李想 (Xiang Li)
XMap 的开发者与维护者。
(本页面更新于2023年2月24日)
教育经历
- 2022 - 2023: 加州大学尔湾分校,访问学者(DSP实验室)
- 2019 至今: 清华大学,网络科学与网络空间研究院,博士生(网络空间安全)
- 2015 - 2019: 南开大学,工学学士(信息安全),法学学士(法学)
研究领域
- 网络安全
- 协议安全
- IPv6安全
- DNS安全
- 互联网测量
- 网络协议fuzzing
论文列表
会议论文
[Security ‘23] Run Guo, Jianjun Chen, Yihang Wang, Keran Mu, Baojun Liu, Xiang Li, Chao Zhang, Haixin Duan, Jianping Wu (2023). Temporal CDN-Convex Lens: A CDN-Assisted Practical Pulsing DDoS Attack. In USENIX Security ‘23. Anaheim, California, August 9–11, 2023. (Acceptance rate: ??%, Acceptance rate in summer: 82/402=20.4%, Acceptance rate in fall: 89/569=15.6%), Acceptance rate in winter: ??%).
[Security ‘23] Xiang Li, Chaoyi Lu, Baojun Liu, Qifan Zhang, Zhou Li, Haixin Duan, Qi Li (2023). The Maginot Line: Attacking the Boundary of DNS Caching Protection. In USENIX Security ‘23. Anaheim, California, August 9–11, 2023. (Acceptance rate: ??%, Acceptance rate in summer: 82/402=20.4%, Acceptance rate in fall: 89/569=15.6%), Acceptance rate in winter: ??%).
[SIGMETRICS ‘23] Mingming Zhang, Xiang Li, Baojun Liu, Jianyu Lu, Jianjun Chen, Yiming Zhang, Xiaofeng Zheng, Haixin Duan, Shuang Hao (2023). DareShark: Detecting and Measuring Security Risks of Hosting-Based Dangling Domains. In SIGMETRICS ‘23. Orlando, Florida, June 19-23, 2023. (Acceptance rate: ??%, Acceptance rate in summer: 17/93=18.3%), Acceptance rate in fall: 26/119=21.9%), Acceptance rate in winter: ??%).
- Presented in OARC 40
[VehicleSec ‘23] Shangru Song, Hetian Shi, Ruoyu Lun, Yunchao Guan, Xiang Li, Jihu Zheng, Jianwei Zhuge (2023). Demo: Ransom Vehicle through Charging Pile. In VehicleSec 2023. San Diego, California, Feburary 27, 2023. (Acceptance rate: 32/83=36.0% (overall), 20/49=40.8% (regular), 2/6=33.3% (short), 6/16=37.5% (wpi), and 4/12=33.3% (demons/posters).
[NDSS ‘23] Xiang Li, Baojun Liu, Xuesong Bai, Mingming Zhang, Qifan Zhang, Zhou Li, Haixin Duan, Qi Li (2023). Ghost Domain Reloaded: Vulnerable Links in Domain Name Delegation and Revocation. In NDSS ‘23. San Diego, California, 27 February – 3 March, 2023. (Acceptance rate: 101/581=17.4%, Acceptance rate in summer: 36/183=19.7%), Acceptance rate in fall: 65/398=16.3%).
- Presented in OARC 39
- Presented in ICANN DNS Symposium 2022
- Presented in Black Hat Asia 2023
[DSN ‘21] Xiang Li, Baojun Liu, Xiaofeng Zheng, Haixin Duan, Qi Li, Youjun Huang (2021). Fast IPv6 Network Periphery Discovery and Security Implications. In DSN ‘21. Taipei, Taiwan, June 21-24, 2021 (Virtually). (Acceptance rate: 48/279=17.2%).
期刊论文
审稿相关
审稿评委
- TDSC ‘23
- DTRP ‘23
- SCN ‘22
外部审稿人
- AsiaCCS ‘23
- ESF Proposal ‘22
- NDSS ‘22
- ICDCS ‘21
- ESORICS ‘20
- ICPDAS ‘19
开发者
XMap 是一款兼含 IPv6 与 IPv4 网络空间探测功能的快速扫描器,并且也是第一款学术界+工业界中专门用于 IPv6 资产快速扫描的工具。其参考 ZMap 的原理进行开发,从底层完全改写了 ZMap 的核心代码,将 ZMap 在 IPv4 网络空间的多种扫描优势移植到 IPv6 空间,并且结合我们自身最新的研究发现,增添了 IPv6 设备快速发现技术以及多端口扫描功能,且完全兼容 ZMap,具备“5分钟”扫描32位网络空间的能力。
奖励与荣誉
- 2022年,首届IPv6技术应用创新大赛科教赛道一等奖
- 2022年,首届IPv6技术应用创新大赛科教赛道三等奖
- 2022年,清华大学校设综合优秀奖学金(二等)
- 2019年,天津市与南开大学“优秀本科毕业生”称号
- 2018年,南开大学公能一等奖学金
- 2018年,中国互联网发展基金会网络安全专项基金网络安全奖学金
- 2018年,第十一届全国大学生信息安全竞赛“创新实践能力赛”二等奖
- 2017年,第三届全国密码技术竞赛三等奖
- 2017年,国家奖学金
- 2016年,国家奖学金
漏洞发现
- CNVD/CNNVD/CVE:109/5/34 (total)
- 不死域名漏洞 (2022): n/n/9
- DNS缓存污染漏洞 (2022): n/n/3
- IPv6路由循环漏洞 (2021):109/5/22