Xiaolei Ren 0001

dblp:177/5330-1 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2023
0000-0002-0425-8987ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2023 Intelligent Zigbee Protocol Fuzzing via Constraint-Field Dependency Inference
Mengfei Ren 0001, Haotian Zhang 0006, Xiaolei Ren 0001, Jiang Ming 0002, Yu Lei 0001
ESORICS (2)3
2023 MagicMirror: Towards High-Coverage Fuzzing of Smart Contracts
abstract
A smart contract is often used to handle financial transactions. Unlike traditional programs, contract codes cannot be changed after deployment. It is crucial to test smart contracts thoroughly before deployment. In this paper, we present a fuzzing approach to testing smart contracts. Our fuzzing approach utilizes constraint solving, selective state exploration, and combinatorial testing to improve code coverage. Constraint solving generates test inputs that meet preconditions in a smart contract. Selective state exploration allows different state-dependent behaviors to be exercised while alleviating the state explosion problem. Combinatorial testing is used to exercise parameter interactions in a systematic manner. We implemented our approach in a tool called MagicMirror and evaluated our approach using more than 2,000 contracts. The experimental results show that MagicMirror effectively achieves high code coverage and detects vulnerabilities.
Huadong Feng, Xiaolei Ren 0001, Qiping Wei, Yu Lei 0001, Raghu Kacker, D. Richard Kuhn, Dimitris E. Simos
ICST2
2021 Unleashing the hidden power of compiler optimization on binary code difference: an empirical study
abstract
Hunting binary code difference without source code (i.e., binary diffing) has compelling applications in software security. Due to the high variability of binary code, existing solutions have been driven towards measuring semantic similarities from syntactically different code. Since compiler optimization is the most common source contributing to binary code differences in syntax, testing the resilience against the changes caused by different compiler optimization settings has become a standard evaluation step for most binary diffing approaches. For example, 47 top-venue papers in the last 12 years compared different program versions compiled by default optimization levels (e.g., -Ox in GCC and LLVM). Although many of them claim they are immune to compiler transformations, it is yet unclear about their resistance to non-default optimization settings. Especially, we have observed that adversaries explored non-default compiler settings to amplify malware differences.
Xiaolei Ren 0001, Michael Ho, Jiang Ming 0002, Yu Lei 0001, Li Li 0029
PLDI1
2021 Z-Fuzzer: device-agnostic fuzzing of Zigbee protocol implementation
abstract
With the proliferation of the Internet of Things (IoT) devices, Zigbee is widely adopted as a resource-efficient wireless protocol. Recently, severe vulnerabilities in Zigbee protocol implementations have compromised IoT devices from different manufacturers. It becomes imperative to perform security testing on Zigbee protocol implementations. However, it is not a trivial task to apply the existing vulnerability detection techniques such as fuzzing to Zigbee protocol implementations. In particular, it remains a significant obstacle to deal with low-level hardware events. Many existing protocol fuzzing tools lack a proper execution environment for the Zigbee protocol, which communicates via a radio channel instead of the Internet.
Mengfei Ren 0001, Xiaolei Ren 0001, Huadong Feng, Jiang Ming 0002, Yu Lei 0001
WISEC2