Runhan Feng

dblp:237/8451 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
6since 2021 · last 2026
0009-0008-7824-6322ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 2 first-author · 3 since 2021Security and privacy · 3 · 2 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Poster: Automated Extraction of Protocol State Machines from 3GPP Specifications with Domain-Informed Prompts and LLM Ensembles
Runhan Feng, Hongbo Tang, Jie Yang 0085, Hang Qiu 0003
SECON2
2025 Pay Your Attention on Lib! Android Third-Party Library Detection via Feature Language Model
abstract
The widespread use of third-party libraries (TPL) has brought many conveniences to Android application devel-opment, fostering the development of the Android application ecosystem. Detecting the presence of TPLs in Android applications is crucial in the Android era, as it enables the rapid identification of their usage when security vulnerabilities arise in TPL code. Android code obfuscation can significantly impact the task of detecting TPLs, especially as obfuscation methods continue to iterate. Rule-based matching methods, which are commonly used in most approaches, often struggle to adapt to new obfuscation strategies. This paper proposes LibAttention, a feature-Ianguage-model-based Android TPL detection technique. LibAttention converts app binary code and TPL source code into Android intermediate representation Smali and extracts features that are less suscep-tible to obfuscation. These features are then fed into a language model to train an encoder from scratch. During the detection process, LibAttention encodes and compresses the app and TPL code representations and feeds them into downstream models for training and prediction. LibAttention is trained for third-party library detection tasks on downstream models, utilizing datasets compiled with various obfuscation modes and threshold adjustments to establish detection standards. Subsequently, de-tection and evaluation are conducted on the large-scale AndroZoo dataset. Its pretraining-fine-tuning model architecture eliminates the dependency on large amounts of labeled data samples. The experimental results indicate that the detection capabilities of LibAttention are more effective compared to the baseline results, significantly mitigating the impact of the Android R8 obfuscation tool on applications. Moreover, when compared to existing rule-based Android TPL detection techniques, LibAt-tention demonstrates significant improvements on the Android R8 obfuscation dataset, boasting over a 30% enhancement in the F1-score.
Dahan Pan, Runhan Feng, Donghui Yu, Ya Fang, Yuanyuan Zhang 0002
SANER3
2025 5GC-PDA:A Novel Proactive Defense Architecture for Enhancing 5G Core Network Security
abstract
The arrival of 5G era brings great convenience and unprecedented opportunities to human society under the new technical features of ultra-high speed, ultra-low latency, and mega-connectivity. As the management hub and "brain" of the 5G network architecture, the security of the core network is paramount. However, its evolution towards cloudification has led to frequent cybersecurity incidents; an attack on the 5G core network could trigger severe consequences. To address this, this paper first systematically analyzes potential vulnerabilities and attack paths within the 5G core network from an attacker’s perspective. Subsequently, an endogenous proactive defense architecture, grounded in the principles of dynamism, heterogeneity, and redundancy, is proposed. The working mechanism of this architecture is elaborated in detail, alongside a theoretical analysis of its security properties. To validate the efficacy of the proposed architecture, defensive performance was first compared across different schemes via simulation. The results demonstrate that our architecture achieves optimal defensive performance while significantly increasing the attacker’s cost. Furthermore, the proposed architecture was implemented on the Unified Data Management (UDM) network function within the open-source free5gc platform, and its enhanced protective capability was assessed through real-world attack testing. Experimental results indicate that the architecture effectively elevates the overall security posture of the 5G core network, introducing only marginal performance overhead.
Xingxing Liao, Jie Yang 0085, Runhan Feng
TrustCom5
2024 Accurate and Efficient Code Matching Across Android Application Versions Against Obfuscation
abstract
In an effort to enhance the attractiveness of apps, developers consistently and frequently release updates to introduce new features and address known issues. Although frequent updates are beneficial for improving user experience, they also increase the workload for reverse engineers since existing analysis results may become obsolete after the release of a new version. Matching code across app versions can help reverse engineers quickly migrate existing analysis results to new versions, verifying whether their prior findings still hold in the new version. This allows them to focus more on the modified portions of the code, thus increasing reverse engineering efficiency. Nevertheless, existing techniques cannot effectively match the code of apps protected by obfuscation techniques, which are pervasively adopted in prac-tice. To address the challenges introduced by code obfuscation, this study presents MatchScope, a novel automated approach designed to match code at the method level across versions of Android app binaries. MatchScope effectively leveraging different levels of fine-grained code features, including class structures and method opcodes, etc., for similarity comparison, thus achieving high accuracy. To further enhance the matching efficiency, we design an index-aware matching algorithm, significantly reducing the scope and number of pairwise comparisons required compared with existing work. The critical insight of our algorithm lies in that the obfuscation tools usually rely on an incrementing index to generate obfuscated names for classes in a deterministic way. Our evaluation on 20 open-source and 60 real-world apps demonstrates the effectiveness of MatchScope. The precision and recall of MatchScope on the ground truth achieve 97.49 % and 92.34 %, respectively, which are 19.50 % and 30.74 % higher than the state-of-the-art tool.
Runhan Feng, Yetong Zhou, Ziyang Yan, Yuanyuan Zhang 0002
SANER1
2022 Automated Detection of Password Leakage from Public GitHub Repositories
abstract
The prosperity of the GitHub community has raised new concerns about data security in public repositories. Practitioners who manage authentication secrets such as textual passwords and API keys in the source code may accidentally leave these texts in the public repositories, resulting in secret leakage. If such leakage in the source code can be automatically detected in time, potential damage would be avoided. With existing approaches focusing on detecting secrets with distinctive formats (e.g., API keys, cryptographic keys in PEM format), textual passwords, which are ubiquitously used for authentication, fall through the crack. Given that textual passwords could be virtually any strings, a naive detection scheme based on regular expression performs poorly. This paper presents PassFinder, an automated approach to effectively detecting password leakage from public repositories that involve various programming languages on a large scale. PassFinder utilizes deep neural networks to unveil the intrinsic characteristics of textual passwords and understand the semantics of the code snippets that use textual passwords for authentication, i.e., the contextual information of the passwords in the source code. Using this new technique, we performed the first large-scale and longitudinal analysis of password leakage on GitHub. We inspected newly uploaded public code files on GitHub for 75 days and found that password leakage is pervasive, affecting over sixty thousand repositories. Our work contributes to a better understanding of password leakage on GitHub, and we believe our technique could promote the security of the open-source ecosystem.
Runhan Feng, Ziyang Yan, Shiyan Peng, Yuanyuan Zhang 0002
ICSE1
2021 MagikCube: Securing Cross-Domain Publish/Subscribe Systems with Enclave
abstract
The publish/subscribe(pub/sub) is an asynchronous messaging service or content distribution framework. For the idempotency it provides, pub/sub diagram is an efficient solution for large-scale content distributing systems, thus it is widely used in stock exchange systems or e-Health content sharing systems. Some wide-area applications require cross-domain pub/sub service, making it a natural choice to deploy on the public cloud. However, it would bring about security and privacy issues. Recent research proposes security enhancements to prevent thefts, such as searchable data encryption and attribute-based encryption, which allow the matching process to perform encrypted matching without learning the content of the publications and subscriptions. Besides the considerable performance loss, they could not resist the collusion attacks. If the malicious brokers collude with a malicious publisher or subscriber in a cross-domain environment, they can still infer the subscriptions of benign subscribers. We propose the MagikCube framework that provides confidentiality and integrity of the contents and also protects the privacy of the publishers and subscribers in cross-domain scenarios. Moreover, MagikCube can also resist the collusion attacks from malicious brokers in a cross-domain environment. It achieves these security goals by dynamically selecting and placing the sensitive data and some necessary components in enclaves protected by trusted hardware such as Intel SGX. Our experiment result shows that, compared with the baseline model, MagikCube does not introduce much overhead loss when providing better security for all the participants in the pub/sub system.
Shuran Wang, Dahan Pan, Runhan Feng, Yuanyuan Zhang 0002
TrustCom3
2019 An empirical study of SMS one-time password authentication in Android apps
abstract
A great quantity of user passwords nowadays has been leaked through security breaches of user accounts. To enhance the security of the Password Authentication Protocol (PAP) in such circumstance, Android app developers often implement a complementary One-Time Password (OTP) authentication by utilizing the short message service (SMS). Unfortunately, SMS is not specially designed as a secure service and thus an SMS One-Time Password is vulnerable to many attacks. To check whether a wide variety of currently used SMS OTP authentication protocols in Android apps are properly implemented, this paper presents an empirical study against them. We first derive a set of rules from RFC documents as the guide to implement secure SMS OTP authentication protocol. Then we implement an automated analysis system, AUTH-EYE, to check whether a real-world OTP authentication scheme violates any of these rules. Without accessing server source code, AUTH-EYE executes Android apps to trigger the OTP-relevant functionalities and then analyzes the OTP implementations including those proprietary ones. By only analyzing SMS responses, AUTH-EYE is able to assess the conformance of those implementations to our recommended rules and identify the potentially insecure apps. In our empirical study, AUTH-EYE analyzed 3,303 popular Android apps and found that 544 of them adopt SMS OTP authentication. The further analysis of AUTH-EYE demonstrated a far-from-optimistic status: the implementations of 536 (98.5%) out of the 544 apps violate at least one of our defined rules. The results indicate that Android app developers should seriously consider our discussed security rules and violations so as to implement SMS OTP properly.
Siqi Ma 0001, Runhan Feng, Juanru Li, Yang Liu 0118, Surya Nepal, Diethelm Ostry, Elisa Bertino, Robert H. Deng, Zhuo Ma 0001, Sanjay K. Jha
ACSAC2
2019 APPCOMMUNE: Automated Third-Party Libraries De-duplicating and Updating for Android Apps
abstract
The increasing usage of third-party libraries in Android apps is double-edged, boosting the development but introducing extra code base and potential vulnerabilities. Unlike desktop operating systems, Android does not support the sharing of third-party libraries between different apps. Thus both the de-duplicating and the updating of those libraries are difficult to be managed in a unified way. In this paper, we propose a third-party library sharing method to address the issues of code bloating and obsolete code updating. Our approach separates all integrated third-party libraries from app code and makes them still accessible through a dynamic loading mechanism. The separated libraries are managed centrally and can be shared by different apps. This not only saves the storage but also guarantees a prompt update of outdated libraries for every app. We implement APPCOMMUNE, a novel app installation and execution infrastructure to support the proposed third-party library sharing without modifying the commodity Android system. Our experiments with 212 popular third-party libraries and 502 real-world Android apps demonstrate the feasibility and efficiency: all apps work stably with our library sharing model, and 11.1% storage and bandwidth are saved for app downloading and installation. In addition, APPCOMMUNE updates 86.4% of the managed third-party libraries (with 44.6% to the latest versions).
Bodong Li, Yuanyuan Zhang 0002, Juanru Li, Runhan Feng, Dawu Gu
SANER4