Xingman Chen

dblp:277/8177 · DBLP profile ↗
← Back
7ranked-venue papers
1as first author
5since 2021 · last 2024
0000-0002-7120-9261ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021
YearPublicationVenuePosition
2024 Understanding the IO Performance Gap Between OS-Level and VM-Level Containers in High-Density Deployment
abstract
Containers are widely deployed in clouds. There are two common container architectures: operating system-level (OS-level) container and virtual machine-level (VM-level) container. Typical examples are runc and Kata. It is well known that VM- level containers provide better isolation than OS-level containers, but at a higher overhead. Although there are quantitative analyses of the performance gap between these two container architectures, they rarely discuss the performance gap under the constrained resources nrovisioned to containers. Since the high-density deployment of containers is demanding in the cloud, each container is provisioned with limited resources specified by the cgroup mechanism. In this paper, we provide an in-depth analysis of the storage and network (two key aspects) performance differences between runc and Kata under varying resource constraints. We identify configuration implications that are crucial to performance and find that some of them are not exposed by the Kata interfaces. Based on that, we propose a profiling tool to automatically offer configuration suggestions for optimizing container performance. Our evaluation shows that the auto-generated configuration can improve the performance of MySQL by up to 107% in the TPCC benchmark compared with the default Kata setup.
Wentai Li, Kaijun Zhou 0001, Jiacheng Shi 0002, Xingman Chen, Luyuan Wang, Jinyu Gu 0001
ICDCS4
2023 MTSan: A Feasible and Practical Memory Sanitizer for Fuzzing COTS Binaries
Xingman Chen, Yinghao Shi, Zheyu Jiang, Yuan Li 0061, Ruoyu Wang 0001, Hai-Xin Duan, Haoyu Wang 0001, Chao Zhang 0008
USENIX Security Symposium1
2023 TAICHI: Transform Your Secret Exploits Into Mine From a Victim's Perspective
abstract
Acquiring and analyzing exploits, which take advantage of vulnerabilities to conduct malicious actions, are crucial for victims (and defenders) when responding to system compromising incidents. However, exploits are sensitive and valuable assets that are not available to victims. The most common resource available for victims to investigate is network traffic, which covers the exploitation period. Thus reconstructing exploits from network traffic is demanded. In practice, the reconstruction process is performed manually, thus inefficient and non-scalable. In this article, we present an automated solutionTAICHIto reconstruct exploits from network traffic, able to generate replica exploits and facilitate timely incident analysis. By nature, a working exploit has to satisfy (1)path constraintswhich ensure the program path same as the original exploit's is explored and the same vulnerability is triggered, and (2)exploit constraintswhich ensure the same exploitation strategy is applied, e.g., to bypass deployed defenses or to stitch multiple gadgets together. We propose a hybrid solution to this problem by integrating techniques including multi-version execution (MVE), dynamic taint analysis (DTA), and concolic execution. We have implemented a prototype ofTAICHIon x86 and x86-64 Linux and tested it on the Cyber Grand Challenge (CGC) dataset, several Capture the Flag (CTF) challenges, and Metasploit exploit modules targeting real world applications. The evaluation results showed thatTAICHIcould reconstruct exploits efficiently with a high success rate. Moreover, it could be applied to production environments without disrupting running services, and could reconstruct exploits even if only one round of exploitation traffic is available.
Zhongyu Pei, Xingman Chen, Songtao Yang 0001, Hai-Xin Duan, Chao Zhang 0008
IEEE Trans. Dependable Secur. Comput.2
2021 ROLoad: Securing Sensitive Operations with Pointee Integrity
abstract
Sensitive operations (e.g. control-flow transfers) are attractive targets for attackers. To protect them from being hijacked, we propose a new solution ROLoad to guarantee the integrity of their operands, which are loaded from (potentially corrupted) memory. We extend the RISC-V instruction set, implement an FPGA-based prototype of ROLoad, and then demonstrate two specific defense applications. Results show that this solution only costs few extra hardware resources (< 3.32%). However, it could enable many lightweight (e.g. with overheads less than 0.31%) defenses, and provide broader and stronger security guarantees than existing hardware solutions, e.g. ARM BTI and Intel CET.
Wende Tan, Yuan Li 0061, Chao Zhang 0008, Xingman Chen, Songtao Yang 0001, Ying Liu 0024
DAC4
2021 VScape: Assessing and Escaping Virtual Call Protections
Kaixiang Chen, Chao Zhang 0008, Tingting Yin, Xingman Chen
USENIX Security Symposium4
2020 Finding Cracks in Shields: On the Security of Control Flow Integrity Mechanisms
abstract
Control-flow integrity (CFI) is a promising technique to mitigate control-flow hijacking attacks. In the past decade, dozens of CFI mechanisms have been proposed by researchers. Despite the claims made by themselves, the security promises of these mechanisms have not been carefully evaluated, and thus are questionable.
Yuan Li 0061, Chao Zhang 0008, Xingman Chen, Songtao Yang 0001, Ying Liu 0024
CCS4
2020 RIPT - An Efficient Multi-Core Record-Replay System
abstract
Given the same input, a program may not behave the same in two runs due to some non-deterministic features, e.g., context switch and randomization. Such behaviors would cause non-deterministic program bugs which are hard to discover or diagnose. Record-and-replay is a promising technique to address such issues, however, performance and transparency are the main obstacles of existing works. In this poster, we propose a novel record-and-replay system named RIPT. RIPT utilizes Intel Processor Trace to record control flow information with very low overhead, and transparently captures non-deterministic sources such as system calls and signals with a kernel module. During replay, RIPT recovers the effect of non-deterministic events from the collected information, and makes target programs behave the same as recorded. We evaluate it with real-world program bugs and show that RIPT works well in practice.
Jiashuo Liang, Guancheng Li, Chao Zhang 0008, Ming Yuan 0003, Xingman Chen, Xinhui Han
CCS5