VLDB 2026 Research / reviewers in the wild / expert
Xinhui Han
dblp:38/2577
· DBLP profile ↗
34ranked-venue papers
2as first author
18since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 23 · 10 since 2021Computer networks · 5 · 1 first-author · 3 since 2021Systems, architecture and hardware · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | BDLF-Qwen3: Enhanced Cross-Architecture Binary Function Similarity Detection Through Binary Dynamic Layer FusionabstractBinary code analysis is essential for software security across various instruction set architectures. Cross-architecture binary function similarity detection faces significant challenges due to substantial differences in instruction sets and architectural conventions. Existing approaches struggle to capture relationships between code abstraction levels, and lack comprehensive cross-architecture datasets for effective evaluation. Inspired by human cognitive processes of dynamically integrating multi-level information, we propose Binary Dynamic Layer Fusion (BDLF), a novel neural architecture that enhances cross-architecture similarity detection through adaptive layer-wise feature integration. BDLF leverages Qwen3's multilingual code understanding and introduces dynamic weight generation to optimally combine representations from all previous layers. We also construct Cross-Bin, a high quality cross-architecture binary function dataset. BDLF-Qwen3 employs two-stage training: partial fine-tuning with pairwise similarity learning followed by BDLF enhancement with InfoNCE contrastive learning. Experiments demonstrate BDLF-Qwen3 significantly outperforms state-of-the-art methods, achieving 36-65\% improvement in Recall@10 across diverse CPU architectures. Yuanda Wang, Xinhui Han, Chao Zhang 0008 |
AAAI | 3 |
| 2026 | Drawbridge: Securing Early-Boot DMA Through IO Bridges
Changling Zhou, Xinhui Han |
ISCAS | 3 |
| 2026 | LatticeBox: A Hardware-Software Co-Designed Framework for Scalable and Low-Latency Compartmentalization
Zhanpeng Liu, Wende Tan, Xinhui Han |
NDSS | 5 |
| 2025 | PTC: Prefix Tuning CodeT5 for High-Quality Secure Network Measurement Script GenerationabstractThe automated generation of secure network measurement scripts is vital for reliable network operations, but traditional models often neglect security, leading to vulnerabilities like command injection and buffer overflows. We propose PTC (Prefix Tuning CodeT5), a novel method leveraging prefix tuning on the CodeT5 model to generate secure, functionally correct scripts without full retraining. PTC introduces a security-oriented loss function to enhance code correctness and security compliance, reducing vulnerabilities while meeting functional requirements. We evaluate PTC on several groups of targets, and results show that our solution outperforms baseline models, producing secure and functional network measurement scripts across various scenarios. This approach effectively bridges the gap between code generation and security, offering a practical solution for developing robust network tools for real-world applications. Yuanda Wang, Xinhui Han |
DSN | 2 |
| 2025 | CCTAG: Configurable and Combinable Tagged Architecture
Zhanpeng Liu, Wende Tan, Yuan Li 0061, Xinhui Han, Songtao Yang 0001, Chao Zhang 0008 |
NDSS | 6 |
| 2025 | Age of collection with non-orthogonal multiple access: A theoretical-plus-experimental study
Yurong Lai, Xinhui Han, Xueer Wang, Tse-Tin Chan, Haoyuan Pan |
Comput. Networks | 2 |
| 2025 | CALLEE: Recovering Call Graphs for Binaries With Transfer and Contrastive LearningabstractRecovering call graphs of binary programs plays an instrumental role in facilitating inter-procedural analysis tasks and subsequent applications. A salient challenge inherent in this process is the identification of indirect call targets, i.e., indirect callees. Existing solutions all have high false positives and negatives, making call graphs inaccurate. In this paper, we introduce CALLEE, an approach combining transfer learning and contrastive learning. The key insight is that, deep neural networks (DNNs) can automatically identify patterns concerning indirect calls. Inspired by question-answering applications, we employ contrastive learning to answer the callsite-callee question. To overcome the data-intensive nature of DNNs, we use transfer learning to pre-train on easy-to-collect direct calls and then fine-tune with indirect calls. Upon evaluating CALLEE across various target sets, our findings underscored its efficacy, associating callsites with callees surpasses state-of-the-art solutions, achieving over seven to eight times higher performance in both MRR and Recall@5. Further, when implementing CALLEE within two distinct applications-binary code similarity detection and hybrid fuzzing-we observed a marked enhancement in their operational performance. Wenyu Zhu, Yuanda Wang, Chao Zhang 0008, Xinhui Han |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Successive Interference Cancellation-Enabled Timely Status Update in Linear Multi-Hop Wireless NetworksabstractWe investigate the timely status update in linear multi-hop wireless networks, where a source tries to deliver status update packets to a destination through a sequence of half-duplex relays. Timeliness is measured by the age of information (AoI) metric. Maintaining a low AoI at the destination typically necessitates frequent transmission of update packets from the source. However, high packet transmission frequency in multi-hop scenarios can result in mutual wireless interference at intermediate relays. Specifically, when an intermediate relay receives wireless signals of a new packet from its previous node, simultaneous transmission of an old packet by its subsequent node to the next hop may cause wireless signals to interfere at the intermediate relay, conventionally leading to packet collision. A key motivation to solve this issue is that the intermediate relay has previously received the old packet (which can thus be forwarded to the subsequent node for further relaying). Hence, successive interference cancellation (SIC) can be employed to mitigate interference of the old packet and recover the new packet. This paper designs an SIC-enabled packet relaying scheme tailored to low AoI. Initially focusing on a three-hop network, we subsequently extend our approach to general multi-hop networks. We model the multi-hop relaying scheme using a Markov chain to derive the theoretical average AoI. Theoretical and simulation results indicate that the SIC-enabled packet relaying scheme significantly reduces the average AoI compared to the non-SIC approaches, owing to an increased packet transmission frequency at the source and the effectiveness of SIC techniques at the relays. Xinhui Han, Haoyuan Pan, Zhaorui Wang 0001, Jianqiang Li 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | Age of Information in Linear Multi-Hop Wireless NetworksabstractWe investigate the information freshness, measured by age of information (AoI), of a linear multi-hop wireless network, where a source tries to deliver status update packets to a destination via a series of half-duplex relays. Sending update packets frequently from the source is critical to achieve a low AoI at the destination. However, if the packet generation rate is not designed properly, an intermediate relay may receive mutual wireless interference from its previous and subsequent nodes. When the previous node sends a new packet to the intermediate relay, the subsequent node simultaneously forwards an old packet to the next hop in which the wireless signal is also received by the intermediate relay. A key motivation to solve this problem is that the intermediate relay has previously received the old packet (which thus can be forwarded to the subsequent node for further relaying). Hence, successive interference cancellation (SIC) can be used to remove the interference of the old packet and then recover the new packet. Taking a three-hop network as an example, we design an SIC-enabled packet relaying scheme tailored to low AoI, which can be generalized to scenarios beyond three hops. We model the three-hop relaying scheme using a Markov chain to derive the theoretical average AoI (AAoI) and peak AoI (PAoI). Theoretical and simulation results show that the SIC-enabled packet relaying scheme significantly reduces the AAoI and PAoI compared to the non-SIC counterpart, thanks to a more frequent packet generation rate at the source and the SIC technique at the relays. Xinhui Han, Haoyuan Pan |
VTC Spring | 1 |
| 2024 | Reducing Age of Collection with Dynamic-Frame Time Division Multiple AccessabstractThis paper introduces a dynamic-frame time division multiple access (DF-TDMA) scheme aimed at decreasing the age of collection (AoC) in collaborative monitoring scenarios. Unlike the conventional age of information (AoI) metric, AoC decreases only when partial information from multiple sources is aggregated to form a complete observation. Previous studies on AoC predominantly assumed that complete observations are derived from aggregating information from all sources. However, this assumption does not hold in scenarios where sources are correlated, and a complete observation can be achieved with partial information from only a subset of sources. To address this, new channel access protocols are necessary to achieve a low network-wide average peak AoC. DF-TDMA is proposed as a solution, featuring dynamically adjustable TDMA frame sizes to minimize time wastage and thereby reduce AoC. While the dynamic frame size adjustment complicates AoC analysis, we theoretically derive the average peak AoC of DF-TDMA. Simulations show that DF-TDMA maintains a stable average peak AoC across varying numbers of sources N, and notably reduces the average peak AoC compared to a fixed-frame TDMA scheme, particularly under conditions with a large N. Yurong Lai, Xinhui Han, Xueer Wang, Haoyuan Pan |
VTC Fall | 2 |
| 2024 | Research on blind reversible database watermarking algorithm based on dual embedding strategyabstractAbstract Massive databases encounter security such as data theft, illegal copying, and copyright infringement during creating, transmitting, and sharing of big data. The reversible data watermarking technology can effectively solve these problems, which can extract the watermark information accurately and recover the original carrier data without any distortion. However, most existing methods extract watermark information non-blindly and cannot effectively achieve a balance between watermark embedding capacity and data distortion. This paper proposes a blind reversible database watermarking method based on dual embedding, which combines histogram shifting and distortion-free watermarking methods to achieve an adaptive selection of histogram bins, blind extraction of watermark information, and carrier data recovery. The proposed method preprocesses the database tuples by scrambling them and constructs a prediction error histogram using first-layer tuples in square prediction within each group. The watermark information is embedded through adaptive selection and expansion of histogram bins, while the distortion-free watermarking method is used in another layer to assist in the recovery of original carrier data. The experimental results show that the proposed method can achieve an embedding capacity of more than three times the capacity of existing methods. It can also achieve blind watermark extraction and outperform some other state-of-the-art methods. Wenfa Qi, Cheng Li 0045, Xinhui Han |
Comput. J. | 3 |
| 2023 | RaceBench: A Triggerable and Observable Concurrency Bug BenchmarkabstractConcurrency bugs are one of the most harmful and hard-to-address issues in multithreaded software. Such bugs are hard to discover, reproduce, diagnose or fix due to their non-deterministic nature. Although more and more bug discovery solutions are proposed in recent years, it is difficult to evaluate them with existing concurrency bug datasets. The demand for building a high-quality benchmark of concurrency bugs emerges. Jiashuo Liang, Ming Yuan 0003, Zhanzhao Ding, Siqi Ma 0001, Xinhui Han, Chao Zhang 0008 |
AsiaCCS | 5 |
| 2023 | An Improved Reversible Database Watermarking Method based on Histogram ShiftingabstractDatabase watermarking is typically employed to address the issues of data theft, illegal replication, and copyright infringement that may arise during the sharing of databases. Unfortunately, the existing methods often cause permanent distortion to the original data, and it is challenging to strike a balance between the watermark embedding capacity and data distortion. Therefore, this paper proposes a reversible database watermarking method based on histogram shifting, rhombus prediction, and double embedding with high capacity and low distortion, called RPDE-HSW. By utilizing the rhombus prediction, we respectively constructed two prediction error histograms in each subgroup and expanded the watermark capacity through the adoption of double-layer embedding and single-bin embedding 2 bits. A scrambling algorithm is used to make the attribute value distribution more discretized, resulting in a sparse distribution of the database histogram. Subsequently, we optimized the selection rules for the watermark embedding carrier, effectively eliminating the redundant distortion caused by histogram shifting. Experimental results demonstrate that the proposed method achieves smaller data distortion and higher watermark embedding capacity, outperforming some other state-of-the-art works, and does not affect the classification results and data mining. Cheng Li 0045, Xinhui Han, Wenfa Qi, Zongming Guo |
IH&MMSec | 2 |
| 2023 | Identifying Library Functions in Stripped Binary: Combining Function Similarity and Call Graph Features
Zhanpeng Liu, Xinhui Han |
SecureComm (2) | 2 |
| 2023 | DDRace: Finding Concurrency UAF Vulnerabilities in Linux Drivers with Directed Fuzzing
Ming Yuan 0003, Bodong Zhao, Penghui Li 0001, Jiashuo Liang, Xinhui Han, Xiapu Luo, Chao Zhang 0008 |
USENIX Security Symposium | 5 |
| 2022 | Poster: MSILDiffer - A Security Patch Analysis Framework Based on Microsoft Intermediate Language for Large SoftwareabstractIn this poster, we proposed a .NET patch analysis framework named MSILDiffer based on Microsoft Intermediate Language (MSIL). First, MSILDiffer directly extracts MSIL instructions from the .NET assemblies, and retrieves the hierarchy of classes as well as their internal class methods. Then, with coarse and fine granularity feature extraction and comparison, MSILDiffer quickly filters out the code with substantial changes after patch. Besides, we build a dataset of patch analysis containing 24.46 million class methods based on the Microsoft Exchange mail system security patches. With the assistance of MSILDiffer, we generated 32 call paths and crafted corresponding POCs for 1-day vulnerabilities in the dataset. Through the experiment evaluation, MSILDiffer is superior to JustAssembly in terms of coverage, accuracy and time consumption of patch difference analysis. Can Huang 0001, Cheng Li 0045, Jiashuo Liang, Xinhui Han |
CCS | 4 |
| 2022 | Poster: TaintGrep: A Static Analysis Tool for Detecting Vulnerabilities of Android Apps Supporting User-defined RulesabstractIn this poster, we present TaintGrep, a novel static analysis approach to detect vulnerabilities of Android applications. This approach combines the advantages of semantic pattern matching and taint analysis to get better accuracy and be able to detect cross-function vulnerabilities. Compared with many traditional tools, TaintGrep does not require the full source code or building environment to analyze. Moreover, it supports users in defining their customized matching rules using their vulnerability mining experience, which makes this approach more flexible and scalable. In the preliminary experiment, we give a detailed analysis of the rules of two typical vulnerabilities: generic DoS and arbitrary file read/write, and have detected 77 0day vulnerabilities with these rules in 16 well-known Android applications. Ruiguo Yang, Jiajin Cai, Xinhui Han |
CCS | 3 |
| 2021 | Code is the (F)Law: Demystifying and Mitigating Blockchain Inconsistency Attacks Caused by Software BugsabstractBlockchains promise to provide a tamper-proof medium for transactions, and thus enable many applications including cryptocurrency. As a system built on consensus, the correctness of a blockchain heavily relies on the consistency of states between its nodes. But consensus protocols of blockchains only guarantee the consistency in the transaction sequence rather than nodes' internal states. Instead, nodes must replay and exe-cute all transactions to maintain their local states independently. When executing transactions, any different execution result could cause a node out-of-sync and thus gets isolated from other nodes.After systematically modeling the transaction execution process in blockchains, we present a new attack INCITE, which can lead different nodes to different states. Specifically, attackers could invoke an ambiguous transaction of a vulnerable smart contract, utilize software bugs in smart contracts to lead nodes that execute this transaction into different states. Unlike attacks that bring short-term inconsistencies, such as fork attacks, INCITE can cause nodes in the blockchain to fall into a long-term inconsistent state, which further leads to great damages to the chain (e.g., double-spending attacks and expelling mining power). We have discovered 7 0day vulnerabilities in 5 popular blockchains which can enable this attack. We also proposed a defense solution to mitigate this threat. Experiments showed that it is effective and lightweight. Guorui Yu, Shibin Zhao, Chao Zhang 0008, Zhiniang Peng, Yuandong Ni, Xinhui Han |
INFOCOM | 6 |
| 2020 | LPET - Mining MS-Windows Software Privilege Escalation Vulnerabilities by Monitoring Interactive BehaviorabstractLocal Privilege Escalation (LPE) is a common attack vector used by attackers to gain higher-level permissions. In this poster, we present a system called LPET to mine LPE vulnerabilities of third-party software in MS-Windows. Our insight is that the LPE is often caused by the interactions between high-privilege processes and user-controllable files. The interactions include creating a file, starting a process and others. Based on this observation, LPET first monitors software behaviors and constructs a directed interaction graph to abstract entities, such as files and processes, and their interactions. Then LPET analyzes exploiting paths from the graph by extracting user-controllable entities and checking their privileges. Finally, LPET verifies the exploiting paths using replacement or hijacking attacks. In the preliminary experiments, LPET found vulnerabilities in various software. Moreover, we discovered a common weakness pattern that some components were executed by software with high privilege after being released in the user-controllable temporary directory during installation, update, and uninstallation. By replacing the components, attackers with low privilege can hijack the execution flow of software to execute their codes with high privilege. We found that a wide range of software suffers from this weakness pattern, including Cisco AnyConnect, Dropbox, Notepad++. Can Huang 0001, Xinhui Han, Guorui Yu |
CCS | 2 |
| 2020 | RIPT - An Efficient Multi-Core Record-Replay SystemabstractGiven the same input, a program may not behave the same in two runs due to some non-deterministic features, e.g., context switch and randomization. Such behaviors would cause non-deterministic program bugs which are hard to discover or diagnose. Record-and-replay is a promising technique to address such issues, however, performance and transparency are the main obstacles of existing works. In this poster, we propose a novel record-and-replay system named RIPT. RIPT utilizes Intel Processor Trace to record control flow information with very low overhead, and transparently captures non-deterministic sources such as system calls and signals with a kernel module. During replay, RIPT recovers the effect of non-deterministic events from the collected information, and makes target programs behave the same as recorded. We evaluate it with real-world program bugs and show that RIPT works well in practice. Jiashuo Liang, Guancheng Li, Chao Zhang 0008, Ming Yuan 0003, Xingman Chen, Xinhui Han |
CCS | 6 |
| 2020 | ReDex: Unpacking Android Packed Apps by Executing Every MethodabstractIn recent years, Android commercial packers have been widely used to encrypt dex files of apps, making analysts and malware detection solutions hard to obtain the actual dex files for further analysis. Therefore, we propose a novel unpacking system named ReDex. ReDex uses Java reflection to execute all methods with forged arguments and collects the original instructions when the method is executing. Although apps may crash due to forged arguments, ReDex can collect its original instructions released by the commercial packer before the crash. Also, we design an exception/crash handling module, which can avoid most of the crashes and restart the unpacking process at the next method after the crash. The comparison with 2 state-of-the-art unpackers on 100 packed apps with source code and 140 wild packed apps shows that ReDex can unpack more apps. Besides, we conduct an experiment with 1,801 real-world apps packed by 7 representative packers. Of 21 million methods, ReDex can extract 19,239,743 (90.30%) methods. The exception/crash handling module effectively reduces the crash rate to 2.31%. In these packed apps, we find 4 interesting packing techniques. ReDex can deal with these packing techniques while 2 state-of-the-art unpackers cannot. Jiajin Cai, Tongxin Li 0002, Can Huang 0001, Xinhui Han |
TrustCom | 4 |
| 2017 | Unleashing the Walking Dead: Understanding Cross-App Remote Infections on Mobile WebViewsabstractAs a critical feature for enhancing user experience, cross-app URL invocation has been reported to cause unauthorized execution of app components. Although protection has already been put in place, little has been done to understand the security risks of navigating an app's WebView through an URL, a legitimate need for displaying the app's UI during cross-app interactions. In our research, we found that the current design of such cross-WebView navigation actually opens the door to a cross-app remote infection, allowing a remote adversary to spread malicious web content across different apps' WebView instances and acquire stealthy and persistent control of these apps. This new threat, dubbed Cross-App WebView Infection (XAWI), enables a series of multi-app, colluding attacks never thought before, with significant real world impacts. Particularly, we found that the remote adversary can collectively utilize multiple infected apps' individual capabilities to escalate his privileges on a mobile device or orchestrate a highly realistic remote Phishing attack (e.g., running a malicious script in Chrome to stealthily change Twitter's WebView to fake Twitter's own login UI). We show that the adversary can easily find such attack "building blocks" (popular apps whose WebViews can be redirected by another app) through an automatic fuzz, and discovered about 7.4% of the most popular apps subject to the XAWI attacks, including Facebook, Twitter, Amazon and others. Our study reveals the contention between the demand for convenient cross-WebView communication and the need for security control on the channel, and makes the first step toward building OS-level protection to safeguard this fast-growing technology. Tongxin Li 0002, Xueqiang Wang, Mingming Zha 0001, Kai Chen 0012, XiaoFeng Wang 0001, Luyi Xing, Xiaolong Bai, Nan Zhang 0018, Xinhui Han |
CCS | 9 |
| 2017 | Ghost Installer in the Shadow: Security Analysis of App Installation on AndroidabstractAndroid allows developers to build apps with app installation functionality themselves with minimal restriction and support like any other functionalities. Given the critical importance of app installation, the security implications of the approach can be significant. This paper reports the first systematic study on this issue, focusing on the security guarantees of different steps of the App Installation Transaction (AIT). We demonstrate the serious consequences of leaving AIT development to individual developers: most installers (e.g., Amazon AppStore, DTIgnite, Baidu) are riddled with various security-critical loopholes, which can be exploited by attackers to silently install any apps, acquiring dangerous-level permissions or even unauthorized access to system resources. Surprisingly, vulnerabilities were found in all steps of AIT. The attacks we present, dubbed Ghost Installer Attack (GIA), are found to pose a realistic threat to Android ecosystem. Further, we developed both a user-app-level and a system-level defense that are innovative and practical. Yeonjoon Lee, Tongxin Li 0002, Nan Zhang 0018, Soteris Demetriou, Mingming Zha 0001, XiaoFeng Wang 0001, Kai Chen 0012, Xiao-yong Zhou, Xinhui Han, Michael Grace |
DSN | 9 |
| 2017 | Accurate and efficient exploit capture and classification
Tao Wei 0002, Hui Xue 0003, Chao Zhang 0008, Xinhui Han |
Sci. China Inf. Sci. | 6 |
| 2015 | Perplexed Messengers from the Cloud: Automated Security Analysis of Push-Messaging IntegrationsabstractIn this paper, we report the first large-scale, systematic study on the security qualities of emerging push-messaging services, focusing on their app-side service integrations. We identified a set of security properties different push-messaging services (e.g., Google Cloud Messaging) need to have, and automatically verified them in different integrations using a new technique, called Seminal. Seminal is designed to extract semantic information from a service's sample code, and leverage the information to evaluate the security qualities of the service's SDKs and its integrations within different apps. Using this tool, we studied 30 leading services around the world, and scanned 35,173 apps. Our findings are astonishing: over 20% apps in Google Play and 50% apps in mainstream Chinese app markets are riddled with security-critical loopholes, putting a huge amount of sensitive user data at risk. Also, our research brought to light new types of security flaws never known before, which can be exploited to cause serious confusions among popular apps and services (e.g., Facebook, Skype, Yelp, Baidu Push). Taking advantage of such confusions, the adversary can post his content to the victim's apps in the name of trusted parties and intercept her private messages. The study highlights the serious challenges in securing push-messaging services and an urgent need for improving their security qualities. Yangyi Chen, Tongxin Li 0002, XiaoFeng Wang 0001, Kai Chen 0012, Xinhui Han |
CCS | 5 |
| 2015 | Cracking App Isolation on Apple: Unauthorized Cross-App Resource Access on MAC OS~X and iOSabstractOn modern operating systems, applications under the same user are separated from each other, for the purpose of protecting them against malware and compromised programs. Given the complexity of today's OSes, less clear is whether such isolation is effective against different kind of cross-app resource access attacks (called XARA in our research). To better understand the problem, on the less-studied Apple platforms, we conducted a systematic security analysis on MAC OS~X and iOS. Our research leads to the discovery of a series of high-impact security weaknesses, which enable a sandboxed malicious app, approved by the Apple Stores, to gain unauthorized access to other apps' sensitive data. More specifically, we found that the inter-app interaction services, including the keychain, WebSocket and NSConnection on OS~X and URL Scheme on the MAC OS and iOS, can all be exploited by the malware to steal such confidential information as the passwords for iCloud, email and bank, and the secret token of Evernote. Further, the design of the app sandbox on OS~X was found to be vulnerable, exposing an app's private directory to the sandboxed malware that hijacks its Apple Bundle ID. As a result, sensitive user data, like the notes and user contacts under Evernote and photos under WeChat, have all been disclosed. Fundamentally, these problems are caused by the lack of app-to-app and app-to-OS authentications. To better understand their impacts, we developed a scanner that automatically analyzes the binaries of MAC OS and iOS apps to determine whether proper protection is missing in their code. Running it on hundreds of binaries, we confirmed the pervasiveness of the weaknesses among high-impact Apple apps. Since the issues may not be easily fixed, we built a simple program that detects exploit attempts on OS~X, helping protect vulnerable apps before the problems can be fully addressed. Luyi Xing, Xiaolong Bai, Tongxin Li 0002, XiaoFeng Wang 0001, Kai Chen 0012, Xiaojing Liao, Shi-Min Hu 0001, Xinhui Han |
CCS | 8 |
| 2015 | SF-DRDoS: The store-and-flood distributed reflective denial of service attack
Bingshuang Liu, Jun Li 0001, Tao Wei 0002, Skyler Berg, Jiayi Ye, Chao Zhang 0008, Xinhui Han |
Comput. Commun. | 9 |
| 2014 | Mayhem in the Push Clouds: Understanding and Mitigating Security Hazards in Mobile Push-Messaging ServicesabstractPush messaging is among the most important mobile-cloud services, offering critical supports to a wide spectrum of mobile apps. This service needs to coordinate complicated interactions between developer servers and their apps in a large scale, making it error prone. With its importance, little has been done, however, to understand the security risks of the service. In this paper, we report the first security analysis on those push-messaging services, which reveals the pervasiveness of subtle yet significant security flaws in them, affecting billions of mobile users. Through even the most reputable services like Google Cloud Messaging (GCM) and Amazon Device Messaging (ADM), the adversary running carefully-crafted exploits can steal sensitive messages from a target device, stealthily install or uninstall any apps on it, remotely lock out its legitimate user or even completely wipe out her data. This is made possible by the vulnerabilities in those services' protection of device-to-cloud interactions and the communication between their clients and subscriber apps on the same devices. Our study further brings to light questionable practices in those services, including weak cloud-side access control and extensive use of PendingIntent, as well as the impacts of the problems, which cause popular apps or system services like Android Device Manager, Facebook, Google+, Skype, PayPal etc. to leak out sensitive user data or unwittingly act on the adversary's command. To mitigate this threat, we developed a technique that helps the app developers establish end-to-end protection of the communication with their apps, over the vulnerable messaging services they use. Tongxin Li 0002, Xiao-yong Zhou, Luyi Xing, Yeonjoon Lee, Muhammad Naveed 0001, XiaoFeng Wang 0001, Xinhui Han |
CCS | 7 |
| 2014 | POSTER: AdHoneyDroid - Capture Malicious Android AdvertisementsabstractIn this paper we explore the problem of collecting malicious smartphone advertisements. Most smartphone app contains advertisements and also suffers from vulnerable advertisement libraries. Malicious advertisements exploit the ad library vulnerability and attack victim smartphones. Similar to the traditional honeypots, we need an effective way to capture malicious ads. In this paper, we provide our approach named AdHoneyDroid. We build a crawler to gather apps on the android marketplaces and manually collect ad libraries and their vulnerabilities. Then AdHoneyDroid executes the apps and detects malicious advertisements. In our approach, we adopt the idea of API sandbox and TaintDroid to detect the attack event. We store the malicious advertisements in a database for future analysis. Malicious ads can help security analysts have a better understanding of current mobile attacks and also disclose the attack payloads. Shuaifu Dai, Tongxin Li 0002, Xinhui Han |
CCS | 5 |
| 2014 | POSTER: UAFChecker: Scalable Static Detection of Use-After-Free VulnerabilitiesabstractUse-after-free vulnerabilities are gaining more and more attentions in recent years, since they are commonly exploited in applications like browsers, and exposed in abundant security updates, e.g., from Microsoft, Google or Mozilla. This kind of vulnerabilities are triggered by dereferencing a dangling pointer, and may introduce high risks into the system once they are exploited. In this paper, we propose a comprehensive solution called UAFChecker to detect use-after-free vulnerabilities in source code. Our solution utilizes classical static analysis techniques, including taint analysis and symbolic execution, to make an inter-procedural analysis to find as many use-after-free vulnerabilities as possible, with a low false negative rate and a low false positive rate. We implement a prototype of UAFChecker based on the compiler framework LLVM. We then use the Juliet Test Suite to evaluate UAFChecker's capability of detecting use-after-free vulnerabilities. Results show that UAFChecker is able to identify most use-after-free vulnerabilities in the Juliet Test Suite. We also test UAFChecker against two open source applications, and successfully find out all known use-after-free vulnerabilities in them. Jiayi Ye, Chao Zhang 0008, Xinhui Han |
CCS | 3 |
| 2014 | The store-and-flood distributed reflective denial of service attackabstractDistributed reflective denial of service (DRDoS) attacks, especially those based on UDP reflection and amplification, can generate hundreds of gigabits per second of attack traffic, and have become a significant threat to Internet security. In this paper we show that an attacker can further make the DRDoS attack more dangerous. In particular, we describe a new DRDoS attack called store-and-flood DRDoS, or SF-DRDoS. By leveraging peer-to-peer (P2P) file-sharing networks, SF-DRDoS becomes more surreptitious and powerful than traditional DRDoS. An attacker can store carefully prepared data on reflector nodes before the flooding phase to greatly increase the amplification factor of an attack. We implemented a prototype of SF-DRDoS on Kad, a popular Kademlia-based P2P file-sharing network. With real-world experiments, this attack achieved an amplification factor of 2400 on average, with the upper bound of attack bandwidth at 670 Gbps in Kad. Finally, we discuss possible defenses to mitigate the threat of SF-DRDoS. Bingshuang Liu, Skyler Berg, Jun Li 0001, Tao Wei 0002, Chao Zhang 0008, Xinhui Han |
ICCCN | 6 |
| 2011 | WebPatrol: automated collection and replay of web-based malware scenariosabstractTraditional remote-server-exploiting malware is quickly evolving and adapting to the new web-centric computing paradigm. By leveraging the large population of (insecure) web sites and exploiting the vulnerabilities at client-side modern (complex) browsers (and their extensions), web-based malware becomes one of the most severe and common infection vectors nowadays. While traditional malware collection and analysis are mainly focusing on binaries, it is important to develop new techniques and tools for collecting and analyzing web-based malware, which should include a complete web-based malicious logic to reflect the dynamic, distributed, multi-step, and multi-path web infection trails, instead of just the binaries executed at end hosts. This paper is a first attempt in this direction to automatically collect web-based malware scenarios (including complete web infection trails) to enable fine-grained analysis. Based on the collections, we provide the capability for offline "live" replay, i.e., an end user (e.g., an analyst) can faithfully experience the original infection trail based on her current client environment, even when the original malicious web pages are not available or already cleaned. Our evaluation shows that WebPatrol can collect/cover much more complete infection trails than state-of-the-art honeypot systems such as PHoneyC [11] and Capture-HPC [1]. We also provide several case studies on the analysis of web-based malware scenarios we have collected from a large national education and research network, which contains around 35,000 web sites. Kevin Zhijie Chen, Guofei Gu, Jianwei Zhuge, Jose Nazario, Xinhui Han |
AsiaCCS | 5 |
| 2010 | Preventing drive-by download via inter-module communication monitoringabstractDrive-by download attack is one of the most severe threats to Internet users. Typically, only visiting a malicious page will result in compromise of the client and infection of malware. By the end of 2008, drive-by download had already become the number one infection vector of malware [5]. The downloaded malware may steal the users' personal identification and password. They may also join botnet to send spams, host phishing site or launch distributed denial of service attacks. Chengyu Song, Jianwei Zhuge, Xinhui Han, Zhiyuan Ye |
AsiaCCS | 3 |
| 2007 | Collecting Autonomous Spreading Malware Using High-Interaction Honeypots
Jianwei Zhuge, Thorsten Holz, Xinhui Han, Chengyu Song |
ICICS | 3 |