Miao Yu, Yanhao Wang, Yue Liu, Qinsheng Hou, Zhenbang Ma, Haixin Duan, Jianwei Zhuge, Baojun Liu 0002
IEEE European Symposium on Security and Privacy (EuroS&P) 2022
Ethics in Security Research: Visions, Reality, and Paths Forward
Yiming Zhang 0009, Mingxuan Liu 0006, Mingming Zhang 0010, Chaoyi Lu, Haixin Duan
IEEE European Symposium on Security and Privacy Workshops 2022
Large-scale Security Measurements on the Android Firmware Ecosystem
Qinsheng Hou, Wenrui Diao, Yanhao Wang, Xiaofeng Liu 0013, Song Liu, Lingyun Ying, Shanqing Guo, Yuanzhi Li, Meining Nie, Haixin Duan
IEEE/ACM International Conference on Software Engineering (ICSE) 2022
ValCAT: Variable-Length Contextualized Adversarial Transformations Using Encoder-Decoder Language Model
Chuyun Deng, Mingxuan Liu 0006, Yue Qin, Jia Zhang 0004, Hai-Xin Duan, Donghong Sun
Annual Conference of the North American Chapter of the ACL (NAACL-HLT) 2022
PMTUD is not Panacea: Revisiting IP Fragmentation Attacks against TCP
Xuewei Feng, Qi Li 0002, Kun Sun 0001, Ke Xu 0002, Baojun Liu 0002, Xiaofeng Zheng, Qiushi Yang, Haixin Duan, Zhiyun Qian
Network and Distributed System Security Symposium (NDSS) 2022
Measuring the Practical Effect of DNS Root Server Instances: A China-Wide Case Study
Fenglu Zhang, Chaoyi Lu, Baojun Liu 0002, Haixin Duan, Ying Liu 0024
Passive and Active Measurement Conference (PAM) 2022
Encrypted Malware Traffic Detection via Graph-based Network Analysis
Zhuoqun Fu, Mingxuan Liu 0006, Yue Qin, Jia Zhang 0004, Yuan Zou, Qilei Yin, Qi Li 0002, Haixin Duan
International Symposium on Research in Attacks, Intrusions and Defenses (RAID) 2022
Timing-Based Browsing Privacy Vulnerabilities Via Site Isolation
Zihao Jin, Ziqiao Kong, Shuo Chen 0001, Haixin Duan
IEEE Symposium on Security and Privacy (S&P) 2022
Analyzing Ground-Truth Data of Mobile Gambling Scams
Geng Hong, Zhemin Yang, Sen Yang 0011, Xiaojing Liao, Xiaolin Du, Min Yang 0002, Haixin Duan
IEEE Symposium on Security and Privacy (S&P) 2022
Exploit the Last Straw That Breaks Android Systems
Lei Zhang 0096, Keke Lian, Haoyu Xiao, Zhibo Zhang 0006, Peng Liu 0005, Yuan Zhang 0009, Min Yang 0002, Haixin Duan
IEEE Symposium on Security and Privacy (S&P) 2022
Building an Open, Robust, and Stable Voting-Based Domain Top List
Qinge Xie, Shujun Tang, Xiaofeng Zheng, Qingran Lin, Baojun Liu 0002, Haixin Duan, Frank Li 0001
USENIX Security Symposium 2022
A Large-scale and Longitudinal Measurement Study of DKIM Deployment
Chuhan Wang 0001, Kaiwen Shen, Minglei Guo, Yuxuan Zhao, Mingming Zhang 0010, Jianjun Chen 0005, Baojun Liu 0002, Xiaofeng Zheng, Haixin Duan, Yanzhong Lin, Qingfeng Pan
USENIX Security Symposium 2022
Measuring the Deployment of 5G Security Enhancement
Shiyue Nie, Yiming Zhang 0009, Tao Wan 0004, Haixin Duan, Song Li
ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec) 2022
An Extensive Study of Residential Proxies in China
Mingshuo Yang, Yunnan Yu, Xianghang Mi, Shujun Tang, Shanqing Guo, Yilin Li, Xiaofeng Zheng, Haixin Duan
arXiv preprint (CoRR) 2022
Detecting and Characterizing SMS Spearphishing Attacks
Mingxuan Liu 0006, Yiming Zhang 0009, Baojun Liu 0002, Zhou Li 0001, Haixin Duan, Donghong Sun
Annual Computer Security Applications Conference (ACSAC) 2021
Rusted Anchors: A National Client-Side View of Hidden Root CAs in the Web PKI Ecosystem
Yiming Zhang 0009, Baojun Liu 0002, Chaoyi Lu, Zhou Li 0001, Haixin Duan, Jiachen Li, Zaifeng Zhang
ACM Conference on Computer and Communications Security (CCS) 2021
Fast IPv6 Network Periphery Discovery and Security Implications
Xiang Li 0108, Baojun Liu 0002, Xiaofeng Zheng, Haixin Duan, Qi Li 0002, Youjun Huang
IEEE/IFIP International Conference on Dependable Systems and Networks (DSN) 2021
Mingling of Clear and Muddy Water: Understanding and Detecting Semantic Confusion in Blackhat SEO
Hao Yang, Kun Du, Yubao Zhang, Shuai Hao 0001, Haining Wang 0001, Jia Zhang 0004, Haixin Duan
European Symposium on Research in Computer Security (ESORICS) 2021
On Evaluating Delegated Digital Signing of Broadcasting Messages in 5G
Hui Gao, Yiming Zhang 0009, Tao Wan 0004, Jia Zhang 0004, Haixin Duan
IEEE Global Communications Conference (GLOBECOM) 2021
From WHOIS to WHOWAS: A Large-Scale Measurement Study of Domain Registration Privacy under the GDPR
Chaoyi Lu, Baojun Liu 0002, Yiming Zhang 0009, Zhou Li 0001, Fenglu Zhang, Haixin Duan, Ying Liu 0024, Joann Qiongna Chen, Jinjin Liang, Zaifeng Zhang, Shuang Hao 0001, Min Yang 0002
Network and Distributed System Security Symposium (NDSS) 2021
Sharing More and Checking Less: Leveraging Common Input Keywords to Detect Bugs in Embedded Systems
Libo Chen 0001, Yanhao Wang, Quanpu Cai, Yunfan Zhan, Hong Hu 0004, Jiaqi Linghu, Qinsheng Hou, Chao Zhang 0008, Haixin Duan, Zhi Xue
USENIX Security Symposium 2021
Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing Attacks
Kaiwen Shen, Chuhan Wang 0001, Minglei Guo, Xiaofeng Zheng, Chaoyi Lu, Baojun Liu 0002, Yuxuan Zhao, Shuang Hao 0001, Haixin Duan, Qingfeng Pan, Min Yang 0002
USENIX Security Symposium 2021
Characterizing Transnational Internet Performance and the Great Bottleneck of China
Pengxiong Zhu, Keyu Man, Zhongjie Wang 0002, Zhiyun Qian, Roya Ensafi, J. Alex Halderman, Hai-Xin Duan
Proceedings of the ACM on Measurement and Analysis of Computing Systems (SIGMETRICS/IMC) 2020
Understanding Promotion-as-a-Service on GitHub
Kun Du, Hao Yang, Yubao Zhang, Haixin Duan, Haining Wang 0001, Shuang Hao 0001, Zhou Li 0001, Min Yang 0002
Annual Computer Security Applications Conference (ACSAC) 2020
Lies in the Air: Characterizing Fake-base-station Spam Ecosystem in China
Yiming Zhang 0009, Baojun Liu 0002, Chaoyi Lu, Zhou Li 0001, Haixin Duan, Shuang Hao 0001, Mingxuan Liu 0006, Ying Liu 0024, Dong Wang, Qiang Li
ACM Conference on Computer and Communications Security (CCS) 2020
DNS Cache Poisoning Attack Reloaded: Revolutions with Side Channels
Keyu Man, Zhiyun Qian, Zhongjie Wang 0002, Xiaofeng Zheng, Youjun Huang, Haixin Duan
ACM Conference on Computer and Communications Security (CCS) 2020
Talking with Familiar Strangers: An Empirical Study on HTTPS Context Confusion Attacks
Mingming Zhang 0010, Xiaofeng Zheng, Kaiwen Shen, Ziqiao Kong, Chaoyi Lu, Yu Wang 0288, Haixin Duan, Shuang Hao 0001, Baojun Liu 0002, Min Yang 0002
ACM Conference on Computer and Communications Security (CCS) 2020
CDN Backfired: Amplification Attacks Based on HTTP Range Requests
Weizhong Li, Kaiwen Shen, Run Guo, Baojun Liu 0002, Jia Zhang 0004, Haixin Duan, Shuang Hao 0001, Xiarun Chen, Yao Wang
IEEE/IFIP International Conference on Dependable Systems and Networks (DSN) 2020
Argot: Generating Adversarial Readable Chinese Texts
Zihan Zhang, Mingxuan Liu 0006, Chao Zhang 0008, Yiming Zhang 0009, Zhou Li 0001, Qi Li 0002, Haixin Duan, Donghong Sun
International Joint Conference on Artificial Intelligence (IJCAI) 2020
CDN Judo: Breaking the CDN DoS Protection with Itself
Run Guo, Weizhong Li, Baojun Liu 0002, Shuang Hao 0001, Jia Zhang 0004, Haixin Duan, Kaiwen Shen, Jianjun Chen 0005, Ying Liu 0024
Network and Distributed System Security Symposium (NDSS) 2020
Characterizing Transnational Internet Performance and the Great Bottleneck of China
Pengxiong Zhu, Keyu Man, Zhongjie Wang 0002, Zhiyun Qian, Roya Ensafi, J. Alex Halderman, Hai-Xin Duan
ACM SIGMETRICS Conference 2020
TextExerciser: Feedback-driven Text Input Exercising for Android Applications
Yuyu He, Lei Zhang 0096, Zhemin Yang, Yinzhi Cao, Keke Lian, Shuai Li 0006, Wei Yang 0013, Zhibo Zhang 0006, Min Yang 0002, Yuan Zhang 0009, Haixin Duan
IEEE Symposium on Security and Privacy (S&P) 2020
Poison Over Troubled Forwarders: A Cache Poisoning Attack Targeting DNS Forwarding Devices
Xiaofeng Zheng, Chaoyi Lu, Jian Peng, Qiushi Yang, Dongjie Zhou, Baojun Liu 0002, Keyu Man, Shuang Hao 0001, Haixin Duan, Zhiyun Qian
USENIX Security Symposium 2020
Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing Attacks
Kaiwen Shen, Chuhan Wang 0001, Minglei Guo, Xiaofeng Zheng, Chaoyi Lu, Baojun Liu 0002, Yuxuan Zhao, Shuang Hao 0001, Haixin Duan, Qingfeng Pan, Min Yang 0002
arXiv preprint (CoRR) 2020
Finding the best answer: measuring the optimization of public and authoritative DNS
Jia Zhang 0004, Hai-Xin Duan, Jian Jiang 0002, Jinjin Liang, Jianping Wu
Science China Information Sciences 2019
Casino royale: a deep exploration of illegal online gambling
Hao Yang, Kun Du, Yubao Zhang, Shuang Hao 0001, Zhou Li 0001, Mingxuan Liu 0006, Haining Wang 0001, Hai-Xin Duan, Yazhou Shi, XiaoDong Su, Guang Liu, Zhifeng Geng, Jianping Wu
Annual Computer Security Applications Conference (ACSAC) 2019
Who is answering my queries: understanding and characterizing interception of the DNS resolution path
Baojun Liu 0002, Chaoyi Lu, Hai-Xin Duan, Ying Liu 0024, Zhou Li 0001, Shuang Hao 0001, Min Yang 0002
ACM/IRTF Applied Networking Research Workshop (ANRW) 2019
TraffickStop: Detecting and Measuring Illicit Traffic Monetization Through Large-Scale DNS Analysis
Baojun Liu 0002, Zhou Li 0001, Peiyuan Zong, Chaoyi Lu, Hai-Xin Duan, Ying Liu 0024, Sumayah A. Alrwais, XiaoFeng Wang 0001, Shuang Hao 0001, Yaoqi Jia, Yiming Zhang 0009, Kai Chen 0012, Zaifeng Zhang
IEEE European Symposium on Security and Privacy (EuroS&P) 2019
NETHCF: Enabling Line-rate and Adaptive Spoofed IP Traffic Filtering
Guanyu Li, Menghao Zhang 0001, Chang Liu 0021, Xiao Kong, Ang Chen 0001, Guofei Gu, Haixin Duan
IEEE International Conference on Network Protocols (ICNP) 2019
An End-to-End, Large-Scale Measurement of DNS-over-Encryption: How Far Have We Come?
Chaoyi Lu, Baojun Liu 0002, Zhou Li 0001, Shuang Hao 0001, Hai-Xin Duan, Mingming Zhang 0010, Chunying Leng, Ying Liu 0024, Zaifeng Zhang, Jianping Wu
ACM Internet Measurement Conference (IMC) 2019
TL;DR Hazard: A Comprehensive Study of Levelsquatting Scams
Kun Du, Hao Yang, Zhou Li 0001, Hai-Xin Duan, Shuang Hao 0001, Baojun Liu 0002, Yuxiao Ye, Mingxuan Liu 0006, XiaoDong Su, Guang Liu, Zhifeng Geng, Zaifeng Zhang, Jinjin Liang
International Conference on Security and Privacy in Communication Networks (SecureComm) 2019
Fuzzing IPC with Knowledge Inference
Kun Yang, Hanqing Zhao, Chao Zhang 0008, Jianwei Zhuge, Haixin Duan
IEEE International Symposium on Reliable Distributed Systems (SRDS) 2019
How You Get Shot in the Back: A Systematical Study about Cryptojacking in the Real World
Geng Hong, Zhemin Yang, Sen Yang 0011, Lei Zhang 0096, Yuhong Nan, Zhibo Zhang 0006, Min Yang 0002, Yuan Zhang 0009, Zhiyun Qian, Hai-Xin Duan
ACM Conference on Computer and Communications Security (CCS) 2018
Path Leaks of HTTPS Side-Channel by Cookie Injection
Fuqing Chen, Hai-Xin Duan, Xiaofeng Zheng, Jian Jiang 0002, Jianjun Chen 0005
Constructive Side-Channel Analysis and Secure Design (COSADE) 2018
A Reexamination of Internationalized Domain Names: The Good, the Bad and the Ugly
Baojun Liu 0002, Chaoyi Lu, Zhou Li 0001, Ying Liu 0024, Hai-Xin Duan, Shuang Hao 0001, Zaifeng Zhang
IEEE/IFIP International Conference on Dependable Systems and Networks (DSN) 2018
Analysis and Measurement of Zone Dependency in the Domain Name System
Jian Jiang 0002, Jia Zhang 0004, Hai-Xin Duan, Kang Li 0001, Wu Liu
IEEE International Conference on Communications (ICC) 2018
ICUFuzzer: Fuzzing ICU Library for Exploitable Bugs in Multiple Software
Kun Yang, Yuan Deng, Chao Zhang 0008, Jianwei Zhuge, Hai-Xin Duan
Information Security Conference (ISC) 2018
Abusing CDNs for Fun and Profit: Security Issues in CDNs' Origin Validation
Run Guo, Jianjun Chen 0005, Baojun Liu 0002, Jia Zhang 0004, Chao Zhang 0008, Hai-Xin Duan, Tao Wan 0004, Jian Jiang 0002, Shuang Hao 0001, Yaoqi Jia
IEEE International Symposium on Reliable Distributed Systems (SRDS) 2018
We Still Don't Have Secure Cross-Domain Requests: an Empirical Study of CORS
Jianjun Chen 0005, Jian Jiang 0002, Hai-Xin Duan, Tao Wan 0004, Shuo Chen 0001, Vern Paxson, Min Yang 0002
USENIX Security Symposium 2018
Who Is Answering My Queries: Understanding and Characterizing Interception of the DNS Resolution Path
Baojun Liu 0002, Chaoyi Lu, Hai-Xin Duan, Ying Liu 0024, Zhou Li 0001, Shuang Hao 0001, Min Yang 0002
USENIX Security Symposium 2018
Measuring Privacy Threats in China-Wide Mobile Networks
Mingming Zhang 0010, Baojun Liu 0002, Chaoyi Lu, Jia Zhang 0004, Shuang Hao 0001, Hai-Xin Duan
USENIX Free and Open Communications on the Internet Workshop (FOCI) 2018
An Empirical Study of Web Resource Manipulation in Real-world Mobile Applications
Xiaohan Zhang 0001, Yuan Zhang 0009, Qianqian Mo, Hao Xia, Zhemin Yang, Min Yang 0002, Xiaofeng Wang 0006, Long Lu, Hai-Xin Duan
USENIX Security Symposium 2018
Don't Let One Rotten Apple Spoil the Whole Barrel: Towards Automated Detection of Shadowed Domains
Daiping Liu, Zhou Li 0001, Kun Du, Haining Wang 0001, Baojun Liu 0002, Hai-Xin Duan
ACM Conference on Computer and Communications Security (CCS) 2017
How to Notify a Vulnerability to the Right Person? Case Study: In an ISP Scope
Jia Zhang 0004, Hai-Xin Duan, Wu Liu, Xingkun Yao
IEEE Global Communications Conference (GLOBECOM) 2017
How to Learn Klingon without a Dictionary: Detection and Measurement of Black Keywords Used by the Underground Economy
Hao Yang, Xiulin Ma, Kun Du, Zhou Li 0001, Hai-Xin Duan, XiaoDong Su, Guang Liu, Zhifeng Geng, Jianping Wu
IEEE Symposium on Security and Privacy (S&P) 2017
An accurate distributed scheme for detection of prefix interception
Song Li, Hai-Xin Duan, Zhiliang Wang, Jinjin Liang, Xing Li 0001
Science China Information Sciences 2016
MAF-SAM: An effective method to perceive data plane threats of inter domain routing system
Yi Guo, Hai-Xin Duan, Jikun Chen, Fu Miao
Computer Networks 2016
Reexamining DNS From a Global Recursive Resolver Perspective
Hongyu Gao, Vinod Yegneswaran, Jian Jiang 0002, Yan Chen 0004, Phillip A. Porras, Shalini Ghosh, Hai-Xin Duan
IEEE/ACM Transactions on Networking 2016
What You See Isn't Always What You Get: A Measurement Study of Usage Fraud on Android Apps
Wei Liu, Yueqian Zhang, Zhou Li 0001, Hai-Xin Duan
Workshop on Security and Privacy in Smartphones and Mobile Devices (SPSM@CCS) 2016
Host of Troubles: Multiple Host Ambiguities in HTTP Implementations
Jianjun Chen 0005, Jian Jiang 0002, Hai-Xin Duan, Nicholas Weaver, Tao Wan 0004, Vern Paxson
ACM Conference on Computer and Communications Security (CCS) 2016
Forwarding-Loop Attacks in Content Delivery Networks
Jianjun Chen 0005, Xiaofeng Zheng, Hai-Xin Duan, Jinjin Liang, Jian Jiang 0002, Kang Li 0001, Tao Wan 0004, Vern Paxson
Network and Distributed System Security Symposium (NDSS) 2016
Seeking Nonsense, Looking for Trouble: Efficient Promotional-Infection Detection through Semantic Inconsistency Search
Xiaojing Liao, Kan Yuan, XiaoFeng Wang 0001, Zhongyu Pei, Hao Yang, Jianjun Chen 0005, Hai-Xin Duan, Kun Du, Eihal Alowaisheq, Sumayah A. Alrwais, Luyi Xing, Raheem A. Beyah
IEEE Symposium on Security and Privacy (S&P) 2016
The Ever-Changing Labyrinth: A Large-Scale Analysis of Wildcard DNS Powered Blackhat SEO
Kun Du, Hao Yang, Zhou Li 0001, Hai-Xin Duan, Kehuan Zhang
USENIX Security Symposium 2016
Route Leaks Identification by Detecting Routing Loops
Song Li, Hai-Xin Duan, Zhiliang Wang, Xing Li 0001
International Conference on Security and Privacy in Communication Networks (SecureComm) 2015
Cookies Lack Integrity: Real-World Implications
Xiaofeng Zheng, Jian Jiang 0002, Jinjin Liang, Hai-Xin Duan, Shuo Chen 0001, Tao Wan 0004, Nicholas Weaver
USENIX Security Symposium 2015
IntentFuzzer: detecting capability leaks of android applications
Kun Yang, Jianwei Zhuge, Yongke Wang, Lujue Zhou, Hai-Xin Duan
ACM Asia Conference on Computer and Communications Security (AsiaCCS) 2014
When HTTPS Meets CDN: A Case of Authentication in Delegated Service
Jinjin Liang, Jian Jiang 0002, Hai-Xin Duan, Kang Li 0001, Tao Wan 0004, Jianping Wu
IEEE Symposium on Security and Privacy (S&P) 2014
Measuring Query Latency of Top Level DNS Servers
Jinjin Liang, Jian Jiang 0002, Hai-Xin Duan, Kang Li 0001, Jianping Wu
Passive and Active Measurement Conference (PAM) 2013
An empirical reexamination of global DNS behavior
Hongyu Gao, Vinod Yegneswaran, Yan Chen 0004, Phillip A. Porras, Shalini Ghosh, Jian Jiang 0002, Hai-Xin Duan
ACM SIGCOMM Conference 2013
Research on the Anti-attack Design Principles of Low-Latency Anonymous Communication
Ming Zheng, Jianping Wu, Hai-Xin Duan
IEEE International Conference on Trust, Security and Privacy in Computing (TrustCom) 2013
Ghost Domain Names: Revoked Yet Still Resolvable
Jian Jiang 0002, Jinjin Liang, Kang Li 0001, Jun Li 0001, Hai-Xin Duan, Jianping Wu
Network and Distributed System Security Symposium (NDSS) 2012
Anonymity analysis of P2P anonymous communication systems
Jia Zhang 0004, Hai-Xin Duan, Wu Liu, Jianping Wu
Computer Communications 2011
A federated identity management system with centralized trust and unified Single Sign-On
Jian Jiang 0002, Hai-Xin Duan, Tao Lin, Fenglin Qin, Hong Zhang
International Conference on Communications and Networking in China (ChinaCom) 2011
User cooperation trust model and its application in network security management
Wu Liu, Ping Ren, Ke Liu, Hai-Xin Duan
International Conference on Fuzzy Systems and Knowledge Discovery (FSKD) 2011
Anonymous Communication over Invisible Mix Rings
Ming Zheng, Hai-Xin Duan, Jianping Wu
International Conference on Algorithms and Architectures for Parallel Processing (ICA3PP) 2011
Cooperation-Based Trust Model and Its Application in Network Security Management
Wu Liu, Hai-Xin Duan, Ping Ren
International Conference on Algorithms and Architectures for Parallel Processing (ICA3PP) 2011
Distinguishing the Master to Defend DDoS Attack in Peer-to-Peer Networks
Lei Hou, Hai-Xin Duan, Jianping Wu
CIT 2010
Analysis of Anonymity in P2P Anonymous Communication Systems
Jia Zhang 0004, Hai-Xin Duan, Wu Liu, Jianping Wu
IEEE International Conference on Advanced Information Networking and Applications Workshops 2010
IABA: An improved PNN Algorithm for anomaly detection in network security management
Wu Liu, Hai-Xin Duan, Ping Ren, Jianping Wu
International Conference on Computing, Networking and Communications (ICNC) 2010
WindTalker: A P2P-Based Low-Latency Anonymous Communication Network
Jia Zhang 0004, Hai-Xin Duan, Wu Liu, Jianping Wu
IEICE Transactions on Communications 2009
Selecting Trust Peers Based on Updated Credit Value in Peer-to-Peer Networks
Lei Hou, Hai-Xin Duan, Jianping Wu
International Conference on Security and Management 2009
RRM: An incentive reputation model for promoting good behaviors in distributed systems
Hong Zhang, Hai-Xin Duan, Wu Liu
Science China Information Sciences 2008
Dynamic emulation based modeling and detection of polymorphic shellcode at the network level
Lanjia Wang, Hai-Xin Duan, Xing Li 0001
Science China Information Sciences 2008
Scheduling Peers Based on Credit Construction Period in Peer-to-Peer Networks
Lei Hou, Hai-Xin Duan, Jianping Wu
IEEE International Conference on Parallel and Distributed Systems (ICPADS) 2008
Attacking Test and Online Forensics in IPv6 Networks
Wu Liu, Hai-Xin Duan, Tao Lin, Xing Li 0001, Jian-Ping Wu
International Conference on IT Security Incident Management and IT Forensics (IMF) 2008
An Admission Control Policy Based on Social Networks for P2P Systems
Yuan Liang, Hai-Xin Duan
International Conference on Web-Age Information Management (WAIM) 2008
AMCAS: An Automatic Malicious Code Analysis System
Jia Zhang 0004, Yuntao Guan, Xiaoxin Jiang, Hai-Xin Duan, Jianping Wu
International Conference on Web-Age Information Management (WAIM) 2008
Modeling and analyzing of the interaction between worms and antiworms during network worm propagation
Feng Yang, Hai-Xin Duan, Xing Li 0001
Science China Information Sciences 2005
Efficient performance estimate for one-class support vector machine
Quang-Anh Tran, Xing Li 0001, Hai-Xin Duan
Pattern Recognition Letters 2005
An Extensible AAA Infrastructure for IPv6
Hong Zhang, Hai-Xin Duan, Wu Liu, Jianping Wu
International Conference on Computational Intelligence and Security (CIS) 2005
PDTM: A Policy-Driven Trust Management Framework in Distributed Systems
Wu Liu, Hai-Xin Duan, Jianping Wu, Xing Li 0001
International Conference on Computational Intelligence and Security (CIS) 2005
New Algorithm Mining Intrusion Patterns
Wu Liu, Jianping Wu, Hai-Xin Duan, Xing Li 0001
International Conference on Fuzzy Systems and Knowledge Discovery (FSKD) 2005
New Method for Intrusion Features Mining in IDS
Wu Liu, Jianping Wu, Hai-Xin Duan, Xing Li 0001
International Conference on Intelligent Computing (ICIC) 2005
Port Scan Behavior Diagnosis by Clustering
Lanjia Wang, Hai-Xin Duan, Xing Li 0001
International Conference on Information and Communications Security (ICICS) 2005
The Authorization Service in Dynamic Trust Domains
Wu Liu, Jianping Wu, Hai-Xin Duan, Xing Li 0001
International Conference on Information Technology and Applications (ICITA) 2005
Improved Marking Model ERPPM Tracing Back to DDoS Attacker
Wu Liu, Hai-Xin Duan, Jianping Wu, Xing Li 0001
International Conference on Information Technology and Applications (ICITA) 2005
Anomaly Internet Network Traffic Detection by Kernel Principle Component Classifier
Hanghang Tong, Chongrong Li, Jingrui He, Jiajian Chen, Quang-Anh Tran, Hai-Xin Duan, Xing Li 0001
International Symposium on Neural Networks (ISNN) 2005
Workflow Oriented Network Management - A Web/Java Approach
Jiahai Yang 0001, Hai-Xin Duan, Jianping Wu, Xing Li 0001
Journal of Network and Systems Management 2004
XML Based X.509 Authorization in CERNET Grid
Wu Liu, Jianping Wu, Hai-Xin Duan, Xing Li 0001, Ping Ren
International Conference on Grid and Cooperative Computing (GCC) 2004
Algorithms for Congestion Detection and Control
Wu Liu, Hai-Xin Duan, Jianping Wu, Xing Li 0001, Ping Ren
International Conference on Grid and Cooperative Computing Workshops 2004
Improved algorithms tracing back to attacking sources
Wu Liu, Hai-Xin Duan, Yong Feng, Yong-Bin Li, Ping Ren
IASTED International Conference on Parallel and Distributed Computing and Networks 2004
Distributed IDS Tracing Back to Attacking Sources
Wu Liu, Hai-Xin Duan, Jianping Wu, Ping Ren, Li-Hua Lu
International Conference on Grid and Cooperative Computing (GCC) 2003
Policy based access control framework for large networks
Hai-Xin Duan, Jianping Wu, Xing Li 0001
IEEE International Conference on Networks (ICON) 2000

🏛Professional Service

Professional Bodies

  • Member, Academic Degrees Committee of the State Council (2020—)
  • Secretary-General, CCF Technical Committee on Network and System Security
  • Executive Director, China Cyberspace Security Association
  • Member, China Network Security Industry Alliance (2016—)
  • Guest Professor, Harbin Institute of Technology (Weihai)

Editorial Board

  • Associate Editor, ACM Transactions on Privacy and Security (2020—)

Journal Reviewer

  • IEEE Transactions on Networking
  • IEEE/ACM Transactions on Networking
  • Journal of Network and Computer Applications

Conference Program Committees

  • SecureComm 2023 — PC Chair
  • NDSS — PC Member (multiple years)
  • ACM CCS — PC Member (multiple years)
  • USENIX Security — PC Member (multiple years)
  • IEEE S&P — PC Member (multiple years)

Community Initiatives (Co-founder)

  • InForSec — Chair (2015—)
    International Security Research Forum
  • XCTF — (2016—)
    China's premier CTF competition series
  • DataCon — (2019—)
    Data Security Competition & Conference