Xiaobo Xiang

dblp:227/8898 · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
4since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 ADGE: Automated Directed GUI Explorer for Android Applications
abstract
With the continuous growth in the number of Android applications and the size of their codebases, it has become increasingly difficult for testers to manually analyze and trigger the functionalities of interest in each application. For instance, it is hard to trigger vulnerability points reported by scanners or reproduce captured crash scenarios. On the other hand, most existing automated exploration techniques exhibit slow performance when triggering specified targets due to the extensive exploration of different paths. Target-directed techniques can effectively address this issue but are relatively underexplored in existing research. The only target-directed exploration tool, GOALEXPLORER, is constrained by the limitations in the precision of its static analysis, which negatively impacts both exploration efficiency and effectiveness. To boost the efficiency of target-directed exploration, we propose an automated GUI testing method guided by target functions called Automated Directed GUI Explorer (ADGE). Specifically, ADGE first generates a tainted Inter-procedural Control Flow Graph with the GUI widgets by modeling the role of GUI widgets in the control flow as well as their relationship with the target using static analysis. In the dynamic exploration phase, ADGE constructs the real-time model of the fragments and menus on the current screen to guide its exploration decisions with the knowledge of static model. To validate the effectiveness of ADGE, we conduct extensive comparisons of ADGE with the state-of-the-art baseline GOALEXPLORER on 55 benchmark applications. The results demonstrate that ADGE reduced the average time to trigger targets by 44% compared to GOALEXPLORER, while also successfully triggering more than 5.24% targets. Furthermore, during the testing process, ADGE successfully triggered 5 crash events.
Xiaobo Xiang, Qingli Guo, Xiaorui Gong
ICST2
2023 AppChainer: investigating the chainability among payloads in android applications
abstract
Abstract Statistics show that more than 80 applications are installed on each android smartphone. Vulnerability research on Android applications is of critical importance. Recently, academic researchers mainly focus on single bug patterns, while few of them investigate the relations between multiple bugs. Industrial researchers proposed a series of logic exploit chains leveraging multiple logic bugs. However, there is no general model to evaluate the chaining abilities between bugs. This paper presents a formal model to elucidate the relations between multiple bugs in Android applications. To prove the effectiveness of the model, we design and implement a prototype system named AppChainer. AppChainer automatically identifies attack surfaces of Android applications and investigates whether the payloads entering these attack surfaces are “chainable”. Experimental results on 2138 popular Android applications show that AppChainer is effective in identifying and chaining attacker-controllable payloads. It identifies 14467 chainable payloads and constructs 5458 chains both inside a single application and among various applications. The time cost and resource consumption of AppChainer are also acceptable. For each application, the average analysis time is 317 s, and the average memory consumed is 2368 MB. Compared with the most relevant work Jandroid, the experiment results on our custom DroidChainBench show that AppChainer outperforms Jandroid at the precision rate and performs equally with Jandroid at the recall rate.
Xiaobo Xiang, Qingli Guo, Xiaorui Gong, Baoxu Liu
Cybersecur.1
2021 Ghost in the Binder: Binder Transaction Redirection Attacks in Android System Services
abstract
Binder, the main mechanism for Android applications to access system services, adopts a client-server role model in its design, assuming the system service as the server and the application as the client. However, a growing number of scenarios require the system service to act as a Binder client and to send queries to a Binder server possibly instantiated by the application. Departing from this role-reversal possibility, this paper proposes the Binder Transaction Redirection (BiTRe) attacks, where the attacker induces the system service to transact with a customized Binder server and then attacks from the Binder server---an often unprotected direction. We demonstrate the scale of the attack surface by enumerating the utilizable Binder interfaces in BiTRe, and discover that the attack surface grows with the Android release version. In Android 11, more than 70% of the Binder interfaces are affected by or can be utilized in BiTRe. We prove the attacks' feasibility by (1) constructing a prototype system that can automatically generate executable programs to reach a substantial part of the attack surface, and (2) identifying a series of vulnerabilities, which are acknowledged by Google and assigned ten CVEs.
Xiaobo Xiang, Ren Zhang 0003, Hanxiang Wen, Xiaorui Gong, Baoxu Liu
CCS1
2021 SEPAL: Towards a Large-scale Analysis of SEAndroid Policy Customization
abstract
Nowadays, SEAndroid has been widely deployed in Android devices to enforce security policies and provide flexible mandatory access control (MAC), for the purpose of narrowing down attack surfaces and restricting risky operations. Generally, the original SEAndroid security policy rules are carefully and strictly written and maintained by the Android community. However, in practice, mobile device manufacturers usually have to customize these policy rules and add their own new rules to satisfy their functionality extensions, which breaks the integrity of SEAndroid and causes serious security issues. Still, up to now, it is a challenging task to identify these security issues due to the large and ever-increasing number of policy rules, as well as the complexity of policy semantics.
Dongsong Yu, Guangliang Yang 0001, Guozhu Meng, Xiaorui Gong, Xiaobo Xiang, Kai Chen 0012, Wenke Lee, Wenchang Shi
WWW6
2019 Memory access integrity: detecting fine-grained memory access errors in binary code
abstract
As one of the most notorious programming errors, memory access errors still hurt modern software security. Particularly, they are hidden deeply in important software systems written in memory unsafe languages like C/C++. Plenty of work have been proposed to detect bugs leading to memory access errors. However, all existing works lack the ability to handle two challenges. First, they are not able to tackle fine-grained memory access errors, e.g., data overflow inside one data structure. These errors are usually overlooked for a long time since they happen inside one memory block and do not lead to program crash. Second, most existing works rely on source code or debugging information to recover memory boundary information, so they cannot be directly applied to detection of memory access errors in binary code. However, searching memory access errors in binary code is a very common scenario in software vulnerability detection and exploitation. In order to overcome these challenges, we propose Memory Access Integrity (MAI), a dynamic method to detect fine-grained memory access errors in off-the-shelf binary executables. The core idea is to recover fine-grained accessing policy between memory access behaviors and memory ranges, and then detect memory access errors based on the policy. The key insight in our work is that memory accessing patterns reveal information for recovering the boundary of memory objects and the accessing policy. Based on these recovered information, our method maintains a new memory model to simulate the life cycle of memory objects and report errors when any accessing policy is violated. We evaluate our tool on popular CTF datasets and real world softwares. Compared with the state of the art detection tool, the evaluation result demonstrates that our tool can detect fine-grained memory access errors effectively and efficiently. As the practical impact, our tool has detected three 0-day memory access errors in an audio decoder.
Wenjie Li 0006, Dongpeng Xu 0001, Xiaorui Gong, Xiaobo Xiang, Fangming Gu, Qianxiang Zeng
Cybersecur.5
2018 Revery: From Proof-of-Concept to Exploitable
abstract
Automatic exploit generation is an open challenge. Existing solutions usually explore in depth the crashing paths, i.e., paths taken by proof-of-concept (POC) inputs triggering vulnerabilities, and generate exploits when exploitable states are found along the paths. However, exploitable states do not always exist in crashing paths. Moreover, existing solutions heavily rely on symbolic execution and are not scalable in path exploration and exploit generation. In addition, few solutions could exploit heap-based vulnerabilities. In this paper, we propose a new solution revery to search for exploitable states in paths diverging from crashing paths, and generate control-flow hijacking exploits for heap-based vulnerabilities. It adopts three novel techniques:(1) a digraph to characterize a vulnerability's memory layout and its contributor instructions;(2) a fuzz solution to explore diverging paths, which have similar memory layouts as the crashing paths, in order to search more exploitable states and generate corresponding diverging inputs;(3) a stitch solution to stitch crashing paths and diverging paths together, and synthesize EXP inputs able to trigger both vulnerabilities and exploitable states. We have developed a prototype of revery based on the binary analysis engine angr, and evaluated it on a set of 19 real world CTF (capture the flag) challenges. Experiment results showed that it could generate exploits for 9 (47%) of them, and generate EXP inputs able to trigger exploitable states for another 5 (26%) of them.
Chao Zhang 0008, Xiaobo Xiang, Wenjie Li 0006, Xiaorui Gong, Bingchang Liu, Kaixiang Chen
CCS3