Weijie Wang 0005

dblp:18/689-5 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
7since 2021 · last 2025
0000-0002-6445-1746ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 VN-GT: Optimizing Virtual Network Deployment via Game Theory
abstract
The static and homogeneous nature of traditional networks presents a significant challenge for our defense efforts. These characteristics enable an experienced attacker to quickly determine our network topology and gather detailed information about the internal hosts through systematic scanning techniques. Implementing a virtual network view can mitigate this by simulating a virtual topology, thereby consuming the attacker’s resources and time. However, deploying a virtual network view reduces network throughput and increase latency. Additionally, an improperly configured virtual network view can waste resources and degrade Quality of Service (QoS). Most existing studies have focused solely on the defender’s perspective, resulting in overly idealistic solutions that are ineffective in real-world scenarios. To address this, we propose VN-GT, a game-theoretic based model that optimizes virtual network deployment by considering both attackers and defenders. We provide a detailed example scenario, analyze the game’s equilibrium, and validate the effectiveness of our method through a real attack and defense experiment.
Weijie Wang 0005, Yan Wang 0081, Guokun Xu, Zuxin Chen, Siyuan Li 0014, Min Yu 0001, Weiqing Huang, Degang Sun
ICASSP1
2025 Lares: LLM-driven Code Slice Semantic Search for Patch Presence Testing
abstract
In modern software ecosystems, 1-day vulnerabilities pose significant security risks due to extensive code reuse. Identifying vulnerable functions in target binaries alone is insufficient; it is also crucial to determine whether these functions have been patched. Existing methods, however, suffer from limited usability and accuracy. They often depend on the compilation process to extract features, requiring substantial manual effort and failing for certain software. Moreover, they cannot reliably differentiate between code changes caused by patches or compilation variations.To overcome these limitations, we propose Lares, a scalable and accurate method for patch presence testing. Lares introduces Code Slice Semantic Search, which directly extracts features from the patch source code and identifies semantically equivalent code slices in the pseudocode of the target binary. By eliminating the need for the compilation process, Lares improves usability, while leveraging large language models (LLMs) for code analysis and SMT solvers for logical reasoning to enhance accuracy. Experimental results show that Lares achieves superior precision, recall, and usability. Furthermore, it is the first work to evaluate patch presence testing across optimization levels, architectures, and compilers. The datasets and source code used in this article are available at https://github.com/Siyuan-Li201/Lares.
Siyuan Li 0014, Yaowen Zheng, Hong Li 0004, Jingdong Guo, Chaopeng Dong, Chunpeng Yan, Weijie Wang 0005, Yimo Ren, Limin Sun 0001, Hongsong Zhu
ASE7
2025 PREXP: Uncovering and Exploiting Security-Sensitive Objects in the Linux Kernel
abstract
Security-Sensitive Objects (SSOs) are often critical components in the exploitation of Linux kernel memory corruption vulnerabilities. While existing research has advanced SSOs identification and classification, there remains a significant gap in systematically understanding how these objects can be effectively exploited in real-world security analysis. To address this challenge, we present PREXP, a novel approach to analyzing SSOs exploitability and automating the transformation of Proof-of-Concept (PoC) into exploitable states. Our approach encompasses three key techniques: (1) capability analysis and attribute modeling of vulnerable object (2) extraction and filtering of target SSOs and (3) automatically augmenting PoCs with SSO-specific code to create exploitation capabilities. To evaluate our approach, we tested our prototype on 30 public CVEs, successfully parsing vulnerable object in 22 cases (73.3%) and achieving accurate SSO matches in 18 (60.0%). PREXP outperformed state-of-the-art tools such as SCAVY and AlphaEXP in structure-matching, and enabled the generation of new Control Flow Hijacking Primitives (CFHPs) for 3 previously unexploited vulnerabilities, demonstrating its practical value in real-world exploit development.
Zuxin Chen, Yaowen Zheng, Hong Li 0004, Siyuan Li 0014, Weijie Wang 0005, Dongliang Fang, Zhiqiang Shi, Limin Sun 0001
IEEE Trans. Inf. Forensics Secur.5
2024 MLNT: A Multi-Level Network Traps Deployment Method
abstract
Traditional honeypot technology combines trap deployment component with attack deception response component, and the more network traps are deployed, the more system resources, such as virtual machines and containers, are required. To alleviate this problem, we propose a transparent network deception defense method called MLNT. MLNT decouples the trap deployment component and attack deception response component, reducing the dependence of high-density traps on system resources. First, MLNT can complete multi-layer network trap deployment, including trap service ports of real assets, network node traps of security domains, and security domain traps. Second, MLNT can transparently deploy network traps on real protection targets. It protects valuable assets in Industrial Control Networks and the Internet of Things, where software agents can not be installed. Finally, we implemented the MLNT framework using FPGA and tested it’s capability of delaying the attackers’ progress. The experimental results demonstrate the effectiveness and feasibility of MLNT.
Guokun Xu, Weijie Wang 0005, Degang Sun, Yanpeng Ma, Yan Wang 0081, Weiqing Huang
CSCWD2
2024 LibAM: An Area Matching Framework for Detecting Third-Party Libraries in Binaries
abstract
Third-party libraries (TPLs) are extensively utilized by developers to expedite the software development process and incorporate external functionalities. Nevertheless, insecure TPL reuse can lead to significant security risks. Existing methods, which involve extracting strings or conducting function matching, are employed to determine the presence of TPL code in the target binary. However, these methods often yield unsatisfactory results due to the recurrence of strings and the presence of numerous similar non-homologous functions. Furthermore, the variation in C/C++ binaries across different optimization options and architectures exacerbates the problem. Additionally, existing approaches struggle to identify specific pieces of reused code in the target binary, complicating the detection of complex reuse relationships and impeding downstream tasks. And, we call this issue the poor interpretability of TPL detection results. In this article, we observe that TPL reuse typically involves not just isolated functions but also areas encompassing several adjacent functions on the Function Call Graph (FCG). We introduce LibAM, a novel Area Matching framework that connects isolated functions into function areas on FCG and detects TPLs by comparing the similarity of these function areas, significantly mitigating the impact of different optimization options and architectures. Furthermore, LibAM is the first approach capable of detecting the exact reuse areas on FCG and offering substantial benefits for downstream tasks. To validate our approach, we compile the first TPL detection dataset for C/C++ binaries across various optimization options and architectures. Experimental results demonstrate that LibAM outperforms all existing TPL detection methods and provides interpretable evidence for TPL detection results by identifying exact reuse areas. We also evaluate LibAM’s scalability on large-scale, real-world binaries in IoT firmware and generate a list of potential vulnerabilities for these devices. Our experiments indicate that the Area Matching framework performs exceptionally well in the TPL detection task and holds promise for other binary similarity analysis tasks. Last but not least, by analyzing the detection results of IoT firmware, we make several interesting findings, for instance, different target binaries always tend to reuse the same code area of TPL. The datasets and source code used in this article are available at https://github.com/Siyuan-Li201/LibAM .
Siyuan Li 0014, Yongpan Wang, Chaopeng Dong, Shouguo Yang, Hong Li 0004, Hao Sun 0028, Zhe Lang, Zuxin Chen, Weijie Wang 0005, Hongsong Zhu, Limin Sun 0001
ACM Trans. Softw. Eng. Methodol.9
2023 LWVN: A Lightweight Virtual Network View Method to Defend Lateral Movement
abstract
Due to traditional network topologies’ static and homomorphic characteristics, attackers can rapidly expand their attack results through lateral movement (LM) attacks. Virtual Network View technology has emerged as an effective approach to disrupt attackers’ ability to detect and exploit network topologies during LM and can increase the difficulty of malicious activities. However, existing Virtual Network View deployS virtual views for each core asset, resulting in wasting of resource. To alleviate this problem, we propose a lightweight Virtual Network View deployment method called LWVN. First, the Location Centrality (LC) of the network nodes in the attack path is measured, the larger the LC is, the network node is more important and the more virtual network view costs we can invest. To further quantify the comprehensive impact of network nodes’ location centrality on high-value assets, we quantify the Assets’ Value(AV). Then, we model internal network risk and operational costs as constraints and find the optimal strategies for deploying a virtual network view. We define metrics for hidden capacity, detect capacity, and deployment cost to measure the effectiveness of deployment virtual network views. We conduct simulations to verify the effectiveness and feasibility of LWVN.
Degang Sun, Guokun Xu, Weijie Wang 0005, Yan Wang 0081, Qiujian Lv
TrustCom3
2023 VN-SMT: An SMT-based Construction Method on Virtual Network to Defend Insider Reconnaissance
abstract
Due to networks’ static and homomorphic nature, experienced attackers can quickly get the target network’s topology and internal host information by scanning. The virtual network view prevents network reconnaissance by simulating a virtual network topology for the network hosts, to consume the attacker’s attack resources and time. However, deploying a virtual network view will reduce network throughput and increase network latency, and an unreasonable virtual network view configuration will waste resources and reduce Quality of Services(QoS). We, therefore, propose a method VN-SMT that can rationally configure virtual network view. This method generates an optimal virtual network view base on existing host configuration, risk constraints, and budget constraints. We define metrics for deception, concealment, and resource consumption to measure the effectiveness of virtual network views. We conduct simulations to verify the effectiveness and feasibility of VN-SMT.
Weijie Wang 0005, Yan Wang 0081, Guokun Xu, Qiujian Lv, Zuxin Chen, Siyuan Li 0014
WCNC1