[1] Qi Wang, Jianjun Chen, Zheyu Jiang, Run Guo, Ximeng Liu, Chao Zhang, Haixin Duan. Break the Wall from Bottom: Automated Discovery of Protocol-Level Evasion Vulnerabilities in Web Application Firewalls. 2024 IEEE Symposium on Security and Privacy (IEEE S&P'24,网络安全四大顶会之一).
[2] Enze Wang, Jianjun Chen, Wei Xie, Chuhan Wang, Yifei Gao, Zhenhua Wang, Haixin Duan, Yang Liu, Baosheng Wang. Where URLs Become Weapons: Automated Discovery of SSRF Vulnerabilities in Web Applications. 2024 IEEE Symposium on Security and Privacy (IEEE S&P'24,网络安全四大顶会之一).
[3] Jiahe Zhang, Jianjun Chen, Qi Wang, Hangyu Zhang, Chuhan Wang, Jianwei Zhuge, Haixin Duan. Inbox Invasion: Exploiting MIME Ambiguities to Evade Email Attachment Detectors. 31th ACM Conference on Computer and Communications Security (CCS'24,网络安全四大顶会之一).
[4] Yuejia Liang, Jianjun Chen, Run Guo, Kaiwen Shen, Hui Jiang, Man Hou, Yue Yu, Haixin Duan. Internet’s Invisible Enemy: Detecting and Measuring Web Cache Poisoning in the Wild. 31th ACM Conference on Computer and Communications Security (CCS'24,网络安全四大顶会之一).
[5] Ziyu Lin, Zhiwei Lin, Ximeng Liu, Jianjun Chen, Run Guo, Cheng Chen, Shaodong Xiao. CDN Cannon: Exploiting CDN Back-to-Origin Strategies for Amplification Attacks. 33th USENIX Conference on Security Symposium (USENIX Security'24,网络安全四大顶会之一).
[6] Yi He, Ruoyu Lun, Yunchao Guan, Shangru Song, Zhihao Guo, Hetian Shi, Jianwei Zhuge, Jianjun Chen, Qiang We, Zehui Wu, Miao Yu, Qi Li. Demystifying the Security Implications in IoT Device Rental Services. 33th USENIX Conference on Security Symposium (USENIX Security'24,网络安全四大顶会之一).
[7] Chuhan Wang, Yasuhiro Kuranaga, Yihang Wang, Mingming Zhang, Linkai Zheng, Xiang Li, Jianjun Chen, Haixin Duan, Yanzhong Lin, Qingfeng Pan.BreakSPF: How Shared Infrastructures Magnify SPF Vulnerabilities Across the Internet. Proceedings 2024 Network and Distributed System Security Symposium (NDSS'24, 网络安全四大顶会之一)- .
[8] Linkai Zheng, Xiang Li, Chuhan Wang, Run Guo, Haixin Duan, Jianjun Chen, Kaiwen Shen. ReqsMiner: Automated Discovery of CDN Forwarding Request Inconsistencies with Differential Fuzzing. Proceedings 2024 Network and Distributed System Security Symposium (NDSS'24, 网络安全四大顶会之一).
[9] Zicong Gao, Chao Zhang , Hangtian Liu, Wenhou Sun, Zhizhuo Tang, Liehui Jiang, Jianjun Chen, Yong Xie. Faster and Better: Detecting Vulnerabilities in Linux-based IoT Firmware with Optimized Reaching Definition Analysis. Proceedings 2024 Network and Distributed System Security Symposium (NDSS'24, 网络安全四大顶会之一).
[10] Run Guo, Jianjun Chen, Yihang Wang, Keran Mu, Baojun Liu, Xiang Li, Chao Zhang, Haixin Duan, Jianping Wu. Temporal CDN-Convex Lens: A CDN-Assisted Practical Pulsing DDoS Attack. 32th USENIX Conference on Security Symposium (USENIX Security'23,网络安全四大顶会之一).
[11] Wei Xu, Xiang Li, Chaoyi Lu, Baojun Liu, Jia Zhang, Jianjun Chen, Tao Wan, Haixin Duan. TsuKing: Coordinating DNS Resolvers and Queries into Potent DoS Amplifiers. 30th ACM Conference on Computer and Communications Security (CCS'23,网络安全四大顶会之一).
[12] Zhenrui Zhang, Geng Hong, Xiang Li, Zhuoqun Fu, Jia Zhang, Mingxuan Liu, Chuhan Wang, Jianjun Chen, Baojun Liu, Haixin Duan, Chao Zhang, Min Yang. Under the Dark: A Systematical Study of Stealthy Mining Pools (Ab)use in the Wild. 30th ACM Conference on Computer and Communications Security (CCS'23,网络安全四大顶会之一).
[13] Fenglu Zhang, Baojun Liu, Eihal Alowaisheq, Jianjun Chen, Chaoyi Lu, Linjian Song, Yong Ma, Ying Liu, Haixin Duan, Min Yang. Silence is not Golden: Disrupting the Load Balancing of Authoritative DNS Servers. 30th ACM Conference on Computer and Communications Security. (CCS'23,杰出论文奖,网络安全四大顶会之一).
[14] Songtao Yang, Yubo He, Kaixiang Chen, Zheyu Ma, Xiapu Luo, Yong Xie, Jianjun Chen, Chao Zhang. 1dFuzz: Reproduce 1-day Vulnerabilities with Directed Differential Fuzzing. 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA'23, 软件工程顶会之一)
[15] Mingming Zhang, Xiang Li, Baojun Liu, Jianyu Lu, Yiming Zhang, Jianjun Chen, Haixin Duan, Shuang Hao, Xiaofeng Zheng. DareShark: Detecting and Measuring Security Risks of Hosting-Based Dangling Domains. ACM SIGMETRICS 2023 (SIGMETRICS'23, 网络测量顶会之一)
[16] Zihao Jin, Shuo Chen, Yang Chen, Haixin Duan, Jianjun Chen, Jianping Wu. A Security Study about Electron Applications and a Programming Methodology to Tame DOM Functionalities. Proceedings 2023 Network and Distributed System Security Symposium (NDSS'23,网络安全四大顶会之一).
[17] Wenyu Zhu, Zhiyao Feng, Zihan Zhang, Jianjun Chen, Zhijian Ou, Min Yang, Chao Zhang. Callee: Recovering Call Graphs for Binaries with Transfer and Contrastive Learning. 2023 IEEE Symposium on Security and Privacy (S&P'23, 网络安全四大顶会之一)
[18] Chuhan Wang, Kaiwen Shen, Minglei Guo, Yuxuan Zhao, Mingming Zhang, Jianjun Chen, Baojun Liu, Xiaofeng Zheng, Haixin Duan, Yanzhong Lin, Qingfeng Pan. A Large-scale and Longitudinal Measurement Study of DKIM Deployment. 31th USENIX Conference on Security Symposium (USENIX Security'22,网络安全四大顶会之一).
[19] Kaiwen Shen, Jianyu Lu, Yaru Yang, Jianjun Chen, Mingming Zhang, Haixin Duan, Jia Zhang, Xiaofeng Zheng. HDiff: A Semi-automatic Framework for Discovering Semantic Gap Attack in HTTP Implementations. 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks. (DSN'22, Best Paper Award Runners Up)
[20] Jianjun Chen; Vern Paxson; Jian Jiang; Composition Kills: A Case Study of Email Sender Authentication, 29th USENIX Conference on Security Symposium (USENIX Security’20,杰出论文奖,网络安全四大顶会之一).
[21] Run Guo; Weizhong Li; Baojun Liu; Shuang Hao; Jia Zhang; Haixin Duan; Kaiwen Sheng; Jianjun Chen; Ying Liu; CDN Judo: Breaking the CDN DoS Protection with Itself, Proceedings 2020 Network and Distributed System Security Symposium (NDSS'20, 网络安全四大顶会之一).
[22] Jianjun Chen; Jian Jiang; Haixin Duan; Tao Wan; Shuo Chen; Vern Paxson; Min Yang; We Still Don’t Have Secure Cross-Domain Requests: an Empirical Study of CORS, 27th USENIX Conference on Security Symposium (USENIX Security'18, 网络安全四大顶会之一).
[23] Run Guo; Jianjun Chen; Baojun Liu; Jia Zhang; Chao Zhang; Haixin Duan; Tao Wan; Jian Jiang; Shuang Hao; Yaoqi Jia; Abusing CDNs for Fun and Profit: Security Issues in CDNs' Origin Validation, IEEE 37th Symposium on Reliable Distributed Systems (SRDS'18, CCF B类).
[24] Xiaojing Liao; Kan Yuan; XiaoFeng Wang; Zhongyu Pei; Hao Yang; Jianjun Chen; Haixin Duan; Kun Du; Eihal Alowaisheq; Sumayah Alrwais; Luyi Xing; Raheem Beyah; Seeking Nonsense, Looking for Trouble: Efficient Promotional-Infection Detection through Semantic Inconsistency Search, 2016 IEEE Symposium on Security and Privacy (SP'16, 网络安全四大顶会之一).
[25] Jianjun Chen; Jian Jiang; Haixin Duan; Nicholas Weaver; Tao Wan; Vern Paxson; Host of Troubles: Multiple Host Ambiguities in HTTP Implementations, 23rd ACM SIGSAC Conference on Computer and Communications Security (CCS’16, 网络安全四大顶会之一).
[26] Jianjun Chen; Jian Jiang; Xiaofeng Zheng; Haixin Duan; Jinjin Liang; Kang Li; Tao Wan; Vern Paxson; Forwarding Loop Attacks in Content Delivery Networks, Proceedings 2016 Network and Distributed System Security Symposium (NDSS'16, 中国首个四大安全顶会杰出论文奖, 网络安全四大顶会之一).