VLDB 2026 Research / reviewers in the wild / expert
Yuanyuan Zhang 0002
dblp:23/6185-2
· DBLP profile ↗
51ranked-venue papers
3as first author
12since 2021 · last 2025
0000-0002-6130-4601ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 24 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 13 · 6 since 2021Computer networks · 5 · 1 first-author · 1 since 2021Systems, architecture and hardware · 4 · 1 since 2021Human-computer interaction and ubiquitous computing · 2Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Pay Your Attention on Lib! Android Third-Party Library Detection via Feature Language ModelabstractThe widespread use of third-party libraries (TPL) has brought many conveniences to Android application devel-opment, fostering the development of the Android application ecosystem. Detecting the presence of TPLs in Android applications is crucial in the Android era, as it enables the rapid identification of their usage when security vulnerabilities arise in TPL code. Android code obfuscation can significantly impact the task of detecting TPLs, especially as obfuscation methods continue to iterate. Rule-based matching methods, which are commonly used in most approaches, often struggle to adapt to new obfuscation strategies. This paper proposes LibAttention, a feature-Ianguage-model-based Android TPL detection technique. LibAttention converts app binary code and TPL source code into Android intermediate representation Smali and extracts features that are less suscep-tible to obfuscation. These features are then fed into a language model to train an encoder from scratch. During the detection process, LibAttention encodes and compresses the app and TPL code representations and feeds them into downstream models for training and prediction. LibAttention is trained for third-party library detection tasks on downstream models, utilizing datasets compiled with various obfuscation modes and threshold adjustments to establish detection standards. Subsequently, de-tection and evaluation are conducted on the large-scale AndroZoo dataset. Its pretraining-fine-tuning model architecture eliminates the dependency on large amounts of labeled data samples. The experimental results indicate that the detection capabilities of LibAttention are more effective compared to the baseline results, significantly mitigating the impact of the Android R8 obfuscation tool on applications. Moreover, when compared to existing rule-based Android TPL detection techniques, LibAt-tention demonstrates significant improvements on the Android R8 obfuscation dataset, boasting over a 30% enhancement in the F1-score. Dahan Pan, Runhan Feng, Donghui Yu, Ya Fang, Yuanyuan Zhang 0002 |
SANER | 7 |
| 2024 | COMURICE: Closing Source Code Leakage in Cloud-Based Compiling via EnclaveabstractCloud-native-based software development is in trend now. The end-users use the cloud services to save the local computation resources for other intensive tasks. Compiling is one of the vital required services. The compiling-on-the-cloud service like CloudCompiling or CityCloud requires the user to upload their source code for online compiling. However, the latest online compiling service can neither protect the users' source code privacy nor prove the integrity of the whole compiling process. To fill this gap, we designed COMURICEto provide a user-transparent, secure compiling service employing the trusted execution environment (TEE) to enforce security by blocking all the attempts in code or data theft during the compiling procedure. COMURICEleverages the hardware security feature of TEE to prevent the compiling process from malicious access and modification while encrypting the communication channel to protect the integrity and privacy of the source code. The challenges in realizing COMURICElie in porting a fully functional compiler such as GCC or LLVM and designing an efficient compiling service to minimize the performance lag brought by confidential computing. According to the characteristics of the compiling process, it consists of several routines, pre-processing, compiling/obfuscation, and linking. The division of the routines requires multiple enclaves to run simultaneously. In the experiment, we compare COMURICE'Scompiling service with nativeLLVM, SCONELLVM, and GrapheneLLVM. From a performance perspective, COMURICEpays a fair cost for security. Generally, a project compiling with COMURICEsuffers 1–2 times more performance loss than nativeLLVM. Compared to other confidential compiling techniques like GrapheneLLVM or SCONELLVM, COMURICEis up to 20 times faster when compiling the same projects. Dahan Pan, Yingpeng Chen, Donghui Yu, Yuanyuan Zhang 0002 |
CSCloud | 6 |
| 2024 | DDGF: Dynamic Directed Greybox Fuzzing with Path ProfilingabstractCoverage-Guided Fuzzing (CGF) has become the most popular and effective method for vulnerability detection. It is usually designed as an automated “black-box” tool. Security auditors start it and then just wait for the results. However, after a period of testing, CGF struggles to find new coverage gradually, thus making it inefficient. It is difficult for users to explain reasons that prevent fuzzing from making further progress and to determine whether the existing coverage is sufficient. In addition, there is no way to interact and direct the fuzzing process. In this paper, we design the dynamic directed greybox fuzzing (DDGF) to facilitate collaboration between the user and fuzzer. By leveraging Ball-Larus path profiling algorithm, we propose two new techniques: dynamic introspection and dynamic direction. Dynamic introspection reveals the significant imbalance in the distribution of path frequency through encoding and decoding. Based on the insight from introspection, users can dynamically direct the fuzzer to focus testing on the selected paths in real time. We implement DDGF based on AFL++. Experiments on Magma show that DDGF is effective in helping the fuzzer to reproduce vulnerabilities faster, with up to 100x speedup and only 13% performance overhead. DDGF shows the great potential of human-in-the-loop for fuzzing. Haoran Fang, Kaikai Zhang, Donghui Yu, Yuanyuan Zhang 0002 |
ISSTA | 4 |
| 2024 | Enhancing Effective Bidirectional Isolation for Function Fusion in Serverless ArchitecturesabstractServerless computing has emerged as a popular paradigm in modern cloud environments, offering flexibility and scalability to tenants. A serverless function might handle sensitive tenant data. Employing Trusted Execution Environment (TEE) techniques to protect such a function from untrusted cloud service providers is attractive for tenant privacy. However, this introduces response latency, thereby impacting the performance of function execution. This paper introduces Fundue, a serverless architecture with bidirectional isolation between tenant and cloud provider that achieves light-weight isolation of functions and reduces cold start latency by fusing functions. Fundue enables multiple functions uploaded by the same tenant to share a single execution environment embedded into the enclave. Fundue allocates separate memory for each serverless function within the execution environment and establishes robust isolation between functions through bounds checking mechanisms. We extensively evaluate Fundue with diverse workloads and representative serverless functions. Our results demonstrate a significant reduction in response latency of serverless function execution, ranging from 17.8% to 88.7% compared to AccTEE, an open-source two-way sandbox serverless framework. Additionally, Fundue mitigates vulnerabilities in existing execution environments, such as stack-based buffer overflows. Yingpeng Chen, Donghui Yu, Yuanyuan Zhang 0002, Bert Lagaisse |
Middleware | 4 |
| 2024 | Accurate and Efficient Code Matching Across Android Application Versions Against ObfuscationabstractIn an effort to enhance the attractiveness of apps, developers consistently and frequently release updates to introduce new features and address known issues. Although frequent updates are beneficial for improving user experience, they also increase the workload for reverse engineers since existing analysis results may become obsolete after the release of a new version. Matching code across app versions can help reverse engineers quickly migrate existing analysis results to new versions, verifying whether their prior findings still hold in the new version. This allows them to focus more on the modified portions of the code, thus increasing reverse engineering efficiency. Nevertheless, existing techniques cannot effectively match the code of apps protected by obfuscation techniques, which are pervasively adopted in prac-tice. To address the challenges introduced by code obfuscation, this study presents MatchScope, a novel automated approach designed to match code at the method level across versions of Android app binaries. MatchScope effectively leveraging different levels of fine-grained code features, including class structures and method opcodes, etc., for similarity comparison, thus achieving high accuracy. To further enhance the matching efficiency, we design an index-aware matching algorithm, significantly reducing the scope and number of pairwise comparisons required compared with existing work. The critical insight of our algorithm lies in that the obfuscation tools usually rely on an incrementing index to generate obfuscated names for classes in a deterministic way. Our evaluation on 20 open-source and 60 real-world apps demonstrates the effectiveness of MatchScope. The precision and recall of MatchScope on the ground truth achieve 97.49 % and 92.34 %, respectively, which are 19.50 % and 30.74 % higher than the state-of-the-art tool. Runhan Feng, Yetong Zhou, Ziyang Yan, Yuanyuan Zhang 0002 |
SANER | 5 |
| 2024 | Enabling Fast and Privacy-Preserving Broadcast Authentication With Efficient Revocation for Inter-Vehicle ConnectionsabstractMany vehicular applications, especially safety-related ones, rely on spatial-temporal messages periodically broadcast by vehicles. In the absence of a secure authentication scheme, invalid spatial-temporal messages may be sent out by malicious vehicles. Meanwhile, malicious applications may also collect a lot of personal information from spatial-temporal messages. Since inter-vehicle connections are often deployed in high-moving traffic, any authentication must be implemented in real-time. To meet all these properties, we propose a Fast and Anonymous Spatial-Temporal Trust (FastTrust) scheme for inter-vehicle connections. In contrast to most authentication protocols which rely on fixed infrastructures, FastTrust is mostly designed on hash chains and an entropy-based commitment, and is able to secure periodic spatial-temporal messages. FastTrust also protects vehicles’ privacy by deploying a pseudonym-varying scheduling mechanism to satisfy the anonymity and unlinkability requirements. Finally, in order to efficiently isolate malicious vehicles, a lightweight certificate management scheme is proposed for the limited bandwidth of vehicular networks. We provide analytical evaluations to show that our FastTrust achieves the security and privacy properties. Extensive validations are done to show that FastTrust can authenticate dozens of times faster than the existing signature algorithms, and isolate malicious vehicles at a low cost in terms of communication and computational resources. Chen Lyu 0002, Amit Pande, Yuanyuan Zhang 0002, Dawu Gu, Prasant Mohapatra |
IEEE Trans. Mob. Comput. | 3 |
| 2023 | SEnFuzzer: Detecting SGX Memory Corruption via Information Feedback and Tailored Interface AnalysisabstractIntel SGX provides protected memory called enclave to secure the private user data against corrupted or malicious OS environment. However, several researches have shown that the SGX applications suffer from memory corruption vulnerabilities, thus leading to critical information leakage. Detecting memory corruption vulnerability in SGX applications can be cumbersome. Existing works either use symbolic execution or formal methods to analyze the enclave library, which is known to be inefficient and errors prone. Fuzzing, an effective and efficient vulnerability detection method is rarely used in SGX and has limitations. Donghui Yu, Haoran Fang, Ya Fang, Yuanyuan Zhang 0002 |
RAID | 5 |
| 2022 | VirTEE: a full backward-compatible TEE with native live migration and secure I/OabstractModern security architectures provide Trusted Execution Environments (TEEs) to protect critical data and applications against malicious privileged software in so-called enclaves. However, the seamless integration of existing TEEs into the cloud is hindered, as they require substantial adaptation of the software executing inside an enclave as well as the cloud management software to handle enclaved workloads. We tackle these challenges by presenting VirTEE, the first TEE architecture that allows strongly isolated execution of unmodified virtual machines (VMs) in enclaves, as well as secure live migration of VM enclaves between VirTEE-enabled servers. Combined with its secure I/O capabilities, VirTEE enables the integration of enclaved computing in today's complex cloud infrastructure. We thoroughly evaluate our RISC-V-based prototype, and show its effectiveness and efficiency. Pouya Mahmoody, Ferdinand Brasser, Patrick Jauernig, Ahmad-Reza Sadeghi, Donghui Yu, Dahan Pan, Yuanyuan Zhang 0002 |
DAC | 8 |
| 2022 | Automated Detection of Password Leakage from Public GitHub RepositoriesabstractThe prosperity of the GitHub community has raised new concerns about data security in public repositories. Practitioners who manage authentication secrets such as textual passwords and API keys in the source code may accidentally leave these texts in the public repositories, resulting in secret leakage. If such leakage in the source code can be automatically detected in time, potential damage would be avoided. With existing approaches focusing on detecting secrets with distinctive formats (e.g., API keys, cryptographic keys in PEM format), textual passwords, which are ubiquitously used for authentication, fall through the crack. Given that textual passwords could be virtually any strings, a naive detection scheme based on regular expression performs poorly. This paper presents PassFinder, an automated approach to effectively detecting password leakage from public repositories that involve various programming languages on a large scale. PassFinder utilizes deep neural networks to unveil the intrinsic characteristics of textual passwords and understand the semantics of the code snippets that use textual passwords for authentication, i.e., the contextual information of the passwords in the source code. Using this new technique, we performed the first large-scale and longitudinal analysis of password leakage on GitHub. We inspected newly uploaded public code files on GitHub for 75 days and found that password leakage is pervasive, affecting over sixty thousand repositories. Our work contributes to a better understanding of password leakage on GitHub, and we believe our technique could promote the security of the open-source ecosystem. Runhan Feng, Ziyang Yan, Shiyan Peng, Yuanyuan Zhang 0002 |
ICSE | 4 |
| 2022 | An empirical study of security issues in SSO server-side implementations
Hui Wang 0037, Dawu Gu, Yuanyuan Zhang 0002, Yikun Hu 0003 |
Sci. China Inf. Sci. | 3 |
| 2021 | MagikCube: Securing Cross-Domain Publish/Subscribe Systems with EnclaveabstractThe publish/subscribe(pub/sub) is an asynchronous messaging service or content distribution framework. For the idempotency it provides, pub/sub diagram is an efficient solution for large-scale content distributing systems, thus it is widely used in stock exchange systems or e-Health content sharing systems. Some wide-area applications require cross-domain pub/sub service, making it a natural choice to deploy on the public cloud. However, it would bring about security and privacy issues. Recent research proposes security enhancements to prevent thefts, such as searchable data encryption and attribute-based encryption, which allow the matching process to perform encrypted matching without learning the content of the publications and subscriptions. Besides the considerable performance loss, they could not resist the collusion attacks. If the malicious brokers collude with a malicious publisher or subscriber in a cross-domain environment, they can still infer the subscriptions of benign subscribers. We propose the MagikCube framework that provides confidentiality and integrity of the contents and also protects the privacy of the publishers and subscribers in cross-domain scenarios. Moreover, MagikCube can also resist the collusion attacks from malicious brokers in a cross-domain environment. It achieves these security goals by dynamically selecting and placing the sensitive data and some necessary components in enclaves protected by trusted hardware such as Intel SGX. Our experiment result shows that, compared with the baseline model, MagikCube does not introduce much overhead loss when providing better security for all the participants in the pub/sub system. Shuran Wang, Dahan Pan, Runhan Feng, Yuanyuan Zhang 0002 |
TrustCom | 4 |
| 2021 | A Semantics-Based Hybrid Approach on Binary Code Similarity ComparisonabstractBinary code similarity comparison is a methodology for identifying similar or identical code fragments in binary programs. It is indispensable in fields of software engineering and security, which has many important applications (e.g., plagiarism detection, bug detection). With the widespread of smart and Internet of Things (IoT) devices, an increasing number of programs are ported to multiple architectures (e.g., ARM, MIPS). It becomes necessary to detect similar binary code across architectures as well. The main challenge of this topic lies in the semantics-equivalent code transformation resulting from different compilation settings, code obfuscation, and varied instruction set architectures. Another challenge is the trade-off between comparison accuracy and coverage. Unfortunately, existing methods still heavily rely on semantics-less code features which are susceptible to the code transformation. Additionally, they perform the comparison merely either in a static or in a dynamic manner, which cannot achieve high accuracy and coverage simultaneously. In this paper, we propose a semantics-based hybrid method to compare binary function similarity. We execute the reference function with test cases, then emulate the execution of every target function with the runtime information migrated from the reference function. Semantic signatures are extracted during the execution as well as the emulation. Lastly, similarity scores are calculated from the signatures to measure the likeness of functions. We have implemented the method in a prototype system designated as BinMatch which performs binary code similarity comparison across architectures of x86, ARM and MIPS on the Linux platform. We evaluate BinMatch with nine real-word projects compiled with different compilation settings, on variant architectures, and with commonly-used obfuscation methods, totally performing over 100 million pairs of function comparison. The experimental results show that BinMatch is resilient to the semantics-equivalent code transformation. Besides, it not only covers all target functions for similarity comparison, but also improves the accuracy comparing to the state-of-the-art solutions. Yikun Hu 0003, Hui Wang 0037, Yuanyuan Zhang 0002, Bodong Li, Dawu Gu |
IEEE Trans. Software Eng. | 3 |
| 2019 | SymSem: Symbolic Execution with Time Stamps for Deobfuscation
Huayi Li, Yuanyuan Zhang 0002, Dawu Gu |
Inscrypt | 2 |
| 2019 | NLP-EYE: Detecting Memory Corruptions via Semantic-Aware Memory Operation Function Identification
Siqi Ma 0001, Yuanyuan Zhang 0002, Juanru Li, Zheyu Ma, Long Mai, Tiancheng Chen, Dawu Gu |
RAID | 3 |
| 2019 | APPCOMMUNE: Automated Third-Party Libraries De-duplicating and Updating for Android AppsabstractThe increasing usage of third-party libraries in Android apps is double-edged, boosting the development but introducing extra code base and potential vulnerabilities. Unlike desktop operating systems, Android does not support the sharing of third-party libraries between different apps. Thus both the de-duplicating and the updating of those libraries are difficult to be managed in a unified way. In this paper, we propose a third-party library sharing method to address the issues of code bloating and obsolete code updating. Our approach separates all integrated third-party libraries from app code and makes them still accessible through a dynamic loading mechanism. The separated libraries are managed centrally and can be shared by different apps. This not only saves the storage but also guarantees a prompt update of outdated libraries for every app. We implement APPCOMMUNE, a novel app installation and execution infrastructure to support the proposed third-party library sharing without modifying the commodity Android system. Our experiments with 212 popular third-party libraries and 502 real-world Android apps demonstrate the feasibility and efficiency: all apps work stably with our library sharing model, and 11.1% storage and bandwidth are saved for app downloading and installation. In addition, APPCOMMUNE updates 86.4% of the managed third-party libraries (with 44.6% to the latest versions). Bodong Li, Yuanyuan Zhang 0002, Juanru Li, Runhan Feng, Dawu Gu |
SANER | 2 |
| 2019 | Security analysis of third-party in-app payment in mobile applications
Juanru Li, Yuanyuan Zhang 0002, Dawu Gu |
J. Inf. Secur. Appl. | 3 |
| 2018 | An Empirical Study of SDK Credential Misuse in iOS AppsabstractDuring the development of web-based mobile apps, third-party SDKs (Software Development Kit) are frequently used to facilitate the integration of certain functionality such as push notification and mobile payment. Unfortunately, security issues are often considered as a second-tier problem and app developers are prone to implement apps with SDK misuses. Among those typical SDK misuses, the misuse of credentials is the one that introduces serious security threats. A credential is a set of unique information (e.g., APP ID, App Token, etc) allocated to a specific developer to help app authenticate the identity. However, if not properly used, the credential can be easily obtained by attackers and leads to not only the leak of confidential information of mobile developers but also direct threats to the privacy of end users. To investigate the SDK credential misuse issue on iOS platform, in this paper we conduct an empirical study against 100 popular iOS apps using two popular mobile SDKs (each SDK are widely used by at least 40 million users). We implemented iCredFinder, an automated analysis tool to search credential misuses in those apps and our experiment demonstrates 68 apps contain at least one misuse case. Our study demonstrates the severity of credential misuse on iOS platform: even for those well-developed SDKs and apps, credentials are not well protected and can be easily discovered. We expect that our study could help developers fix those flaws and promote better implementations. Haohuang Wen, Juanru Li, Yuanyuan Zhang 0002, Dawu Gu |
APSEC | 3 |
| 2018 | K-Hunt: Pinpointing Insecure Cryptographic Keys from Execution TracesabstractThe only secrets in modern cryptography (crypto for short) are the crypto keys. Understanding how crypto keys are used in a program and discovering insecure keys is paramount for crypto security. This paper presents K-Hunt, a system for identifying insecure keys in binary executables. K-Hunt leverages the properties of crypto operations for identifying the memory buffers where crypto keys are stored. And, it tracks their origin and propagation to identify insecure keys such as deterministically generated keys, insecurely negotiated keys, and recoverable keys. K-Hunt does not use signatures to identify crypto operations, and thus can be used to identify insecure keys in unknown crypto algorithms and proprietary crypto implementations. We have implemented K-Hunt and evaluated it with 10 cryptographic libraries and 15 applications that contain crypto operations. Our evaluation results demonstrate that K-Hunt locates the keys in symmetric ciphers, asymmetric ciphers, stream ciphers, and digital signatures, regardless if those algorithms are standard or proprietary. More importantly, K-Hunt discovers insecure keys in 22 out of 25 evaluated programs including well-developed crypto libraries such as Libsodium, Nettle, TomCrypt, and WolfSSL. Juanru Li, Zhiqiang Lin 0001, Juan Caballero, Yuanyuan Zhang 0002, Dawu Gu |
CCS | 4 |
| 2018 | BinMatch: A Semantics-Based Hybrid Approach on Binary Code Clone AnalysisabstractBinary code clone analysis is an important technique which has a wide range of applications in software engineering (e.g., plagiarism detection, bug detection). The main challenge of the topic lies in the semantics-equivalent code transformation (e.g., optimization, obfuscation) which would alter representations of binary code tremendously. Another challenge is the trade-off between detection accuracy and coverage. Unfortunately, existing techniques still rely on semantics-less code features which are susceptible to the code transformation. Besides, they adopt merely either a static or a dynamic approach to detect binary code clones, which cannot achieve high accuracy and coverage simultaneously. In this paper, we propose a semantics-based hybrid approach to detect binary clone functions. We execute a template binary function with its test cases, and emulate the execution of every target function for clone comparison with the runtime information migrated from that template function. The semantic signatures are extracted during the execution of the template function and emulation of the target function. Lastly, a similarity score is calculated from their signatures to measure their likeness. We implement the approach in a prototype system designated as BinMatch which analyzes IA-32 binary code on the Linux platform. We evaluate BinMatch with eight real-world projects compiled with different compilation configurations and commonly-used obfuscation methods, totally performing over 100 million pairs of function comparison. The experimental results show that BinMatch is robust to the semantics-equivalent code transformation. Besides, it not only covers all target functions for clone analysis, but also improves the detection accuracy comparing to the state-of-the-art solutions. Yikun Hu 0003, Yuanyuan Zhang 0002, Juanru Li, Hui Wang 0037, Bodong Li, Dawu Gu |
ICSME | 2 |
| 2018 | Burn After Reading: Expunging Execution Footprints of Android Apps
Junliang Shu, Juanru Li, Yuanyuan Zhang 0002, Dawu Gu |
NSS | 3 |
| 2018 | FastTrust: Fast and Anonymous Spatial-Temporal Trust for Connected Cars on ExpresswaysabstractConnected cars have received massive attention in Intelligent Transportation System. Many potential services, especially safety-related ones, rely on spatial-temporal messages periodically broadcast by cars. Without a secure authentication algorithm, malicious cars may send out invalid spatial-temporal messages and then deny creating them. Meanwhile, a lot of private information may be disclosed from these spatial-temporal messages. Since cars move on expressways at high speed, any authentication must be performed in real-time to prevent crashes. In this paper, we propose a Fast and Anonymous Spatial-Temporal Trust (FastTrust) mechanism to ensure these properties. In contrast to most authentication protocols which rely on fixed infrastructures, FastTrust is distributed and mostly designed on symmetric-key cryptography and an entropy-based commitment, and is able to fast authenticate spatial-temporal messages. FastTrust also ensures the anonymity and unlinkability of spatial-temporal messages by developing a pseudonym-varying scheduling scheme on cars. We provide both analytical and simulation evaluations to show that FastTrust achieves the security and privacy properties. FastTrust is low-cost in terms of communication and computational resources, authenticating 20 times faster than existing Elliptic Curve Digital Signature Algorithm. Chen Lyu 0002, Amit Pande, Yuanyuan Zhang 0002, Dawu Gu, Prasant Mohapatra |
SECON | 3 |
| 2018 | Passwords in the Air: Harvesting Wi-Fi Credentials from SmartCfg ProvisioningabstractSmart devices without an interactive UI (e.g., a smart bulb) typically rely on specific provisioning schemes to connect to wireless networks. Among all the provisioning schemes, SmartCfg is a popular technology to configure the connection between smart devices and wireless routers. Although the SmartCfg technology facilitates the Wi-Fi configuration, existing solutions seldom take into serious consideration the protection of credentials and therefore introduce security threats against Wi-Fi credentials. Changyu Li, Quanpu Cai, Juanru Li, Yuanyuan Zhang 0002, Dawu Gu, Yu Yu 0001 |
WISEC | 5 |
| 2018 | AppSpear: Automating the hidden-code extraction and reassembling of packed android malware
Bodong Li, Yuanyuan Zhang 0002, Juanru Li, Dawu Gu |
J. Syst. Softw. | 2 |
| 2017 | Oh-Pwn-VPN! Security Analysis of OpenVPN-Based Android Apps
Juanru Li, Yuanyuan Zhang 0002, Hui Wang 0037, Dawu Gu |
CANS | 3 |
| 2017 | NativeSpeaker: Identifying Crypto Misuses in Android Native Code Libraries
Juanru Li, Yuanyuan Zhang 0002, Hui Wang 0037, Yikun Hu 0003, Bodong Li, Dawu Gu |
Inscrypt | 3 |
| 2017 | Embroidery: Patching Vulnerable Binary Code of Fragmentized Android DevicesabstractThe rapid-iteration, web-style update cycle of Android helps fix revealed security vulnerabilities for its latest version. However, such security enhancements are usually only available for few Android devices released by certain manufacturers (e.g., Google's official Nexus devices). More manufactures choose to stop providing system update service for their obsolete models, remaining millions of vulnerable Android devices in use. In this situation, a feasible solution is to leverage existing source code patches to fix outdated vulnerable devices. To implement this, we introduce Embroidery, a binary rewriting based vulnerability patching system for obsolete Android devices without requiring the manufacturer's source code against Android fragmentation. Embroidery patches the known critical framework and kernel vulnerabilities in Android using both static and dynamic binary rewriting techniques. It transplants official patches (CVE source code patches) of known vulnerabilities to different devices by adopting heuristic matching strategies to deal with the code diversity introduced by Android fragmentation, and fulfills a complex dynamic memory modification to implement kernel vulnerabilities patching. We employ Embroidery to patch sophisticated Android kernel and framework vulnerabilities for various manufactures' obsolete devices ranging from Android 4.2 to 5.1. The result shows the patched devices are able to defend against known exploits and the normal functions are not affected. Xuewen Zhang, Yuanyuan Zhang 0002, Juanru Li, Yikun Hu 0003, Huayi Li, Dawu Gu |
ICSME | 2 |
| 2017 | Nightingale: Translating Embedded VM Code in x86 Binary Executables
Haijiang Xie, Yuanyuan Zhang 0002, Juanru Li, Dawu Gu |
ISC | 2 |
| 2017 | Binary code clone detection across architectures and compiling configurationsabstractBinary code clone (or similarity) detection is a fundamental technique for many important applications, such as plagiarism detection, malware analysis, software vulnerability assessment and program comprehension. With the prevailing of smart and IoT (Internet of Things) devices, more and more programs are ported from traditional desktop platform (e.g., IA-32) to ARM and MIPS architectures. It is imperative to detect cloned binary code across architectures. However, because of incomparable instruction sets of different architectures as well as alternative compiling configurations of binaries, it is difficult to conduct a binary code clone detection with traditional syntax-or structure-based methods. To address, we propose a semantics-based approach to fulfill the target. We recognize arguments and indirect jump targets of each binary function, and emulate executions of those functions to extract semantic signatures helping measure the similarity of functions. The approach has been implemented in a prototype system names CACompare to detect cloned binary functions across architectures and compiling configurations. It supports comparisons between mainstream architectures (IA-32, ARM and MIPS) and is able to analysis binaries on Linux platform. The experimental results show that CACompare not only is effective in dealing with binaries of different architectures and variant compiling configurations, but also improves the accuracy of binary code clone detection comparing to state-of-the-art solutions. Yikun Hu 0003, Yuanyuan Zhang 0002, Juanru Li, Dawu Gu |
ICPC | 2 |
| 2017 | Show Me the Money! Finding Flawed Implementations of Third-party In-app Payment in Android Apps
Yuanyuan Zhang 0002, Juanru Li, Yueheng Zhang, Dawu Gu |
NDSS | 2 |
| 2017 | Why Data Deletion Fails? A Study on Deletion Flaws and Data Remanence in Android SystemsabstractSmart mobile devices are becoming the main vessel of personal privacy information. While they carry valuable information, data erasure is somehow much more vulnerable than was predicted. The security mechanisms provided by the Android system are not flexible enough to thoroughly delete sensitive data. In addition to the weakness among several provided data-erasing and file-deleting mechanisms, we also target the Android OS design flaws in data erasure, and unveil that the design of the Android OS contradicts some secure data-erasure demands. We present the data-erasure flaws in three typical scenarios on mainstream Android devices, such as the data clearing flaw , application uninstallation flaw , and factory reset flaw . Some of these flaws are inherited data-deleting security issues from the Linux kernel, and some are new vulnerabilities in the Android system. Those scenarios reveal the data leak points in Android systems. Moreover, we reveal that the data remanence on the disk is rarely affected by the user’s daily operation, such as file deletion and app installation and uninstallation, by a real-world data deletion latency experiment. After one volunteer used the Android phone for 2 months, the data remanence amount was still considerable. Then, we proposed DataRaider for file recovering from disk fragments. It adopts a file-carving technique and is implemented as an automated sensitive information recovering framework. DataRaider is able to extract private data in a raw disk image without any file system information, and the recovery rate is considerably high in the four test Android phones. We propose some mitigation for data remanence issues, and give the users some suggestions on data protection in Android systems. Junliang Shu, Yuanyuan Zhang 0002, Juanru Li, Bodong Li, Dawu Gu |
ACM Trans. Embed. Comput. Syst. | 2 |
| 2016 | The Achilles heel of OAuth: a multi-platform study of OAuth-based authentication
Hui Wang 0037, Yuanyuan Zhang 0002, Juanru Li, Dawu Gu |
ACSAC | 2 |
| 2016 | Open Sesame! Web Authentication Cracking via Mobile App Analysis
Yuanyuan Zhang 0002, Juanru Li, Hui Wang 0037, Dawu Gu |
APWeb (2) | 2 |
| 2016 | Security Testing of Software on Embedded Devices Using x86 Platform
Yesheng Zhi, Yuanyuan Zhang 0002, Juanru Li, Dawu Gu |
CollaborateCom | 2 |
| 2016 | Security Analysis of Vendor Customized Code in Firmware of Embedded Device
Yuanyuan Zhang 0002, Juanru Li, Junliang Shu, Dawu Gu |
SecureComm | 2 |
| 2016 | Cross-Architecture Binary Semantics Understanding via Similar Code ComparisonabstractWith the prevailing of smart devices (e.g., smart phone, routers, cameras), more and more programs are ported from traditional desktop platform to embedded hardware with ARM or MIPS architecture. While the compiled binary code differs significantly due to the variety of CPU architectures, these ported programs share the same code base of the desktop version. Thus it is feasible to utilize the program of commodity computer to help understand those cross-compiled binaries and locate functions with similar semantics. However, as instruction sets of different architectures are generally incomparable, it is difficult to conduct a static cross-architecture binary code similarity comparison. To address, we propose a semantic-based approach to fulfill this target. We dynamically extract the signature, which is composed of conditional operations behaviors as well as system call information, from binaries on different platforms with the same manner. Then the similarity of signatures is measured to help identify functions in ported programs. We have implemented the approach in MOCKINGBIRD, an automated analysis tool to compare code similarity between binaries across architectures. MOCKINGBIRD supports mainstream architectures and is able to analyze ELF executables on Linux platform. We have evaluated MOCKINGBIRD with a set of popular programs with cross-compiled versions. The results show our approach is not only effective for dealing with this new issue of cross-architecture binary code comparison, but also improves the accuracy of similarity based function identification due to the utilization of semantic information. Yikun Hu 0003, Yuanyuan Zhang 0002, Juanru Li, Dawu Gu |
SANER | 2 |
| 2016 | Privacy-preserving data sharing scheme over cloud for social applications
Chen Lyu 0002, Shifeng Sun 0001, Yuanyuan Zhang 0002, Amit Pande, Haining Lu, Dawu Gu |
J. Netw. Comput. Appl. | 3 |
| 2015 | Vulnerability Assessment of OAuth Implementations in Android ApplicationsabstractEnforcing security on various implementations of OAuth in Android apps should consider a wide range of issues comprehensively. OAuth implementations in Android apps differ from the recommended specification due to the provider and platform factors, and the varied implementations often become vulnerable. Current vulnerability assessments on these OAuth implementations are ad hoc and lack a systematic manner. As a result, insecure OAuth implementations are still widely used and the situation is far from optimistic in many mobile app ecosystems. Hui Wang 0037, Yuanyuan Zhang 0002, Juanru Li, Bodong Li, Dawu Gu |
ACSAC | 2 |
| 2015 | From Collision To Exploitation: Unleashing Use-After-Free Vulnerabilities in Linux KernelabstractSince vulnerabilities in Linux kernel are on the increase, attackers have turned their interests into related exploitation techniques. However, compared with numerous researches on exploiting use-after-free vulnerabilities in the user applications, few efforts studied how to exploit use-after-free vulnerabilities in Linux kernel due to the difficulties that mainly come from the uncertainty of the kernel memory layout. Without specific information leakage, attackers could only conduct a blind memory overwriting strategy trying to corrupt the critical part of the kernel, for which the success rate is negligible. Juanru Li, Junliang Shu, Tianyi Xie, Yuanyuan Zhang 0002, Dawu Gu |
CCS | 6 |
| 2015 | SSG: Sensor Security Guard for Android Smartphones
Bodong Li, Yuanyuan Zhang 0002, Chen Lyu 0002, Juanru Li, Dawu Gu |
CollaborateCom | 2 |
| 2015 | AppSpear: Bytecode Decrypting and DEX Reassembling for Packed Android Malware
Yuanyuan Zhang 0002, Juanru Li, Junliang Shu, Bodong Li, Dawu Gu |
RAID | 2 |
| 2015 | SGOR: Secure and scalable geographic opportunistic routing with received signal strength in WSNs
Chen Lyu 0002, Dawu Gu, Shifeng Sun 0001, Yuanyuan Zhang 0002, Amit Pande |
Comput. Commun. | 5 |
| 2014 | APKLancet: tumor payload diagnosis and purification for android applicationsabstractA huge number of Android applications are bundled with relatively independent modules either during the development or by intentionally repackaging. Undesirable behaviors such as stealthily acquiring and distributing user's private information are frequently discovered in some bundled third-party modules, i.e., advertising libraries or malicious code (we call the module tumor payload in this work), which sabotage the integrity of the original app and lie as a threat to both the security of mobile system and the user's privacy. Juanru Li, Yuanyuan Zhang 0002, Junliang Shu, Dawu Gu |
AsiaCCS | 3 |
| 2014 | Android App Protection via Interpretation ObfuscationabstractTo protect Android app from malicious reproduction or tampering, code obfuscation techniques are introduced to increase the difficulty of reverse engineering and program understanding. Current obfuscation schemes focus more on the protection of the meta information over the executable code which contains valuable or patented algorithms. Therefore, a more sophisticated obfuscator is needed to improve the protection on the executable code. In this paper we propose SMOG, a comprehensive executable code obfuscation system to protect Android app. SMOG is composed of two parts, an obfuscation engine and an execution environment. The obfuscation engine is at software vendor's side to conduct the obfuscation on the app's executable code, and then release the obfuscated app to the end-user along with an execution token. The execution environment is setup by integrating the received execution token, which endows the Android Dalvik VM the capability to execute the obfuscated app. SMOG is an easily deployed system which proves fine-grained level protection. The obfuscated app generated by SMOG could resist static and dynamic reverse engineering. Moreover, the benchmark result shows SMOG only costs about 5% more performance in dispatching the incoming bytecode to the proper interpreter. Junliang Shu, Juanru Li, Yuanyuan Zhang 0002, Dawu Gu |
DASC | 3 |
| 2014 | TagDroid: Hybrid SSL Certificate Verification in Android
Yuanyuan Zhang 0002, Hui Wang 0037, Juanru Li, Dawu Gu |
ICICS | 2 |
| 2014 | iCryptoTracer: Dynamic Analysis on Misuse of Cryptography Functions in iOS Applications
Yuanyuan Zhang 0002, Juanru Li, Dawu Gu |
NSS | 2 |
| 2013 | Automatic Detection and Analysis of Encrypted Messages in Malware
Ruoxu Zhao, Dawu Gu, Juanru Li, Yuanyuan Zhang 0002 |
Inscrypt | 4 |
| 2011 | Flooding attacks against network coding and countermeasuresabstractNetwork coding has attracted the attention of many researchers in security and cryptography. While most of the works have been dedicated to the protection of messages carrying information, nothing has been done to protect the acknowledgment messages needed in network coding. These flooding attacks are critical in resource constraint networks such as wireless sensor networks. An adversary can easily create congestion in the network and exhaust all the resources available. The degradation of the QoS (delay, energy) goes beyond the capabilities of cryptographic solutions. We investigate the security capabilities of multipath acknowledgment. Yuanyuan Zhang 0002, Wassim Znaidi, Cédric Lauradoux, Marine Minier |
NSS | 1 |
| 2009 | Design and Implementation of Self-securing DiskabstractSelf-securing storage devices prevents intruders from undetectably tampering with or permanently deleting stored data. To accomplish this, we design an efficient self-securing disk architecture, which is based on traditional self-securing storage prototype S4: 1) On the confidentiality protection side, authenticated encryption mode GCM is adapted to process disk block in parallel ,and authentication latency is overlapped with disk access latency so that our scheme is more efficient and secure than Windows BitLocker. 2) On the integrity protection side, GHASH proposed in GCM is used to generate MAC which is more efficient than SHA-1, MD5. Moreover, ldquoMinimum Integrity Verification Treerdquo is put forward to decrease performance loss at a maximum. 3) On the access control protection side, we propose a cryptographically featured capability based access control model, which is based on existing OSD access control model. We use hybrid hard drive as an instance to build a self-securing disk prototype which is implemented by simulation. The encryption/authentication overheads are significantly reduced due to buffer techniques and combined GCM/Flash scheme. According to the simulation results, the performance overhead is less than 18%, which is efficient and practical. Mengqi Zeng, Dawu Gu, Fangyong Hou, Yuanyuan Zhang 0002 |
NAS | 4 |
| 2008 | Reliable Key Establishment Scheme Exploiting Unidirectional Links in Wireless Sensor NetworksabstractWireless sensor networks are designed for outdoor environment surveillance and require benign coverage, steady working status and long lifetime, moreover, they require efficient security services for rigorous applications. Most security schemes are designed to work efficiently only when bidirectional links exist. So do most key establishment protocols for WSNs. Traditional key establishment schemes delete all the unidirectional links from the network. Hence, the sensors covered only by unidirectional links are excluded from the collaborating network, even if they are stable and energetic. These schemes shorten the lifetime and decrease the connectivity of the whole network. To improve the network connectivity and increase the number of available sensors in the network, a security mechanism is proposed for wireless sensor networks exploiting unidirectional links. By searching local connection components in a small area, this mechanism helps negotiate shared secrets among nodes that may covered by unidirectional links. It obtains identity authentication and perfect resilience against node compromise.The simulation reveals that, our scheme can greatly increase the proportion of available sensor nodes and network connectivity, which will efficiently prolong the network lifetime. Yuanyuan Zhang 0002, Dawu Gu, Bart Preneel |
EUC (1) | 1 |
| 2008 | Efficient Authenticated Encryption for Hybrid Hard Drives Based on GCMabstractHybrid hard drives (HHD) are coming up with potential high viability in mobile computing. It's quite necessary to put forward an efficient secure scheme for hybrid hard drives. NAND Flash of HHD is made full use as a container and a buffer for metadata. We propose an efficient combined scheme based on Galois/Counter Mode (GCM) to protect hard disk data by authenticated encryption, and build a secure architecture for HHD. Our results show that we not only protect the disk data by authenticated encryption, but also gain high performance. According to the simulation results, for the best of our methods, the performance overhead is less than 18%, which is efficient and acceptable practically. Mengqi Zeng, Fangyong Hou, Dawu Gu, Yuanyuan Zhang 0002, NingNan Song |
HPCC | 4 |
| 2008 | Exploiting unidirectional links for key establishment protocols in heterogeneous sensor networks
Yuanyuan Zhang 0002, Dawu Gu, Juanru Li |
Comput. Commun. | 1 |