Min-Chieh Wu

dblp:276/1377 · DBLP profile ↗
← Back
4ranked-venue papers
3as first author
3since 2021 · last 2026
0009-0002-1499-5996ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Mitigating Attacks on Web Applications via Fine-Grained Adaptive Control-Flow Integrity
abstract
While control-flow integrity (CFI) has been extensively applied to binary programs to ensure correct code execution, its application to web applications remains largely at the research stage. A key challenge lies in the inherent flexibility of web application programming and the extensive customizations it allows, which make optimizations based on static code analysis far less effective. To achieve practical performance, existing systems are limited to coarse-grained control-flow integrity, which leaves in trinsic detection blind spots. We propose fine-grained adaptive control-flow integrity (fgaCFI), the first web application CFI system that achieves basic-block level CFI with practical performance overhead. The Lightweight Dynamic Bytecode Monitor (LDBM) prototype, targeting PHP-based applications, supports three CFI monitoring granularity levels and adjustable monitoring scopes. Our results showed that basic-block level CFI achieved 100% detection coverage, outperforming function-level CFI with 83.33% detection coverage and request-level CFI with 58.33% detection coverage. By adapting to the uneven distribution of vulner abilities in the software modules, LDBM was able to maintain an 8.77% performance overhead on average.
Min-Chieh Wu, Yu-Sung Wu
IEEE Trans. Dependable Secur. Comput.1
2026 Suppressing False Positives in Web Application Firewalls With Program Trace Anomaly Detection
abstract
Web Application Firewalls (WAFs) have become the standard line of defense against web security attacks in production systems. However, due to the diverse and continuously evolving nature of web applications, WAF detection rules (or models) must remain sufficiently generic to accommodate attack variants and reduce maintenance costs, resulting in a substantial number of false positives. We propose program-trace-based anomaly detection as a means to suppress the false positives. Our prototype, TraceSense, analyzes the control flow of PHP-based web applications at adjustable granularity levels to detect attacks without re lying on manually crafted rules. The evaluation based on real world Common Vulnerabilities and Exposures (CVEs) demonstrates that TraceSense can accurately identify successful at tacks—comparable to rule-based WAFs—while reliably ignoring unsuccessful attacks that would trigger false positives in conventional systems. The alerts from program-trace-based anomaly detection are inherently self-explanatory. System administrators can use the built-in visualization tool to dismiss residual false positives and investigate unknown vulnerabilities.
Min-Chieh Wu, Yu-Wei Liao, Yu-Sung Wu
IEEE Trans. Reliab.1
2025 Poster: High-Fidelity and Contextual User Activity Memory Forensics
abstract
Retrieving application user activities from a memory dump has traditionally been a labor-intensive process, due to both the sheer volume of memory data and the complexity of opaque data structures. We introduce RAM-Weaver, a system that enables contextual querying of user activities from application memory dump files. RAM-Weaver distills essential information from raw dumps and leverages large language models (LLMs) to navigate opaque data structures and support interactive queries. This distillation process can reduce the data volume by up to 99.9% and improve the signal-to-noise ratio by nearly 37 dB, making it feasible to run on smaller, offline models. When combined with full-scale, cloud-hosted models, RAM-Weaver can retrieve user activity data with exceptionally high accuracy.
Min-Chieh Wu, Jui-An Chang, Yu-Sung Wu
CCS1
2020 POSTER: Data Leakage Detection for Health Information System based on Memory Introspection
abstract
The abundance of highly sensitive personal information in the Health Information System (HIS) has made it a prime target of data breach attacks. However, securing the system with existing Data Leakage Prevention (DLP) solutions is difficult due to a lack of security perimeter and diverse composition of software components. We propose the use of hypervisor-based memory introspection for implementing data leakage detection in such an environment. The approach looks for the presence of sensitive raw data in the memory of both the client machines and the server machines, transcending the dependence of pre-existing security perimeters. It is inherently compatible with different types of application software and robust against transport or at-rest data encryption. A prototype has been built on the Bareflank hypervisor and the OpenEMR platform. The evaluation results confirmed the effectiveness of the approach.
Sanoop Mallissery, Min-Chieh Wu, Chun-An Bau, Guan-Zhang Huang, Chen-Yu Yang, Wei-Chun Lin, Yu-Sung Wu
AsiaCCS2