VLDB 2026 Research / reviewers in the wild / expert
Zhechang Zhang
dblp:334/9029
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0001-7152-116XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SACK: Systematic Generation of Function Substitution Attacks Against Control-Flow Integrity
Zhechang Zhang, Hengkai Ye, Hong Hu 0004 |
NDSS | 1 |
| 2024 | CountDown: Refcount-guided Fuzzing for Exposing Temporal Memory Errors in Linux KernelabstractKernel use-after-free (UAF) bugs are severe threats to system security due to their complex root causes and high exploitability.We find that 36.1% of recent kernel UAF bugs are caused by improper uses of reference counters, dubbed refcount-related UAF bugs.Current kernel fuzzing tools based on code coverage can detect common memory errors, but none of them is aware of the root cause.As a consequence, they only trigger refcount-related UAF bugs passively and coincidentally, and may miss many deep hidden vulnerabilities.To actively trigger refcount-related UAF bugs, in this paper, we propose CountDown, a novel refcount-guided kernel fuzzer.CountDown collects diverse refcount operations from kernel executions and reshapes syscall relations based on commonly accessed refcounts.When generating user-space programs, CountDown prefers to combine syscalls that ever access the same refcounts, aiming to trigger complex refcount behaviors.It also injects refcountdecreasing and refcount-accessing syscalls to intentionally free the refcounted object and trigger invalid accesses through dangling pointers.We test CountDown on mainstream Linux kernels and compare it with popular fuzzers.On average, our tool can detect 66.1% more UAF bugs and 32.9% more KASAN reports than stateof-the-art tools.CountDown has found nine new kernel memory bugs, where two are fixed and one is confirmed. Shuangpeng Bai, Zhechang Zhang, Hong Hu 0004 |
CCS | 2 |
| 2023 | VIPER: Spotting Syscall-Guard Variables for Data-Only Attacks
Hengkai Ye, Zhechang Zhang, Hong Hu 0004 |
USENIX Security Symposium | 3 |
| 2022 | StateDiver: Testing Deep Packet Inspection Systems with State-Discrepancy GuidanceabstractDeep Packet Inspection (DPI) systems are essential for securing modern networks (e.g., blocking or logging abnormal network connections). However, DPI systems are known to be vulnerable in their implementations, which could be exploited for evasion attacks. Due to the critical role DPI systems play, many efforts have been made to detect vulnerabilities in the DPI systems through manual inspection, symbolic execution, and fuzzing, which suffer from either poor scalability, path explosion, or inappropriate feedback. In this paper, based on our observation that a DPI system usually reaches an abnormal internal state before a forbidden packet passes through it, we propose a fuzzing framework that prioritizes inputs/mutations which could trigger the DPI system’s abnormal internal states. Further, to avoid deep understanding of the DPI systems under inspection (e.g., to identify the abnormal states), we feed one pair of inputs to multiple DPI systems and check whether the state changes of these DPI systems are consistent — an inconsistent internal state change/transference in one of the DPI systems indicates a new abnormal state is reached in the corresponding DPI system. Naturally, inputs that trigger new abnormal states are preferentially selected for mutations to generate new inputs. Following this idea, we develop StateDiver, the first fuzzing framework that uses the state discrepancy between different DPI systems as feedback to find more bypassing strategies. We make StateDiver publicly available online. With the help of StateDiver, we tested 3 famous open-source DPI systems (Snort, Snort++, and Suricata) and discovered 16 bypass strategies (8 new and 8 previously known). We have reported all the vulnerabilities to the vendors and received one CVE by the time of paper writing. We also compared StateDiver with Geneva, the state-of-the-art fuzzing tool for detecting DPI bugs. Results showed that StateDiver outperformed Geneva at the number and speed of finding vulnerabilities, indicating the ability of StateDiver to detect strategies bypassing DPI systems effectively. Zhechang Zhang, Bin Yuan 0002, Kehan Yang, Deqing Zou, Hai Jin 0001 |
ACSAC | 1 |