Guangliang Yang 0001

dblp:153/5855 · DBLP profile ↗
← Back
26ranked-venue papers
4as first author
17since 2021 · last 2026
0000-0001-7066-0109ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 24 · 4 first-author · 15 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Measuring and Understanding Expectation Inconsistency in Java Libraries
Yuan Zhang 0009, Letian Yuan, Guangliang Yang 0001, Youkun Shi, Min Yang 0002
IEEE Trans. Inf. Forensics Secur.4
2025 The Skeleton Keys: A Large Scale Analysis of Credential Leakage in Mini-apps
Yizhe Shi, Zhemin Yang, Kangwei Zhong, Guangliang Yang 0001, Xiaohan Zhang 0001, Min Yang 0002
NDSS4
2025 Detecting Taint-Style Vulnerabilities in Microservice-Structured Web Applications
abstract
Microservice architecture has been becoming increasingly popular for building scalable and maintainable applications. A microservice-structured web application (shortened to microservice application) enhances security by providing a loose-coupling design and enforcing the security isolation between different microservices. However, in this paper, our study shows microservice applications still suffer from taint-style vulnerability, one of the most serious vulnerabilities. We propose a novel security analysis approach, named MScan, that can effectively detect taint-style vulnerabilities in real-world evolving-fast microservice applications. Our approach mainly consists of three phases. First, MScan identifies the entry points accessible to external malicious users by applying a gateway-centric analysis. Second, MScan utilizes a new data structure, i.e. service dependence graph, to bridge inter-service communication. Finally, MScan employs a distance-guided strategy for selective context-sensitive taint analysis to detect vulnerabilities. By applying MScan on 25 open-source microservice applications and 5 industrial microservice applications from a world-leading fintech company, we found MScan can effectively vet these applications with the discovery of 59 high-risk 0-day vulnerabilities. We have conducted responsible vulnerability disclosure. Up to now, 31 CVE identifiers have been issued.
Yuan Zhang 0009, Youkun Shi, Guangliang Yang 0001, Min Yang 0002, Junyao He
SP5
2025 MOCGuard: Automatically Detecting Missing-Owner-Check Vulnerabilities in Java Web Applications
abstract
Java web applications have been extensively utilized for hosting and powering high-value commercial websites. However, their intricate complexities leave them susceptible to a critical security flaw, named Missing-Owner-Check (MOC), that may expose websites to unauthorized access and data breaches. However, the research on identifying and analyzing MOC vulnerabilities has been limited over the years. In this work, we propose a novel end-to-end vulnerability analysis approach, called MOCGuard, that can effectively vet Java web applications against MOC issues. Different from related techniques, MOCGuard pinpoints MOC vulnerabilities from a new perspective of database-centric analysis. MOCGuard first applies database structure analysis to infer user table and user-owned data. Then, MOCGuard conducts insecure access checks across both the Java and SQL layers. To thoroughly evaluate the effectiveness of MOCGuard, we collaborated with a world-leading tech company. Through our evaluation of 30 high-profile open-source Java web applications and 7 industrial Java web applications, we demonstrate that MOCGuard is automatic and effective. Consequently, it successfully uncovered 161 (confirmed) 0-day MOC vulnerabilities, leading to the assignment of 73 CVE identifiers.
Youkun Shi, Yuan Zhang 0009, Guangliang Yang 0001, Enhao Li, Min Yang 0002
SP4
2025 Effective Directed Fuzzing with Hierarchical Scheduling for Web Vulnerability Detection
Yuan Zhang 0009, Jiarun Dai, Xinyou Huang, Bocheng Xiang, Guangliang Yang 0001, Letian Yuan, Lei Zhang 0096, Min Yang 0002
USENIX Security Symposium6
2025 Facilitating Access Control Vulnerability Detection in Modern Java Web Applications With Accurate Permission Check Identification
Youkun Shi, Guangliang Yang 0001, Yuan Zhang 0009, Yinzhi Cao, Enhao Li, Xiapu Luo, Min Yang 0002
IEEE Trans. Inf. Forensics Secur.3
2025 PHPJoy: A Novel Extended Graph-Based PHP Code Analysis Framework
abstract
Nowadays, the PHP language is widely used in web development. Owing to PHP’s inherent flexibility and dynamic language features (e.g., cross-module dependencies and runtime polymorphism), PHP applications are prone to various security vulnerabilities, such as XSS and SQL injection. As an effective PHP semantic understanding and security vetting technique, static program analysis has been widely applied. However, prior work faced difficulties in dealing with diverse and dynamic PHP features, which caused serious false negatives (e.g., call target missing).In this paper, we propose a novel extended graph-based program analysis approach, calledPHPJoy, that can effectively and universally learn the semantic landscape of the target PHP program and conduct security validations. Specifically,PHPJoyfirst performs fine-grained program analysis (i.e., cross-module analysis and field-level analysis) for the purpose of learning the extended semantic graphs. Then, based on the graph-based semantic information,PHPJoyuniversally models various security issues by efficiently utilizing a new security-oriented graph query framework, which provides rich and easy-to-use graph query APIs and a high-performance cache-and-prefetch strategy.We evaluatePHPJoyon 333 popular PHP programs. The results show thatPHPJoycan effectively discover 269,901,982 semantic graph edges, improving by 23.76% when compared to the existing analysis tools. Our further analysis also shows that the runtime analysis overhead is reduced by 76.54%. Furthermore,PHPJoysuccessfully hunts 53 zero-day security vulnerabilities in the wild, which verifies the practicality ofPHPJoy.
Youkun Shi, Yuan Zhang 0009, Tianhan Luo, Guangliang Yang 0001, Shengke Ye, Xiapu Luo, Min Yang 0002
IEEE Trans. Software Eng.4
2024 Jasmine: Scale up JavaScript Static Security Analysis with Computation-based Semantic Explanation
abstract
Static data flow analysis techniques have been broadly applied in analyzing and detecting security threats in web applications. However, without actual code execution, they often suffer serious precision issues and may even miss serious vulnerabilities, especially when facing modern JavaScript applications characterized by complex operations and semantics. To combat these complex semantics, we propose a novel semantic understanding approach, namely computation-based semantic explanation (CSE). CSE can effectively identify and resolve common failures arising from complex semantics in static data flow analysis, ultimately improving the detection of potential vulnerabilities.We implement a prototype tool of CSE, called Jasmine. By applying Jasmine to more than 10K real-world JavaScript programs, we find complex operations and semantics are prevalent in practice and heavily impede the state-of-art static techniques (e.g., Github’s CodeQL and IBM’s WALA) from regular security validations. Our experiments show Jasmine can effectively resolve complex semantics and lead to the discovery of 22 hidden vulnerabilities, which are not detectable by existing tools. Among these vulnerabilities, 13 ones are previously unknown, i.e., zero-day vulnerabilities. Up to now, nine CVEs have been issued, and five of them have been rated as ‘critical’ with a 9.8 severity score.
Zhongfu Su, Guangliang Yang 0001, Wenke Lee
SP3
2024 The Dark Forest: Understanding Security Risks of Cross-Party Delegated Resources in Mobile App-in-App Ecosystems
abstract
In app-in-app ecosystems, mobile applications (i.e., host apps) often delegate their rich resources to hosted parties (i.e., sub-apps), which can be utilized to provide millions of effective services including shopping, banking, and government. These resources vary from system abilities (e.g., web socket and GPS location) to app and user data (e.g., storage and phone number). This leads to an important research question—carefully design and enforce security regulations on these cross-party delegated resources (CPDR). Real-world host apps, according to our study, adopt 11 common security regulations in protecting the integrity, confidentiality, and availability of CPDR. However, existing practice and compliance between host apps and sub-apps are vague and inconsistent, leading to violations of these security regulations. To the best of our knowledge, no prior works have studied these security regulations. In this paper, we perform the first systematic study of the security regulations and their security weaknesses in real-world app-in-app ecosystems. We propose three novel attack vectors including masquerade attack, data-driven attack, and channel hijacking. We find that violations of the common security regulations are widespread among all 9 studied app-in-app ecosystems. More importantly, such security weakness can lead to severe consequences such as manipulating sub-apps’ back-end servers and stealing sensitive user data. We responsibly report all of our findings to host app developers of affected app-in-app ecosystems and help them fix their vulnerabilities.
Zhibo Zhang 0006, Lei Zhang 0096, Guangliang Yang 0001, Min Yang 0002
IEEE Trans. Inf. Forensics Secur.3
2023 NestFuzz: Enhancing Fuzzing with Comprehensive Understanding of Input Processing Logic
abstract
Fuzzing is one of the most popular and practical techniques for security analysis. In this work, we aim to address the critical problem of high-quality input generation with a novel input-aware fuzzing approach called NestFuzz. NestFuzz can universally and automatically model input format specifications and generate valid input.
Zhemin Yang, Lei Zhang 0096, Guangliang Yang 0001, Wenzheng Hong, Yuan Zhang 0009, Min Yang 0002
CCS4
2023 Notice the Imposter! A Study on User Tag Spoofing Attack in Mobile Apps
Shuai Li 0006, Zhemin Yang, Guangliang Yang 0001, Hange Zhang, Nan Hua, Yurui Huang, Min Yang 0002
USENIX Security Symposium3
2022 Collect Responsibly But Deliver Arbitrarily?: A Study on Cross-User Privacy Leakage in Mobile Apps
abstract
Recent years have witnessed the interesting trend that modern mobile apps perform more and more likely as user-to-user platforms, where app users can be freely and conveniently connected. Upon these platforms, rich and diverse data is often delivered across users, which brings users great conveniences and plentiful services, but also introduces privacy security concerns. While prior work has primarily studied illegitimate personal data collection problems in mobile apps, few paid little attention to the security of this emerging user-to-user platform feature, thus providing a rather limited understanding of the privacy risks in this aspect.
Shuai Li 0006, Zhemin Yang, Nan Hua, Peng Liu 0005, Xiaohan Zhang 0001, Guangliang Yang 0001, Min Yang 0002
CCS6
2022 Understanding and Mitigating Remote Code Execution Vulnerabilities in Cross-platform Ecosystem
abstract
JavaScript cross-platform frameworks are becoming increasingly popular. They help developers easily and conveniently build cross-platform applications while just needing only one JavaScript codebase. Recent security reports showed several high-profile cross-platform applications (e.g., Slack, Microsoft Teams, and Github Atom) suffered injection issues, which were often introduced by Cross-site Scripting (XSS) or embedded untrusted remote content like ads. These injections open security holes for remote web attackers, and cause serious security risks, such as allowing injected malicious code to run arbitrary local executables in victim devices (referred to as XRCE attacks). However, until now, XRCE vectors and behaviors and the root cause of XRCE were rarely studied and understood. Although the cross-platform framework developers and community responded quickly by offering multiple security features and suggestions, these mitigations were empirically proposed with unknown effectiveness.
Joey Allen, Guangliang Yang 0001, Grant Williams, Wenke Lee
CCS4
2022 Identity Confusion in WebView-based Mobile App-in-app Ecosystems
Lei Zhang 0096, Zhibo Zhang 0006, Ancong Liu, Yinzhi Cao, Xiaohan Zhang 0001, Yuan Zhang 0009, Guangliang Yang 0001, Min Yang 0002
USENIX Security Symposium8
2021 The Service Worker Hiding in Your Browser: The Next Web Attack Target?
abstract
In recent years, service workers are gaining attention from both web developers and attackers due to the unique features they provide. Recent findings have shown that an attacker can register a malicious service worker to take advantage of the victim such as by turning the victim’s device into a crypto-currency miner. However, the possibility of benign service workers being leveraged is not well studied.
Phakpoom Chinprutthiwong, Raj Vardhan, Guangliang Yang 0001, Yangyong Zhang, Guofei Gu
RAID3
2021 Abusing Hidden Properties to Attack the Node.js Ecosystem
Yichang Xiong, Guangliang Yang 0001, Hong Hu 0004, Guofei Gu, Wenke Lee
USENIX Security Symposium4
2021 SEPAL: Towards a Large-scale Analysis of SEAndroid Policy Customization
abstract
Nowadays, SEAndroid has been widely deployed in Android devices to enforce security policies and provide flexible mandatory access control (MAC), for the purpose of narrowing down attack surfaces and restricting risky operations. Generally, the original SEAndroid security policy rules are carefully and strictly written and maintained by the Android community. However, in practice, mobile device manufacturers usually have to customize these policy rules and add their own new rules to satisfy their functionality extensions, which breaks the integrity of SEAndroid and causes serious security issues. Still, up to now, it is a challenging task to identify these security issues due to the large and ever-increasing number of policy rules, as well as the complexity of policy semantics.
Dongsong Yu, Guangliang Yang 0001, Guozhu Meng, Xiaorui Gong, Xiaobo Xiang, Kai Chen 0012, Wenke Lee, Wenchang Shi
WWW2
2020 Security Study of Service Worker Cross-Site Scripting
abstract
Nowadays, modern websites are utilizing service workers to provide users with app-like functionalities such as offline mode and push notifications. To handle such features, the service worker is equipped with special privileges including HTTP traffic manipulation. Thus, it is designed with security as a priority. However, we find that many websites introduce a questionable practice that can jeopardize the security of a service worker.
Phakpoom Chinprutthiwong, Raj Vardhan, Guangliang Yang 0001, Guofei Gu
ACSAC3
2019 Life after Speech Recognition: Fuzzing Semantic Misinterpretation for Voice Assistant Applications
Yangyong Zhang, Lei Xu 0024, Abner Mendoza, Guangliang Yang 0001, Phakpoom Chinprutthiwong, Guofei Gu
NDSS4
2019 Iframes/Popups Are Dangerous in Mobile WebView: Studying and Mitigating Differential Context Vulnerabilities
Guangliang Yang 0001, Jeff Huang 0001, Guofei Gu
USENIX Security Symposium1
2018 Towards Fine-grained Network Security Forensics and Diagnosis in the SDN Era
abstract
Diagnosing network security issues in traditional networks is difficult. It is even more frustrating in the emerging Software Defined Networks. The data/control plane decoupling of the SDN framework makes the traditional network troubleshooting tools unsuitable for pinpointing the root cause in the control plane. In this paper, we propose ForenGuard, which provides flow-level forensics and diagnosis functions in SDN networks. Unlike traditional forensics tools that only involve either network level or host level, ForenGuard monitors and records the runtime activities and their causal dependencies involving both the SDN control plane and data plane. Starting with a forwarding problem (e.g., disconnection) which could be caused by a security issue, ForenGuard can backtrack the previous activities in both the control and data plane through causal relationships and pinpoint the root cause of the problem. ForenGuard also provides a user-friendly interface that allows users to specify the detection point and diagnose complicated network problems. We implement a prototype system of ForenGuard on top of the Floodlight controller and use it to diagnose several real control plane attacks. We show that ForenGuard can quickly display causal relationships of activities and help to narrow down the range of suspicious activities that could be the root causes. Our performance evaluation shows that ForenGuard will add minor runtime overhead to the SDN control plane and can scale well in various network workloads.
Haopei Wang, Guangliang Yang 0001, Phakpoom Chinprutthiwong, Lei Xu 0024, Yangyong Zhang, Guofei Gu
CCS2
2018 Automated Generation of Event-Oriented Exploits in Android Hybrid Apps
Guangliang Yang 0001, Jeff Huang 0001, Guofei Gu
NDSS1
2018 Study and Mitigation of Origin Stripping Vulnerabilities in Hybrid-postMessage Enabled Mobile Applications
abstract
PostMessage is popular in HTML5 based web apps to allow the communication between different origins. With the increasing popularity of the embedded browser (i.e., WebView) in mobile apps (i.e., hybrid apps), postMessage has found utility in these apps. However, different from web apps, hybrid apps have a unique requirement that their native code (e.g., Java for Android) also needs to exchange messages with web code loaded in WebView. To bridge the gap, developers typically extend postMessage by treating the native context as a new frame, and allowing the communication between the new frame and the web frames. We term such extended postMessage "hybrid postMessage" in this paper. We find that hybrid postMessage introduces new critical security flaws: all origin information of a message is not respected or even lost during the message delivery in hybrid postMessage. If adversaries inject malicious code into WebView, the malicious code may leverage the flaws to passively monitor messages that may contain sensitive information, or actively send messages to arbitrary message receivers and access their internal functionalities and data. We term the novel security issue caused by hybrid postMessage "Origin Stripping Vulnerability" (OSV). In this paper, our contributions are fourfold. First, we conduct the first systematic study on OSV. Second, we propose a lightweight detection tool against OSV, called OSV-Hunter. Third, we evaluate OSV-Hunter using a set of popular apps. We found that 74 apps implemented hybrid postMessage, and all these apps suffered from OSV, which might be exploited by adversaries to perform remote real-time microphone monitoring, data race, internal data manipulation, denial of service (DoS) attacks and so on. Several popular development frameworks, libraries (such as the Facebook React Native framework, and the Google cloud print library) and apps (such as Adobe Reader and WPS office) are impacted. Lastly, to mitigate OSV from the root, we design and implement three new postMessage APIs, called OSV-Free. Our evaluation shows that OSV-Free is secure and fast, and it is generic and resilient to the notorious Android fragmentation problem. We also demonstrate that OSV-Free is easy to use, by applying OSV-Free to harden the complex "Facebook React Native" framework. OSV-Free is open source, and its source code and more implementation and evaluation details are available online.
Guangliang Yang 0001, Jeff Huang 0001, Guofei Gu, Abner Mendoza
IEEE Symposium on Security and Privacy1
2017 Precisely and Scalably Vetting JavaScript Bridge in Android Hybrid Apps
Guangliang Yang 0001, Abner Mendoza, Jialong Zhang 0001, Guofei Gu
RAID1
2015 Using Provenance Patterns to Vet Sensitive Behaviors in Android Apps
Chao Yang 0022, Guangliang Yang 0001, Ashish Gehani, Vinod Yegneswaran, Dawood Tariq, Guofei Gu
SecureComm2
2014 AUTOPROBE: Towards Automatic Active Malicious Server Probing Using Dynamic Binary Analysis
abstract
Malware continues to be one of the major threats to Internet security. In the battle against cybercriminals, accurately identifying the underlying malicious server infrastructure (e.g., C&C servers for botnet command and control) is of vital importance. Most existing passive monitoring approaches cannot keep up with the highly dynamic, ever-evolving malware server infrastructure. As an effective complementary technique, active probing has recently attracted attention due to its high accuracy, efficiency, and scalability (even to the Internet level). In this paper, we propose Autoprobe, a novel system to automatically generate effective and efficient fingerprints of remote malicious servers. Autoprobe addresses two fundamental limitations of existing active probing approaches: it supports pull-based C&C protocols, used by the majority of malware, and it generates fingerprints even in the common case when C&C servers are not alive during fingerprint generation. Using real-world malware samples we show that Autoprobe can successfully generate accurate C&C server fingerprints through novel applications of dynamic binary analysis techniques. By conducting Internet-scale active probing, we show that Autoprobe can successfully uncover hundreds of malicious servers on the Internet, many of them unknown to existing blacklists. We believe Autoprobe is a great complement to existing defenses, and can play a unique role in the battle against cybercriminals.
Zhaoyan Xu, Antonio Nappa, Robert Baykov, Guangliang Yang 0001, Juan Caballero, Guofei Gu
CCS4