VLDB 2026 Research / reviewers in the wild / expert
Shengke Ye
dblp:320/6506
· DBLP profile ↗
2ranked-venue papers
0as first author
2since 2021 · last 2025
0009-0007-2997-051XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | PHPJoy: A Novel Extended Graph-Based PHP Code Analysis FrameworkabstractNowadays, the PHP language is widely used in web development. Owing to PHP’s inherent flexibility and dynamic language features (e.g., cross-module dependencies and runtime polymorphism), PHP applications are prone to various security vulnerabilities, such as XSS and SQL injection. As an effective PHP semantic understanding and security vetting technique, static program analysis has been widely applied. However, prior work faced difficulties in dealing with diverse and dynamic PHP features, which caused serious false negatives (e.g., call target missing).In this paper, we propose a novel extended graph-based program analysis approach, calledPHPJoy, that can effectively and universally learn the semantic landscape of the target PHP program and conduct security validations. Specifically,PHPJoyfirst performs fine-grained program analysis (i.e., cross-module analysis and field-level analysis) for the purpose of learning the extended semantic graphs. Then, based on the graph-based semantic information,PHPJoyuniversally models various security issues by efficiently utilizing a new security-oriented graph query framework, which provides rich and easy-to-use graph query APIs and a high-performance cache-and-prefetch strategy.We evaluatePHPJoyon 333 popular PHP programs. The results show thatPHPJoycan effectively discover 269,901,982 semantic graph edges, improving by 23.76% when compared to the existing analysis tools. Our further analysis also shows that the runtime analysis overhead is reduced by 76.54%. Furthermore,PHPJoysuccessfully hunts 53 zero-day security vulnerabilities in the wild, which verifies the practicality ofPHPJoy. Youkun Shi, Yuan Zhang 0009, Tianhan Luo, Guangliang Yang 0001, Shengke Ye, Xiapu Luo, Min Yang 0002 |
IEEE Trans. Software Eng. | 5 |
| 2024 | New PHP Language Features Make Your Static Code Analysis Tools Miss VulnerabilitiesabstractDue to the nature of directly interacting with user inputs, PHP applications are susceptible to taint-style vulnerabilities. To detect such vulnerabilities, Static Code Analysis Tools (SCATs) are widely used for their broad code coverage and scalability. Modeling language features (i.e., to represent and simulate the behavior of program codes) is the keystone of SCATs' vulnerability detection capabilities. Meanwhile, being an actively maintained language, the PHP community introduces several new language features almost every year, rendering many unmodeled features. Though efforts have been made to reduce the number of unmodeled features, e.g., proposing new modeling methods, the impact of the introduction of new PHP features on SCAT during the language evolution is not well-conscious and systematically assessed. To fill the gap, this paper performs a systematic study of new language features and their impact on the ability of SCATs to detect taint-style vulnerabilities in PHP codes. To be specific, we identify 25 widely-used new language features that potentially compromise SCATs' vulnerability detection capabilities. Besides, we assess the impact of these new features on five open-source SCATs and show that the vulnerability detection ability is significantly compromised, with each SCAT affected by 10 features on average. To mitigate the impact, we conduct a theoretical analysis to diagnose the underlying reasons and propose several effective adaptation strategies. Finally, we provide key insights and implications for various stakeholders in static code analysis, emphasizing the need for them to recognize and proactively address the potential effects of language evolution. Lin Wang 0042, Yuan Zhang 0009, Shengke Ye, Min Yang 0002 |
ICSME | 4 |