Ruilin Li 0002

dblp:24/7930-2 · DBLP profile ↗
← Back
22ranked-venue papers
6as first author
6since 2021 · last 2025
0000-0003-4395-1351ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 4 first-author · 2 since 2021Software engineering, systems software and programming languages · 4 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorTheory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2025 Practical Object-Level Sanitizer with Aggregated Memory Access and Custom Allocator
abstract
To mitigate potential memory safety vulnerabilities, recently there have been significant advances in sanitizers for pre-production bug detection. However, the limited inability to balance performance and detection accuracy still holds. The main reason is due to excessive reliance on shadow memory and a large number of memory access checks at runtime, incurring a significant performance overhead (if fine-grained memory safety detection is performed, the overhead will be even greater). In this paper, we propose a novel Object-Level Address Sanitizer OLASan to reduce performance overhead further while implementing accurate memory violations (including intra-object overflow) detection. Unlike previous sanitizers ignoring the correlation between memory access and objects, OLASan aggregates multiple memory accesses of same object at function level to perform on-demand targeted sanitization, thus avoiding examining most memory accesses at runtime. Specifically, OLASan characterizes various memory access patterns to identify those which can be aggregated, and implements memory safety checks with customized memory tagging. We implement OLASan atop the LLVM framework and evaluate it on SPEC CPU benchmarks. Evaluations show that OLASan outperforms the state-of-the-art methods with 51.18%, 25.20% and 6.52% less runtime overhead than ASan, ASan-- and GiantSan respectively. Moreover, aided by customized memory tagging, OLASan achieves zero false negatives for the first time when testing Juliet suites. Finally, we confirm that OLASan also offers comparable detection capabilities on real bugs.
Ruilin Li 0002, Chao Feng 0002, Chaojing Tang
ICSE2
2023 Automated Exploitable Heap Layout Generation for Heap Overflows Through Manipulation Distance-Guided Fuzzing
Jiongyi Chen, Runhao Li, Chao Feng 0002, Ruilin Li 0002, Chaojing Tang
USENIX Security Symposium5
2022 Default: Mutual Information-based Crash Triage for Massive Crashes
abstract
With the considerable success achieved by modern fuzzing infrastructures, more crashes are produced than ever before. To dig out the root cause, rapid and faithful crash triage for large numbers of crashes has always been attractive. However, hindered by the practical difficulty of reducing analysis imprecision without compromising efficiency, this goal has not been accomplished.
Jiongyi Chen, Chao Feng 0002, Ruilin Li 0002, Wenrui Diao, Kehuan Zhang, Jing Lei 0001, Chaojing Tang
ICSE4
2022 Automated detection on the security of the linked-list operations
Hongyu Kuang, Jian Wang 0020, Ruilin Li 0002, Chao Feng 0002, Yunfei Su
Frontiers Comput. Sci.3
2022 Pusher: an augmented fuzzer based on the connection between input and comparison operand
Jiaxi Ye, Ruilin Li 0002, Chao Feng 0002, Yunfei Su, Chaojing Tang
Frontiers Comput. Sci.3
2021 Reducing Test Cases with Attention Mechanism of Neural Networks
Jiongyi Chen, Chao Feng 0002, Ruilin Li 0002, Yunfei Su, Jing Lei 0001, Chaojing Tang
USENIX Security Symposium4
2018 A real-time inversion attack on the GMR-2 cipher used in the satellite phones
Jiao Hu, Ruilin Li 0002, Chaojing Tang
Sci. China Inf. Sci.2
2017 Dual Relationship Between Impossible Differentials and Zero Correlation Linear Hulls of SIMON-Like Ciphers
Xuan Shen, Ruilin Li 0002, Bing Sun 0001, Chao Li 0002, Maodong Liao
ISPEC2
2017 Automatic Reverse Engineering of Private Flight Control Protocols of UAVs
abstract
The increasing use of civil unmanned aerial vehicles (UAVs) has the potential to threaten public safety and privacy. Therefore, airspace administrators urgently need an effective method to regulate UAVs. Understanding the meaning and format of UAV flight control commands by automatic protocol reverse-engineering techniques is highly beneficial to UAV regulation. To improve our understanding of the meaning and format of UAV flight control commands, this paper proposes a method to automatically analyze the private flight control protocols of UAVs. First, we classify flight control commands collected from a binary network trace into clusters; then, we analyze the meaning of flight control commands by the accumulated error of each cluster; next, we extract the binary format of commands and infer field semantics in these commands; and finally, we infer the location of the check field in command and the generator polynomial matrix. The proposed approach is validated via experiments on a widely used consumer UAV.
Jian Wang 0020, Chaojing Tang, Ruilin Li 0002
Secur. Commun. Networks4
2016 Provable Security Evaluation of Structures Against Impossible Differential and Zero Correlation Linear Cryptanalysis
Bing Sun 0001, Meicheng Liu, Jian Guo 0001, Vincent Rijmen, Ruilin Li 0002
EUROCRYPT (1)5
2015 Links Among Impossible Differential, Integral and Zero Correlation Linear Cryptanalysis
Bing Sun 0001, Zhiqiang Liu 0001, Vincent Rijmen, Ruilin Li 0002, Qingju Wang 0001, Hoda Alkhzaimi, Chao Li 0002
CRYPTO (1)4
2015 Differential fault analysis on LED using Super-Sbox
abstract
Light encryption device (LED) is a 64 bit lightweight block cipher proposed by Guo et al . at CHES 2011, and its key size is primarily defined as 64 and 128 bits. This study studies differential fault analysis (DFA) of LED using the technique of Super‐Sbox analysis. Under various fault models, the fault pattern propagation rule of the Super‐Sbox can be obtained, based on which the efficiency of fault attack on LED can be greatly improved. For LED‐64, under the nibble‐based fault model, a random nibble fault at the 30th round can reduce the size of key search space to 2 7 –2 20 (average 2 14.02 ). Even if a random nibble fault is injected into the 29th round, the size of the key search space can also be reduced to about 2 17.43 –2 17.72 (average 2 17.65 ) using early‐abort technique. Although under the byte‐based fault model, a random byte fault at the 30th round can reduce the size of the key space to 2 7 –2 16 (average 2 11.92 ). If the adversary has the capability of injecting two random nibble faults at some specified rounds, then the above fault attack on LED‐64 can be similarly extended to LED‐128, and the size of the exhaustive search space for the 128 bit key can be reduced to 2 15 –2 27.94 (average 2 21.96 ). These results demonstrate that Super‐Sbox is a powerful technique that can be used to obtain significant improvements in the key filtration, and thus improve the efficiency of DFA on some special ciphers.
Guangyao Zhao, Ruilin Li 0002, Chao Li 0002, Bing Sun 0001
IET Inf. Secur.2
2014 On the Practical Security Bound of GF-NLFSR Structure with SPN Round Function
Guangyao Zhao, Chao Li 0002, Ruilin Li 0002, Xuan Shen
ProvSec4
2013 A Low Data Complexity Attack on the GMR-2 Cipher Used in the Satellite Phones
Ruilin Li 0002, Chao Li 0002, Bing Sun 0001
FSE1
2013 Fault analysis study of the block cipher FOX64
Ruilin Li 0002, Jianxiong You, Bing Sun 0001, Chao Li 0002
Multim. Tools Appl.1
2011 Impossible differential cryptanalysis of SPN ciphers
abstract
Impossible differential cryptanalysis is a very popular tool for analysing the security of modern block ciphers and the core of such attack is based on the existence of impossible differentials. Currently, most methods for finding impossible differentials are based on the miss-in-the-middle technique and they are very ad hoc. In this study, the authors concentrate on substitution–permutation network (SPN) ciphers whose diffusion layer is defined by a linear transformation P. Based on the theory of linear algebra, the authors propose several criteria on P and its inversion P-1 to characterise the existence of 3/4-round impossible differentials. The authors further discuss the possibility to extend these methods to analyse 5/6-round impossible differentials. Using these criteria, impossible differentials for reduced-round Rijndael are found that are consistent with the ones found before. New 4-round impossible differentials are discovered for block cipher ARIA. Many 4-round impossible differentials are firstly detected for a kind of SPN cipher that employs a 32×32 binary matrix proposed at ICISC 2006 as its diffusion layer. It is concluded that the linear transformation should be carefully designed in order to protect the cipher against impossible differential cryptanalysis.
Ruilin Li 0002, Bing Sun 0001, Chao Li 0002
IET Inf. Secur.1
2011 Differential Fault Analysis on SMS4 using a single fault
Ruilin Li 0002, Bing Sun 0001, Chao Li 0002, Jianxiong You
Inf. Process. Lett.1
2011 Impossible differential cryptanalysis of 13-round CLEFIA-128
Xuehai Tang, Bing Sun 0001, Ruilin Li 0002, Chao Li 0002
J. Syst. Softw.3
2011 A meet-in-the-middle attack on reduced-round ARIA
Xuehai Tang, Bing Sun 0001, Ruilin Li 0002, Chao Li 0002, Juhua Yin
J. Syst. Softw.3
2010 Cryptanalysis of a Generalized Unbalanced Feistel Network Structure
Ruilin Li 0002, Bing Sun 0001, Chao Li 0002, Longjiang Qu
ACISP1
2010 SQUARE attack on block ciphers with low algebraic degree
Bing Sun 0001, Ruilin Li 0002, Longjiang Qu, Chao Li 0002
Sci. China Inf. Sci.2
2009 Differential Fault Analysis on SHACAL-1
abstract
SHACAL-1, known as one of the finalists of the NESSIE project, originates from the compression component of the widely used hash function SHA-1. The requirements of confusion and diffusion are implemented through mixing operations and rotations other than substitution and permutation, thus there exists little literature on its immunity against fault attacks. In this paper, we apply differential fault analysis on SHACAL-1 in a synthetic approach. We introduce the random word fault model, present some theoretical arguments, and give an efficient fault attack based on the characteristic of the cipher. Both theoretical predications and experimental results demonstrate that, 72 random faults are needed to obtain 512 bits key with successful probability more than 60%, while 120 random faults are enough to obtain 512 bits key with successful probability more than 99%.
Ruilin Li 0002, Chao Li 0002, Chunye Gong
FDTC1