VLDB 2026 Research / reviewers in the wild / expert
Wenrui Diao
dblp:149/2350
· DBLP profile ↗
53ranked-venue papers
5as first author
36since 2021 · last 2026
0000-0003-0916-8806ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 30 · 5 first-author · 14 since 2021Software engineering, systems software and programming languages · 18 · 17 since 2021Systems, architecture and hardware · 3 · 1 since 2021Computer networks · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LASGen: Synergistic Harness-Seed Co-Synthesis for High-Coverage Library FuzzingabstractLibrary fuzzing is essential for identifying vulnerabilities in software libraries. However, achieving high coverage remains challenging due to the difficulty of generating effective harness and seed inputs. We present LASGen, an automated framework that integrates static analysis and large language models (LLMs) to generate high-quality fuzzing inputs for arbitrary library functions. LASGen generates coupled harnesses and initial seeds, treating them as a unified task rather than separate steps. This design ensures the seeds are highly compatible with the harness, enabling deeper path exploration. To achieve this, LASGen extracts function-level context via slicing and data-flow analysis, then embeds it into structured prompts to guide LLMs during synthesis, ensuring that the outputs are valid. LASGen also incorporates a self-repair mechanism and seed validation loop to ensure correctness and effectiveness. Experiments on 11 libraries with 127 known vulnerabilities show that LASGen achieves 77.17% vulnerability coverage and 55.61% edge coverage, outperforming state-of-the-art fuzzers while maintaining a lower false-positive rate. When applied to 17 real-world libraries, LASGen discovered 33 previously unknown vulnerabilities, 26 of which have been confirmed and patched, including eight assigned CNVD IDs. Yujie Xing, Jiongyi Chen, Wenrui Diao |
AsiaCCS | 4 |
| 2026 | Unidentifiable Identifier: Attacking Bluetooth Applications with Duplicated UUIDs
Siyu Shen, Yi Chen 0024, Fenghao Xu, Shuaike Dong, Wenrui Diao, Di Tang 0001, Kehuan Zhang |
EuroS&P | 5 |
| 2026 | Dialing Danger: Large-Scale Risk Assessment of Android Secret Codes in OEM Firmware
Ruoyan Lin, Shishuai Yang, Fenghao Xu, Wenrui Diao |
SANER | 4 |
| 2026 | From Patterns to Precision: LLM-Guided Detection of Signature Verification Flaws in Smart Contracts
Huixin Wang, Kailun Yan, Wenrui Diao |
SANER | 3 |
| 2026 | Investigating cross-market android apps: Security, protection, and components
Shishuai Yang, Ruoyan Lin, Jialong Guo, Guangdong Bai, Yujia Luo, Wenrui Diao |
Empir. Softw. Eng. | 6 |
| 2026 | Unveiling the Centralized Security Risks in Decentralized EcosystemsabstractThe decentralized ecosystem is claimed to avoid security risks caused by centralization. Decentralized services, such as crypto wallets and decentralized applications (DApps), are purported to offer more reliable security and better protect user privacy. However, our research suggests a different reality: centralized components or scenarios are still prevalent within decentralized ecosystems, introducing security risks typically associated with centralization. This work systematically investigated the centralized security risks in crypto wallets and DApps. We found seven security risks and developed a series of methods to identify these risks. The detection results indicate that centralized security risks are widespread in the decentralized ecosystem. Among the 28 Ethereum-recommended crypto wallets, 96.4% have security risks. Of the 78 Web3 sites (frontends of DApps), 100% contain third-party scripts, and 44.9% expose the user's address to third parties. Furthermore, we developed a high-precision automated tool and inspected 110,506 on-chain smart contracts (backends of DApps), discovering that 83.5% contain at least one security risk. These risks affect 260 well-known tokens with a combined market capitalization exceeding${\$}$98 billion. Kailun Yan, Jilian Zhang, Wenrui Diao |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | RuleDroid: LLM-Augmented Synthesis of Static Security Detection Rules for Android AppsabstractAndroid’s vast ecosystem and expansive API surfaces pose a serious challenge to static application security testing (SAST) tools. Mainstream tools such as MobSF, APKHunt, and AUSERA mainly rely on manually crafted rules. Crafting these rules demands considerable effort, yet they still cannot cover every security issue. When Android introduces new APIs, changes its permission model, or revises other security policies, the rules soon fall behind. Without constant maintenance, false positives grow, and true vulnerabilities slip through. Recently released LLM-based detectors are easy to use and potentially support a wide range of vulnerability types, but their findings often lack clear explanations and suffer from high false-positive rates.In this paper, we present RULEDROID, a new framework that leverages LLMs to automatically generate Semgrep-compatible static detection rules from up-to-date official Android security documentation. RULEDROIDtackles the limits of pure LLM detection by combining (i) Retrieval-Augmented Generation (RAG), which grounds model outputs in trusted documents, and (ii) a modular workflow that decomposes rule synthesis into welldefined stages. The resulting rules are then applied with proven static-analysis techniques, ensuring consistent and explainable results. We evaluated RULEDROID on three public benchmark datasets. Based on its large and precise rule set, RULEDROIDachieved higher coverage and accuracy than traditional SAST tools, and sharply reduced false positives compared with direct LLM scanning. When applied to real-world apps, RULEDROIDdiscovered multiple new vulnerabilities, resulting in 57 CVE IDs being assigned. These results show that RULEDROIDcombines the broad vulnerability coverage of LLMs with the precision of static analysis, delivering a fully automated docs-to-rules solution for Android security testing. Zhentao Xie, Yaqi Gao, Shishuai Yang, Wenrui Diao, Kehuan Zhang |
IEEE Trans. Software Eng. | 5 |
| 2025 | An Empirical Study on Cross-chain Transactions: Costs, Inconsistencies, and Activities
Kailun Yan, Pranav Agrawal 0002, Jiasun Li, Wenrui Diao, Xiaokuan Zhang |
AsiaCCS | 5 |
| 2025 | FirmProj: Detecting Firmware Leakage in IoT Update Processes via Companion App AnalysisabstractThe rapid growth of the Internet of Things (IoT) has led to the widespread use of companion apps for device management. However, these apps expose a critical vulnerability in the IoT ecosystem: insufficient verification procedures during device firmware updates (DFU), often resulting in firmware leakage. Once leaked, the firmware reveals sensitive design details, creating a straightforward path for attackers to reverse-engineer devices. To address this issue, we designed an automated analysis tool called FirmProj. It systematically evaluates firmware leakage risks by examining IoT companion apps. FirmProj combines advanced static analysis techniques with large language models to identify DFU modules, extract firmware files, and detect security vulnerabilities. In a large-scale study involving 10,047 IoT companion apps, FirmProj successfully retrieved 3,434 firmware files, uncovering severe flaws in DFU implementations that can lead to firmware leakage. These findings resulted in the assignment of 35 CVE IDs. Our results highlight the urgent need to strengthen firmware protection mechanisms throughout the IoT ecosystem. Wenzhi Li, Jialong Guo, Jiongyi Chen, Yujie Xing, Yanbo Xu, Shishuai Yang, Wenrui Diao |
ASE | 8 |
| 2025 | Understanding security risks in mobile-to-PC screen mirroring: an empirical studyabstractAbstract To facilitate collaboration across multiple devices and benefit from larger screens and better user experiences, many users choose to mirror their screen content of smartphones to personal computers. The implementation of the Android screen mirroring feature varies across different manufacturers, resulting in significant security differences among screen mirroring apps. Moreover, actual incidents of screen content leakage have exacerbated users’ concerns about the security of the Android screen mirroring feature. In this work, we systematically analyzed the system architecture of the Android screen mirroring feature and the security risks it faces. Specifically, we identified four critical security risks in the communication process between the mobile and PC sides of screen mirroring apps, including arbitrary access to screen content, MITM (Man-in-the-Middle) attacks, malicious commands injection, and data sniffing attacks. Attackers can exploit these identified security risks to arbitrarily access screen content or manipulate user’s phone to perform malicious operations. To evaluate the security risks of the Android mirroring feature in real-world deployments, we conducted a security evaluation on over 20 popular screen mirroring apps from multiple sources. The results indicate that all of these apps are facing at least one of the aforementioned security risks. Finally, we provide the corresponding recommendations to mitigate the identified security risks. Zhaoyu Qiu, Shishuai Yang, Yujia Luo, Wenrui Diao |
Cybersecur. | 5 |
| 2025 | From guidelines to practice: assessing Android app developer compliance with google's security recommendations
Shishuai Yang, Qinsheng Hou, Fenghao Xu, Wenrui Diao |
Empir. Softw. Eng. | 5 |
| 2024 | Stealing Trust: Unraveling Blind Message Attacks in Web3 AuthenticationabstractAs the field of Web3 continues its rapid expansion, the security of Web3 authentication, often the gateway to various Web3 applications, becomes increasingly crucial. Despite its widespread use as a login method by numerous Web3 applications, the security risks of Web3 authentication have not received much attention. This paper investigates the vulnerabilities in the Web3 authentication process and proposes a new type of attack, dubbed blind message attacks. In blind message attacks, attackers trick users into blindly signing messages from target applications by exploiting users' inability to verify the source of messages, thereby achieving unauthorized access to the target application. We have developed Web3AuthChecker, a dynamic detection tool that interacts with Web3 authentication-related APIs to identify vulnerabilities. Our evaluation of real-world Web3 applications shows that a staggering 75.8% (22/29) of Web3 authentication deployments are at risk of blind message attacks. In response to this alarming situation, we implemented Web3AuthGuard on the open-source wallet MetaMask to alert users of potential attacks. Our evaluation results show that Web3AuthGuard can successfully raise alerts in 80% of the tested Web3 authentications. We have responsibly reported our findings to vulnerable websites and have been assigned two CVE IDs. Kailun Yan, Xiaokuan Zhang, Wenrui Diao |
CCS | 3 |
| 2024 | MiniCAT: Understanding and Detecting Cross-Page Request Forgery Vulnerabilities in Mini-ProgramsabstractMini-programs are lightweight apps running in super apps (such as WeChat, Baidu, Alipay, and TikTok), an emerging paradigm in the era of mobile computing. With the growing popularity of mini-programs, there is an increasing concern for their security and privacy. In essence, mini-programs are WebView-based apps. This means that they may be vulnerable to the same security risks associated with web apps. In this work, we discovered a new mini-program vulnerability called MiniCPRF (Cross-Page Request Forgery in Mini-Programs). The exploit of this vulnerability is easy, and the attack consequences are severe, leading to unauthorized operations, such as free shopping, and the exposure of confidential information, such as credit card numbers. The root causes of MiniCPRF can be attributed to multiple design flaws in both mini-programs and their super apps, including the insecure routing mechanism, lack of message integrity check, and plain-text storage. To evaluate the impacts of MiniCPRF, we designed an automated analysis framework called MiniCAT. It can automatically crawl mini-programs, perform static analysis on them, and generate detection reports. In large-scale real-world evaluations with MiniCAT, we identified that 32.0% (13,349/41,726) of analyzable mini-programs are potentially vulnerable to MiniCPRF, including some famous ones with millions of users, such as Sohu and Wenjuanxing. Following the responsible disclosure principle, we have reported verified vulnerable mini-programs to the corresponding vendors and developers, and three real-world cases have been confirmed by CNVD. Additionally, we suggest mitigation strategies to resolve the security issue related to MiniCPRF. Zidong Zhang, Qinsheng Hou, Lingyun Ying, Wenrui Diao, Yacong Gu, Rui Li 0102, Shanqing Guo, Hai-Xin Duan |
CCS | 4 |
| 2024 | DEMISTIFY: Identifying On-device Machine Learning Models Stealing and Reuse Vulnerabilities in Mobile AppsabstractMobile apps have become popular for providing artificial intelligence (AI) services via on-device machine learning (ML) techniques. Unlike accomplishing these AI services on remote servers traditionally, these on-device techniques process sensitive information required by AI services locally, which can mitigate the severe concerns of the sensitive data collection on the remote side. However, these on-device techniques have to push the core of ML expertise (e.g., models) to smartphones locally, which are still subject to similar vulnerabilities on the remote clouds and servers, especially when facing the model stealing attack. To defend against these attacks, developers have taken various protective measures. Unfortunately, we have found that these protections are still insufficient, and on-device ML models in mobile apps could be extracted and reused without limitation. To better demonstrate its inadequate protection and the feasibility of this attack, this paper presents DeMistify, which statically locates ML models within an app, slices relevant execution components, and finally generates scripts automatically to instrument mobile apps to successfully steal and reuse target ML models freely. To evaluate DeMistify and demonstrate its applicability, we apply it on 1,511 top mobile apps using on-device ML expertise for several ML services based on their install numbers from Google Play and DeMistify can successfully execute 1250 of them (82.73%). In addition, an in-depth study is conducted to understand the on-device ML ecosystem in the mobile application. Chaoshun Zuo, Xiaofeng Liu 0013, Wenrui Diao, Qingchuan Zhao, Shanqing Guo |
ICSE | 4 |
| 2024 | Android's Cat-and-Mouse Game: Understanding Evasion Techniques against Dynamic AnalysisabstractThe Android OS, known for its openness and flexibility, dominates the global smartphone market, enabling the creation and distribution of a vast array of apps. However, this openness also attracts malicious apps that threaten user security. To counter these threats, static and dynamic analysis techniques are employed. Despite these efforts, evasion techniques such as code obfuscation and anti-debugging are increasingly used to bypass these analyses.In this study, we conduct a comprehensive review of current evasion and anti-evasion techniques and assess their real-world impact by analyzing 108,099 benign apps, 11,730 malicious apps, and 11 online dynamic analysis platforms. Our findings reveal that 68.1% of apps employ evasion techniques, with benign apps using them more frequently than malicious ones. Malicious apps, however, demonstrate more cautious behaviors when evading dynamic analysis. Additionally, our evaluation of dynamic analysis platforms shows that most evasion techniques, including simple methods like checking fields in the Build class, successfully evade detection, indicating a significant gap in current anti-evasion capabilities. Our research provides critical insights into the ongoing battle between Android app security and evasion techniques, underscoring the need for improved countermeasures to enhance user security. Rui Li 0102, Shishuai Yang, Wenrui Diao |
ISSRE | 4 |
| 2024 | Beyond the Horizon: Exploring Cross-Market Security Discrepancies in Parallel Android AppsabstractMulti-channel distribution of Android apps offers convenience to users, yet simultaneously introduces security concerns. Although apps published on Google Play and third-party markets share the same version code, differences in app content may still arise. Notably, a recent incident involving the third-party market version of Pinduoduo app containing malicious code highlights the intentionally-differentiated implementations of app functionalities by developers between Google Play and third-party markets. The case of Pinduoduo may be just the tip of the iceberg, underscoring the need for a comprehensive investigation of the disparities between Google Play and third-party market versions of apps.In this work, we systematically analyze the differences in security and privacy of cross-market apps that claim to share the same version code. Specifically, we propose three research questions that cover differences in app protection, security threats, and permission usage. To answer these questions, we constructed a dataset containing 17,218 app pairs (filtered from 236,731 apps) and permission mappings (27,046 SDK mappings, 1,656 ContentProvider mappings, and 309 Intent mappings) for API levels 16 - 33. This dataset enables us to perform a comprehensive differential analysis. Consequently, our investigation unveiled a series of captivating and insightful findings. Approximately 29.02% of apps show differences in one or all three aspects. For example, the third-party market versions of apps often request more permissions compared to their Google Play counterparts, particularly among apps in the game category. Our work can help developers and app store operators improve cross-market app consistency, enhancing the quality of the Android app ecosystem and user experience. Shishuai Yang, Guangdong Bai, Ruoyan Lin, Jialong Guo, Wenrui Diao |
ISSRE | 5 |
| 2024 | CrypTody: Cryptographic Misuse Analysis of IoT Firmware via Data-flow ReasoningabstractCryptographic techniques form the foundation of the security and privacy of computing solutions. However, if cryptographic APIs are not invoked correctly, they can result in significant security problems. In this paper, we abstract the intricate crypto misuse detection problem as a data-flow reasoning task. Towards this end, we propose CrypTody, a novel logic-inference-based framework for detecting crypto misuses via reasoning about data flows on multi-architecture IoT firmware images. It carries out cross-architecture analysis, with detection strategies to reduce false positives and false negatives, such as cross-flow misuse inference. To evaluate the effectiveness of CrypTody, we conducted a large-scale experiment on 1,431 firmware images from 16 vendors. Our evaluation shows that 46% of the firmware images have high-risk misuses and 95% have at least one cryptographic misuse. In total, we find 6,624 potential crypto misuses, with 760 being cross-flow misuses that are not detected by existing solutions. We have responsibly disclosed portions of our findings to the relevant vendors. From the feedback, we note that CrypTody has a low false-positive rate for the confirmed misuses. Some typical cases have been assigned CVEs and fixed by the vendors. Shanqing Guo, Wenrui Diao, Hai-Xin Duan, Zhenkai Liang |
RAID | 3 |
| 2024 | Custom Permission Misconfigurations in Android: A Large-Scale Security AnalysisabstractAndroid’s popularity is due to its openness and vast app ecosystem. Global developers can use Android Studio and rich Android APIs to create their apps. Within this ecosystem, Android permissions play a crucial role in managing access to resources, with system permissions controlled by system apps and custom permissions declared by third-party apps. However, the security of custom permissions has not received enough attention from the mobile security community, resulting in a lack of thorough evaluation of security practices for app developers using custom permissions. This study systematically evaluated the misconfiguration of custom permissions by Android app developers. It is based on ten configuration guidelines derived from the Android development documentation, OS source code, and related research papers to ensure proper functioning and adherence to best security practices of custom permissions. The study established the corresponding violation rules and built a dataset containing 174,740 APK files for large-scale measurement and analysis of guideline violations. The measurement results indicate that misconfiguration of custom permissions by Android app developers is quite common, with approximately 29.02% of the 92,461 apps involving custom permissions having configuration guideline violations. The two most common errors in custom permission configuration are 1) putting custom permissions into a defective custom group and 2) protecting components with undeclared custom permissions. Such misconfigurations can lead to various issues, including private app data leaks, app installation failures, or incomplete implementation of app functions. Rui Li 0102, Wenrui Diao, Debin Gao |
TrustCom | 2 |
| 2024 | Security Assessment of Customizations in Android Smartwatch FirmwareabstractThe widespread use of mobile technology has led to the integration of mobile devices, especially smartwatches, into daily life due to their convenience and functionality. With Android being the most popular mobile operating system, Android-based smartwatches, such as those powered by Google’s Wear OS, have become increasingly popular. However, the customization of smartwatch firmware by manufacturers, while improving user experience, poses significant security risks. This study conducts a comprehensive security analysis of Android smartwatch firmware, focusing on security configurations, patch management, and pre-installed applications. Through the analysis of 176 firmware images from 24 vendors, the study identifies 1,684 insecure configurations resulting from customization, significant delays in applying security patches, and reveals that 26.1% of pre-installed apps have potential security risks. These findings underscore security concerns in Android smartwatch firmware and highlight the need to prioritize security in firmware development and customization practices. Ruoyan Lin, Qinsheng Hou, Peng Tang 0002, Wenrui Diao |
TrustCom | 6 |
| 2024 | Understanding Android OS Forward Compatibility Support for Legacy Apps: A Data-Driven AnalysisabstractThe update of Android OS constantly brings users various new features and enhances system security. On the other hand, the system and API modifications with the update may introduce the app compatibility issue. The app's SDK version may not align with the Android OS version, making apps not work adequately. This condition will inevitably damage the Android ecosystem. Thus, while developing Android OS, Google considered and deployed compatibility support. The software engineering research community also noticed the Android compatibility issue and conducted some investigations. However, most previous studies focus on apps' performance and solutions on compatibility (apps running on multiple OS versions). Rare work considers the Android OS side's forward compatibility implementations (supporting legacy apps running on the latest OS). This work systematically studied how Android OS implements forward compatibility for the apps developed with outdated SDKs, primarily focusing on the targetSdkVersion-based fine-grained control. Specifically, we propose three research questions, covering: 1) the forward compatibility support approaches; 2) the stability of foforward compatibility support in third-party market apps. To address these questions, we conducted comprehensive measurements on Android's forward compatibility support, including its implementation, implications, and evolution. Our measurements were based on large-scale datasets covering the source code of Android 8.0~ 13 and 130,461 apps. Finally, we provide rich data support and analysis to answer these questions. This study offers new insights into Android's forward compatibility support, helping the research community understand the evolution of Android's API design. Rui Li 0102, Kailun Yan, Shishuai Yang, Wenrui Diao |
SANER | 6 |
| 2024 | From Promises to Practice: Evaluating the Private Browsing Modes of Android Browser AppsabstractPrivate browsing is a common feature of web browsers on desktop platforms. This feature protects the privacy of users browsing the Internet and, therefore, is widely welcomed by users. In recent years, with the popularity of smartphones, the private browsing mode has been introduced into mobile browsers. However, its deployment on mobile platforms has not been well evaluated. To bridge the gap, in this work, we systemically studied the private browsing modes of Android browser apps. Specifically, we proposed six private rules for mobile browsers to follow by combining the mobile browsing features with the previous research on private browsing. Furthermore, we designed an automated analysis framework, BroDroid, to detect whether mobile browsers violate these rules. Also, with BroDroid, we evaluated 49 popular browser apps crawled from Google Play. Finally, BroDroid successfully identified 58 violations, some of which come from the promised capabilities of the browser. We reported our discovered issues to the corresponding developers, and four of them (Yandex Browser, Mint Browser, Web Explorer, and Net Fast Web Browser) have acknowledged our findings. Our observation may be the tip of the iceberg, and more efforts should be put into improving the privacy protections of mobile browsers. Xiaoyin Liu, Wenzhi Li, Qinsheng Hou, Shishuai Yang, Lingyun Ying, Wenrui Diao, Shanqing Guo, Hai-Xin Duan |
WWW | 6 |
| 2023 | Do App Developers Follow the Android Official Data Security Guidelines? An Empirical Measurement on App Data SecurityabstractThe popularity of Android OS is largely credited to massive apps, and many app developers are involved in this ecosystem. On the other hand, various vulnerabilities are introduced into apps by developers carelessly, bringing security issues to users. To facilitate secure development and avoid common API misuses, Google provides a series of security guidelines and development practices for developers on the official developer community websites. However, the deployments of these guidelines in the wild have not been systematically evaluated. In this work, through large-scale app measurement (251,749 apps from 10 markets) and analysis, we investigated whether app developers follow the official Android security guidelines and the possible reasons behind it. In practice, we selected five guidelines related to app data security as representatives, covering: (1) secure file creation modes; (2) sensitive data storage; (3) validation check for file paths; (4) hardware ID usage; (5) custom permission protection. We also designed the corresponding detection strategies to check violations of the guidelines. The results show that most developers (> 90 %) can comply with Guidelines 1 and 2. However, some guidelines have not been followed properly. For Guidelines 3, 4, and 5, less than 60 % of developers followed the Google security suggestions. Shishuai Yang, Qinsheng Hou, Wenrui Diao |
APSEC | 4 |
| 2023 | Living in the Past: Analyzing BLE IoT Devices Based on Mobile Companion Apps in Old VersionsabstractBluetooth Low Energy has been a widely adopted communication technique in the consumer IoT market. Meanwhile, the security concerns of these BLE-enabled IoT devices have garnered considerable attention. Instead of investigating the device firmware directly, analyzing its companion mobile app has been proven to be an effective approach for vulnerability discovery. However, developers regularly release new versions of these apps, making it more challenging to analyze and identify vulnerabilities. As a result, this action raises the bar on launching attacks on IoT devices. In our study, we found that the earlier versions of the companion apps can still be exploited to attack IoT devices. The key insight is that these devices usually lack firmware update capabilities.In our work, we performed attacks on three BLE-enabled IoT devices by investigating the early versions of their companion apps. We observed that manufacturers merely updated the companion apps to increase the difficulty of reverse engineering through code protection techniques without addressing the vulnerabilities presented in the device firmware. We then conducted a large-scale measurement and confirmed that most BLE devices can be analyzed from their old app versions. Furthermore, we design an automated tool to help developers identify the risks and improve the security of their apps. In our study, we also discuss some mitigation solutions. Jianqi Du, Zidong Zhang, Fenghao Xu, Wenrui Diao |
MSN | 4 |
| 2023 | Lost in Conversion: Exploit Data Structure Conversion with Attribute Loss to Break Android Systems
Rui Li 0102, Wenrui Diao, Shishuai Yang, Shanqing Guo, Kehuan Zhang |
USENIX Security Symposium | 2 |
| 2023 | Bad Apples: Understanding the Centralized Security Risks in Decentralized EcosystemsabstractThe blockchain-powered decentralized applications and systems have been widely deployed in recent years. The decentralization feature promises users anonymity, security, and non-censorship, which is especially welcomed in the areas of decentralized finance and digital assets. From the perspective of most common users, a decentralized ecosystem means every service follows the principle of decentralization. However, we find that the services in a decentralized ecosystem still may contain centralized components or scenarios, like third-party SDKs and privileged operations, which violate the promise of decentralization and may cause a series of centralized security risks. In this work, we systematically study the centralized security risks existing in decentralized ecosystems. Specifically, we identify seven centralized security risks in the deployment of two typical decentralized services – crypto wallets and DApps, such as anonymity loss and overpowered owner. Also, to measure these risks in the wild, we designed an automated detection tool called Naga and carried out large-scale experiments. Based on the measurement of 28 Ethereum crypto wallets (Android version) and 110,506 on-chain smart contracts, the result shows that the centralized security risks are widespread. Up to 96.4% of wallets and 83.5% of contracts exist at least one security risk, including 260 well-known tokens with a total market cap of over $98 billion. Kailun Yan, Jilian Zhang, Wenrui Diao, Shanqing Guo |
WWW | 4 |
| 2023 | Can We Trust the Phone Vendors? Comprehensive Security Measurements on the Android Firmware EcosystemabstractAndroid is the most popular smartphone platform with over 85% market share. Its success is built on openness, and phone vendors can utilize the Android source code to make customized products with unique software/hardware features. On the other hand, the fragmentation and customization of Android also bring many security risks that have attracted the attention of researchers. Many efforts were put in to investigate the security of customized Android firmware. However, most of the previous works focus on designing efficient analysis tools or analyzing particular aspects of the firmware. There still lacks a panoramic view of Android firmware ecosystem security and the corresponding understandings based on large-scale firmware datasets. In this work, we made a large-scale comprehensive measurement of the Android firmware ecosystem security. Our study is based on 8,325 firmware images from 153 vendors and 813 Android-related CVEs, which is the largest Android firmware dataset ever used for security measurements. In particular, our study followed a series of research questions, covering vulnerabilities, patches, security updates, and pre-installed apps. To automate the analysis process, we designed a framework,AndScanner+, to complete firmware crawling, firmware parsing, patch analysis, and app analysis. Through massive data analysis and case explorations, several interesting findings are obtained. For example, the patch delay and missing issues are widespread in Android firmware images, say 31.4% and 5.6% of all images, respectively. The latest images of several phones still contain vulnerable pre-installed apps, and even the corresponding vulnerabilities have been publicly disclosed. In addition to data measurements, we also explore the causes behind these security threats through case studies and demonstrate that the discovered security threats can be converted into exploitable vulnerabilities. There are 46 new vulnerabilities found byAndScanner+, 36 of which have been assigned CVE/CNVD IDs. This study provides much new knowledge of the Android firmware ecosystem with a deep understanding of software engineering security practices. Qinsheng Hou, Wenrui Diao, Chenglin Mao, Lingyun Ying, Xiaofeng Liu 0013, Yuanzhi Li, Shanqing Guo, Meining Nie, Hai-Xin Duan |
IEEE Trans. Software Eng. | 2 |
| 2022 | Large-scale Security Measurements on the Android Firmware EcosystemabstractAndroid is the most popular smartphone platform with over 85% market share. Its success is built on openness, and phone vendors can utilize the Android source code to make products with unique software/hardware features. On the other hand, the fragmentation and customization of Android also bring many security risks that have attracted the attention of researchers. Many efforts were put in to investigate the security of customized Android firmware. However, most of the previous work focuses on designing efficient analysis tools or analyzing particular aspects of the firmware. There still lacks a panoramic view of Android firmware ecosystem security and the corresponding understandings based on large-scale firmware datasets. In this work, we made a large-scale comprehensive measurement of the Android firmware ecosystem security. Our study is based on 6,261 firmware images from 153 vendors and 602 Android-related CVEs, which is the largest Android firmware dataset ever used for security measurements. In particular, our study followed a series of research questions, covering vulnerabilities, patches, security updates, and pre-installed apps. To automate the analysis process, we designed a framework, AndScanner, to complete ROM crawling, ROM parsing, patch analysis, and app analysis. Through massive data analysis and case explorations, several interesting findings are obtained. For example, the patch delay and missing issues are widespread in Android images, say 24.2% and 6.1% of all images, respectively. The latest images of several phones still contain vulnerable pre-installed apps, and even the corresponding vulnerabilities have been publicly disclosed. In addition to data measurements, we also explore the causes behind these security threats through case studies and demonstrate that the discovered security threats can be converted into exploitable vulnerabilities via 38 newfound vulnerabilities by our framework, 32 of which have been assigned CVE/CNVD numbers. This study provides much new knowledge of the Android firmware ecosystem with deep understanding of software engineering security practices. Qinsheng Hou, Wenrui Diao, Xiaofeng Liu 0013, Lingyun Ying, Shanqing Guo, Yuanzhi Li, Meining Nie, Hai-Xin Duan |
ICSE | 2 |
| 2022 | Demystifying Android Non-SDK APls: Measurement and UnderstandingabstractDuring the Android app development, the SDK is essential, which provides rich APIs to facilitate the implementations of functionalities. However, in the Android framework, there still exist plenty of non-SDK APIs that are not well documented. These non-SDK APIs can be invoked through unconventional ways, such as Java reflection. On the other hand, these APIs are not stable and may be changed or even removed in future Android versions, providing no guarantee for compatibility. From Android 9 (API level 28), Google began to strictly restrict the use of non-SDK APIs, and the corresponding checking mechanism has been integrated into the Android OS. Shishuai Yang, Rui Li 0102, Jiongyi Chen, Wenrui Diao, Shanqing Guo |
ICSE | 4 |
| 2022 | Default: Mutual Information-based Crash Triage for Massive CrashesabstractWith the considerable success achieved by modern fuzzing infrastructures, more crashes are produced than ever before. To dig out the root cause, rapid and faithful crash triage for large numbers of crashes has always been attractive. However, hindered by the practical difficulty of reducing analysis imprecision without compromising efficiency, this goal has not been accomplished. Jiongyi Chen, Chao Feng 0002, Ruilin Li 0002, Wenrui Diao, Kehuan Zhang, Jing Lei 0001, Chaojing Tang |
ICSE | 5 |
| 2022 | Cast Away: On the Security of DLNA Deployments in the SmartTV EcosystemabstractThe casting service on SmartTV has been increasingly used for home entertainment and business, given the convenience offered in media broadcast and screen sharing. Among the underlying protocols that support TV cast, DLNA (Digital Living Networking Alliance) – established by a group of tech giants – has become a prevailing standard in the consumer market. Although DLNA has launched the market for years, concerns may arise about whether its real-world deployment has been clearly understood.In this work, we systematically evaluate the security of DLNA deployments in the SmartTV ecosystem. Specifically, we identify a series of critical security issues in the interactions between SmartTVs and casting apps on the smartphone, ranging from non-mandatory encryption to unauthorized file access. The identified security risks can be exploited by a malicious app on the victim’s phone, without requesting sensitive permissions, to launch multiple attacks, including arbitrary command execution, data theft, MITM (man-in-the-middle) attack, and DoS (denial-of-service) attack. To measure the impact of the identified security issues, we designed semi-automated analysis solutions to facilitate the measurements and conducted real-world experiments on 10 on-shelf TV boxes. The results show that most DLNA implementations of products and apps in the wild are insecure. In the end, we provide immediate improvement solutions to mitigate the identified security issues. Guangwei Tian, Jiongyi Chen, Kailun Yan, Shishuai Yang, Wenrui Diao |
QRS | 5 |
| 2022 | Identifying the BLE Misconfigurations of IoT Devices through Companion Mobile AppsabstractBluetooth Low Energy (BLE) is widely deployed and has become the de-facto communication standard in the IoT ecosystem. Naturally, the security of BLE received much attention from both researchers and attackers. In another aspect, the BLE specifications provide the security guidelines for BLE deployments. Due to various reasons, the developers do not follow the guidelines in the implementation process, which introduces the misconfiguration issue. However, identifying these BLE mis-configurations in IoT device firmware is quite challenging. In this work, we do not handle the BLE-enabled devices directly. Instead, we focus on the security misconfiguration issues in their companion mobile apps, which can reflect the deployment conditions of the corresponding devices. Further, we designed an analysis tool - BSC-Checker to detect the misconfigurations based on pre-defined checking strategies. With BSC-Checker, we conducted large-scale experiments on 4,589 apps from multiple app markets. The result shows that the BLE configurations of most BLE apps disobey at least one security rule, and the current BLE deployment status is not optimistic. Jianqi Du, Fenghao Xu, Chennan Zhang, Zidong Zhang, Xiaoyin Liu, Wenrui Diao, Shanqing Guo, Kehuan Zhang |
SECON | 7 |
| 2022 | PITracker: Detecting Android PendingIntent Vulnerabilities through Intent Flow AnalysisabstractIntent is an essential inter-component communication mechanism of Android OS, which can be used to request an action from another app component. The security of its design and implementation attracts lots of attention. However, the security of PendingIntent, a kind of delayed-triggered Intent, was neglected by most previous research, and the related analysis techniques are still imperfect. In this paper, we design a novel automated tool, PITracker, to detect the PendingIntent vulnerabilities in Android apps. It achieves the Intent flow tracking technique proposed by us, figuring out how an Intent is created and where it goes. In the real-world evaluations, PITracker discovered 2,939 potential threats in 10,000 third-party apps and 214 in 1,412 pre-installed apps. Among them, 11 exploitable vulnerabilities have been confirmed and acknowledged by the corresponding vendors. Chennan Zhang, Wenrui Diao, Shanqing Guo |
WISEC | 3 |
| 2022 | Android Custom Permissions Demystified: A Comprehensive Security EvaluationabstractPermission is the fundamental security mechanism for protecting user data and privacy on Android. Given its importance, security researchers have studied the design and usage of permissions from various aspects. However, most of the previous research focused on the security issues ofsystem permissions. Overlooked by many researchers, an app can usecustom permissionsto share its resources and capabilities with other apps. However, the security implications of using custom permissions have not been fully understood. In this paper, we systematically evaluate the design and implementation of Android custom permissions. Notably, we built an automatic fuzzing tool, calledCuPerFuzzer+, to detect custom permission related vulnerabilities existing in the Android OS.CuPerFuzzer+treats the operations of the permission mechanism as a black-box and executes massive targeted test cases to trigger privilege escalation. In the experiments,CuPerFuzzer+discovered 5,932 effective cases with 47 critical paths successfully. Through investigating these vulnerable cases and analyzing the source code of Android OS, we further identified a series of severe design shortcomings lying in the Android permission framework, includingdangling custom permission,inconsistent permission-group mapping,custom permission elevating,inconsistent permission definition,dormant permission group, andinconsistent permission type. Exploiting these shortcomings, a malicious app can access unauthorized platform resources. On top of these observations, we propose three general design guidelines to secure custom permissions. Our findings have been acknowledged by the Android security team and assignedCVE-2020-0418,CVE-2021-0306,CVE-2021-0307, andCVE-2021-0317. Rui Li 0102, Wenrui Diao, Zhou Li 0001, Shishuai Yang, Shanqing Guo |
IEEE Trans. Software Eng. | 2 |
| 2021 | Android on PC: On the Security of End-user Android EmulatorsabstractAndroid emulators today are not only acting as a debugging tool for developers but also serving the massive end-users. These end-user Android emulators have attracted millions of users due to their advantages of running mobile apps on desktops and are especially appealing for mobile game players who demand larger screens and better performance. Besides, they commonly provide some customized assistant functionalities to improve the user experience, such as keyboard mapping and app installation from the host. To implement these services, emulators inevitably introduce communication channels between host OS and Android OS (in the Virtual Machine), thus forming a unique architecture which mobile phone does not have. However, it is unknown whether this architecture brings any new security risks to emulators. Fenghao Xu, Siyu Shen, Wenrui Diao, Zhou Li 0001, Yi Chen 0024, Rui Li 0102, Kehuan Zhang |
CCS | 3 |
| 2021 | ShadowDroid: Practical Black-box Attack against ML-based Android Malware DetectionabstractMachine learning (ML) techniques have been widely deployed in the field of Android malware detection. On the other hand, ML-based malware detection also faces the threat of adversarial attacks. Recently, some research has demonstrated the possibility of such attacks under the settings of white-box or grey-box. However, a more practical threat model - black-box adversarial attack has not been well validated and evaluated. In this paper, we bridge this research gap and propose a black-box adversarial attack approach, ShadowDroid, against ML-based Android malware detection. On a high level, ShadowDroid tries to construct a substitute model of the target malware detection system. Utilizing this substitute model, we can identify and modify the key features of a malicious app to generate an adversarial sample. During the experiment, we evaluated the effectiveness of ShadowDroid against nine ML-based Android malware detection frameworks. It achieved successful malware evading on five platforms. Based on these results, we also discuss how to design a robust malware detection system to prevent adversarial attacks. Chennan Zhang, Wenrui Diao, Shanqing Guo |
ICPADS | 5 |
| 2021 | Android Custom Permissions Demystified: From Privilege Escalation to Design ShortcomingsabstractPermission is the fundamental security mechanism for protecting user data and privacy on Android. Given its importance, security researchers have studied the design and usage of permissions from various aspects. However, most of the previous research focused on the security issues of system permissions. Overlooked by many researchers, an app can use custom permissions to share its resources and capabilities with other apps. However, the security implications of using custom permissions have not been fully understood.In this paper, we systematically evaluate the design and implementation of Android custom permissions. Notably, we built an automatic fuzzing tool, called CuPerFuzzer, to detect custom permissions related vulnerabilities existing in the Android OS. CuPerFuzzer treats the operations of the permission mechanism as a black-box and executes massive targeted test cases to trigger privilege escalation. In the experiments, CuPerFuzzer discovered 2,384 effective cases with 30 critical paths successfully. Through investigating these vulnerable cases and analyzing the source code of Android OS, we further identified a series of severe design shortcomings lying in the Android permission framework, including dangling custom permission, inconsistent permission-group mapping, custom permission elevating, and inconsistent permission definition. Exploiting any of these shortcomings, a malicious app can obtain dangeroussystem permissions without user consent and further access unauthorized platform resources. On top of these observations, we propose some general design guidelines to secure custom permissions. Our findings have been acknowledged by the Android security team and rated as High severity. Rui Li 0102, Wenrui Diao, Zhou Li 0001, Jianqi Du, Shanqing Guo |
SP | 2 |
| 2020 | An empirical study of potentially malicious third-party libraries in Android appsabstractThe rapid development of Android apps primarily benefits from third-party libraries that provide well-encapsulated functionalities. On the other hand, more and more malicious libraries are discovered in the wild, which brings new security challenges. Despite some previous studies focusing on the malicious libraries, however, most of them only study specific types of libraries or individual cases. The security community still lacks a comprehensive understanding of potentially malicious libraries (PMLs) in the wild. Wenrui Diao, Chengyu Hu 0001, Shanqing Guo, Chaoshun Zuo, Li Li 0044 |
WISEC | 2 |
| 2019 | Your IoTs Are (Not) Mine: On the Remote Binding Between IoT Devices and UsersabstractNowadays, IoT clouds are increasingly deployed to facilitate users to manage and control their IoT devices. Unlike the traditional cloud services with communication between a client and a server, IoT cloud architectures involve three parties: the IoT device, the user, and the cloud. Before a user can remotely access her IoT device, remote communication between them is bootstrapped through the cloud. However, the security implications of such a unique process in IoT are less understood today. In this paper, we report the first step towards systematic analyses of IoT remote binding. To better understand the problem, we describe the life cycle of remote binding with a state-machine model which helps us demystify the complexity in various designs and systematically explore the attack surfaces. With the evaluation of 10 real-world remote binding solutions, our study brings to light questionable practices in the designs of authentication and authorization, including inappropriate use of device IDs, weak device authentication, and weak cloud-side access control, as well as the impact of the discovered problems, which could cause sensitive user data leak, persistent denial-of-service, connection disruption, and even stealthy device control. Jiongyi Chen, Chaoshun Zuo, Wenrui Diao, Shuaike Dong, Qingchuan Zhao, Menghan Sun, Zhiqiang Lin 0001, Yinqian Zhang, Kehuan Zhang |
DSN | 3 |
| 2019 | BadBluetooth: Breaking Android Security Mechanisms via Malicious Bluetooth Peripherals
Fenghao Xu, Wenrui Diao, Zhou Li 0001, Jiongyi Chen, Kehuan Zhang |
NDSS | 2 |
| 2019 | Kindness is a Risky Business: On the Usage of the Accessibility APIs in Android
Wenrui Diao, Yue Zhang 0025, Li Zhang 0039, Zhou Li 0001, Fenghao Xu, Xiaorui Pan, Jian Weng 0001, Kehuan Zhang, XiaoFeng Wang 0001 |
RAID | 1 |
| 2019 | CryptoREX: Large-scale Analysis of Cryptographic Misuse in IoT Devices
Li Zhang 0039, Jiongyi Chen, Wenrui Diao, Shanqing Guo, Jian Weng 0001, Kehuan Zhang |
RAID | 3 |
| 2018 | FragDroid: Automated User Interface Interaction with Activity and Fragment Analysis in Android ApplicationsabstractRecent years have witnessed the enormous growth of Android phones in the consumer market. On the other hand, as the most popular mobile platform, Android also attracts lots of attackers' attention. As a result, more and more Android malicious apps appear in the wild, which poses a serious threat to user's security and privacy. To such massive volume of Android malware, automated UI testing techniques have become the mainstream solutions because of the detection efficiency and accuracy. However, all existing UI testing techniques treat the Activity as the basic unit of UI interactions and cannot carry out a fine-grained analysis for Fragments. Due to the lack of Fragment-level analysis, the path coverage is usually quite limited. To fill this gap, in this paper, we propose FragDroid, a novel automated UI testing framework supporting both Activity and Fragment analysis. To achieve the Fragment-level testing, we design the Activity & Fragment Transition Model (AFTM) to simulate the internal interactions of an app, and ATFM could be utilized to generate test cases automatically through UI interactions. With the assist of AFTM, FragDroid achieves accessing most Activities and Fragments contained in the app along with the capability of detecting arbitrary API calls. We implemented a prototype of FragDroid and evaluated it on 15 popular apps. The results show FragDroid successfully covered 66% Fragments and the corresponding API calls of testing apps. Also, the traditional approaches have to miss at least 9.6% of API calls invoked in Fragments. Ge Han, Shanqing Guo, Wenrui Diao |
DSN | 4 |
| 2018 | DRLgencert: Deep Learning-Based Automated Testing of Certificate Verification in SSL/TLS ImplementationsabstractThe Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols are the foundation of network security. The certificate verification in SSL/TLS implementations is vital and may become the "weak link" in the whole network ecosystem. In previous works, some research focused on the automated testing of certificate verification, and the main approaches rely on generating massive certificates through randomly combining parts of seed certificates for fuzzing. Although the generated certificates could meet the semantic constraints, the cost is quite heavy, and the performance is limited due to the randomness. To fill this gap, in this paper, we propose DRLGENCERT, the first framework of applying deep reinforcement learning to the automated testing of certificate verification in SSL/TLS implementations. DRLGENCERT accepts ordinary certificates as input and outputs newly generated certificates which could trigger discrepancies with high efficiency. Benefited by the deep reinforcement learning, when generating certificates, our framework could choose the best next action according to the result of a previous modification, instead of simple random combinations. At the same time, we developed a set of new techniques to support the overall design, like new feature extraction method for X.509 certificates, fine-grained differential testing, and so forth. Also, we implemented a prototype of DRLGENCERT and carried out a series of real-world experiments. The results show DRLGENCERT is quite efficient, and we obtained 84,661 discrepancy-triggering certificates from 181,900 certificate seeds, say around 46.5% effectiveness. Also, we evaluated six popular SSL/TLS implementations, including GnuTLS, MatrixSSL, MbedTLS, NSS, OpenSSL, and wolfSSL. DRLGENCERT successfully discovered 23 serious certificate verification flaws, and most of them were previously unknown. Wenrui Diao, Yingpei Zeng, Shanqing Guo, Chengyu Hu 0001 |
ICSME | 2 |
| 2018 | IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based Fuzzing
Jiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo, Zhiqiang Lin 0001, XiaoFeng Wang 0001, Wing Cheong Lau, Menghan Sun, Ronghai Yang, Kehuan Zhang |
NDSS | 2 |
| 2018 | Understanding Android Obfuscation Techniques: A Large-Scale Investigation in the Wild
Shuaike Dong, Wenrui Diao, Jian Liu 0008, Zhou Li 0001, Fenghao Xu, Kai Chen 0012, XiaoFeng Wang 0001, Kehuan Zhang |
SecureComm (1) | 3 |
| 2018 | Accessing mobile user's privacy based on IME personalization: Understanding and practical attacksabstractInput Method Editor (IME) is an indispensable component on current smartphones. With its assistance, the number of key presses is reduced, and non-Latin characters could be inputted. Furthermore, modern IMEs integrate several personalized features like reordering suggestion lists and predicting the next words based on user’s input history. Such optimization improves the user experience but turns the IME dictionary into a pool of user privacy. Previous works have discussed the privacy risks coming from malicious IMEs. Indeed, they could cause security and privacy issues if installed by common users, but their impact is limited as the majority of IMEs are well-behaved. However, whether legitimate IMEs are bullet-proof is not answered before. In this paper, we make the first attempt to study the security implications of IME personalization and the back-end infrastructure on Android devices. In the end, we identify a critical vulnerability lying under the Android KeyEvent processing framework, which can be exploited to launch cross-app KeyEvent injection (CAKI) attack and bypass the app-isolation mechanism. By abusing such design flaw, an adversary can harvest entries from the personalized user dictionary of IME through an ostensibly innocuous app only asking for common permissions. Our evaluation over a broad spectrum of Android OSes, devices, and IMEs suggests such issue should be fixed immediately. All Android versions we examined (from very old 2.3.4 to the latest 6.0.1) and most IME apps we surveyed (11 out of 18) are vulnerable. User’s private information, like contact names, location, etc., can be easily exfiltrated. Up to hundreds of millions of mobile users are under this threat. To mitigate this security issue, we propose a practical defense mechanism which augments the existing KeyEvent processing framework without forcing any change to IME apps. Wenrui Diao, Rui Liu 0002, Zhe Zhou 0001, Zhou Li 0001, Kehuan Zhang |
J. Comput. Secur. | 1 |
| 2017 | Vulnerable GPU Memory Management: Towards Recovering Raw Data from GPUabstractAbstract According to previous reports, information could be leaked from GPU memory; however, the security implications of such a threat were mostly over-looked, because only limited information could be indirectly extracted through side-channel attacks. In this paper, we propose a novel algorithm for recovering raw data directly from the GPU memory residues of many popular applications such as Google Chrome and Adobe PDF reader. Our algorithm enables harvesting highly sensitive information including credit card numbers and email contents from GPU memory residues. Evaluation results also indicate that nearly all GPU-accelerated applications are vulnerable to such attacks, and adversaries can launch attacks without requiring any special privileges both on traditional multi-user operating systems, and emerging cloud computing scenarios. Zhe Zhou 0001, Wenrui Diao, Zhou Li 0001, Kehuan Zhang, Rui Liu 0002 |
Proc. Priv. Enhancing Technol. | 2 |
| 2016 | No Pardon for the Interruption: New Inference Attacks on Android Through Interrupt Timing AnalysisabstractMany new specialized hardware components have been integrated into Android smartphones to improve mobility and usability, such as touchscreen, Bluetooth module, and NFC controller. At the system level, the kernel of Android is built on Linux and inherits its device management mechanisms. However, the security implications surfaced from the integration of new hardware components and the tailored Linux kernel are not fully understood. In this paper, we make the first attempt to evaluate such implications. As a result, we identify a critical information leakage channel from the interrupt handling mechanism, which can be exploited to launch inference attacks without any permission. On Android, all reported interrupts are counted by Linux kernel and the statistical information is logged in a system file /proc/interrupts, which is public to any process. Such statistical information reveals the running status of all integrated devices, and could be exploited by attackers to infer sensitive information passing through them. To assess this new threat, we propose a general attack approach -- interrupt timing analysis and apply it to interrupt logs. As showcases, we present two concrete inference attacks against user's unlock pattern and foreground app status respectively. Through analyzing the interrupt time series produced from touchscreen controller, attacker's chance of cracking user's unlock pattern is increased substantially. The interrupt time series produced from Display Sub-System reveals unique UI refreshing patterns and could be leveraged as fingerprints to identify the app running in the foreground. Such information can serve as the stepping stone for the subsequent phishing attacks. The experiment results suggest our inference attacks are highly effective, and the risks should be mitigated immediately. Wenrui Diao, Zhou Li 0001, Kehuan Zhang |
IEEE Symposium on Security and Privacy | 1 |
| 2016 | Evading Android Runtime Analysis Through Detecting Programmed InteractionsabstractDynamic analysis technique has been widely used in Android malware detection. Previous works on evading dynamic analysis focus on discovering the fingerprints of emulators. However, such method has been challenged since the introduction of real devices in recent works. In this paper, we propose a new approach to evade automated runtime analysis through detecting programmed interactions. This approach, in essence, tries to tell the identity of the current app controller (human user or automated exploration tool), by finding intrinsic differences between human user and machine tester in interaction patterns. The effectiveness of our approach has been demonstrated through evaluation against 11 real-world online dynamic analysis services. Wenrui Diao, Zhou Li 0001, Kehuan Zhang |
WISEC | 1 |
| 2015 | When Good Becomes Evil: Keystroke Inference with SmartwatchabstractOne rising trend in today's consumer electronics is the wearable devices, e.g., smartwatches. With tens of millions of smartwatches shipped, however, the security implications of such devices are not fully understood. Although previous studies have pointed out some privacy concerns about the data that can be collected, like personalized health information, the threat is considered low as the leaked data is not highly sensitive and there is no real attack implemented. In this paper we investigate a security problem coming from sensors in smartwatches, especially the accelerometer. The results show that the actual threat is much beyond people's awareness. Being worn on the wrist, the accelerometer built within a smartwatch can track user's hand movements, which makes inferring user inputs on keyboards possible in theory. But several challenges need to be addressed ahead in the real-world settings: e.g., small and irregular hand movements occur persistently during typing, which degrades the tracking accuracy and sometimes even overwhelms useful signals. Zhe Zhou 0001, Wenrui Diao, Zhou Li 0001, Kehuan Zhang |
CCS | 3 |
| 2015 | Mind-Reading: Privacy Attacks Exploiting Cross-App KeyEvent Injections
Wenrui Diao, Zhe Zhou 0001, Kehuan Zhang, Zhou Li 0001 |
ESORICS (2) | 1 |
| 2015 | An Empirical Study on Android for Saving Non-shared Data on Public Storage
Zhe Zhou 0001, Wenrui Diao, Zhou Li 0001, Kehuan Zhang |
SEC | 3 |
| 2014 | Acoustic Fingerprinting Revisited: Generate Stable Device ID Stealthily with Inaudible SoundabstractThe popularity of mobile devices has made people's lives more convenient, but threatened people's privacy at the same time. As end users are becoming more and more concerned on the protection of their private information, it is even harder for hackers to track a specific user by using conventional technologies. For example, cookies might be cleared by users regularly. Besides, OS designers have developed a series of measures to cope with tracker. Apple has stopped apps accessing UDIDs, and Android phones use some special permissions to protect IMEI code. However, some recent studies showed that attackers are able to find new ways to get around those limitations, even though these new methods should be improved in order to be practically deployed in large scale. For example, attackers can trace smart phones by using the hardware features resulting from the imperfect manufacturing process of accelerometers. In this paper, we will present another new and more practical method for the adversaries to generate stable and unique device ID stealthily for the smartphone by exploiting the frequency response of the speaker. With carefully selected audio frequencies and special sound wave patterns, we can reduce the impact of non-linear effects and noises, and keep our feature extraction process un-noticeable to phone owners. The extracted feature is not only very stable for a given smart phone, but also unique to that phone. The feature contains rich information, which is even enough to differentiate millions of smart phones of the same model. We have built a prototype to evaluate our method, and the results show that the generated device ID can be used to track users practically. Zhe Zhou 0001, Wenrui Diao, Kehuan Zhang |
CCS | 2 |