Jian Lin 0007

dblp:46/6839-7 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
5since 2021 · last 2026
0000-0002-8504-5480ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 ROParser: A high-efficient framework for return-oriented programming deobfuscation
Tieming Liu, Jian Lin 0007, Zuozheng Zhou, Jing Jing 0004
Comput. Secur.4
2025 Proteus: An Automatical High-Efficiency Framework for Generating Compact and Printable Shellcode on ARMv8
abstract
Printable shellcode, composed entirely of printable characters, offers significant advantages over traditional shellcode by enhancing its resilience against filtering or modification.However, existing printable shellcode generation methods for the prevalent ARMv8 architecture produce excessively large shellcode, limiting their practicality in real-world exploitation scenarios.This paper addresses the limitation by proposing innovative framework for generating compact printable shellcode on ARMv8 architectures.And we implemented the prototype system, named Proteus.Proteus introduced two key techniques.The first technique involves an embedded instruction patcher that automatically generates the necessary backward jump instruction for the decoding loop during runtime, significantly minimizing the decoder's static footprint.The second technique employs a compact encoding algorithm that transforms arbitrary three-byte sequences into four printable characters, thereby drastically reducing encoding overhead.Thus, Proteus has the capability to efficiently convert arbitrary ARMv8 shellcode into its printable equivalent.The comprehensive evaluation results demonstrate the feasibility and significant performance enhancements compared to the state-of-the-art work.The information redundancy of encoding algorithm is reduced from 1 down to 0.25, and the decoder length is dramatically shrunk from 4320 bytes to just 180 bytes.
Jian Lin 0007, Guoan Liu
Internetware1
2025 Devmp: A Virtual Instruction Extraction Method for Commercial Code Virtualization Obfuscators
abstract
In code virtualization deobfuscation, extracting virtual instructions is a crucial first step for reverse-engineering programs protected by virtual machine obfuscation.This process is essential for uncovering concealed malicious code, yet existing methods face significant limitations, such as the inability to resolve virtual branch jumps and support multi-version of specified obfuscators, severely hindering their effectiveness.To address these challenges, we introduce a novel method for virtual instruction extraction based on dynamic binary instrumentation and symbolic execution.We implement this method in Devmp, a prototype system designed to extract virtual instructions and facilitate virtualization deobfuscation.Devmp dynamically generates instruction traces through binary instrumentation and performs offline analysis to partition handler sets based on virtual machine structures and jump rules.Then it employs symbolic execution to derive state expressions for semantic analysis of handlers and extracts virtual instructions with complete semantics.We evaluate Devmp on eight test programs protected by two versions of VMProtect.Experimental results demonstrate that Devmp outperforms state-of-the-art tools like VMP Analysis Plugin and NoVmpy, achieving a 28.49% increase in virtual instruction recognition rate by optimized virtual branch processing and accurately analyzing all extracted virtual instructions through enhanced cross-version applicability.These results indicate that Devmp not only improves the accuracy and completeness of virtual instruction extraction but also provides a robust and versatile solution for analyzing programs obfuscated by commercial code virtualization obfuscators.
Shenqianqian Zhang, Weiyu Dong, Jian Lin 0007
Internetware3
2023 EnBinDiff: Identifying Data-Only Patches for Binaries
abstract
In this article, we focus ondata-onlypatches, a specific type of security patchesnot incurring any structural changes. As one of the most significant causes leading to false negatives, data-only patches become a fundamental problem that affects all state-of-the-art binary diffing approaches/tools. To this end, we first systematically study data-only patches, and thoroughly illustrate the essence and adverse effect on existing tools. Based on the observations, we further propose and implement a system namedEnBinDiffbased on Value Set Analysis (VSA) to effectively identify data-only patches. Specifically,EnBinDifffirst precisely identifies functions from binaries, and then efficiently locates all “matched” function pairs based on structural binary diffing. After that,EnBinDiffperformsdata-only patch analysis, including stack frame matching and constant value matching, to identify data-only patches from the matched functions. To demonstrate the effectiveness ofEnBinDiff, we conduct an extensive evaluation with multiple datasets. The results demonstrate that the proposed system outperforms state-of-the-art binary diffing tools, and the false negative rate is reduced from 11.02% to 1.63%. Furthermore, we applyEnBinDiffto analyze real-world binaries, and successfully identify 20 1-day vulnerabilities.
Jian Lin 0007, Dingding Wang 0003, Lei Wu 0012, Yajin Zhou, Kui Ren 0001
IEEE Trans. Dependable Secur. Comput.1
2022 CaDeCFF: Compiler-Agnostic Deobfuscator of Control Flow Flattening
abstract
With the increasing influence of malware and various attacks, malware detection methods have been continuously proposed. However, in order to evade malware detection, code obfuscation which makes programs harder to understand, is widely used by malware writers. Control Flow Flattening (CFF) is a common control-flow obfuscation method. However, Control Flow Flattening deobfuscation tools have a low success rate for compilation-optimized binaries because the structural features on which the tools depend have changed.
Weiyu Dong, Jian Lin 0007
Internetware2