Qian Sang

dblp:55/7141 · DBLP profile ↗
← Back
4ranked-venue papers
3as first author
2since 2021 · last 2024
0000-0001-7377-7812ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 2 · 2 first-authorSecurity and privacy · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
2 papers
Program analysis · 100%
Network and information security
2 papers
Systems and software security · 100%

Topics — the 5 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
vulnerability discovery
1.322024
AirTaint: Making Dynamic Taint Analysis Faster and Easier · SP 2024
HTFuzz: Heap Operation Sequence Sensitive Fuzzing · ASE 2022
Program analysis
dynamic analysis
0.922024
AirTaint: Making Dynamic Taint Analysis Faster and Easier · SP 2024
HTFuzz: Heap Operation Sequence Sensitive Fuzzing · ASE 2022
Program analysis › static analysis
taint analysis
0.812024
AirTaint: Making Dynamic Taint Analysis Faster and Easier · SP 2024
Systems and software security › vulnerability discovery
fuzzing
0.612022
HTFuzz: Heap Operation Sequence Sensitive Fuzzing · ASE 2022
Program analysis › dynamic analysis
instrumentation
0.212024
AirTaint: Making Dynamic Taint Analysis Faster and Easier · SP 2024

Methods — techniques the papers use, named apart from their topics

instruction-level emulation · 1.5basic block-level abstraction · 1.5coverage-guided fuzzing · 1.1
YearPublicationVenuePosition
2024 AirTaint: Making Dynamic Taint Analysis Faster and Easier
abstract
Dynamic Taint Analysis (DTA) is a widely used data flow tracking technique and helps security researchers in various applications, such as fuzzing and vulnerability analysis. One critical problem that affects its practicability is the significant overhead. According to our analysis, in some scenarios, the state-of-the-art works even slow the program execution efficiency by more than 100x. The high overhead is mainly because most of them conduct taint analysis at the instruction level and use just-in-time instrumentation methods to insert the tracking codes into the original program.In this paper, we propose AirTaint, a novel approach that combines the basic block-level abstraction of taint rules and assembly code-level instrumentation to conduct high-level dynamic taint analysis. Specifically, AirTaint leverages instruction-level emulation to identify the in and out operands (i.e., registers and memory variables) of each basic block, and then uses the existing taint engine to infer the taint rule abstraction for each basic block. Finally, it inserts the assembly code of the taint rule abstraction into the original program. While running, the program will execute the inserted taint analysis code quickly. In our evaluation based on 14 CVEs in 9 real-world applications, AirTaint detects all these vulnerabilities successfully. And in the comparison experiments, AirTaint performs much better than the existing tools in efficiency on 29 real-world applications, with maximum improvements of 931.0x, 5.97x, and 328.3x than libdft, SelectiveTaint, and TaintRabbit, respectively.
Qian Sang, Yuwei Liu 0001, Xiangkun Jia, Tiffany Bao, Purui Su
SP1
2022 HTFuzz: Heap Operation Sequence Sensitive Fuzzing
abstract
Heap-based temporal vulnerabilities (i.e., use-after-free, double-free and null pointer dereference) are highly sensitive to heap operation (e.g., memory allocation, deallocation and access) sequences. To efficiently find such vulnerabilities, traditional code coverage-guided fuzzing solutions could be promoted by integrating heap operation sequence feedback. But current sequence sensitive solutions have limitations in practice.
Yuanping Yu, Xiangkun Jia, Yuwei Liu 0001, Qian Sang, Chao Zhang 0008, Purui Su
ASE5
2016 Learning automata for image segmentation
Qian Sang, Zongli Lin, Scott T. Acton
Pattern Recognit. Lett.1
2015 A grid-based tracker for erratic targets
Qian Sang, Zongli Lin, Scott T. Acton
Pattern Recognit.1