Pinghong Ren

dblp:283/5142 · DBLP profile ↗
← Back
3ranked-venue papers
0as first author
3since 2021 · last 2025
0000-0002-0027-2976ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 WASDAM: Effectively Detecting Vulnerabilities in Wasm Smart Contracts Based on the Data Access Model
abstract
As WebAssembly (Wasm) smart contracts are widely deployed in blockchain platforms such as EOSIO, the threat of vulnerability attacks has become increasingly significant. Protecting the legitimate interests of blockchain users necessitates robust vulnerability detection approaches. Despite the advancements in existing approaches, several challenges remain, including state dependency, cross-function state transfer, and path selection. To tackle these issues, we introduce a novel concolic fuzzing approach called WASDAM, which integrates data access modeling, dynamic sensitive code tracing, and shortest path optimization to enhance the effectiveness of vulnerability detection. We have developed an open-source prototype of WASDAM and performed comprehensive experimental evaluations. The evaluation results demonstrate that WASDAM detects vulnerabilities in Wasm smart contracts more effectively than the state-of-the-art concolic fuzzer WASAI in terms of various performance metrics.
Chu Chen, Pinghong Ren, Bin Yu 0008
QRS3
2025 WASIF: In-depth detection of vulnerabilities in Wasm smart contracts via information flows and function invocation sequences
abstract
With the widespread adoption of WebAssembly (Wasm) smart contracts in popular blockchain platforms such as EOSIO, vulnerability attacks on Wasm smart contracts have become a serious problem. To protect the legitimate interests of blockchain users, it is necessary to detect vulnerabilities in Wasm smart contracts. However, detection faces a great challenge in that the source code of Wasm smart contracts is rarely released publicly. Although many approaches have made great progress in vulnerability detection, they still suffer from inefficiently generating function invocation sequences to track inter-function dependencies, ineffectively tracking sensitive information flows, and a considerable number of False Positives (FPs). To address these issues, we present a new concolic fuzzing approach for detecting vulnerabilities in Wasm smart contracts via information flows and function invocation sequences, namely, WASIF. Also, we implement the open-source prototype of the WASIF and conduct extensive experiments to evaluate it. The experimental results show that WASIF effectively and efficiently detects vulnerabilities in Wasm smart contracts and outperforms the state-of-the-art concolic fuzzer WASAI on most metrics.
Chu Chen, Yumo Tian, Pinghong Ren
Blockchain Res. Appl.6
2023 SBDT: Search-Based Differential Testing of Certificate Parsers in SSL/TLS Implementations
abstract
Certificate parsers, which are critical components of Secure Sockets Layer or Transport Layer Security (SSL/TLS) implementations, parse incomprehensible certificates into comprehensible inputs to certificate validators and humans. Thus, certificate parsers profoundly affect decision-makings of validators and humans, which in turn affect security. To guarantee the correctness of certificate parsers, an approach for search-based differential testing of certificate parsers, namely SBDT, is put forward. SBDT begins with modeling certificate structures, mutation operations, and bounds. Based on the initial model, SBDT searches for the most promising model node and mutation operator that trigger discrepancies, and generates a certificate from the node and operator it finds. Then, SBDT feeds the certificate to certificate parsers, and searches for multiple types of discrepancies after normalizing the results output by parsers. Distinct discrepancies are employed as feedback to update and prune the model. SBDT starts the next iteration from the updated and pruned model, unless all nodes and mutation operators have been pruned due to reaching their upper bounds. Our work has the following contributions: (1) To the best of our knowledge, this is the first time that testing of certificate parsers has been clearly distinguished from testing of certificate validators, which will facilitate accurate testing of certificate parsers and validators; (2) SBDT is the first systematic and efficient approach for differential testing of certificate parsers by searching, updating, and pruning models; and (3) We have implemented an open-source prototype tool of SBDT, and experimental results show that SBDT is effective and efficient in finding new bugs and enhancements of certificate parsers.
Chu Chen, Pinghong Ren, Cong Tian 0001, Xu Lu 0003, Bin Yu 0008
ISSTA2