Baojun Liu - Publications
2025
-
NOKEScam: Understanding and Rectifying Non-Sense Keywords Spear Scam in Search Engines
USENIX Security Symposium
-
Misty Registry: An Empirical Study of Flawed Domain Registry Operation
USENIX Security Symposium
-
Chaos in the Chain: Evaluate Deployment and Construction Compliance of Web PKI Certificate Chain
ACM Internet Measurement Conference (IMC)
-
Dive into the cloud: Unveiling the (Ab)usage of Serverless Cloud Function in the Wild
ACM Internet Measurement Conference (IMC)
-
HADES Attack: Understanding and Evaluating Manipulation Risks of Email Blocklists
32nd Annual Network and Distributed System Security Symposium (NDSS)
-
Revealing the Black Box of Device Search Engine: Scanning Assets, Strategies, and Ethical Consideration
32nd Annual Network and Distributed System Security Symposium (NDSS)
-
Decoding DNS Centralization: Measuring and Identifying NS Domains Across Hosting Providers
55th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
-
You Can't Eat Your Cake and Have It Too: The Performance Degradation of LLMs with Jailbreak Defense
ACM Web Conference (WWW)
2024
-
Investigating Deployment Issues of DNS Root Server Instances From a China-Wide View
IEEE Transactions on Dependable and Secure Computing
-
Yesterday Once More: Global Measurement of Internet Traffic Shadowing Behaviors
ACM Internet Measurement Conference (IMC)
-
Bounce in the Wild: A Deep Dive into Email Delivery Failures from a Large Email Service Provider
ACM Internet Measurement Conference (IMC)
-
Understanding the Implementation and Security Implications of Protective DNS Services
31st Annual Network and Distributed System Security Symposium (NDSS)
-
TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed Packets
IEEE Symposium on Security and Privacy (SP)
-
Tickets or Privacy? Understand the Ecosystem of Chinese Ticket Grabbing Apps
USENIX Security Symposium
-
Rethinking the Security Threats of Stale DNS Glue Records
USENIX Security Symposium
-
Into the Dark: Unveiling Internal Site Search Abused for Black Hat SEO
USENIX Security Symposium
-
Cross the Zone: Toward a Covert Domain Hijacking via Shared DNS Infrastructure
USENIX Security Symposium
-
A Worldwide View on the Reachability of Encrypted DNS Services
ACM Web Conference (WWW)
2023
-
Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS Servers
ACM Conference on Computer and Communications Security (CCS)
-
Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS Servers
ACM Turing Award Celebration Conference - China (TURC)
-
TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS Amplifiers
ACM Conference on Computer and Communications Security (CCS)
-
Under the Dark: A Systematical Study of Stealthy Mining Pools (Ab)use in the Wild
ACM Conference on Computer and Communications Security (CCS)
-
Wolf in Sheep's Clothing: Evaluating Security Risks of the Undelegated Record on DNS Hosting Services
ACM Internet Measurement Conference (IMC)
-
Ghost Domain Reloaded: Vulnerable Links in Domain Name Delegation and Revocation
30th Annual Network and Distributed System Security Symposium (NDSS)
-
Detecting and Measuring Security Risks of Hosting-Based Dangling Domains
ACM SIGMETRICS International Conference on Measurement and Modeling of Computer Systems (SIGMETRICS)
-
The Maginot Line: Attacking the Boundary of DNS Caching Protection
32nd USENIX Security Symposium (USENIX Security)
-
Temporal CDN-Convex Lens: A CDN-Assisted Practical Pulsing DDoS Attack
32nd USENIX Security Symposium (USENIX Security)
2022
-
Exploring the Characteristics and Security Risks of Emerging Emoji Domain Names
27th European Symposium on Research in Computer Security (ESORICS)
-
Trampoline Over the Air: Breaking in IoT Devices Through MQTT Brokers
7th IEEE European Symposium on Security and Privacy (EuroS&P)
-
PMTUD is not Panacea: Revisiting IP Fragmentation Attacks against TCP
29th Annual Network and Distributed System Security Symposium (NDSS)
-
Measuring the Practical Effect of DNS Root Server Instances: A China-Wide Case Study
Passive and Active Measurement (PAM) Conference
-
Building an Open, Robust, and Stable Voting-Based Domain Top List
31st USENIX Security Symposium (USENIX Security)
-
A Large-scale and Longitudinal Measurement Study of DKIM Deployment
31st USENIX Security Symposium (USENIX Security)
2021
-
DNSWeight: Quantifying Country-Wise Importance of Domain Name System
IEEE Access
-
Detecting and Characterizing SMS Spearphishing Attacks
Annual Computer Security Applications Conference (ACSAC)
-
Rusted Anchors: A National Client-Side View of Hidden Root CAs in the Web PKI Ecosystem
ACM Conference on Computer and Communications Security (CCS)
-
Fast IPv6 Network Periphery Discovery and Security Implications
51st Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
-
From WHOIS to WHOWAS: A Large-Scale Measurement Study of Domain Registration Privacy under the GDPR
28th Annual Network and Distributed System Security Symposium (NDSS)
-
Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Spoofing Attacks
30th USENIX Security Symposium (USENIX Security)
2020
-
Lies in the Air: Characterizing Fake-base-station Spam Ecosystem in China
ACM Conference on Computer and Communications Security (CCS)
-
Talking with Familiar Strangers: An Empirical Study on HTTPS Context Confusion Attacks
ACM Conference on Computer and Communications Security (CCS)
-
CDN Backfired: Amplification Attacks Based on HTTP Range Requests
50th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
-
CDN Judo: Breaking the CDN DoS Protection with Itself
27th Annual Network and Distributed System Security Symposium (NDSS)
-
Poison Over Troubled Forwarders: A Cache Poisoning Attack Targeting DNS Forwarding Devices
29th USENIX Security Symposium (USENIX Security)
2019
-
Who is answering my queries: Understanding and Characterizing Interception of the DNS Resolution Path
Applied Networking Research Workshop (ANRW)
-
TraffickStop: Detecting and Measuring Illicit Traffic Monetization Through Large-Scale DNS Analysis
IEEE European Symposium on Security and Privacy (EuroS&P)
-
An End-to-End, Large-Scale Measurement of DNS-over-Encryption: How Far Have We Come?
ACM Internet Measurement Conference (IMC)
-
Cracking the Wall of Confinement: Understanding and Analyzing Malicious Domain Take-downs
26th Annual Network and Distributed System Security Symposium (NDSS)
-
TL;DR Hazard: A Comprehensive Study of Levelsquatting Scams
15th EAI International Conference on Security and Privacy in Communication Networks (SecureComm)
-
Resident Evil: Understanding Residential IP Proxy as a Dark Service
IEEE Symposium on Security and Privacy (SP)
2018
-
A Reexamination of Internationalized Domain Names: The Good, the Bad and the Ugly
48th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
-
Abusing CDNs for Fun and Profit: Security Issues in CDNs' Origin Validation
37th IEEE Symposium on Reliable Distributed Systems (SRDS)
-
Who Is Answering My Queries: Understanding and Characterizing Interception of the DNS Resolution Path
27th USENIX Security Symposium (USENIX Security)
-
Measuring Privacy Threats in China-Wide Mobile Networks
8th USENIX Workshop on Free and Open Communications on the Internet (FOCI)
2017
-
Don't Let One Rotten Apple Spoil the Whole Barrel: Towards Automated Detection of Shadowed Domains
ACM Conference on Computer and Communications Security (CCS)