Biography

Hello! I am Linkai Zheng, you can call me NanoApe or just Nano. I am a Master student in the Department of Cyberspace Security at the Tsinghua University. I work in the Network and Information Security Lab (NISL) and am advised by Prof. Haixin Duan.

My research pursuits revolve around network security, with a primary focus on Content Delivery Network (CDN) security and protocol security. My current work aims to discover and solving the security risks posed by CDN forwarding request inconsistencies to build safer, better CDN. My research results have received acknowledgements from well-known CDN vendors such as Cloudflare, Azure, StackPath, and Aliyun.

What’s more, I am an active participant in cybersecurity competitions and algorithm competitions. I am a member of Redbud, a Capture the Flag (CTF) team affiliated with Tsinghua University, as well as Water Paddler, an international CTF team. My main skills are Miscellaneous and Cryptography.

Recent News

  • [2023/11] My paper on discovering CDN forwarding request inconsistencies got accepted by NDSS ‘24 Fall.
  • [2023/08] Our paper about bypassing SPF attacks got accepted by NDSS ‘24 Summer, Congrats to Chuhan!
Interests
  • CDN Security
  • Network Security
  • Protocol Security
  • Network & Protocol Fuzzing
  • Network Vulnerability Discovery & Attack
  • Underground Economy
Education
  • Master Candidate in Cyberspace Security, 2021 -- 2024 (expected)

    Tsinghua University

  • B.E. in Computer Science and Technology, 2017 -- 2021

    Tsinghua University

Publications

(2024). ReqsMiner: Automated Discovery of CDN Forwarding Request Inconsistencies and DoS Attacks with Grammar-based Fuzzing. In NDSS ‘24. San Diego, California, 26 February – 1 March, 2024. (Acceptance rate: 104/694=15.0%, Summer: 41/211=19.4%, Fall: 63/483=13.0%).

PDF Cite Project DOI Official

(2024). BreakSPF: How Shared Infrastructures Magnify SPF Vulnerabilities Across the Internet. In NDSS ‘24. San Diego, California, 26 February – 1 March, 2024. (Acceptance rate: 104/694=15.0%, Summer: 41/211=19.4%, Fall: 63/483=13.0%).

PDF Cite DOI Official

Misc

🏅 Awards

CTF

  • Global 3rd Place, WACON 2023 Final, 2023
  • 5th Place, “Rao Pai Cup” Vehicle Cybersecurity Challenge, 2023
  • 3rd Place, Aliyun CTF 2023, 2023
  • Runner-up, XCTF University Cybersecurity Challenge Finals, 2022
  • 3rd Place, “Coding the Future” Cybersecurity Competition, organized by Siemens, 2022
  • 5th Place, The 6th “Qiang Wang Cup” National Cybersecurity Challenge, 2022
  • Runner-up, Peak Geek Cybersecurity Skills Challenge, 2022
  • 4th Place, Digital China Innovation Competition - “Hu Fu” Cybersecurity Finals, 2022
  • Global Runner-up, PlaidCTF 2022, organized by Carnegie Mellon University, 2022
  • 3rd Place, D^3CTF 2022, organized by Team Vidar/CNSS/L-Team, 2022
  • Runner-up, L3HCTF 2021, organized by Team L3H Sec, 2021
  • Global 3rd Place, DEF CON CTF 29 Final, 2021
  • Runner-up, *CTF 2021, organized by Team ******, 2021
  • 🏆 Champion, ByteCTF 2020, organized by ByteDance, 2020
  • 🏆 Champion, WCTF 2020, organized by 360 Security, 2020
  • 3rd Place, THUCTF 2019, organized by Team Redbud, 2019

Algorithm Programming

  • Gold Medal, Collegiate Computer System and Programming Contest (CCSP) Finals, 2021
  • Runner-up, Tsinghua-HKUST Programming Contest, 2019
  • 3rd Place, ACM-ICPC Asia East Continent League Final, 2017
  • 🏆 Champion, Xi’an Station, Asian Qualifiers, The International Collegiate Programming Contest (ACM-ICPC), 2017
  • 🏆 Champion, Harbin Station, The 3rd China Collegiate Programming Contest (CCPC), 2017
  • Silver Medal, National Olympiad in Informatics (NOI), 2016
  • Golden Medal, Asia-Pacific Informatics Olympiad (APIO), 2016

TV Reality Show

  • 🏆 Global King of the Brain, Jiangsu Satellite TV Brain Competitive Reality Show “The Brain: Burning Your Brain”, 2019

Security / Big Data Analysis

  • 6th Place, GeekPwn 2022, 2022
  • 🏆 Champion, QAX DataCon Big Data Security Analysis Competition (Underground Economy Track), 2021

Game AI / Reinforcement Learning

  • 🏆 Champion, The 4th Tencent Geek Challenge [Blog], 2021
  • Runner-up, The 3rd Peking University Game AI Competition, 2017
  • Top 16, The 2nd Peking University Game AI Competition, 2016

Scholarship

  • The 1st Class Outstanding Scholarship, Tsinghua University, 2023
  • ⭐"酒井之星" (Rising Star of the Department of Computer Science), Tsinghua University, 2019
  • Science and Technology Innovation Scholarship, Tsinghua University, (2018, 2020)

Puzzle Hunt

  • 3rd Place, CCBC 10, 2020

🐞 CVEs

Contact

  • zhenglj21 [at] mails [dot] tsinghua [dot] edu [dot] cn
  • FIT 4-204, Tsinghua University, Beijing, 100084
  • Follow Me
  • DM Me