VLDB 2026 Research / reviewers in the wild / expert
Cong Sun 0001
dblp:45/5103-1
· DBLP profile ↗
45ranked-venue papers
10as first author
22since 2021 · last 2026
0000-0001-9116-2694ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 4 first-author · 13 since 2021Software engineering, systems software and programming languages · 10 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 4 first-author · 1 since 2021Systems, architecture and hardware · 5 · 2 since 2021Computer networks · 4 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fine-grained information-flow-driven program partitioning
Xue Rao, Cong Sun 0001, Dongrui Zeng |
Comput. Secur. | 2 |
| 2026 | EADR: Efficient runtime detection and recovery of actuator attacks on UAVsabstractAbstract The actuator is the critical component of the unmanned aerial vehicle (UAV). The interference and suppression to the signal of UAV’s actuators are challenging to directly detect or physically mitigate, thus posing a significant threat to UAV flight safety. Under the assumption of sensor integrity, the state-of-the-art physics-based attack detection approaches can identify the actuator attacks at runtime. However, when both sensor and actuator attacks are allowed simultaneously, such physics-based attack detection approaches cannot differentiate between the two physical attacks, thereby failing to locate the specific compromised actuators or maintain the UAV’s resilience to the actuator attack at runtime. This paper presents EADR , an efficient runtime framework for detecting and recovering from UAV actuator attacks. By leveraging the existing signal-characteristic-based sensor attack detection mechanism, EADR prevents potential sensor attacks from impacting the resilience of actuator attacks. In response to typical attack scenarios, we implement actuator attack detection based on the nonlinear dynamic model combined with the cumulative sum (CUSUM) detection algorithm. We further locate the specific compromised actuators, determine the required compensations for the signal of these actuators at runtime, and apply the compensations to the actuators to effectively recover the UAV system state. The experimental results demonstrate that the time to detection (TTD) of EADR ’s detector is significantly reduced compared with the state-of-the-art approaches. EADR ’s recovery mechanism can reduce the flight positional error by approximately 56.3 – 77.6%. The average runtime overhead of EADR is less than 2%, ensuring the real-time performance required for real-world UAV flight. Cong Sun 0001, Penghao He, Yunbo Wang, Zongxu Zhang, Xiaomin Wei |
Cybersecur. | 1 |
| 2026 | Physical Attacks on a UAV System: Overview and Emerging MethodsabstractWith the widespread adoption of UAV technology, the physical attacks targeting UAVs have become increasingly diverse, garnering growing attention. Physical attacks pose significant threats to the security of critical hardware within UAV systems, potentially leading to severe consequences such as crashes or unauthorized hijacking. Therefore, conducting in-depth research into physical attack methods on UAV systems not only provides theoretical support and strategic guidance for designing defense measures but also facilitates the optimization and tool-based application of existing attack techniques, paving new pathways for the development of anti-UAV technologies. This review begins with a systematic decomposition and detailed introduction of UAV systems from the perspective of hardware functional structures. Subsequently, it delves into vulnerabilities of UAV systems when facing physical attacks and provides a comprehensive review of existing physical attack methods. Particular attention is given to evaluating the effectiveness, technical characteristics, strengths, and limitations of these methods. Additionally, the review explores emerging physical attack techniques and the potential security threats posed by hardware extensions of UAVs in novel application domains. Furthermore, this review proposes a quantitative risk assessment framework for UAV security, systematically evaluating various physical attack methods based on attack cost, effectiveness, and likelihood. Finally, the review discusses future research directions in the domain of physical attacks on UAV systems, emphasizing the need to enhance existing technologies to strengthen anti-UAV capabilities and highlighting the importance of developing comprehensive defense strategies against physical attacks. Xiaomin Wei, Xinghua Li 0001, Cong Sun 0001, Jianfeng Ma 0001 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2025 | Disa: Accurate Learning-based Static Disassembly with AttentionsabstractFor reverse engineering related security domains, such as vulnerability detection, malware analysis, and binary hardening, disassembly is crucial yet challenging. The fundamental challenge of disassembly is to identify instruction and function boundaries. Classic approaches rely on file-format assumptions and architecture-specific heuristics to guess the boundaries, resulting in incomplete and incorrect disassembly, especially when the binary is obfuscated. Recent advancements of disassembly have demonstrated that deep learning can improve both the accuracy and efficiency of disassembly. In this paper, we propose Disa, a new learning-based disassembly approach that uses the information of superset instructions over the multi-head self-attention to learn the instructions' correlations, thus being able to infer function entry-points and instruction boundaries. Disa can further identify instructions relevant to memory block boundaries to facilitate an advanced block-memory model based value-set analysis for an accurate control flow graph (CFG) generation. Our experiments show that Disa outperforms prior deep-learning disassembly approaches in function entry-point identification, especially achieving 9.1% and 13.2% F1-score improvement on binaries respectively obfuscated by the disassembly desynchronization technique and popular source-level obfuscator. By achieving an 18.5% improvement in the memory block precision, Disa generates more accurate CFGs with a 4.4% reduction in Average Indirect Call Targets (AICT) compared with the state-of-the-art heuristic-based approach. Monika Santra, Cong Sun 0001, Dongrui Zeng, Gang Tan |
CCS | 4 |
| 2025 | Sensor attack online classification for UAVs using machine learning
Xiaomin Wei, Yizhen Xu, Cong Sun 0001, Xinghua Li 0001, Jianfeng Ma 0001 |
Comput. Secur. | 4 |
| 2025 | Sliver: A Scalable Slicing-Based Verification for Information Flow SecurityabstractStatic information flow analysis has been studied for a long time. It is usually considered more precise than dynamic taint analysis and more flexible and indispensable when running individual modules or the entire program is difficult. The state-of-the-art static information flow analyses are scalable on analyzing Java programs or mobile apps, and several type systems have enforced information flow security on different languages. However, static information-flow analyses have rarely scaled up to real-world C programs. This work presents Sliver, a slicing-based approach to verify information flow security on real-world C programs. The principle of Sliver is to convert the information-flow-involved parts of the original program into behavior-equivalent slices and use bounded model checking to enforce the end-to-end noninterference property or detect security violations on the slices after self-composition. We develop automated path-signature-guided slicing and adaptive self-composition approaches to ensure Sliver's efficacy and scalability. We also develop a consistency testing technique and metrics to estimate the correctness of slices generated by Sliver. The evaluations demonstrate Sliver's effectiveness, scalability, and the correctness of the generated slices. Xue Rao, Cong Sun 0001, Dongrui Zeng, Yongzhe Huang, Gang Tan |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Understanding the Bad Development Practices of Android Custom Permissions in the WildabstractAndroid system provides application developers with the ability to define custom permissions, which serve to regulate the sharing of resources and functionalities with other applications. However, developers' improper development practices can render the permission mechanism ineffective, facilitating easy exploitation by attackers. This paper presents a comprehensive examination of the problematic practices surrounding custom permissions employed by developers, referred to as Bad Practices of Custom Permissions (BPCP issues). To accomplish this, we conducted an empirical study and identified nine common BPCP issue patterns that can lead to various adverse consequences, such as installation failures, crashes, and even component hijacking. To automatically identify these patterns of bad practices, we devised PERMEAGRE, a static analysis tool. Employing PERMEAGRE, we performed a large-scale analysis of 83,085 applications obtained from seven major app markets, aiming to detect instances of BPCP issues. The results revealed that more than 26% of the analyzed apps contained at least one issue, and a significant number of apps had garnered millions of downloads. Our analysis delved into the underlying causes of these issues. Consequently, this analysis sheds light on the potential threat landscape associated with bad practices in custom permissions, emphasizing the urgent requirement for effective mitigation strategies. Zhiyuan Yu 0001, Xinghua Li 0001, Cen Zhang, Cong Sun 0001, Ning Zhang 0017, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | VIMU: Effective Physics-based Realtime Detection and Recovery against Stealthy Attacks on UAVsabstractSensor attacks on robotic vehicles have become pervasive and manipulative. Their latest advancements exploit sensor and detector characteristics to bypass detection. Recent security efforts have leveraged the physics-based model to detect or mitigate sensor attacks. However, these approaches are only resilient to a few sensor attacks and still need improvement in detection effectiveness. We present VIMU, an efficient sensor attack detection and resilience system for unmanned aerial vehicles. We propose a detection algorithm, CS-EMA, that leverages low-pass filtering to identify stealthy gyroscope attacks while achieving an overall effective sensor attack detection. We develop a fine-grained nonlinear physical model with precise aerodynamic and propulsion wrench modeling. We also augment the state estimation with a FIFO buffer safeguard to mitigate the impact of high-rate IMU attacks. The proposed physical model and buffer safeguard provide an effective system state recovery toward maintaining flight stability. We implement VIMU on PX4 autopilot. The evaluation results demonstrate the effectiveness of VIMU in detecting and mitigating various realistic sensor attacks, especially stealthy attacks. Yunbo Wang, Cong Sun 0001, Qiaosen Liu, Bingnan Su, Zongxu Zhang, Michael Norris, Gang Tan, Jianfeng Ma 0001 |
ACSAC | 2 |
| 2024 | A Survey on Security of Unmanned Aerial Vehicle Systems: Attacks and CountermeasuresabstractWith the wide application of unmanned aerial vehicles (UAVs), security problems of UAV systems are gradually exposed, which bring great risks to UAV application. This article surveys the security of UAV systems, including attacks and countermeasures. First, the UAV system architecture is analyzed to identify security vulnerabilities. A UAV system contains the hardware platform, software platform, radio communication link, and application software. The navigation, guidance, and control systems are three core components in software platform. Then, security threats and attacks are analyzed and categorized from the view of cyberspace security, including spoofing attacks, reply attacks, jamming attacks, Denial-of-Service (DoS) attacks, eavesdropping attacks, side-channel attacks, manipulation attacks, and system intrusion attacks. Countermeasures are categorized based on the UAV system architecture and what attacks each countermeasure type can defend are also summarized. Compared to existing survey on security of a UAV system, more attack types and corresponding countermeasures are concluded. Finally, open issues and corresponding countermeasures on the security of UAV systems are discussed to guide the future research trend, including existing countermeasure weaknesses and challenges, and new issues and challenges. Xiaomin Wei, Jianfeng Ma 0001, Cong Sun 0001 |
IEEE Internet Things J. | 3 |
| 2024 | GNSS spoofing detection for UAVs using Doppler frequency and Carrier-to-Noise Density Ratio
Xiaomin Wei, Cong Sun 0001, Xinghua Li 0001, Jianfeng Ma 0001 |
J. Syst. Archit. | 2 |
| 2024 | LICAPA: Lightweight collective attestation for physical attacks detection in highly dynamic networksabstractUAVs or vehicular networks have been extensively used in different domains. Such a system network consists of various heterogeneous and mobile devices operating autonomously and cooperatively to provide flexible services. However, ensuring devices’ runtime integrity has always been critical to such highly dynamic and disruptive networks. Collective attestation is a popular technique in ensuring service integrity on remote devices. However, the physical attacks pose significant threats to the enforcement of the runtime integrity, and the existing detection approaches raise a considerable number of false positives, which impede the robustness of the network. We propose LICAPA, a collective attestation framework for detecting physical attacks with high accuracy. LICAPA can detect a device under physical attack with the timestamps signed by other recently-attested devices. Such a proof-from-others mechanism provides more knowledge about the compromised device for physical attack detection. It reduces the potential false positives compared with the state-of-the-art approaches. LICAPA provides a physical-adversary-tolerant runtime device joining mechanism and a new attestation report aggregation scheme to reduce the storage and communication cost of the device. On the prototype implementation of the trust anchor, we evaluate LICAPA’s computational costs. The simulation results demonstrate LICAPA’s low communication cost and long resistance time against false detection on physical attack. LICAPA reduces the overall swarm attestation cost by over 20% compared with SALAD (Secure and Lightweight Attestation of Highly Dynamic and Disruptive Networks) and PASTA (Practical Attestation Protocol for Autonomous Embedded Systems). Cong Sun 0001 |
Pervasive Mob. Comput. | 2 |
| 2023 | LibScan: Towards More Precise Third-Party Library Identification for Android Applications
Cong Sun 0001, Dongrui Zeng, Gang Tan, Siqi Ma 0001 |
USENIX Security Symposium | 2 |
| 2023 | CryptoEval: Evaluating the risk of cryptographic misuses in Android apps with data-flow analysisabstractAbstract The misunderstanding and incorrect configurations of cryptographic primitives have exposed severe security vulnerabilities to attackers. Due to the pervasiveness and diversity of cryptographic misuses, a comprehensive and accurate understanding of how cryptographic misuses can undermine the security of an Android app is critical to the subsequent mitigation strategies but also challenging. Although various approaches have been proposed to detect cryptographic misuse in Android apps, studies have yet to focus on estimating the security risks of cryptographic misuse. To address this problem, the authors present an extensible framework for deciding the threat level of cryptographic misuse in Android apps. Firstly, the authors propose a general and unified specification for representing cryptographic misuses to make our framework extensible and develop adapters to unify the detection results of the state‐of‐the‐art cryptographic misuse detectors, resulting in an adapter‐based detection tool chain for a more comprehensive list of cryptographic misuses. Secondly, the authors employ a misuse‐originating data‐flow analysis to connect each cryptographic misuse to a set of data‐flow sinks in an app, based on which the authors propose a quantitative data‐flow‐driven metric for assessing the overall risk of the app introduced by cryptographic misuses. To make the per‐app assessment more useful for app vetting at the app‐store level, the authors apply unsupervised learning to predict and classify the top risky threats to guide more efficient subsequent mitigation. In the experiments on an instantiated implementation of the framework, the authors evaluate the accuracy of our detection and the effect of data‐flow‐driven risk assessment of our framework. Our empirical study on over 40,000 apps, and the analysis of popular apps reveal important security observations on the real threats of cryptographic misuse in Android apps. Cong Sun 0001, Xinpeng Xu, Dongrui Zeng, Gang Tan, Siqi Ma 0001 |
IET Inf. Secur. | 1 |
| 2023 | DeepCatra: Learning flow- and graph-based behaviours for Android malware detectionabstractAbstract As Android malware grows and evolves, deep learning has been introduced into malware detection, resulting in great effectiveness. Recent work is considering hybrid models and multi‐view learning. However, they use only simple features, limiting the accuracy of these approaches in practice. This study proposes DeepCatra, a multi‐view learning approach for Android malware detection, whose model consists of a bidirectional LSTM (BiLSTM) and a graph neural network (GNN) as subnets. The two subnets rely on features extracted from statically computed call traces leading to critical APIs derived from public vulnerabilities. For each Android app, DeepCatra first constructs its call graph and computes call traces reaching critical APIs. Then, temporal opcode features used by the BiLSTM subnet are extracted from the call traces, while flow graph features used by the GNN subnet are constructed from all call traces and inter‐component communications. We evaluate the effectiveness of DeepCatra by comparing it with several state‐of‐the‐art detection approaches. Experimental results on over 18,000 real‐world apps and prevalent malware show that DeepCatra achieves considerable improvement, for example, 2.7%–14.6% on the F1 measure, which demonstrates the feasibility of DeepCatra in practice. Dongrui Zeng, Cong Sun 0001 |
IET Inf. Secur. | 5 |
| 2023 | μDep: Mutation-Based Dependency Generation for Precise Taint Analysis on Android Native CodeabstractThe existence of native code in Android apps plays an important role in triggering inconspicuous propagation of secrets and circumventing malware detection. However, the state-of-the-art information-flow analysis tools for Android apps all have limited capabilities of analyzing native code. Due to the complexity of binary-level static analysis, most static analyzers choose to build conservative models for a selected portion of native code. Though the recent inter-language analysis improves the capability of tracking information flow in native code, it is still far from attaining similar effectiveness of the state-of-the-art information-flow analyzers that focus on non-native Java methods. To overcome the above constraints, we propose a new analysis framework,$\mu$Dep, to detect sensitive information flows of the Android apps containing native code. In this framework, we combine a control-flow based static binary analysis with a mutation-based dynamic analysis to model the tainting behaviors of native code in the apps. Based on the result of the analyses,$\mu$Dep conducts a stub generation for the related native functions to facilitate the state-of-the-art analyzer DroidSafe with fine-grained tainting behavior summaries of native code. The experimental results show that our framework is competitive on the accuracy, and effective in analyzing the information flows in real-world apps and malware compared with the state-of-the-art inter-language static analysis. Cong Sun 0001, Yuwan Ma, Dongrui Zeng, Gang Tan, Siqi Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | BinPointer: towards precise, sound, and scalable binary-level pointer analysisabstractBinary-level pointer analysis is critical to binary-level applications such as reverse engineering and binary debloating. In this paper, we propose BinPointer, a new binary-level interprocedural pointer analysis that relies on an offset-sensitive value-tracking analysis to achieve high precision. We also propose a soundness and precision evaluation methodology based on runtime memory accesses triggered by reference input data. Our experimental results demonstrate that BinPointer has higher precision over prior work, while maintaining acceptable scalability. The soundness of BinPointer is also validated through runtime data. Sun Hyoung Kim, Dongrui Zeng, Cong Sun 0001, Gang Tan |
CC | 3 |
| 2022 | Control Parameters Considered Harmful: Detecting Range Specification Bugs in Drone Configuration Modules via Learning-Guided SearchabstractIn order to support a variety of missions and deal with different flight environments, drone control programs typically provide configurable control parameters. However, such a flexibility introduces vulnerabilities. One such vulnerability, referred to as range specification bugs, has been recently identified. The vulnerability originates from the fact that even though each individual parameter receives a value in the recommended value range, certain combinations of parameter values may affect the drone physical stability. In this paper, we develop a novel learning-guided search system to find such combinations, that we refer to as incorrect configurations. Our system applies metaheuristic search algorithms mutating configurations to detect the configuration parameters that have values driving the drone to unstable physical states. To guide the mutations, our system leverages a machine learning based predictor as the fitness evaluator. Finally, by utilizing multi-objective optimization, our system returns the feasible ranges based on the mutation search results. Because in our system the mutations are guided by a predictor, evaluating the parameter configurations does not require realistic/simulation executions. Therefore, our system supports a comprehensive and yet efficient detection of incorrect configurations. We have carried out an experimental evaluation of our system. The evaluation results show that the system successfully reports potentially incorrect configurations, of which over 85% lead to actual unstable physical states. Ruidong Han, Chao Yang 0016, Siqi Ma 0001, Jianfeng Ma 0001, Cong Sun 0001, Juanru Li, Elisa Bertino |
ICSE | 5 |
| 2021 | ReCFA: Resilient Control-Flow AttestationabstractRecent IoT applications gradually adapt more complicated end systems with commodity software. Ensuring the runtime integrity of these software is a challenging task for the remote controller or cloud services. Popular enforcement is the runtime remote attestation which requires the end system (prover) to generate evidence for its runtime behavior and a remote trusted verifier to attest the evidence. Control-flow attestation is a kind of runtime attestation that provides diagnoses towards the remote control-flow hijacking at the prover. Most of these attestation approaches focus on small or embedded software. The recent advance to attesting complicated software depends on the source code and CFG traversing to measure the checkpoint-separated subpaths, which may be unavailable for commodity software and cause possible context missing between consecutive subpaths in the measurements. Xinzhi Liu, Cong Sun 0001, Dongrui Zeng, Gang Tan, Xiao Kan, Siqi Ma 0001 |
ACSAC | 3 |
| 2021 | Delica: Decentralized Lightweight Collective Attestation for Disruptive IoT NetworksabstractThe recent advance of the Internet of Things and autonomous systems brings massive security threats to the network of low-end embedded devices. Remote attestation is a hardware-assisted technique to verify the integrity and trustworthiness of software on remote devices. The recently proposed collective remote attestations have focused on attesting to the highly dynamic and disruptive device networks. However, they are generally inefficient due to the homogeneous node setting for the robustness of attestation reports aggregation. In this work, we propose Delica, an efficient and robust collective attestation framework for dynamic and disruptive networks. We differentiate the role of provers and aggregators to limit the redundant communications and attestation evidence aggregations for efficiency. Delica is capable of mitigating DoS attacks and detecting physical and black-hole attacks. The experimental results and analysis show that Delica can greatly reduce the per-node computational cost and reduce the network attestation cost by over 75% compared with the state-of-the-art approaches on disruptive networks. Cong Sun 0001, Qingsong Yao, Duo Ding, Jianfeng Ma 0001 |
ICPADS | 2 |
| 2021 | Fine with "1234"? An Analysis of SMS One-Time Password Randomness in Android AppsabstractA fundamental premise of SMS One-Time Password (OTP) is that the used pseudo-random numbers (PRNs) are uniquely unpredictable for each login session. Hence, the process of generating PRNs is the most critical step in the OTP authentication. An improper implementation of the pseudo-random number generator (PRNG) will result in predictable or even static OTP values, making them vulnerable to potential attacks. In this paper, we present a vulnerability study against PRNGs implemented for Android apps. A key challenge is that PRNGs are typically implemented on the server-side, and thus the source code is not accessible. To resolve this issue, we build an analysis tool, OTP-Lint, to assess implementations of the PRNGs in an automated manner without the source code requirement. Through reverse engineering, OTP-Lint identifies the apps using SMS OTP and triggers each app's login functionality to retrieve OTP values. It further assesses the randomness of the OTP values to identify vulnerable PRNGs. By analyzing 6,431 commercially used Android apps downloaded from Google Play and Tencent Myapp, OTP-Lint identified 399 vulnerable apps that generate predictable OTP values. Even worse, 194 vulnerable apps use the OTP authentication alone without any additional security mechanisms, leading to insecure authentication against guessing attacks and replay attacks. Siqi Ma 0001, Juanru Li, Hyoungshick Kim, Elisa Bertino, Surya Nepal, Diethelm Ostry, Cong Sun 0001 |
ICSE | 7 |
| 2021 | Refining Indirect Call Targets at the Binary Level
Sun Hyoung Kim, Cong Sun 0001, Dongrui Zeng, Gang Tan |
NDSS | 2 |
| 2021 | Sdft: A PDG-based Summarization for Efficient Dynamic Data Flow TrackingabstractDynamic taint analysis (DTA) has been widely used in various security-relevant scenarios that need to track the runtime information flow of programs. Dynamic binary instrumentation (DBI) is a prevalent technique in achieving effective dynamic taint tracking on commodity hardware and systems. However, the significant performance overhead incurred by dynamic taint analysis restricts its usage in production systems. Previous efforts on mitigating the performance penalty fall into two categories, parallelizing taint tracking from program execution and abstracting the tainting logic to a higher granularity. Both approaches have only met with limited success. In this work, we propose Sdft, an efficient approach that combines the precision of DBI-based instruction-level taint tracking and the efficiency of function-level abstract taint propagation. First, we build the library function summaries automatically with reachability analysis on the program dependency graph (PDG) to specify the control- and data dependencies between the input parameters, output parameters, and global variables of the target library. Then we derive the taint rules for the target library functions and develop taint tracking for library function that is tightly integrated into the state-of-the-art DTA framework Libdft. By applying our approach to the core C library functions of glibc, we report an average of 1.58x speed up of the tracking performance compared with Libdft64. We also validate the effectiveness of the hybrid taint tracking and the ability on detecting real-world vulnerabilities. Xiao Kan, Cong Sun 0001, Shen Liu 0002, Yongzhe Huang, Gang Tan, Siqi Ma 0001 |
QRS | 2 |
| 2019 | Privacy-Preserving Verification and Root-Cause Tracing Towards UAV Social NetworksabstractUnmanned Aerial Vehicles (UAV) have rapidly developed and been widely applied to military and civilian applications in recent years. Anomaly Detections and finding out the root causes are critically important for UAV social network security. In the UAV social networks, the drone can communicate with one another directly in a form of leading flights with followers during a far away mission. The ground controller cannot get their information directly. Besides, none of the works consider the privacy protection and anomaly root cause tracing during the distributed detection. This paper presents a self-verification approach among UAV flights which can check whether the flights have honestly obeyed the orders or suffered the anomalies. Besides, we do the verification without looking through the plaintext records or data of the drones. Finally, to instruct the drones to solve the problems, we trace the fundamental root causes leading to the anomalies by learning the fault tree. We apply our approach on raw UAV social network data and align our experiment with two former works as baselines for comparison. Our approach can reduce the time cost of verification from exponential growth to linear growth and improve the tracing accuracy rate around 4.3% higher than the former work. Teng Li 0003, Jianfeng Ma 0001, Qingqi Pei, Chengyan Ma 0001, Dawei Wei, Cong Sun 0001 |
ICC | 6 |
| 2019 | SRDPV: secure route discovery and privacy-preserving verification in MANETs
Teng Li 0003, Jianfeng Ma 0001, Cong Sun 0001 |
Wirel. Networks | 3 |
| 2018 | Information flow control on encrypted data for service composition among multiple clouds
Ning Xi 0002, Jianfeng Ma 0001, Cong Sun 0001, Di Lu 0001, Yulong Shen 0001 |
Distributed Parallel Databases | 3 |
| 2018 | Dlog: diagnosing router events with syslogs for anomaly detection
Teng Li 0003, Jianfeng Ma 0001, Cong Sun 0001 |
J. Supercomput. | 3 |
| 2017 | Data-Oriented Instrumentation against Information Leakages of Android ApplicationsabstractAs one of the most prominent threat, information leakages usually take sensitive data from some private sources and improperly release the data through malicious or misused method invocations and intercommunications. As a countermeasure against this threat, a number of detection approaches have been developed based on static analysis, esp. taint analysis. But we still have not reached a satisfactory solution to the patching and mitigation against this threat. In this paper, we propose an approach to automatically instrument malicious Android applications with cryptographic primitives and data randomization. With the help of an off-the-shelf taint analyzer, we detect the parts of code that might leak private information. In order to mitigate these information leakages, the standard cipher transformations and randomization are used to enforce different security policies according to the positions of related information sinks and intermediate system calls along malicious flow paths. The evaluation on different benchmark suites and real-world applications demonstrates that our approach can avoid false positives and mitigate around 91% information leakages in real applications, with acceptable cost on analysis and instrumentations affordable by desktops. Cong Sun 0001, Pengbin Feng, Teng Li 0003, Jianfeng Ma 0001 |
COMPSAC (2) | 1 |
| 2017 | Enforcing Generalized Refinement-Based Noninterference for Secure Interface CompositionabstractInformation flow security has been considered as a critical requirement on complicated component-based software. The recent efforts on the compositional information flow analyses were limited on the expressiveness of security lattice and the efficiency of compositional enforcement. Extending these approaches to support more general security lattices is usually nontrivial because the compositionality of information flow security properties should be properly treated. In this work, we present a new extension of interface automaton. On this interface structure, we propose two refinement-based security properties, adaptable to any finite security lattice. For each property, we present and prove the security condition that ensures the property to be preserved under composition. Furthermore, we implement the refinement algorithms and the security condition decision procedure. We demonstrate the usability and efficiency of our approach with in-depth case studies. The evaluation results show that our compositional enforcement can effectively reduce the verification cost compared with global verification on composite system. Cong Sun 0001, Ning Xi 0002, Jianfeng Ma 0001 |
COMPSAC (1) | 1 |
| 2017 | VuRLE: Automatic Vulnerability Detection and Repair by Learning from Examples
Siqi Ma 0001, Ferdian Thung, David Lo 0001, Cong Sun 0001, Robert H. Deng |
ESORICS (2) | 4 |
| 2017 | Certia: Certifying Interface Automata for Cyber-Physical SystemsabstractInterface automaton is a promising approach to model the temporal behaviors of system components, and its extension has been used to specify the security properties of component based systems. Currently, the formal properties of interface automata have not be certified with machine-checked proof by any proof assistant. In this work, we propose a Coq-library of interface automata which is developed in purpose to certify security properties of component-based cyber-physical systems, with an emphasis upon developing compositional verification of information flow security for cyber-physical applications. Cong Sun 0001, Qingsong Yao, Jianfeng Ma 0001 |
SMARTCOMP | 1 |
| 2017 | NetPro: detecting attacks in MANET routing with provenance and verification
Teng Li 0003, Jianfeng Ma 0001, Cong Sun 0001 |
Sci. China Inf. Sci. | 3 |
| 2017 | Credit-based scheme for security-aware and fairness-aware resource allocation in cloud computing
Di Lu 0001, Jianfeng Ma 0001, Cong Sun 0001, XinDi Ma, Ning Xi 0002 |
Sci. China Inf. Sci. | 3 |
| 2016 | Measuring the risk value of sensitive dataflow path in Android applicationsabstractAbstract Nowadays, smartphones carry large amounts of user privacy and sensitive data. With the popularity of the Android operating system, the cases of sensitive date leakage in Android applications are on the rise and are causing a great loss to Android users. In order to mitigate this condition, static and dynamic taint analysis are applied to precisely detect sensitive data leakages. These approaches cannot distinguish sensitive data leakages in benign apps from the ones in malicious apps. Recently, the difference on sensitive data flows between benign apps and malicious apps has been found to be significant. In this paper, we further find that there exists great difference between benign and malicious apps on the frequencies of sensitive dataflow paths. This difference can be used to enforce a risk value over every sensitive dataflow path. This risk value can guide the identification of sensitive data leakages in malicious apps. We present RISKPATH, a tool that automatically calculates the risk values for sensitive dataflow paths in Android applications. Applying the result of RISKPATH to MUDFLOW framework, we increase the true positive rate of malware detection by 3.96–6.54% on different datasets with reasonable increase in time and memory consumption. Copyright © 2017 John Wiley & Sons, Ltd. Pengbin Feng, Cong Sun 0001, Jianfeng Ma 0001 |
Secur. Commun. Networks | 2 |
| 2015 | Active Semi-supervised Approach for Checking App Behavior against Its DescriptionabstractMobile applications are popular in recent years. They are often allowed to access and modify users' sensitive data. However, many mobile applications are malwares that inappropriately use these sensitive data. To detect these malwares, Gorla et al. Propose CHABADA which compares app behaviors against its descriptions. Data about known malwares are not used in their work, which limits its effectiveness. In this work, we extend the work by Gorla et al. By proposing an active and semi-supervised approach for detecting malwares. Different from CHABADA, our approach will make use of both known benign and malicious apps to predict other malicious apps. Also, our approach will select a good set of apps for experts to label as malicious or benign to form a set of labeled training data -- it is an active approach. Furthermore, it will make use of both labeled data (known malicious or benign apps) and unlabeled data (unknown apps) -- it is a semi-supervised approach. We have evaluated our approach by using a set of 22,555 Android apps. Our approach achieves a good performance in detecting malicious apps with a precision of 99.82%, recall of 92.50%, and F-measure of 96.02%. Our approach improves CHABADA by 365.8%, 64.8%, 209.6% in terms of precision, recall, and F-measure. Siqi Ma 0001, Shaowei Wang 0002, David Lo 0001, Robert H. Deng, Cong Sun 0001 |
COMPSAC | 5 |
| 2015 | CRVad: Confidential Reasoning and Verification Towards Secure Routing in Ad Hoc Networks
Teng Li 0003, Jianfeng Ma 0001, Cong Sun 0001 |
ICA3PP (3) | 3 |
| 2015 | Secure service composition with information flow control in service clouds
Ning Xi 0002, Cong Sun 0001, Jianfeng Ma 0001, Yulong Shen 0001 |
Future Gener. Comput. Syst. | 2 |
| 2014 | Verifying Secure Interface Composition for Component-Based System DesignsabstractInformation flow security has been considered as a critical requirement on software systems, especially when heterogeneous components from different parties cooperate to achieve end-to-end enforcement on data confidentiality. Enforcing the information flow security properties on complicated systems faces a great challenge because the properties cannot be preserved under composition and most of the current approaches are not scalable enough. To address this problem, there have been several recent efforts on the compositional information flow analyses developed for different abstraction levels. But these approaches have rarely been considered to incorporate with the process of system design. Integrating the security enforcement with the model-based development process can provide the designer with ability to verify information flow security in the early stage of system development. We propose a compositional information flow verification which is integrated with model-based system design in Sys ML by an automated model translation from semi-formal behavior and structure models to interface automata. Our compositional approach is general to support the complex security lattices and a variety of in distinguish ability relations. The evaluation results show the usability of our approach on practical system designs and the scalability of the compositional verification. Cong Sun 0001, Ning Xi 0002, Jinku Li, Qingsong Yao, Jianfeng Ma 0001 |
APSEC (1) | 1 |
| 2014 | Automated enforcement for relaxed information release with reference points
Cong Sun 0001, Ning Xi 0002, Sheng Gao 0002, Zhong Chen 0001, Jianfeng Ma 0001 |
Sci. China Inf. Sci. | 1 |
| 2014 | Trust-based service composition in multi-domain environments under time constraint
Tao Zhang 0029, Jianfeng Ma 0001, Qi Li 0011, Ning Xi 0002, Cong Sun 0001 |
Sci. China Inf. Sci. | 5 |
| 2014 | Balancing trajectory privacy and data utility using a personalized anonymization model
Sheng Gao 0002, Jianfeng Ma 0001, Cong Sun 0001, Xinghua Li 0001 |
J. Netw. Comput. Appl. | 3 |
| 2013 | Decentralized Information Flow Verification Framework for the Service Chain Composition in Mobile Computing EnvironmentsabstractDynamic service composition in wireless environment provides us with a promising approach to build complex applications based on the basic value-added services. In different network domains, multiple services may provide data with different security levels. In order to prevent from information leakage, information flow security is a major concern in composite services. However, the energy-limited nature of user terminal in mobile computing environments poses a significant challenge for the centralized information flow verification where the verification node need cost lots of computation and network resources. In this paper, we specify the security constraints for each service participant to secure the information flow in service chain based on the lattice model, and then present a decentralized information flow verification framework that cooperates different service participants to complete the verification process distributively with respect to their information flow policies. Through the experiments and evaluations, the results show it decreases the verification cost on single service node. Ning Xi 0002, Jianfeng Ma 0001, Cong Sun 0001, Tao Zhang 0029 |
ICWS | 3 |
| 2013 | Service Composition in Multi-domain Environment under Time ConstraintabstractTime constrained service composition raises several problems. Researches on QoS-driven service composition provide some preliminary solutions, but there are still some unsolved issues, which can be attributed to the following reasons: (1) the huge time consumption of inter-domain validation, (2) the dynamic execution time of services and (3) the difficulty in defining time constraint due to the opaque feature of composite services. In this paper, we propose a novel service composition algorithm, which models the service composition as multi-domain scheduling problem with minimal service resources and time constraint. Each service is modeled as an exclusive resource during its execution period. By computing the inter-domain communications and available services in each domain, the domain with optimal utilization rate is obtained to arrange services. Meanwhile, loop parallelization is adopted when a service cannot be executed on schedule. Moreover, redundant services of the initial composition are further optimized. Our experiment results show that our approach can effectively achieve service composition with time constraint. Tao Zhang 0029, Jianfeng Ma 0001, Cong Sun 0001, Qi Li 0011, Ning Xi 0002 |
ICWS | 3 |
| 2013 | TrPF: A Trajectory Privacy-Preserving Framework for Participatory SensingabstractThe ubiquity of the various cheap embedded sensors on mobile devices, for example cameras, microphones, accelerometers, and so on, is enabling the emergence of participatory sensing applications. While participatory sensing can benefit the individuals and communities greatly, the collection and analysis of the participators' location and trajectory data may jeopardize their privacy. However, the existing proposals mostly focus on participators' location privacy, and few are done on participators' trajectory privacy. The effective analysis on trajectories that contain spatial-temporal history information will reveal participators' whereabouts and the relevant personal privacy. In this paper, we propose a trajectory privacy-preserving framework, named TrPF, for participatory sensing. Based on the framework, we improve the theoretical mix-zones model with considering the time factor from the perspective of graph theory. Finally, we analyze the threat models with different background knowledge and evaluate the effectiveness of our proposal on the basis of information entropy, and then compare the performance of our proposal with previous trajectory privacy protections. The analysis and simulation results prove that our proposal can protect participators' trajectories privacy effectively with lower information loss and costs than what is afforded by the other proposals. Sheng Gao 0002, Jianfeng Ma 0001, Weisong Shi, Guoxing Zhan, Cong Sun 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2012 | Verifying Location-Based Services with Declassification Enforcement
Cong Sun 0001, Sheng Gao 0002, Jianfeng Ma 0001 |
APWeb | 1 |
| 2011 | A Multi-compositional Enforcement on Information Flow Security
Cong Sun 0001, Ennan Zhai, Zhong Chen 0001, Jianfeng Ma 0001 |
ICICS | 1 |