Proactive Vulnerability Discovery and Assessment in Smart, Connected Systems Through Systematic Problem Analysis
Qi Alfred Chen
Ph.D. Thesis, University of Michigan, June 2018
[PDF]
[NDSS'18] Exposing Congestion Attack on Emerging Connected Vehicle based Traffic Signal Control
Qi Alfred Chen, Yucheng Yin, Yiheng Feng, Z. Morley Mao, and Henry X. Liu
Proceedings of the 25th Network and Distributed System Security Symposium (NDSS'18), San Diego, Feb. 2018. (acceptance rate 21.5% = 71/331)
[PDF] [BIB] [Slides] [Website] [Attack demo]
Media coverage: My article in The Conversation, The Register, Trend Micro, Naked Security, Slashdot, Bleeping Computer, Smart Cities Dive, Boing Boing, The Morning Paper, Michigan Engineer, PriusChat ...
[CCS'17] Client-side Name Collision Vulnerability in the New gTLD Era: A Systematic Study
Qi Alfred Chen, Matthew Thomas, Eric Osterweil, Yulong Cao, Jie You, Z. Morley Mao
Proceedings of the 24th ACM Conference on Computer and Communications Security (CCS'17), Dallas, Oct. 2017. (acceptance rate 18.1% = 151/836)
[PDF] [BIB] [Slides]
[NDSS'17] ContexIoT: Towards Providing Contextual Integrity to Appified IoT Platforms
Yunhan Jack Jia, Qi Alfred Chen, Shiqi Wang, Amir Rahmati, Earlence Fernandes, Z. Morley Mao, and Atul Prakash
Proceedings of the 24th Network and Distributed System Security Symposium (NDSS'17), San Diego, Feb. 2017. (acceptance rate 16.1% = 68/423)
[PDF] [BIB] [IoT malware taxonomy]
[S&P'16] MitM Attack by Name Collision: Cause Analysis and Vulnerability Assessment in the New gTLD Era
Qi Alfred Chen, Eric Osterweil, Matthew Thomas, and Z. Morley Mao
Proceedings of the 37th IEEE Symposium on Security and Privacy (S&P'16), San Jose, May 2016. (acceptance rate 13.3% = 55/413)
[PDF] [BIB] [Slides]
[US-CERT Alert (TA16-144A)] [RIPE 72 Discussion] [Verisign Enterprise Remediation Suggestions] [Snort signature]
Media coverage: SecurityAffairs NakedSecurity SecurityWeek Reddit SCMagazine HelpNetSecurity SecurityIntelligence...
[NDSS'16] Kratos: Discovering Inconsistent Security Policy Enforcement in the Android Framework
Yuru Shao, Jason Ott, Qi Alfred Chen, Zhiyun Qian, and Z. Morley Mao
Proceedings of the 23rd Network and Distributed System Security Symposium (NDSS'16), San Diego, Feb. 2016. (acceptance rate 15.4% = 60/389)
[PDF] [BIB] [Vulnerability result website]
[CCS'15] Static Detection of Packet Injection Vulnerabilities -- A Case for Identifying Attacker-controlled Implicit Information Leaks
Qi Alfred Chen, Zhiyun Qian, Yunhan Jia, Yuru Shao, and Z. Morley Mao
Proceedings of the 22nd ACM Conference on Computer and Communications Security (CCS'15), Denver, Oct. 2015. (acceptance rate 19.8% = 128/646)
[PDF] [BIB] [Slides] [Vulnerability result website]
[Usenix Security'14] Peeking into Your App without Actually Seeing It: UI State Inference and Novel Android Attacks
Qi Alfred Chen, Zhiyun Qian, and Z. Morley Mao
Proceedings of the 23rd USENIX Security Symposium (USENIX Security'14), San Diego, Aug. 2014. (acceptance rate 19.0% = 67/352)
[PDF] [BIB] [Slides] [Website] [Attack demos] [Lightning videos: 60 sec 90 sec]
Media coverage: Ars Technica CNET News Slashdot CBS News BBC News NBC News Android Headlines Tom's Guide PC Magazine HotHardware ...
[TRB'18] Vulnerability of Traffic Control System Under Cyber-Attacks Using Falsified Data
Yiheng Feng, Shihong Huang, Qi Alfred Chen, Henry X. Liu, and Z. Morley Mao
Proceedings of the Transportation Research Board 2018 Annual Meeting (TRB'18), Washington, D.C., Jan. 2018. (selected for journal publication with acceptance rate 20.0%)
[PDF] [BIB]
[IV'17] Towards Secure and Safe Appified Automated Vehicles
Yunhan Jack Jia, Ding Zhao, Qi Alfred Chen, and Z. Morley Mao
Proceedings of the 28th IEEE Intelligent Vehicles Symposium (IV'17), Redondo Beach, Jun. 2017. (selected for oral presentation with acceptance
rate 10.0%)
[PDF] [BIB] [OpenAV project website]
[IMC'16] Understanding On-device Bufferbloat for Cellular Upload
Yihua Guo, Feng Qian, Qi Alfred Chen, Z. Morley Mao, and Subhabrata Sen
Proceedings of the 16th ACM SIGCOMM Internet Measurement Conference (IMC'16), Santa Monica, Nov. 2016. (acceptance rate 25.3% = 46/182)
[PDF] [BIB]
[Mobicom'15] Performance Characterization and Call Reliability Problem Diagnosis for Voice over LTE
Yunhan Jack Jia, Qi Alfred Chen, Z. Morley Mao, Jie Hui, Kranthi Sontineni, Alex Yoon, Samson Kwong, and Kevin Lau
Proceedings of the 21th ACM Annual International Conference on Mobile Computing and Networking (Mobicom'15), Paris, France, Sept. 2015. (acceptance rate 18.4% = 38/207)
[PDF] [BIB] [Lightning video]
[IMC'14] QoE Doctor: Diagnosing Mobile App QoE with Automated UI Control and Cross-layer Analysis
Qi Alfred Chen, Haokun Luo, Sanae Rosen, Z. Morley Mao, Karthik Iyer, Jie Hui, Kranthi Sontineni, and Kevin Lau
Proceedings of the 14th ACM Internet Measurement Conference (IMC'14), Vancouver, Canada, Nov. 2014. (acceptance rate 22.9% = 43/188)
[PDF] [BIB] [Slides] [Tool demos: Post status on Facebook, Post photos on Facebook]
[Mobicom'14] Discovering Fine-grained RRC State Dynamics and Performance Impacts in Cellular Networks
Sanae Rosen, Haokun Luo, Qi Alfred Chen, Z. Morley Mao, Jie Hui, Aaron Drake, and Kevin Lau
Proceedings of the 20th ACM Annual International Conference on Mobile Computing and Networking (Mobicom'14), Maui, Sept. 2014. (acceptance rate 16.4% = 36/220)
[PDF] [BIB]
[TRR'18] Vulnerability of Traffic Control System Under Cyberattacks with Falsified Data [PDF] [BIB]
Yiheng Feng, Shihong Huang, Qi Alfred Chen, Henry X. Liu, and Z. Morley Mao
Transportation Research Record (TRR), Volume 2672, Issue 1, Page 1-11, Mar. 2018. (Indexed by SCI, Impact Factor 0.695)
[AsiaCCS'18] No One In The Middle: Enabling Network Access Control Via Transparent Attribution [PDF] [BIB]
Jeremy Erickson, Qi Alfred Chen, Xiaochen Yu, Erinjen Lin, Robert Levy, and Z. Morley Mao
Proceedings of the 13th ACM ASIA Conference on Computer and Communications Security (ASIACCS’18), Songdo, Incheon, Korea, June 2018. (acceptance rate 20%)
QoE Inference and Improvement Without End-Host Control [PDF]
Ashkan Nikravesh, Qi Alfred Chen, Scott Haseley, Xiao Zhu, Geoffrey Challen, and Z. Morley Mao
Proceedings of the 3rd ACM/IEEE Symposium on Edge Computing (SEC’18), Bellevue, Washington, October 2018.
[Euro S&P'17] Open Doors for Bob and Mallory: Open Port Usage in Android Apps and Security Implications
Yunhan Jack Jia, Qi Alfred Chen, Yikai Lin, Chao Kong, and Z. Morley Mao
Proceedings of the 2nd IEEE European Symposium on Security and Privacy (Euro S&P'17), Paris, France, Apr. 2017. (acceptance rate 19.6% = 38/194)
[PDF] [BIB] [Video demos: Threat model, Attack (CVE-2016-5227), Defense] [Tool release]
Media coverage: My interview at WXYZ-TV (ABC afflicated) Wired Michigan Engineering TechRepublic Bleeping Computer Android Headlines ...
An Initial Investigation of Protocol Customization [PDF] [BIB]
David Ke Hong, Qi Alfred Chen, and Z. Morley Mao
Proceedings of the 2017 ACM CCS Workshop on Forming an Ecosystem Around Software Transformation (FEAST'17), Dallas, Nov., 2017.
[FC'16] Android UI Deception Revisited: Attacks and Defenses [PDF] [BIB]
Earlence Fernandes, Qi Alfred Chen, Justin Paupore, Georg Essl, J. Alex Halderman, Z. Morley Mao, and Atul Prakash
Proceedings of the 20th International Conference on Financial Cryptography and Data Security (FC'16), Barbados, Feb. 2016. (acceptance rate 26%)
QoE Inference Without Application Control [PDF]
Ashkan Nikravesh, David Ke Hong, Qi Alfred Chen, Harsha V. Madhyastha, and Z. Morley Mao
Proceedings of the ACM SIGCOMM Workshop on QoE-based Analysis and Management of Data Communication Networks (Internet-QoE'16), Florianopolis, Brazil, Aug. 2016.
Efficient Route Guidance in Vehicular Wireless Networks [PDF] [BIB] [Slides]
Yu Stephanie Sun, Lei Xie, Qi Alfred Chen, Sanglu Lu, and Daoxu Chen
Proceedings of IEEE Wireless Communications and Networking Conference (WCNC'14), Istanbul, Turkey, Apr. 2014.
-
A Confidence-Based Filtering Method for DDoS Attack Defense in Cloud Environment [PDF] [BIB]
Wanchun Dou, Qi Chen and Jinjun Chen
Future Generation Computer Systems (FGCS), Volume 29, Issue 7, Pages 1838–1850, Sept. 2013. (Indexed by SCI, Impact Factor 2.639)
CBF: A Packet Filtering Method for DDoS Attack Defense in Cloud Environment [PDF][BIB]
Qi Chen, Wenmin Lin, Shui Yu, and Wanchun Dou
Proceedings of the 9th IEEE International Conference on Dependable, Autonomic and Secure Computing (DASC'11), Sydney, Australia, Dec. 2011.