VLDB 2026 Research / reviewers in the wild / expert
Lok-Kwong Yan
dblp:13/11042
· DBLP profile ↗
7ranked-venue papers
3as first author
0since 2021 · last 2018
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-authorSystems, architecture and hardware · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
3 papers |
Program analysis · 67% Software maintenance and evolution · 19% Operating systems · 8% | |
| Network and information security
2 papers |
Malware analysis · 61% Systems and software security · 39% |
Topics — the 8 heaviest of 10, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Program analysis › binary analysis
dynamic binary analysis |
0.5 | 2 | 2017 | DECAF: A Platform-Neutral Whole-System Dynamic Binary Analysis Platform · IEEE Trans. Software Eng. 2017 Make it work, make it right, make it fast: building a platform-neutral whole-system dynamic binary analysis platform · ISSTA 2014 |
Program analysis › static analysis
taint analysis |
0.5 | 2 | 2017 | DECAF: A Platform-Neutral Whole-System Dynamic Binary Analysis Platform · IEEE Trans. Software Eng. 2017 Make it work, make it right, make it fast: building a platform-neutral whole-system dynamic binary analysis platform · ISSTA 2014 |
Software maintenance and evolution › software reengineering
software debloating |
0.3 | 1 | 2018 | Debloating Software through Piece-Wise Compilation and Loading · USENIX Security Symposium 2018 |
Program analysis
dynamic analysis |
0.2 | 1 | 2014 | Make it work, make it right, make it fast: building a platform-neutral whole-system dynamic binary analysis platform · ISSTA 2014 |
Malware analysis › android malware
android malware analysis |
0.1 | 1 | 2012 | DroidScope: Seamlessly Reconstructing the OS and Dalvik Semantic Views for Dynamic Android Malware Analysis · USENIX Security Symposium 2012 |
Systems and software security › program analysis
dynamic analysis |
0.1 | 1 | 2012 | DroidScope: Seamlessly Reconstructing the OS and Dalvik Semantic Views for Dynamic Android Malware Analysis · USENIX Security Symposium 2012 |
Malware analysis
dynamic malware analysis |
0.1 | 1 | 2012 | Hubble: Transparent and Extensible Malware Analysis by Combining Hardware Virtualization and Software Emulation · NDSS 2012 |
Operating systems › virtualization
virtual machine introspection |
0.1 | 2 | 2017 | DECAF: A Platform-Neutral Whole-System Dynamic Binary Analysis Platform · IEEE Trans. Software Eng. 2017 Make it work, make it right, make it fast: building a platform-neutral whole-system dynamic binary analysis platform · ISSTA 2014 |
Methods — techniques the papers use, named apart from their topics
just-in-time binary translation · 0.3formal analysis · 0.3just-in-time virtual machine introspection · 0.2instruction-level tainting · 0.2event-driven programming · 0.2dynamic instrumentation · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2018 | Debloating Software through Piece-Wise Compilation and Loading
Anh Quach, Aravind Prakash, Lok-Kwong Yan |
USENIX Security Symposium | 3 |
| 2017 | DECAF: A Platform-Neutral Whole-System Dynamic Binary Analysis PlatformabstractDynamic binary analysis is a prevalent and indispensable technique in program analysis. While several dynamic binary analysis tools and frameworks have been proposed, all suffer from one or more of: prohibitive performance degradation, a semantic gap between the analysis code and the program being analyzed, architecture/OS specificity, being user-mode only, and lacking APIs. We present DECAF, a virtual machine based, multi-target, whole-system dynamic binary analysis framework built on top of QEMU. DECAF provides Just-In-Time Virtual Machine Introspection and a plugin architecture with a simple-to-use event-driven programming interface. DECAF implements a new instruction-level taint tracking engine at bit granularity, which exercises fine control over the QEMU Tiny Code Generator (TCG) intermediate representation to accomplish on-the-fly optimizations while ensuring that the taint propagation is sound and highly precise. We perform a formal analysis of DECAF's taint propagation rules to verify that most instructions introduce neither false positives nor false negatives. We also present three platform-neutral plugins-Instruction Tracer, Keylogger Detector, and API Tracer, to demonstrate the ease of use and effectiveness of DECAF in writing cross-platform and system-wide analysis tools. Implementation of DECAF consists of 9,550 lines of C++ code and 10,270 lines of C code and we evaluate DECAF using CPU2006 SPEC benchmarks and show average overhead of 605 percent for system wide tainting and 12 percent for VMI. Andrew Henderson, Lok-Kwong Yan, Xunchao Hu, Aravind Prakash, Heng Yin 0001, Stephen McCamant |
IEEE Trans. Software Eng. | 2 |
| 2014 | Make it work, make it right, make it fast: building a platform-neutral whole-system dynamic binary analysis platformabstractDynamic binary analysis is a prevalent and indispensable technique in program analysis. While several dynamic binary analysis tools and frameworks have been proposed, all suffer from one or more of: prohibitive performance degradation, semantic gap between the analysis code and the program being analyzed, architecture/OS specificity, being user-mode only, lacking APIs, etc. We present DECAF, a virtual machine based, multi-target, whole-system dynamic binary analysis framework built on top of QEMU. DECAF provides Just-In-Time Virtual Machine Introspection combined with a novel TCG instruction-level tainting at bit granularity, backed by a plugin based, simple-to-use event driven programming interface. DECAF exercises fine control over the TCG instructions to accomplish on-the-fly optimizations. We present 3 platform-neutral plugins - Instruction Tracer, Keylogger Detector, and API Tracer, to demonstrate the ease of use and effectiveness of DECAF in writing cross-platform and system-wide analysis tools. Implementation of DECAF consists of 9550 lines of C++ code and 10270 lines of C code and we evaluate DECAF using CPU2006 SPEC benchmarks and show average overhead of 605% for system wide tainting and 12% for VMI. Andrew Henderson, Aravind Prakash, Lok-Kwong Yan, Xunchao Hu, Xujiewen Wang, Rundong Zhou, Heng Yin 0001 |
ISSTA | 3 |
| 2013 | A write-time based memristive PUF for hardware security applicationsabstractHardware security has emerged as an important field of study aimed at mitigating issues such as piracy, counterfeiting, and side channel attacks. One popular solution for such hardware security attacks are physical unclonable functions (PUF) which provide a hardware specific unique signature or identification. The uniqueness of a PUF depends on intrinsic process variations within individual integrated circuits. As process variations become more prevalent due to technology scaling into the nanometer regime, novel nanoelectronic technologies such as memristors become viable options for improved security in emerging integrated circuits. In this paper, we describe a novel memristive PUF (M-PUF) architecture that utilizes variations in the write-time of a memristor as an entropy source. The results presented show strong statistical performance for the M-PUF in terms of uniqueness, uniformity, and bit-aliasing. Additionally, nanoscale M-PUFs are shown to exhibit reduced area utilization as compared to CMOS counterparts. Garrett S. Rose, Nathan R. McDonald, Lok-Kwong Yan, Bryant T. Wysocki |
ICCAD | 3 |
| 2012 | Hubble: Transparent and Extensible Malware Analysis by Combining Hardware Virtualization and Software Emulation
Lok-Kwong Yan, Manjukumar Jayachandra, Mu Zhang 0001, Heng Yin 0001 |
NDSS | 1 |
| 2012 | DroidScope: Seamlessly Reconstructing the OS and Dalvik Semantic Views for Dynamic Android Malware Analysis
Lok-Kwong Yan, Heng Yin 0001 |
USENIX Security Symposium | 1 |
| 2012 | V2E: combining hardware virtualization and softwareemulation for transparent and extensible malware analysisabstractA transparent and extensible malware analysis platform is essential for defeating malware. This platform should be transparent so malware cannot easily detect and bypass it. It should also be extensible to provide strong support for heavyweight instrumentation and analysis efficiency. However, no existing platform can meet both requirements. Leveraging hardware virtualization technology, analysis platforms like Ether can achieve good transparency, but its instrumentation support and analysis efficiency is poor. In contrast, software emulation provides strong support for code instrumentation and good analysis efficiency by using dynamic binary translation. However, analysis platforms based on software emulation can be easily detected by malware and thus is poor in transparency. To achieve both transparency and extensibility, we propose a new analysis platform that combines hardware virtualization and software emulation. The essence is precise heterogeneous replay: the malware execution is recorded via hardware virtualization and then replayed in software. Our design ensures the execution replay is precise. Moreover, with page-level recording granularity, the platform can easily adjust to analyze various forms of malware (a process, a kernel module, or a shared library). We implemented a prototype called V2E and demonstrated its capability and efficiency by conducting an extensive evaluation with both synthetic samples and 14 realworld emulation-resistant malware samples. Lok-Kwong Yan, Manjukumar Jayachandra, Mu Zhang 0001, Heng Yin 0001 |
VEE | 1 |