Baojun Liu - Publications
2027
-
80
Marketplace Chameleons: Demystifying the Scam Ecosystem of Second-Hand Online PlatformsNetwork and Distributed System Security Symposium (NDSS)
-
81
Standards-to-Surface: A Comprehensive Evaluation of Windows Code-Signing (Non)ComplianceNetwork and Distributed System Security Symposium (NDSS)
-
82
Tracking the Shadows: A Longitudinal, End-to-End Analysis of the Criminal Ecosystem for Email Account CompromiseNetwork and Distributed System Security Symposium (NDSS)
2026
-
63
Should I Trust You? Rethinking the Principle of Zone-Based Isolation DNS Bailiwick Checking33rd Annual Network and Distributed System Security Symposium (NDSS)NDSS Distinguished Paper Award
-
64
CoordMail: Exploiting SMTP Timeout and Command Interaction to Coordinate Email Middleware for Convergence Amplification Attack33rd Annual Network and Distributed System Security Symposium (NDSS)
-
65
Understanding the Status and Strategies of the Code Signing Abuse Ecosystem33rd Annual Network and Distributed System Security Symposium (NDSS)
-
66
Beyond Jailbreak: Unveiling Risks in LLM Applications Arising from Blurred Capability Boundaries33rd Annual Network and Distributed System Security Symposium (NDSS)
-
67
One Email, Many Faces: A Deep Dive into Identity Confusion in Email Aliases33rd Annual Network and Distributed System Security Symposium (NDSS)NDSS Distinguished Paper Award
-
68
Breaking Free from Ivory Tower: Evaluating and Enhancing Real-world Chinese Underground Adversarial Jargon DetectionIEEE Symposium on Security and Privacy (S&P)
-
69
Characterizing Iran's Phased National Internet Shutdown in 2025: A Progressive and Distributed ActionThe ACM Web Conference (WWW)
-
70
Unveiling the Resilience of LLM-Enhanced Search Engines Against Black-Hat SEO ManipulationThe ACM Web Conference (WWW)
-
71
Alias Equals Zone? Large-Scale and Stealthy Takeover of Domain Hosting Service via CNAME-Following Cross-Domain Verification35th USENIX Security Symposium (USENIX Security)
-
72
Shielding QR Codes: Unveiling the Real-World Illicit Promotion Behind Adversarial QR Code35th USENIX Security Symposium (USENIX Security)
-
73
Cracks in the Walled Garden: Dissecting the Gray-Market of Unauthorized iOS App Distribution via Ad Hoc Sideloading35th USENIX Security Symposium (USENIX Security)
-
74
Good Cache, BAD Cache: Exploiting DNSSEC Validation Failures for DNS Cache Poisoning AttacksACM SIGSAC Conference on Computer and Communications Security (CCS)
-
75
The Trade-off Between Performance and Security: Exploring Vulnerabilities in DNS Task Queue SchedulingACM SIGSAC Conference on Computer and Communications Security (CCS)
-
76
When Delivery Meets Error: Exploring Email Delivery Retry Strategies and DefectsACM Internet Measurement Conference (IMC)
-
77
Unintended Revelations and Risks: Understanding Cellular DNS Leakage on the Public InternetACM Internet Measurement Conference (IMC)
-
78
One Click to Leak: Characterizing the Real-World Usage and Threat Impact of MNO-based Single Sign-On WebsitesACM SIGSAC Conference on Computer and Communications Security (CCS)
-
79
Traffic Shadowing: A Global Investigation of Internet Traffic Observation and User Data ReutilizationIEEE Transactions on Networking
— IEEE S&P —
— WWW —
— USENIX Security —
— ACM CCS —
— ACM IMC —
— ACM CCS —
— IEEE/ACM ToN (Journal) —
2025
-
48
HADES Attack: Understanding and Evaluating Manipulation Risks of Email Blocklists32nd Annual Network and Distributed System Security Symposium (NDSS)
-
49
Revealing the Black Box of Device Search Engine: Scanning Assets, Strategies, and Ethical Consideration32nd Annual Network and Distributed System Security Symposium (NDSS)
-
50
You Can't Eat Your Cake and Have It Too: The Performance Degradation of LLMs with Jailbreak DefenseACM Web Conference (WWW)
-
51
Decoding DNS Centralization: Measuring and Identifying NS Domains Across Hosting Providers55th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
-
52
Beyond Exploit Scanning: A Functional Change-Driven Approach to Remote Software Version IdentificationUSENIX Security Symposium
-
53
Your Shield is My Sword: A Persistent Denial-of-Service Attack via the Reuse of Unvalidated Caches in DNSSEC Validation34th USENIX Security Symposium (USENIX Security)USENIX Security Honorable Mention
-
54
NOKEScam: Understanding and Rectifying Non-Sense Keywords Spear Scam in Search EnginesUSENIX Security Symposium
-
55
Misty Registry: An Empirical Study of Flawed Domain Registry OperationUSENIX Security Symposium
-
56
Email Cloaking: Deceiving Users and Spam Email Detectors with Invisible HTML SettingsEuropean Symposium on Research in Computer Security (ESORICS)
-
57
Exploring and Analyzing Cross Layer DoS Attack Against UDP-based Services on LinuxACM Conference on Computer and Communications Security (CCS)
-
58
RebirthDay Attack: Reviving DNS Cache Poisoning with the Birthday ParadoxACM Conference on Computer and Communications Security (CCS)
-
59
Understanding and Characterizing Intermediate Paths of Email Delivery: The Hidden DependenciesACM Internet Measurement Conference (IMC)
-
60
Analyzing Compliance and Complications of Integrating Internationalized X.509 CertificatesACM Internet Measurement Conference (IMC)
-
61
Chaos in the Chain: Evaluate Deployment and Construction Compliance of Web PKI Certificate ChainACM Internet Measurement Conference (IMC)
-
62
Dive into the cloud: Unveiling the (Ab)usage of Serverless Cloud Function in the WildACM Internet Measurement Conference (IMC)
— WWW —
— IEEE/IFIP DSN —
— USENIX Security —
— ESORICS —
— ACM CCS —
— ACM IMC —
2024
-
37
Understanding the Implementation and Security Implications of Protective DNS Services31st Annual Network and Distributed System Security Symposium (NDSS)
-
38
TuDoor Attack: Systematically Exploring and Exploiting Logic Vulnerabilities in DNS Response Pre-processing with Malformed PacketsIEEE Symposium on Security and Privacy (SP)
-
39
A Worldwide View on the Reachability of Encrypted DNS ServicesACM Web Conference (WWW)
-
40
ChatScam: Unveiling the Rising Impact of ChatGPT on Domain Name Abuse54th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
-
41
Tickets or Privacy? Understand the Ecosystem of Chinese Ticket Grabbing AppsUSENIX Security Symposium
-
42
Rethinking the Security Threats of Stale DNS Glue RecordsUSENIX Security Symposium
-
43
Into the Dark: Unveiling Internal Site Search Abused for Black Hat SEOUSENIX Security Symposium
-
44
Cross the Zone: Toward a Covert Domain Hijacking via Shared DNS InfrastructureUSENIX Security Symposium
-
45
Yesterday Once More: Global Measurement of Internet Traffic Shadowing BehaviorsACM Internet Measurement Conference (IMC)
-
46
Bounce in the Wild: A Deep Dive into Email Delivery Failures from a Large Email Service ProviderACM Internet Measurement Conference (IMC)
-
47
Investigating Deployment Issues of DNS Root Server Instances From a China-Wide View*IEEE Transactions on Dependable and Secure Computing*
— IEEE S&P —
— WWW —
— IEEE/IFIP DSN —
— USENIX Security —
— ACM IMC —
— IEEE TDSC (Journal) —
2023
-
28
Ghost Domain Reloaded: Vulnerable Links in Domain Name Delegation and Revocation30th Annual Network and Distributed System Security Symposium (NDSS)
-
29
Detecting and Measuring Security Risks of Hosting-Based Dangling DomainsACM SIGMETRICS International Conference on Measurement and Modeling of Computer Systems (SIGMETRICS)
-
30
Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS ServersACM Turing Award Celebration Conference - China (TURC)
-
31
The Maginot Line: Attacking the Boundary of DNS Caching Protection32nd USENIX Security Symposium (USENIX Security)
-
32
Temporal CDN-Convex Lens: A CDN-Assisted Practical Pulsing DDoS Attack32nd USENIX Security Symposium (USENIX Security)
-
33
Wolf in Sheep's Clothing: Evaluating Security Risks of the Undelegated Record on DNS Hosting ServicesACM Internet Measurement Conference (IMC)
-
34
Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS ServersACM SIGSAC Conference on Computer and Communications Security (CCS)ACM CCS Distinguished Paper Award
-
35
TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS AmplifiersACM Conference on Computer and Communications Security (CCS)
-
36
Under the Dark: A Systematical Study of Stealthy Mining Pools (Ab)use in the WildACM Conference on Computer and Communications Security (CCS)
— SIGMETRICS —
— TURC —
— USENIX Security —
— ACM IMC —
— ACM CCS —
2022
-
22
Measuring the Practical Effect of DNS Root Server Instances: A China-Wide Case StudyPassive and Active Measurement (PAM) Conference
-
23
PMTUD is not Panacea: Revisiting IP Fragmentation Attacks against TCP29th Annual Network and Distributed System Security Symposium (NDSS)
-
24
Trampoline Over the Air: Breaking in IoT Devices Through MQTT Brokers7th IEEE European Symposium on Security and Privacy (EuroS&P)
-
25
Building an Open, Robust, and Stable Voting-Based Domain Top List31st USENIX Security Symposium (USENIX Security)
-
26
A Large-scale and Longitudinal Measurement Study of DKIM Deployment31st USENIX Security Symposium (USENIX Security)
-
27
Exploring the Characteristics and Security Risks of Emerging Emoji Domain Names27th European Symposium on Research in Computer Security (ESORICS)
— NDSS —
— Euro S&P —
— USENIX Security —
— ESORICS —
2021
-
16
From WHOIS to WHOWAS: A Large-Scale Measurement Study of Domain Name Registration Privacy28th Annual Network and Distributed System Security Symposium (NDSS)
-
17
Fast IPv6 Network Periphery Discovery and Security Implications51st Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
-
18
Weak Links in Authentication Chains: A Large-scale Analysis of Email Sender Authentication30th USENIX Security Symposium (USENIX Security)
-
19
Rusted Anchors: A National Client-Side View of Hidden Root CAs in the Web PKI EcosystemACM Conference on Computer and Communications Security (CCS)
-
20
Detecting and Characterizing SMS Spearphishing AttacksAnnual Computer Security Applications Conference (ACSAC)
-
21
DNSWeight: Quantifying Country-Wise Importance of Domain Name System*IEEE Access*
— IEEE/IFIP DSN —
— USENIX Security —
— ACM CCS —
— ACSAC —
— IEEE Access —
2020
-
11
CDN Judo: Breaking the CDN DoS Protection with ItselfNetwork and Distributed System Security Symposium (NDSS)
-
12
CDN Backfired: Amplification Attacks Based on HTTP Range RequestsIEEE/IFIP International Conference on Dependable Systems and Networks (DSN)IEEE/IFIP DSN Best Paper Award
-
13
Poison Over Troubled Forwarders: A Cache Poisoning Attack Targeting DNS Forwarding DevicesUSENIX Security Symposium
-
14
Lies in the Air: Characterizing Fake-base-station Spam EcosystemACM SIGSAC Conference on Computer and Communications Security (CCS)
-
15
Talking with Familiar Strangers: An Empirical Study on HTTPS Context Confusion AttacksACM SIGSAC Conference on Computer and Communications Security (CCS)
— IEEE/IFIP DSN —
— USENIX Security —
— ACM CCS —
2019
-
6
Cracking the Wall of Confinement: Understanding and Analyzing Malicious Domain Take-downsNetwork and Distributed System Security Symposium (NDSS)NDSS Best Paper Award
-
7
Resident Evil: Understanding Residential IP Proxy as a Dark ServiceIEEE Symposium on Security and Privacy (S&P)
-
8
TraffickStop: Detecting and Measuring Illicit Traffic Monetization Through Large-Scale DNS Log AnalysisIEEE European Symposium on Security and Privacy (EuroS&P)
-
9
TL;DR Hazard: A Comprehensive Study of Levelsquatting ScamsInternational Conference on Security and Privacy in Communication Networks (SecureComm)
-
10
An End-to-End, Large-Scale Measurement of DNS-over-Encryption: How Far Have We Come?ACM Internet Measurement Conference (IMC)ISOC Applied Networking Research Award (ANRP) 2020ACM IMC Best Paper Award NomineeACM IMC Community Contribution Award Nominee
— IEEE S&P —
— Euro S&P —
— SecureComm —
— ACM IMC —
2018
-
2
A Reexamination of Internationalized Domain Names: the Good, the Bad and the UglyIEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
-
3
Who is answering my queries: Understanding and Characterizing Interception of the DNS Resolution PathUSENIX Security Symposium
-
4
Measuring Privacy Threats in China-Wide Mobile NetworksUSENIX Workshop on Free and Open Communications on the Internet (FOCI)
-
5
Abusing CDNs for Fun and Profit: Security Issues in CDNs' Origin ValidationIEEE International Symposium on Reliable Distributed Systems (SRDS)
— USENIX Security —
— FOCI —
— SRDS —
2017
-
1
Don't Let One Rotten Apple Spoil the Whole Barrel: Towards Automated Detection of Shadowed DomainsACM SIGSAC Conference on Computer and Communications Security (CCS)