Qinkun Bao

dblp:182/9633 · DBLP profile ↗
← Back
8ranked-venue papers
1as first author
5since 2021 · last 2026
0000-0003-1837-6439ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 5 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 N-SIM: Enhancing Program Similarity Analysis with Over-Basic-Block Semantic Comparison
Qinkun Bao, Dinghao Wu
ENASE (1)2
2023 SymGX: Detecting Cross-boundary Pointer Vulnerabilities of SGX Applications via Static Symbolic Execution
abstract
Intel Security Guard Extensions (SGX) have shown effectiveness in critical data protection. Recent symbolic execution-based techniques reveal that SGX applications are susceptible to memory corruption vulnerabilities. While existing approaches focus on conventional memory corruption in ECalls of SGX applications, they overlook an important type of SGX dedicated vulnerability: cross-boundary pointer vulnerabilities. This vulnerability is critical for SGX applications since they heavily utilize pointers to exchange data between secure enclaves and untrusted environments. Unfortunately, none of the existing symbolic execution approaches can effectively detect cross-boundary pointer vulnerabilities due to the lack of an SGX-specific analysis model that properly handles three unique features of SGX applications: Multi-entry Arbitrary-order Execution, Stateful Execution, and Context-aware Pointers. To address such problems, we propose a new analysis model named Global State Transition Graph with Context Aware Pointers (GSTG-CAP) that simulates properties-preserving execution behaviors for SGX applications and drives symbolic execution for vulnerability detection. Based on GSTG-CAP, we build a novel symbolic execution-based vulnerability detector named SYMGX to detect cross-boundary pointer vulnerabilities. According to our evaluation, SYMGX can find 30 0-DAY vulnerabilities in 14 open-source projects, three of which have been confirmed by developers. SYMGX also outperforms two state-of-the-art tools, COIN and TeeRex, in terms of effectiveness, efficiency, and accuracy.
Yuanpeng Wang, Ziqi Zhang 0017, Ningyu He, Zhineng Zhong, Shengjian Guo, Qinkun Bao, Ding Li 0001, Yao Guo 0001, Xiangqun Chen
CCS6
2023 Source Code Implied Language Structure Abstraction through Backward Taint Analysis
Pei Wang 0007, Qinkun Bao, Dinghao Wu
ICSOFT3
2021 Abacus: Precise Side-Channel Analysis
abstract
Side-channel attacks allow adversaries to infer sensitive information from non-functional characteristics. Prior side-channel detection work is able to identify numerous potential vulnerabilities. However, in practice, many such vulnerabilities leak a negligible amount of sensitive information, and thus developers are often reluctant to address them. Existing tools do not provide information to evaluate a leak's severity, such as the number of leaked bits. To address this issue, we propose a new program analysis method to precisely quantify the leaked information in a single-trace attack through side-channels. It can identify covert information flows in programs that expose confidential information and can reason about security flaws that would otherwise be difficult, if not impossible, for a developer to find. We model an attacker's observation of each leakage site as a constraint. We use symbolic execution to generate these constraints and then run Monte Carlo sampling to estimate the number of leaked bits for each leakage site. By applying the Central Limit Theorem, we provide an error bound for these estimations. We have implemented the technique in a tool called Abacus, which not only finds very fine-grained side-channel vulnerabilities but also estimates how many bits are leaked. Abacus outperforms existing dynamic side-channel detection tools in performance and accuracy. We evaluate Abacus on OpenSSL, mbedTLS, Libgcrypt, and Monocypher. Our results demonstrate that most reported vulnerabilities are difficult to exploit in practice and should be de-prioritized by developers. We also find several sensitive vulnerabilities that are missed by the existing tools. We confirm those vulnerabilities with manual checks and by contacting the developers.
Qinkun Bao, Xiaoting Li 0001, James R. Larus, Dinghao Wu
ICSE1
2021 Characterizing AI Model Inference Applications Running in the SGX Environment
abstract
Intel Software Guard Extensions (SGX) is a set of extensions built into Intel CPUs for the trusted computation. It creates a hardware-assisted secure container, within which programs are protected from data leakage and data manipulations by privileged software and hypervisors. With the trend that more and more machine learning based programs are moving to cloud computing, SGX can be used in cloud-based Machine Learning applications to protect user data from malicious privileged programs.However, applications running in SGX suffer from several overheads, including frequent context switching, memory page encryption/decryption, and memory page swapping, which significantly degrade the execution efficiency. In this paper, we aim to i) comprehensively explore the execution of general AI applications running on SGX, ii) systematically characterize the data reuses at both page granularity and cacheline granularity, and iii) provide optimization insights for efficient deployment of machine learning based applications on SGX. To the best of our knowledge, our work is the first to study machine learning applications on SGX and explore the potential of data reuses to reduce the runtime overheads in SGX.
Shixiong Jing, Qinkun Bao, Pei Wang 0007, Xulong Tang, Dinghao Wu
NAS2
2018 Software protection on the go: a large-scale empirical study on mobile app obfuscation
abstract
The prosperity of smartphone markets has raised new concerns about software security on mobile platforms, leading to a growing demand for effective software obfuscation techniques. Due to various differences between the mobile and desktop ecosystems, obfuscation faces both technical and non-technical challenges when applied to mobile software. Although there have been quite a few software security solution providers launching their mobile app obfuscation services, it is yet unclear how real-world mobile developers perform obfuscation as part of their software engineering practices.
Pei Wang 0007, Qinkun Bao, Shuai Wang 0011, Zhaofeng Chen, Tao Wei 0002, Dinghao Wu
ICSE2
2018 RedDroid: Android Application Redundancy Customization Based on Static Analysis
abstract
Smartphone users are installing more and bigger apps. At the meanwhile, each app carries considerable amount of unused stuff, called software bloat, in its apk file. As a result, the resources of a smartphone, such as hard disk and network bandwidth, has become even more insufficient than ever before. Therefore, it is critical to investigate existing apps on the market and apps in development to identify the sources of software bloat and develop techniques and tools to remove the bloat. In this paper, we present a comprehensive study of software bloat in Android applications, and categorize them into two types, compile-time redundancy and install-time redundancy. In addition, we further propose a static analysis based approach to identifying and removing software bloat from Android applications. We implemented our approach in a prototype called RedDroid, and we evaluated RedDroid on thousands of Android applications collected from Google Play. Our experimental results not only validate the effectiveness of our approach, but also report the bloatware issue in real-world Android applications for the first time.
Yufei Jiang, Qinkun Bao, Shuai Wang 0011, Xiao Liu 0025, Dinghao Wu
ISSRE2
2018 Improving SDN Scalability With Protocol-Oblivious Source Routing: A System-Level Study
abstract
Software-defined networking (SDN) has been considered as a break-through technology for the next-generation Internet. It enables fine-grained flow control that can make networks more flexible and programmable. However, this might lead to scalability issues due to the possible flow state explosion in SDN switches. SDN-based source routing can reduce the volume of flow-tables significantly by encoding the path information into packet headers. In this paper, we leverage the protocol-oblivious forwarding instruction set to design protocol-oblivious source routing (POSR), which is a protocol-independent, bandwidth-efficient, and flow-table-saving packet forwarding technique. We lay out the packet format for POSR, come up with the packet processing pipelines for realizing unicast, multicast, and link failure recovery, and implement POSR in a protocol-oblivious forwarding-enabled SDN network system. Experiments are then performed in a network testbed, which consists of 14 stand-alone SDN switches, to validate the advantages of POSR. Specifically, we compare POSR with several OpenFlow-based benchmarks for unicast, multicast, and link failure recovery, and confirm that POSR can reduce flow-table utilization effectively, shorten path setup latency and expedite link failure recovery.
Shengru Li, Kai Han 0003, Nirwan Ansari, Qinkun Bao, Daoyun Hu, Shui Yu 0001, Zuqing Zhu
IEEE Trans. Netw. Serv. Manag.4