Guofei Gu

dblp:64/1147 · DBLP profile ↗
← Back
130ranked-venue papers
10as first author
31since 2021 · last 2026
0000-0003-0630-741XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 101 · 10 first-author · 24 since 2021Computer networks · 19 · 5 since 2021Systems, architecture and hardware · 9 · 2 since 2021Databases, data management, data science and information retrieval · 5 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 since 2021Artificial intelligence and machine learning · 1
YearPublicationVenuePosition
2026 Demystifying Progressive Web Application Permission Systems
abstract
Progressive Web Applications (PWAs) blend the advantages of web and native apps, offering features like offline access, push notifications, and installability. Beyond these, modern PWAs are increasingly granted system-level capabilities such as auto-start on login and shared context with native applications. However, their permission management remains poorly defined and inconsistently implemented across platforms and browsers. To investigate these gaps, we developed Permissioner, a cross-platform analysis tool, and conducted a systematic study of PWA permissions. Our analysis uncovered critical issues of inconsistency, incompleteness, and unclear boundaries in permission enforcement, leading to various attacks including permission leakage, device identification, and Permission API abuse. We further examined why some browsers resist adopting more granular permission controls, identifying trade-offs involving usability, compatibility, and platform limitations. Through collaboration with browser vendors, several issues reported in our findings were acknowledged and resolved, notably by Firefox and Chrome. Our work highlights the urgent need for a unified, robust permission model for PWAs and provides actionable guidance toward achieving this goal.
Mengxiao Wang, Guofei Gu
DSN3
2026 On the Security Risks of Memory Adaptation and Augmentation in Data-plane DoS Mitigation
Hocheol Nam 0001, Daehyun Lim, Huancheng Zhou, Guofei Gu, Min Suk Kang
NDSS4
2025 Demystifying the Perceptions Gap Between Designers and Practitioners in Two Security Standards
abstract
Although widely adopted, the effectiveness of corporate security standards like ISO 27001 and NIST CSF is not well established. Budgetary restrictions, skills shortages, existing infrastructure, adoption difficulties, and usability challenges can hinder the implementation of complete security measures. As a result, organizations can opt to adopt only part of the available security procedures. Among the different security techniques and validations available, many companies choose to follow security standards such as the NIST Cybersecurity Framework or ISO 27001:2013, which consist of many individual guidelines. However, some of these guidelines may be outdated, unclear, or incapable of addressing new technologies, resulting in insufficient practical and actionable security improvements. We conducted two studies to understand the perceptions and pain points of practitioners. In the first study, 30 security experts evaluated the perceived effectiveness of the 113 ISO 27001 guidelines and the 108 NIST Cybersecurity Framework guidelines, ranking them as High, Medium or Low. They also provided their perspectives and insights behind the total 1326 ratings and what areas of improvement existed in the standards. Building on the initial study’s recommendations, we engaged 14 additional security experts to explore the pain points and potential changes in security systems through in-depth interviews. Our findings indicate that in order to enhance the perception and effectiveness of the standards, timely updates, flexibility, maintainability, cost-effectiveness, and the ability to impact technical security are needed.
Shreyas Kumar, Evelyn Crowe, Guofei Gu
EuroS&P3
2025 Incentivizing Security Excellence in Cyber Liability Insurance
abstract
This paper investigates current practices and inherent shortcomings in Cyber Liability Insurance (CLI), highlighting critical gaps due to inconsistent risk assessment methodologies and weak incentives for cybersecurity excellence. We employ a mixed-method research design that combines a quantitative pilot study of 209 businesses, direct policy-purchasing experiments, and structured interviews with 26 Chief Information Security Officers (CISO). The findings reveal significant premium variations—from $600 to nearly $7,000 for identical coverages—due primarily to inconsistent security assessments and policy complexities. Furthermore, empirical policy acquisitions demonstrated that multiple insurers approved coverage with minimal or no cybersecurity diligence, underscoring systemic issues in insurer incentive alignment. Based on these insights, we propose a structured framework advocating customized dynamic cyber liability policies with risk-based premiums, stan-dardized assessments, and incentives aligned with proactive cybersecurity practices. This framework promotes transparency, incentivizes better security practices, and outlines clear directions for future research, contributing toward a more responsive cyber-liability insurance market.
Shreyas Kumar, Paula deWitte, Guofei Gu
EuroS&P3
2025 "Alexa, Is Dynamic Content Safe?" Understanding the Risks of Dynamic Content in the Alexa Skill Ecosystem
abstract
Despite the increasing popularity of voice assistants such as Amazon Alexa, the security implications of dynamic skill content (content modifiable without resubmission) in voice assistant skills (voice-activated applications) remain largely unexplored. This paper presents the first large-scale analysis of Alexa's dynamic content ecosystem using D-Explorer, a ChatGPT powered chatbot. From a dataset of 10,407 skill interactions, we investigate: 1) the mechanisms of Alexa dynamic content, 2) the associated security risks, and 3) the prevalence of these risks in published skills. Our analysis reveals that 34% of skills contain dynamic content in interactions, 95% access external resources (increasing attack vectors), 7% of skill conversations exhibit problematic (potentially harmful or privacy-infringing) interactions related to dynamic content, and 90% of skills connect to a potentially vulnerable dynamic resource during interaction. These findings expose significant vulnerabilities, highlighting the critical need for stricter developer rules and security measures to prevent unpredictable, harmful, and privacy compromising interactions within the Alexa skill ecosystem.
Nathan McClaran, Payton Walker, Yangyong Zhang, Nitesh Saxena, Guofei Gu
WISEC6
2025 Beyond Visual Confusion: Understanding How Inconsistencies in ENS Normalization Facilitate Homoglyph Attacks
abstract
In recent years, the Ethereum Name Service (ENS) has garnered significant attention within the community for enabling the use of Unicode in domain names, thereby facilitating the inclusion of a wide array of character sets such as Greek, Cyrillic, Arabic, and Chinese. While this feature enhances the versatility and global accessibility of domain names, it concurrently introduces a substantial security vulnerability due to the presence of homoglyphs-characters that are visually similar to others across Unicode and ASCII sets. These similarities can be exploited in homoglyph attacks, posing a distinct threat to domain name integrity. Despite community efforts to counteract this issue through a normalization process prior to domain resolution, our analysis uncovers significant discrepancies in how the normalization processes are applied across various applications. This inconsistency could result in the same domain name being resolved to different addresses in different applications, underscoring a critical vulnerability. We also discovered the new attack scenario in ENS which may cause legitimate domains resolved into malicious addresses even when they are verified by authorities. To systematically evaluate this inconsistency, we designed a tool for detecting application-level discrepancies in domain normalization process without requiring access to the application's source code. Our evaluation on hundreds of real-world Web3 applications identifies widespread deviations from established homoglyph mitigation practices, with more than 60% digital wallets and 80% dApps (decentralized applications) not able to produce consistent ENS resolving results, potentially impacting millions of users. This analysis underscores the urgent need for a standardized implementation of normalization processes to safeguard the integrity and security of ENS domains.
Sridatta Raghavendra Chintapalli, Mengxiao Wang, Guofei Gu
WWW4
2025 Update If You Dare: Demystifying Bare-Metal Device Firmware Update Security of Appified IoT Systems
abstract
Due to the economy and low power consumption features, bare-metal IoT devices have been widely used in various areas of our life, and they are usually paired with companion mobile apps to configure them and view their states (a.k.a., appified IoT system). The IoT systems have already become the lucrative and profitable targets for attackers because the compromised IoT devices will pose severe threats to IoT security and reliability. This problem become worse on bare-metal IoT devices since the tradeoff among price, functionality, performance, and energy efficiency usually results in insufficient security protection. Such bare-metal IoT devices usually adopt OTA (Over-The-Air) methods to update firmware, which is managed by the companion apps running on smartphones. Despite the prevalence of these appified IoT systems, there is a lack of systematic research on the security of bare-metal IoT device firmware update (DFU), although recent studies have reported security flaws in such systems. In this article, we propose a holistic approach to investigate DFU security of these appified IoT systems through collaborative analyzing the bare-metal firmware and the companion app. Additionally, we have developed an IoT system analysis framework named$\mathsf{BareDFU}$to automate the complex and time-consuming analysis tasks and facilitate the investigation. After applying$\mathsf{BareDFU}$to analyze 1,637 companion IoT apps, we found 710 of them contained security flaws spanning all three DFU stages: authentication, firmware acquisition, and firmware verification. Furthermore, we leveraged$\mathsf{BareDFU}$to investigate the bare-metal DFU security of six commercial appified IoT systems, and discovered they all had DFU flaws, which we successfully exploited to launch proof-of-concept firmware modification attacks. The affected vendors have acknowledged our findings and addressed the security flaws.
Lei Xue 0001, Yuxiao Yan, Qiyi Tang 0003, Le Yu 0002, Xiapu Luo, Sen Nie, Shi Wu, Guofei Gu, Chenxu Wang 0001
IEEE Trans. Dependable Secur. Comput.9
2025 Driving State-Aware Anomaly Detection for Autonomous Vehicles
abstract
With the increasing popularity of autonomous driving systems (ADS) in autonomous vehicles (AV), in recent years, there have been many attacks targeting AVs and ADSs. Meanwhile, recent studies have attempted to improve the safety and security of AVs from different perspectives, and they mainly focus on the spoofing attacks against the sensors and the injection attacks against the vehicle chassis and actuators. However, direct attacks on ADSs (i.e., communication hijacking and malicious codes) remain inadequately addressed, and even worse, such attacks can cause AVs to make unsafe driving decisions rapidly. In this paper, we introduceDSAD, a driving state-aware anomaly detection framework designed to enhance AV safety and security by identifying ADS attacks, such as communication hijacking and malicious codes, through chassis states. First,DSADmodels ADS operations (i.e., driving states) as a two-layer state machine, utilizing real-time chassis data to infer driving states and detect anomalies in ADS outputs. This reduces false positives and negatives by aligning detection with the diverse operational modes of AVs. To achieve this, we develop a prototype system,DSAD, incorporating a Detection Policy Update mechanism that dynamically adjusts detection policies based on the vehicle’s driving states, such as lane changing and obstacle avoidance. Second,DSADconsiders both collision avoidance and control stability, addressing potential conflicts through hard and soft requirements. Furthermore,DSADintegrates a fault handling module compatible with existing autonomous driving fault handling mechanisms, ensuring timely response to detected anomalies. We develop a prototype anomaly detection system calledDSADand deploy it on four ADSs. We evaluateDSADusing various attack scenarios, and the results show thatDSADcan identify over 90% of attacks on ADSs.
Lei Xue 0001, Xiapu Luo, Xiaobo Ma 0001, Guofei Gu
IEEE Trans. Inf. Forensics Secur.5
2024 WIRE: Web3 Integrated Reputation Engine
abstract
Distributed Applications (DApps), powered by smart contracts, have sparked a significant transformation in the Web3 ecosystem by enabling the execution of real-world contracts on decentralized networks. However, the growing popularity of DApps has also led to an increase in malicious activities exploiting smart contracts, thereby exposing users to greater financial risks. Inspired by the FICO score system in traditional finance, we introduce WIRE, a reputation engine designed to evaluate the trustworthiness of deployed DApps. WIRE first derives diverse properties from contract activities, rather than relying solely on potentially irrelevant or unavailable source code. Based on selected properties, WIRE trains a machine learning model for assessing the trustworthiness of individual contracts. Further-more, WIRE utilizes a bytecode disassembler to identify related contracts of a DApp, thus determining its overall trustworthiness score. Moreover, WIRE's dashboard offers explainable and detailed reports that are accessible to users without professional knowledge. The evaluation results show that WIRE can provide a reliable and explainable reputation score for DApps. As a result, WIRE's users can distinguish between benign and malicious DApps or contracts with a high confidence.
Suraj Shamsundar Jain, Huancheng Zhou, Guofei Gu
ICDCS3
2024 Cerberus: Enabling Efficient and Effective In-Network Monitoring on Programmable Switches
abstract
With the increasing volume of network traffic and the emergence of new types of attacks, traditional network monitoring is facing significant challenges in ensuring network security and performance. In-network monitoring (INM) systems based on programmable switches, e.g., P4-based INM systems, have emerged as a more promising approach for high-performance and real-time network monitoring. However, existing P4-based INM systems have resource limitations in handling diverse and high-volume INM tasks such as multi-vector DDoS defenses. Worse still, attackers may try to dynamically change attack vectors to disrupt inadaptable systems and even lead to denial-of-service (DoS) attacks against INM.To address these challenges, we present Cerberus, an efficient and effective in-network security monitoring system. To support various INM tasks, we abstract them into key-feature (K-F) pairs and design a novel memory slicing mechanism to share memory among multiple K-F pairs. To handle high-volume traffic, we propose a new co-monitoring mechanism that complements the data and control planes, thereby greatly enhancing the efficiency of Cerberus. To adapt to changing network conditions, we design a new resource manager that dynamically reallocates resources for INM tasks and adjusts loads for the data and control planes without interrupting running services. We design a series of INM modules, including DDoS defenses, and develop a prototype of Cerberus. We conduct extensive evaluations to demonstrate that Cerberus can enhance the concurrency and capacity of programmable switches by an order of magnitude. Moreover, Cerberus is more adaptable in handling various INM tasks.
Huancheng Zhou, Guofei Gu
SP2
2024 You Can Obfuscate, but You Cannot Hide: CrossPoint Attacks against Network Topology Obfuscation
Xuanbo Huang, Kaiping Xue, Lutong Chen, Mingrui Ai, Huancheng Zhou, Bo Luo, Guofei Gu, Qibin Sun
USENIX Security Symposium7
2024 Enhancing security in SDN: Systematizing attacks and defenses from a penetration perspective
Jinwoo Kim 0006, Minjae Seo, Seungsoo Lee 0001, Jaehyun Nam, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu, Seungwon Shin 0001
Comput. Networks7
2023 #DM-Me: Susceptibility to Direct Messaging-Based Scams
abstract
In an emerging scam on social media platforms, cyber-miscreants are luring users into sending them a direct-message (DM) and are subsequently exploiting the messaging channel. We term this attack approach as the DM-Me scam. We report on a survey of 214 MTurk participants, in which we make the first effort to systematically study the susceptibility of users in falling victim to DM-Me scams. We find that most participants chose to send a direct message to at least one scammer, and made such choices more than half the time. This susceptibility can be attributed to the misplaced trust in scammers and the lack of negative consequences foreseen by participants in messaging accounts that they do not fully trust. Interestingly, our results also suggest that women mostly from the 31-40 age-group and who predominantly use Instagram a few times a week are less susceptible than men to financial DM-Me scams as they appear to face more discomfort in initiating a conversation with unfamiliar accounts for such services. We conclude with future research directions in mitigating the risks posed by DM-Me scammers, specifically by developing reliable indicators to aid users in assessing the trustworthiness of an account.
Raj Vardhan, Alok Chandrawal, Phakpoom Chinprutthiwong, Yangyong Zhang, Guofei Gu
AsiaCCS5
2023 Do Users Really Know Alexa? Understanding Alexa Skill Security Indicators
abstract
Amazon Alexa’s booming third-party skill market has grown from 160 to 100,000 skills within three years. In this work, we make the first effort in demystifying the Alexa skill permission system by studying its security indicators. Our user study results show that most of the surveyed Alexa users did not understand the security implications of interacting with third parties via Alexa’s voice user interface (VUI). Despite the potential risks of undesired resource sharing, more than two-thirds of the surveyed Alexa users considered third-party skills safe because they think these skills are Alexa- or Amazon-owned applications. Together with other uncovered deficiencies of skill security indicator designs, our study indicates a pressing need for a paradigm shift in designing security indicators for VUI systems.
Yangyong Zhang, Raj Vardhan, Phakpoom Chinprutthiwong, Guofei Gu
AsiaCCS4
2023 Automatic Synthesis of Network Security Services: A First Step
abstract
In the network security life cycle, security needs are initialized by network operators and typically documented in natural languages, and later implemented and deployed in developed/acquired security appliances, typically written in a programming language by third-party developers. However, oftentimes, those security appliances/programs may not quite match the urgent and fast-evolving security needs since the whole developing/deployment procedure is very time-consuming. In this paper, we propose a novel framework, AUTOSEC, to aid network operators in building up or rapid prototyping operational network security services directly from high-level service needs as automatically as possible. AUTOSEC helps bridge the huge gap from human intents in natural language descriptions to the deliverable network security services. More specifically, AUTOSEC utilizes Natural Language Processing (NLP) techniques to infer security intents from natural language descriptions, and then performs Interactive Synthesis to assist users to validate and refine parsed intents if necessary. AUTOSEC further lever-ages Software-Defined Networking (SDN) and Network Function Virtualization (NFV) techniques to automatically compose and instantiate security services in terms of refined security intents. In the evaluation, we demonstrate the early success of AUTOSEC with security policy descriptions collected from various data sources including research papers, appliance descriptions, real-world security standards, and human-written policies.
Lei Xu 0024, Yangyong Zhang, Phakpoom Chinprutthiwong, Guofei Gu
ICCCN4
2023 Mew: Enabling Large-Scale and Dynamic Link-Flooding Defenses on Programmable Switches
abstract
Link-flooding attacks (LFAs) can cut off the Internet connection to selected server targets and are hard to mitigate because adversaries use normal-looking and low-rate flows and can dynamically adjust the attack strategy. Traditional centralized defense systems cannot locally and efficiently suppress malicious traffic. Though emerging programmable switches offer an opportunity to bring defense systems closer to targeted links, their limited resource and lack of support for runtime reconfiguration limit their usage for link-flooding defenses.We present Mew1, a resource-efficient and runtime adaptable link-flooding defense system. Mew can counter various LFAs even when a massive number of flows are concentrated on a link, or when the attack strategy changes quickly. We design a distributed storage mechanism and a lossless state migration mechanism to reduce the storage bottleneck of programmable networks. We develop cooperative defense APIs to support multi-grained co-detection and co-mitigation without excessive overhead. Mew's dynamic defense mechanism can constantly analyze network conditions and activate corresponding defenses without rebooting devices or interrupting other running functions. We develop a prototype of Mew by using real-world programmable switches, which are located in five cities. Our experiments show that the real-world prototype can defend against large-scale and dynamic LFAs effectively.
Huancheng Zhou, Sungmin Hong, Xiapu Luo, Weichao Li 0001, Guofei Gu
SP6
2023 On Detecting Route Hijacking Attack in Opportunistic Mobile Networks
abstract
In this paper, we show that Hybrid Routing and Prophet protocols in Opportunistic Mobile Networks (OMNs) are vulnerable to theCollusiveHijackattack, in which a malicious attacker, Eve, compromises a set of nodes and lies about their Inter-Contact-Times (ICTs). Eve claims that her nodes meet more frequently than in reality to hijack the routes of legitimate nodes in OMNs. The CollusiveHijack attack enables Eve to launch more severe attacks like packet modification, traffic analysis, and incentive seeking attacks. To identify the CollusiveHijack attack, we propose the Kolmogorov-Smirnov two-sample test to determine whether the statistical distribution of the packets’ delays follows the derived distribution from the ICTs among the nodes. We propose three techniques to detect the CollusiveHijack attack, the Path Detection Technique (PDT), the Hop Detection Technique (HDT), and the Early Hop Detection Technique (EHDT), which trade off compatibility with the Bundle Security Protocol, the detection rate, and the detection latency. We evaluated our techniques through extensive trace-driven simulations and a proof-of-concept system implementation and show that they can detect CollusiveHijack attacks with 80.0% to 99.4% detection rates (when Eve hijacks more than 60 packets) while maintaining a low false positive rate ($\sim$3.6%) and a short detection latency (7-14 hours) for EHDT (75%-85% enhancement compared to PDT and HDT).
Ala Altaweel, Radu Stoleru, Guofei Gu, Arnab Kumar Maity, Suman Bhunia
IEEE Trans. Dependable Secur. Comput.3
2023 NetHCF: Filtering Spoofed IP Traffic With Programmable Switches
abstract
In this paper, we identify the opportunity of using programmable switches to improve the state of the art in spoofed IP traffic filtering, and proposeNetHCF, a line-rate in-network system to filter spoofed traffic. One key challenge in the design ofNetHCFis to handle the restrictions stemmed from the limited computational model and memory resources of programmable switches. We address this by decomposing the HCF scheme into two complementary parts, by aggregating the IP-to-Hop-Count (IP2HC) mapping table for efficient memory usage, and by designing adaptive mechanisms to handle routing changes, IP popularity changes, and network activity dynamics. We implement an open-source prototype ofNetHCF, and conduct extensive evaluations. The evaluation results demonstrate thatNetHCFis able to process most legitimate traffic in 1$\mu$s, filter spoofed IP traffic effectively under network dynamics, with less than 30% of switch resource occupation.
Menghao Zhang 0001, Chang Liu 0021, Mingwei Xu 0001, Guofei Gu
IEEE Trans. Dependable Secur. Comput.6
2023 SysFlow: Toward a Programmable Zero Trust Framework for System Security
abstract
Zero Trust, as an emerging trend of cybersecurity paradigms in modern infrastructure (e.g., enterprise, cloud, edge, IoT, and 5G), is moving security defenses from static and perimeter-based control systems to focus on users and resources with no assumption of implicit trust. However, the current Zero Trust Architecture (ZTA) mainly focuses on the network security and lacks in-depth considerations on system-level security policies and abstractions, which leaves the realization of the principle incomplete. To bridge the gap, we propose an innovativeprogrammablesystem security framework called SYSFLOW to enable unified, dynamic, and fine-grained Zero Trust security control for system resources. SYSFLOW introduces a novelsystem flowabstraction to modelsystem activitiesacross the entire infrastructure, and provides a system-level data plane and control plane separation and abstraction. The new logically centralized controller accommodates a unifiedprogrammablePolicy Decision Point (PDP) that acquires a holistic view of system behaviors for controlling system resource accesses by translated programmable security policies into system flow rules. The SYSFLOW data plane, acting as Policy Enforcement Point (PEP), enforces translated system flow rules, which can be updated dynamically and facilitate fine-grained responsive actions. Our extensive evaluations demonstrate the effectiveness and scalability of SYSFLOW, which addresses the security issues in various scenarios with a minor performance overhead.
Sungmin Hong, Lei Xu 0024, Hongda Li 0002, Hongxin Hu, Guofei Gu
IEEE Trans. Inf. Forensics Secur.6
2022 Understanding and Detecting Remote Infection on Linux-based IoT Devices
abstract
The rocketed population, poor security, and 24/7 online properties make Linux-based Internet of Things (IoT) devices ideal targets for attackers. However, due to the budget constraints and an enormous number of vulnerabilities on such devices, protecting them against attacks is very challenging. Therefore, understanding and detecting IoT malware remote infection, which is before the compromised IoT devices are monetized by adversaries, is crucial to mitigate damages and financial loss caused by IoT malware. In this paper, we conduct an empirical study on a large-scale dataset covering 403,464 samples collected from VirusShare and a large group of IoT honeypots to gain a deep insight into the characteristics of IoT malware remote infection. We share detailed statistics of shell commands found in our dataset, highlight malicious behaviors performed through those commands, investigate current states of fingerprinting methods of those commands, and offer a taxonomy of shell commands by introducing the notion of infection capability. To demonstrate the usefulness of the knowledge gained from our study, we develop an approach to detect ongoing remote infection activities based on infection capabilities. Our evaluation shows that our detection approach can achieve a 99.22% detection rate for remote infections in the wild and introduce small performance overhead.
Hongda Li 0002, Qiqing Huang, Hongxin Hu, Long Cheng 0005, Guofei Gu, Ziming Zhao 0001
AsiaCCS6
2022 SAID: State-aware Defense Against Injection Attacks on In-vehicle Network
Lei Xue 0001, Kaifa Zhao, Jianfeng Li 0006, Le Yu 0002, Xiapu Luo, Yajin Zhou, Guofei Gu
USENIX Security Symposium9
2022 SWAPP: A New Programmable Playground for Web Application Security
Phakpoom Chinprutthiwong, Guofei Gu
USENIX Security Symposium3
2022 Towards Automatically Reverse Engineering Vehicle Diagnostic Protocols
Le Yu 0002, Pengfei Jing, Xiapu Luo, Lei Xue 0001, Kaifa Zhao, Yajin Zhou, Ting Wang 0006, Guofei Gu, Sen Nie, Shi Wu
USENIX Security Symposium9
2022 BiasHacker: Voice Command Disruption by Exploiting Speaker Biases in Automatic Speech Recognition
abstract
Modern speech recognition systems that are widely deployed today still suffer from known gender and racial biases. In this work, we demonstrate the potential to exploit the existing biases in these systems to achieve a new attack goal. We consider the potential for command disruption by an attacker that can be conducted in a manner that allows for access and control of a victim's voice assistant device. We present a novel attack, BiasHacker, which crafts specialized chatter noise to exploit racial and gender biases in speech recognition systems for the purposes of command disruption. Our experimental results confirm both racial and gender bias that is still present in the speech recognition systems of two modern smart speaker devices. We also evaluated the effectiveness of three types of chatter noise (American English (AE)-Male, Nigerian-Female, Korean-Female) for disruption and demonstrate that the AE-Male chatter is consistently more successful. Comparing the average success rate of each chatter type, in scenarios where disruption was achieved, we find that when targeting the Google Home mini smart speaker, the AE-Male chatter noise increases average disruption success compared to the Nigerian-Female and Korean-Female chatter noises by 112% and 121%, respectively. Also, when targeting the Amazon Echo Dot 2 the AE-Male chatter noise increases average disruption success compared to the Nigerian-Female and Korean-Female chatter noises by 42% and 69%, respectively.
Payton Walker, Nathan McClaran, Nitesh Saxena, Guofei Gu
WISEC5
2022 Disrupting the SDN Control Channel via Shared Links: Attacks and Countermeasures
abstract
Software-Defined Networking (SDN). SDN enables network innovations with a centralized controller controlling the whole network through the control channel. Because the control channel delivers all network control traffic, its security and reliability are of great importance. For the first time in the literature, we propose the CrossPath attack that disrupts the SDN control channel by exploiting the shared links in paths of control traffic and data traffic. In this attack, crafted data traffic can implicitly disrupt the forwarding of control traffic in the shared links. As the data traffic does not enter the control channel, the attack is stealthy and cannot be easily perceived by the controller. In order to identify the target paths containing the shared links to attack, we develop a novel technique called adversarial path reconnaissance. Our experimental results show its feasibility and efficiency of identifying the target path. We systematically study the impacts of the attack on various network applications in a real SDN testbed. Experiments show the attack significantly degrades the performance of existing network applications and causes serious network anomalies, e.g., routing blackhole, flow table resetting, and even network-wide DoS. To defeat the CrossPath attack, we design a lightweight defense system named CrossGuard. Experiments demonstrate that it can effectively protect the control channel and quickly locate the attack flow with 98% accuracy while introducing a small overhead.
Renjie Xie, Jiahao Cao 0001, Qi Li 0002, Kun Sun 0001, Guofei Gu, Mingwei Xu 0001, Yuan Yang 0001
IEEE/ACM Trans. Netw.5
2021 The Service Worker Hiding in Your Browser: The Next Web Attack Target?
abstract
In recent years, service workers are gaining attention from both web developers and attackers due to the unique features they provide. Recent findings have shown that an attacker can register a malicious service worker to take advantage of the victim such as by turning the victim’s device into a crypto-currency miner. However, the possibility of benign service workers being leveraged is not well studied.
Phakpoom Chinprutthiwong, Raj Vardhan, Guangliang Yang 0001, Yangyong Zhang, Guofei Gu
RAID5
2021 Practical Speech Re-use Prevention in Voice-driven Services
abstract
Voice-driven services (VDS) are being used in a variety of applications ranging from smart home control to payments using digital assistants. The input to such services is often captured via an open voice channel, e.g., using a microphone, in an unsupervised setting. One of the key operational security requirements in such setting is the freshness of the input speech. We present AEOLUS, a security overlay that proactively embeds a dynamic acoustic nonce at the time of user interaction, and detects the presence of the embedded nonce in the recorded speech to ensure freshness. We demonstrate that acoustic nonce can (i) be reliably embedded and retrieved, and (ii) be non-disruptive (and even imperceptible) to a VDS user. Optimal parameters (acoustic nonce’s operating frequency, amplitude, and bitrate) are determined for (i) and (ii) from a practical perspective. Experimental results show that AEOLUS yields 0.5% FRR at 0% FAR for speech re-use prevention upto a distance of 4 meters in three real-world environments with different background noise levels. We also conduct a user study with 120 participants, which shows that the acoustic nonce does not degrade overall user experience for 94.16% of speech samples, on average, in these environments. AEOLUS can therefore be used in practice to prevent speech re-use and ensure the freshness of speech input.
Yangyong Zhang, Sunpreet S. Arora, Maliheh Shirvanian, Guofei Gu
RAID5
2021 Happer: Unpacking Android Apps via a Hardware-Assisted Approach
abstract
Malware authors are abusing packers (or runtime-based obfuscators) to protect malicious apps from being analyzed. Although many unpacking tools have been proposed, they can be easily impeded by the anti-analysis methods adopted by the packers, and they fail to effectively collect the hidden Dex data due to the evolving protection strategies of packers. Consequently, many packing behaviors are unknown to analysts and packed malware can circumvent the inspection. To fill the gap, in this paper, we propose a novel hardware-assisted approach that first monitors the packing behaviors and then selects the proper approach to unpack the packed apps. Moreover, we develop a prototype named Happerwith a domain-specific language named behavior description language (BDL) for the ease of extending Happerafter tackling several technical challenges. We conduct extensive experiments with 12 commercial Android packers and more than 24k Android apps to evaluate Happer. The results show that Happerobserved 27 packing behaviors, 17 of which have not been elaborated by previous studies. Based on the observed packing behaviors, Happeradopted proper approaches to collect all the hidden Dex data and assembled them to valid Dex files.
Lei Xue 0001, Hao Zhou 0043, Xiapu Luo, Yajin Zhou, Yang Shi 0002, Guofei Gu, Fengwei Zhang, Man Ho Au
SP6
2021 Abusing Hidden Properties to Attack the Node.js Ecosystem
Yichang Xiong, Guangliang Yang 0001, Hong Hu 0004, Guofei Gu, Wenke Lee
USENIX Security Symposium6
2021 Enabling Performant, Flexible and Cost-Efficient DDoS Defense With Programmable Switches
abstract
Distributed Denial-of-Service (DDoS) attacks have become a critical threat to the Internet. Due to the increasing number of vulnerable Internet of Things (IoT) devices, attackers can easily compromise a large set of nodes and launch high-volume DDoS attacks from the botnets. State-of-the-art DDoS defenses, however, have not caught up with the fast development of the attacks. Middlebox-based defenses can achieve high performance with specialized hardware; however, these defenses incur a high cost, and deploying new defenses typically requires a device upgrade. On the other hand, software-based defenses are highly flexible, but software-based packet processing leads to high performance overheads. In this article, we propose Poseidon, a system that addresses these limitations in today's DDoS defenses. It leverages emerging programmable switches, which can be reconfigured in the field without additional hardware upgrades. Users of Poseidon can specify their defense strategies in a modular fashion in the form of a set of defense primitives; this can be further customized easily for each network and extended to include new defenses. Poseidon then maps the defense primitives to run on programmable switches-and when necessary, on server software-for effective defense. When attacks change, Poseidon can reconfigure the underlying defense primitives to respond to the new attack patterns. Evaluations using our prototype demonstrate that Poseidon can effectively defend against high-volume attacks, easily support customization of defense strategies, and adapt to dynamic attacks with low overheads.
Menghao Zhang 0001, Chang Liu 0021, Mingwei Xu 0001, Ang Chen 0001, Hongxin Hu, Guofei Gu, Qi Li 0002
IEEE/ACM Trans. Netw.8
2021 Control Plane Reflection Attacks and Defenses in Software-Defined Networks
abstract
Software-Defined Networking (SDN) continues to be deployed spanning from enterprise data centers to cloud computing with the proliferation of various SDN-enabled hardware switches and dynamic control plane applications. However, state-of-the-art SDN-enabled hardware switches have rather limited downlink message processing capability, especially for Flow-Mod and Statistic Query, which may not suffice the huge need of dynamic control plane applications. In this paper, we systematically study the interactions between the control plane applications and the data plane switches, and present two new attacks, namely Control Plane Reflection Attacks, to exploit the limited processing capability of SDN-enabled hardware switches. The reflection attacks adopt direct and indirect data plane events to force the control plane to issue massive expensive downlink messages towards SDN switches. Moreover, we propose a two-phase probing-triggering attack strategy, which makes the reflection attacks much more efficient and powerful. Experiments on a testbed with 3 different physical OpenFlow switches demonstrate that the attacks can lead to catastrophic results such as hurting the establishment of new flows and even disruption of connection between SDN controller and switches. To mitigate such attacks, we present several countermeasures from different perspectives. In particular, we propose a novel, systematical defense framework, SwitchGuard, to detect anomalies of downlink messages and prioritize these messages based on a novel monitoring granularity, i.e., host-application pair (HAP). Implementations and evaluations demonstrate that SwitchGuard can effectively reduce the latency for legitimate hosts and applications under the control plane reflection attacks with only minor overheads.
Menghao Zhang 0001, Lei Xu 0024, Jiasong Bai, Mingwei Xu 0001, Guofei Gu
IEEE/ACM Trans. Netw.6
2020 Security Study of Service Worker Cross-Site Scripting
abstract
Nowadays, modern websites are utilizing service workers to provide users with app-like functionalities such as offline mode and push notifications. To handle such features, the service worker is equipped with special privileges including HTTP traffic manipulation. Thus, it is designed with security as a priority. However, we find that many websites introduce a questionable practice that can jeopardize the security of a service worker.
Phakpoom Chinprutthiwong, Raj Vardhan, Guangliang Yang 0001, Guofei Gu
ACSAC4
2020 PPMLP 2020: Workshop on Privacy-Preserving Machine Learning In Practice
abstract
With the rapid development of technology, data is becoming ubiquitous. User privacy and data security are drawing much attention over the recent years, especially with the European Union's General Data Protection Regulation (GDPR) and other laws coming into force. On one hand, from the customers' perspective, how to protect user privacy while making use of customers? data is a challenging task. On the other hand, data silos are becoming one of the most prominent issues for the society. From the business? perspective, how to bridge these isolated data islands to build better AI systems while meeting the data privacy and regulatory compliance requirements has imposed great challenges to the traditional machine learning paradigm. PPMLP will provide an opportunity to connect researchers from both CCS community and machine learning community to tackle these challenges.
Benyu Zhang, Matei Zaharia, Shouling Ji, Raluca A. Popa, Guofei Gu
CCS5
2020 SODA: A Generic Online Detection Framework for Smart Contracts
Ting Chen 0002, Rong Cao, Xiapu Luo, Guofei Gu, Yufei Zhang 0002, Zhou Liao, Zheyuan He, Yuxing Tang, Xiaodong Lin 0001, Xiaosong Zhang 0001
NDSS5
2020 When Match Fields Do Not Need to Match: Buffered Packets Hijacking in SDN
Jiahao Cao 0001, Renjie Xie, Kun Sun 0001, Qi Li 0002, Guofei Gu, Mingwei Xu 0001
NDSS5
2020 Poseidon: Mitigating Volumetric DDoS Attacks with Programmable Switches
Menghao Zhang 0001, Chang Liu 0021, Ang Chen 0001, Hongxin Hu, Guofei Gu, Qi Li 0002, Mingwei Xu 0001
NDSS7
2020 Unexpected Data Dependency Creation and Chaining: A New Attack to SDN
abstract
Software-Defined Networking (SDN) is an emerging network architecture that provides programmable networking through a logically centralized controller. As SDN becomes more prominent, its security vulnerabilities become more evident than ever. Serving as the "brain" of a software-defined network, how the control plane (of the network) is exposed to external inputs (i.e., data plane messages) is directly correlated with how secure the network is. Fortunately, due to some unique SDN design choices (e.g., control plane and data plane separation), attackers often struggle to find a reachable path to those vulnerable logic hidden deeply within the control plane.In this paper, we demonstrate that it is possible for a weak adversary who only controls a commodity network device (host or switch) to attack previously unreachable control plane components by maliciously increasing reachability in the control plane. We introduce D2C2(data dependency creation and chaining) attack, which leverages some widely-used SDN protocol features (e.g., custom fields) to create and chain unexpected data dependencies in order to achieve greater reachability. We have developed a novel tool, SVHunter, which can effectively identify D2C2vulnerabilities. Till now we have evaluated SVHunter on three mainstream open-source SDN controllers (i.e., ONOS, Floodlight, and Opendaylight) as well as one security-enhanced controller (i.e., SE-Floodlight). SVHunter detects 18 previously unknown vulnerabilities, all of which can be exploited remotely to launch serious attacks such as executing arbitrary commands, exfiltrating confidential files, and crashing SDN services.
Guofei Gu, Dinghao Wu, Peng Liu 0005
SP4
2019 NETHCF: Enabling Line-rate and Adaptive Spoofed IP Traffic Filtering
abstract
In this paper, we design NETHCF, a line-rate in-network system for filtering spoofed traffic. NETHCF leverages the opportunity provided by programmable switches to design a novel defense against spoofed IP traffic, and it is highly efficient and adaptive. One key challenge stems from the restrictions of the computational model and memory resources of programmable switches. We address this by decomposing the HCF system into two complementary components-one component for the data plane and another for the control plane. We also aggregate the IP-to-Hop-Count (IP2HC) mapping table for efficient memory usage, and design adaptive mechanisms to handle end-to-end routing changes, IP popularity changes, and network activity dynamics. We have built a prototype on a hardware Tofino switch, and our evaluation demonstrates that NETHCF can achieve line-rate and adaptive traffic filtering with low overheads.
Menghao Zhang 0001, Chang Liu 0021, Ang Chen 0001, Guofei Gu, Hai-Xin Duan
ICNP6
2019 Life after Speech Recognition: Fuzzing Semantic Misinterpretation for Voice Assistant Applications
Yangyong Zhang, Lei Xu 0024, Abner Mendoza, Guangliang Yang 0001, Phakpoom Chinprutthiwong, Guofei Gu
NDSS6
2019 The CrossPath Attack: Disrupting the SDN Control Channel via Shared Links
Jiahao Cao 0001, Qi Li 0002, Renjie Xie, Kun Sun 0001, Guofei Gu, Mingwei Xu 0001, Yuan Yang 0001
USENIX Security Symposium5
2019 Iframes/Popups Are Dangerous in Mobile WebView: Studying and Mitigating Differential Context Vulnerabilities
Guangliang Yang 0001, Jeff Huang 0001, Guofei Gu
USENIX Security Symposium3
2019 Guest Editors' Introduction: Special Section on Security in Emerging Networking Technologies
abstract
The papers in this special section examine security in emerging networking technologies. Network infrastructure is undergoing a major shift away from ossified hardware-based networks to programmable software-based networks. One compelling example of this paradigm shift is the advent of Software- Defined Networking (SDN). A traditional network mixes control and traffic processing logic in single hardware devices, making the network more complex and harder to manage. SDN has addressed this issue by decoupling the control plane in network devices from the data plane to simplify production networks. On the other hand, enterprise networks are populated with a large number of proprietary and expensive hardware-based middleboxes, such as firewall, IDS/IPS, and load balancing. Hardware-based middleboxes present significant drawbacks such as high costs, management complexity, slow time to market, and unscalability. Network Function Virtualization (NFV) was proposed as another new network paradigm to address those drawbacks by replacing hardware-based network functions with virtualized software systems running on generic and inexpensive commodity hardware. Given their benefits, SDN and NFV have recently attracted significant attention from both academia and industry.
Gail-Joon Ahn, Guofei Gu, Hongxin Hu, Seungwon Shin 0001
IEEE Trans. Dependable Secur. Comput.2
2018 vNIDS: Towards Elastic Security with Safe and Efficient Virtualization of Network Intrusion Detection Systems
abstract
Traditional Network Intrusion Detection Systems (NIDSes) are generally implemented on vendor proprietary appliances or middleboxes with poor versatility and flexibility. Emerging Network Function Virtualization (NFV) and Software-Defined Networking (SDN) technologies can virtualize NIDSes and elastically scale them to deal with attack traffic variations. However, such an elasticity feature must not come at the cost of decreased detection effectiveness and expensive provisioning. In this paper, we propose an innovative NIDS architecture, vNIDS, to enable safe and efficient virtualization of NIDSes. vNIDS addresses two key challenges with respect to effective intrusion detection and non-monolithic NIDS provisioning in virtualizing NIDSes. The former challenge is addressed by detection state sharing while minimizing the sharing overhead in virtualized environments. In particular, static program analysis is employed to determine which detection states need to be shared. vNIDS addresses the latter challenge by provisioning virtual NIDSes as microservices and employing program slicing to partition the detection logic programs so that they can be executed by each microservice separately. We implement a prototype of vNIDS to demonstrate the feasibility of our approach. Our evaluation results show that vNIDS could offer both effective intrusion detection and efficient provisioning for NIDS virtualization.
Hongda Li 0002, Hongxin Hu, Guofei Gu, Gail-Joon Ahn
CCS3
2018 Towards Fine-grained Network Security Forensics and Diagnosis in the SDN Era
abstract
Diagnosing network security issues in traditional networks is difficult. It is even more frustrating in the emerging Software Defined Networks. The data/control plane decoupling of the SDN framework makes the traditional network troubleshooting tools unsuitable for pinpointing the root cause in the control plane. In this paper, we propose ForenGuard, which provides flow-level forensics and diagnosis functions in SDN networks. Unlike traditional forensics tools that only involve either network level or host level, ForenGuard monitors and records the runtime activities and their causal dependencies involving both the SDN control plane and data plane. Starting with a forwarding problem (e.g., disconnection) which could be caused by a security issue, ForenGuard can backtrack the previous activities in both the control and data plane through causal relationships and pinpoint the root cause of the problem. ForenGuard also provides a user-friendly interface that allows users to specify the detection point and diagnose complicated network problems. We implement a prototype system of ForenGuard on top of the Floodlight controller and use it to diagnose several real control plane attacks. We show that ForenGuard can quickly display causal relationships of activities and help to narrow down the range of suspicious activities that could be the root causes. Our performance evaluation shows that ForenGuard will add minor runtime overhead to the SDN control plane and can scale well in various network workloads.
Haopei Wang, Guangliang Yang 0001, Phakpoom Chinprutthiwong, Lei Xu 0024, Yangyong Zhang, Guofei Gu
CCS6
2018 Effective Topology Tampering Attacks and Defenses in Software-Defined Networks
abstract
As Software-Defined Networking has gained increasing prominence, new attacks have been demonstrated which can corrupt the SDN controller's view of network topology. These topology poisoning attacks, most notably host-location hijacking and link fabrication attacks, enable adversaries to impersonate end-hosts or inter-switch links in order to monitor, corrupt, or drop network flows. In response, defenses have been developed to detect such attacks and raise an alert. In this paper, we analyze two such defenses, TopoGuard and Sphinx, and present two new attacks, Port Probing and Port Amnesia, that can successfully bypass them. We then develop and present extensions to TopoGuard to make it resilient to such attacks.
Richard Skowyra, Lei Xu 0024, Guofei Gu, Veer Dedhia, Thomas Hobson, Hamed Okhravi, James Landry
DSN3
2018 CloudRand: Building Heterogeneous and Moving-Target Network Interfaces
abstract
Some fundamental reasons why our networked systems are still vulnerable to network attacks are because (1) they are more open than necessary; (2) they arehomogeneous, i.e., the same way to exploit a vulnerability on one machine is easily applicable to many other machines (which is particularly a severe issue in cloud computing environments when virtual machines images are heavily reused/cloned); (3) current networked services are merelystatic targets, i.e., they are easily predictable and do not change. While network authentication and access control mechanisms such as firewall and VPN can help reduce the openness (mostly at network perimeter level), they do not help much on the latter two factors. To bridge the gap and greatly complement existing network authentication/access control mechanisms, we propose CloudRand, a new framework to make networked systems/services in the cloudheterogeneous(every host has a different networking interface) andmoving targets(such interfaces keep changing and they are unpredictable to untrusted entities). Inspired by the previous work on host-level (memory or instruction) Address Space Randomization (ASR), we build a lightweight solution to randomize network service interfaces. Thus, even derived from the same image, each virtual machine can have very different network service interfaces and they keep changing to further reduce the attack surface. CloudRand is an application-independent security service, orthogonal to existing application/network security mechanisms such as authentication, encryption, and access control. To fit into different environments such as clouds or enterprise networks, we provide various prototype systems at different levels for flexible deployment choices, e.g., host level (kernel drivers for both Linux and Windows), network level (based on Click modular router or software-defined networking technology), virtual machine hypervisor level (based on Xen), and application level (browser plugin). Our extensive evaluation shows that this solution has low overhead, and it can it can significantly reduce the network attack surface and successfully defeat malware epidemic attacks.
Seungwon Shin 0001, Zhaoyan Xu, Yeonkeun Kim, Guofei Gu
ICCCN4
2018 Automated Generation of Event-Oriented Exploits in Android Hybrid Apps
Guangliang Yang 0001, Jeff Huang 0001, Guofei Gu
NDSS3
2018 Error-Sensor: Mining Information from HTTP Error Traffic for Malware Intelligence
Jialong Zhang 0001, Jiyong Jang, Guofei Gu, Marc Ph. Stoecklin, Xin Hu 0001
RAID3
2018 Control Plane Reflection Attacks in SDNs: New Attacks and Countermeasures
Menghao Zhang 0001, Lei Xu 0024, Jun Bi, Guofei Gu, Jiasong Bai
RAID5
2018 Mobile Application Web API Reconnaissance: Web-to-Mobile Inconsistencies & Vulnerabilities
abstract
Modern mobile apps use cloud-hosted HTTP-based API services and heavily rely on the Internet infrastructure for data communication and storage. To improve performance and leverage the power of the mobile device, input validation and other business logic required for interfacing with web API services are typically implemented on the mobile client. However, when a web service implementation fails to thoroughly replicate input validation, it gives rise to inconsistencies that could lead to attacks that can compromise user security and privacy. Developing automatic methods of auditing web APIs for security remains challenging. In this paper, we present a novel approach for automatically analyzing mobile app-to-web API communication to detect inconsistencies in input validation logic between apps and their respective web API services. We present our system, WARDroid, which implements a static analysis-based web API reconnaissance approach to uncover inconsistencies on real world API services that can lead to attacks with severe consequences for potentially millions of users throughout the world. Our system utilizes program analysis techniques to automatically extract HTTP communication templates from Android apps that encode the input validation constraints imposed by the apps on outgoing web requests to web API services. WARDroid is also enhanced with blackbox testing of server validation logic to identify inconsistencies that can lead to attacks. We evaluated our system on a set of 10,000 popular free apps from the Google Play Store. We detected problematic logic in APIs used in over 4,000 apps, including 1,743 apps that use unencrypted HTTP communication. We further tested 1,000 apps to validate web API hijacking vulnerabilities that can lead to potential compromise of user privacy and security and found that millions of users are potentially affected from our sample set of tested apps.
Abner Mendoza, Guofei Gu
IEEE Symposium on Security and Privacy2
2018 Study and Mitigation of Origin Stripping Vulnerabilities in Hybrid-postMessage Enabled Mobile Applications
abstract
PostMessage is popular in HTML5 based web apps to allow the communication between different origins. With the increasing popularity of the embedded browser (i.e., WebView) in mobile apps (i.e., hybrid apps), postMessage has found utility in these apps. However, different from web apps, hybrid apps have a unique requirement that their native code (e.g., Java for Android) also needs to exchange messages with web code loaded in WebView. To bridge the gap, developers typically extend postMessage by treating the native context as a new frame, and allowing the communication between the new frame and the web frames. We term such extended postMessage "hybrid postMessage" in this paper. We find that hybrid postMessage introduces new critical security flaws: all origin information of a message is not respected or even lost during the message delivery in hybrid postMessage. If adversaries inject malicious code into WebView, the malicious code may leverage the flaws to passively monitor messages that may contain sensitive information, or actively send messages to arbitrary message receivers and access their internal functionalities and data. We term the novel security issue caused by hybrid postMessage "Origin Stripping Vulnerability" (OSV). In this paper, our contributions are fourfold. First, we conduct the first systematic study on OSV. Second, we propose a lightweight detection tool against OSV, called OSV-Hunter. Third, we evaluate OSV-Hunter using a set of popular apps. We found that 74 apps implemented hybrid postMessage, and all these apps suffered from OSV, which might be exploited by adversaries to perform remote real-time microphone monitoring, data race, internal data manipulation, denial of service (DoS) attacks and so on. Several popular development frameworks, libraries (such as the Facebook React Native framework, and the Google cloud print library) and apps (such as Adobe Reader and WPS office) are impacted. Lastly, to mitigate OSV from the root, we design and implement three new postMessage APIs, called OSV-Free. Our evaluation shows that OSV-Free is secure and fast, and it is generic and resilient to the notorious Android fragmentation problem. We also demonstrate that OSV-Free is easy to use, by applying OSV-Free to harden the complex "Facebook React Native" framework. OSV-Free is open source, and its source code and more implementation and evaluation details are available online.
Guangliang Yang 0001, Jeff Huang 0001, Guofei Gu, Abner Mendoza
IEEE Symposium on Security and Privacy3
2018 Uncovering HTTP Header Inconsistencies and the Impact on Desktop/Mobile Websites
abstract
The paradigm shift to a mobile-first economy has seen a drastic increase in mobile-optimized websites that in many cases are derived from their desktop counterparts. Mobile website design is often focused on performance optimization rather than security, and possibly developed by different teams of developers. This has resulted in a number of subtle but critical inconsistencies in terms of security guarantees provided on the web platform, such as protection mechanisms against common web attacks. In this work, we have conducted the first systematic measurement study of inconsistencies between mobile and desktop HTTP security response configuration in the top 70,000 websites. We show that HTTP security configuration inconsistencies between mobile and desktop versions of the same website can lead to vulnerabilities. Our study compares data snapshots collected one year apart to garner insights into the longitudinal trends of mobile versus desktop inconsistencies in websites. To complement our measurement study, we present a threat analysis that explores some possible attack scenarios that can leverage the inconsistencies found on real websites. We systematically analyze the security impact of the inconsistent implementations between the mobile and desktop versions of a website and show how it can lead to real-world exploits. We present several case studies of popular websites to show real-world impact of how these inconsistencies are leveraged to compromise security and privacy of web users. Our results show little to no improvements across our datasets, which highlight the continued pervasiveness of subtle inconsistencies affecting even some high profile websites.
Abner Mendoza, Phakpoom Chinprutthiwong, Guofei Gu
WWW3
2018 Security and performance of software-defined networks and functions virtualization
David Hausheer, Oliver Hohlfeld, Stefan Schmid 0001, Guofei Gu
Comput. Networks4
2018 Shadow Attacks Based on Password Reuses: A Quantitative Empirical Analysis
abstract
With the proliferation of websites, the security level of password-protected accounts is no longer purely determined by individual ones. Users may register multiple accounts on the same site or across multiple sites, and these passwords from the same users are likely to be the same or similar. As a result, an adversary can compromise the account of a user on a web forum, then guess the accounts of the same user in sensitive accounts, e.g., online banking services, whose accounts could have the same or even stronger passwords. We name this attack as the shadow attack on passwords. To understand the situation, we examined the state-ofthe-art Intra-Site Password Reuses (ISPR) and Cross-Site Password Reuses (CSPR) based on the leaked passwords from the biggest Internet user group (i.e., 668 million members in China). With a collection of about 70 million real-world web passwords across four large websites in China, we obtained around 4.6 million distinct users who have multiple accounts on the same site or across different sites. We found that for the users with multiple accounts in a single website, 59.72 percent reused their passwords and for the users with multiple accounts on multiple websites, 33.16 + 8.91 percent reused their passwords across websites. For the users that have multiple accounts but different passwords, the set of passwords of the same user exhibits patterns that can help password guessing: a leaked weak password reveals partial information of a strong one, which degrades the strength of the strong one. Given the aforementioned findings, we conducted an experiment and achieved a 39.38 percent improvement of guessing success rate with John the Ripper guessing tool. To the best of our knowledge, we are the first to provide a large-scale, empirical, and quantitative measurement of web password reuses, especially ISPR, and shed light on the severity of such threat in the real world.
Weili Han, Zhigong Li, Minyue Ni, Guofei Gu, Wenyuan Xu 0001
IEEE Trans. Dependable Secur. Comput.4
2018 LinkScope: Toward Detecting Target Link Flooding Attacks
abstract
A new class of target link flooding attacks (LFAs) can cut off the Internet connections of a target area without being detected, because they employ legitimate flows to congest selected links. Although new mechanisms for defending against LFA have been proposed, the deployment issues limit their usage, since they require either additional modules to enhance routers or using the software-defined network to replace the traditional routers. In this paper, we propose a novel framework that employs both the end-to-end and hop-by-hop network measurement techniques to capture the abnormal path performance degradation for detecting LFA and then locate the target links or areas whenever possible, and develop a prototype of the framework named LinkScope. Although using network measurement to capture network anomaly is not new, we tackle a number of challenging issues, such as conducting large-scale Internet path monitoring via non-cooperative measurement so that users do not need to install LinkScope on every host, profiling the performance of asymmetric Internet paths and detecting LFA. The extensive evaluation in a testbed and the Internet shows that with limited bandwidth and computational overhead, LinkScope can achieve timely detection and diagnosis of LFA with high detection rate and low false positive rate.
Lei Xue 0001, Xiaobo Ma 0001, Xiapu Luo, Edmond W. W. Chan, TungNgai Miu, Guofei Gu
IEEE Trans. Inf. Forensics Secur.6
2018 Realtime DDoS Defense Using COTS SDN Switches via Adaptive Correlation Analysis
abstract
Distributed denial-of-service (DDoS) defense is still a difficult problem though it has been extensively studied. The existing approaches are not capable of detecting various types of DDoS attacks. In particular, new emerging sophisticated DDoS attacks (e.g., Crossfire) constructed by low-rate and short-lived benign traffic are even more challenging to capture. Moreover, it is difficult to enforce realtime defense to throttle these detected attacks since the attack traffic can be concealed in benign traffic. Software defined networking (SDN) opens a new door to address these issues. In this paper, we propose Reinforcing Anti-DDoS Actions in Realtime (RADAR) to detect and throttle DDoS attacks via adaptive correlation analysis built upon unmodified commercial off-the-shelf SDN switches. It is a practical system to defend against a wide range of flooding-based DDoS attacks, e.g., link flooding (including Crossfire), SYN flooding, and UDP-based amplification attacks, while requiring neither modifications in SDN switches/protocols nor extra appliances. It accurately detects attacks by identifying attack features in suspicious flows, and locates attackers (or victims) to throttle the attack traffic by adaptive correlation analysis. We implement RADAR prototype using open source Floodlight controller, and evaluate its performance under various DDoS attacks by real hardware testbed based experiments. We observe that our scheme can successfully detect and effectively defend against various DDoS attacks with acceptable overhead.
Qi Li 0002, Guofei Gu, Jiahao Cao 0001, David K. Y. Yau
IEEE Trans. Inf. Forensics Secur.3
2017 EvilDirect: A New Wi-Fi Direct Hijacking Attack and Countermeasures
abstract
In this paper, we first show that Group Owner (GO) devices in Wi-Fi Direct are vulnerable to the EvilDirect attack. In the EvilDirect attack, a rogue GO is set up by an adversary to look like the legitimate GO (with the same MAC address, SSID, and operating channel). The adversary intercepts the clients' invitation requests and accepts them before the legitimate GO. Accordingly, the adversary hijacks the wireless communications between the clients and the legitimate GO. To defend against the EvilDirect attack, we propose the idea of exploiting the received signal strength (RSS) variations on the wireless channel between each client and the legitimate GO. Our solution, EvilDirectHunter checks whether the RSS profiles of both the client and the potential GO devices are similar with each other. Both devices incrementally prove this similarity by exchanging challenge and response packets. EvilDirectHunter is evaluated by implementing it as an Android App, and by modifying the Android kernel code responsible for Wi- Fi Direct in Google Nexus 5 and Samsung Galaxy S2 smartphones. The results show that EvilDirectHunter is able, within seconds, to identify EvilDirect attacks with a high detection rate (100%) while maintaining a low false positive rate (4.5%).
Ala Altaweel, Radu Stoleru, Guofei Gu
ICCCN3
2017 Understanding the Market-Level and Network-Level Behaviors of the Android Malware Ecosystem
abstract
The prevalence of malware in Android marketplaces is a growing and significant problem. Most existing studies focus on detecting Android malware or designing new security extensions to defend against specific types of attacks. In this paper, we perform an empirical study on analyzing the market-level and network-level behaviors of the Android malware ecosystem. We focus on studying whether there are interesting characteristics of those market accounts that distribute malware and specific networks that are mainly utilized by Android malware authors. We further investigate community patterns among Android malware from the perspective of their market account infrastructure and remote server infrastructure. Spurred by these analysis, we design a novel community inference algorithm to find more malicious apps by exploiting their community relationships. By using a small seed set (50) of known malicious apps, we can effectively find another extra 20 times of malicious apps, while maintaining considerable accuracy higher than 94%.
Chao Yang 0022, Jialong Zhang 0001, Guofei Gu
ICDCS3
2017 Bring your own controller: Enabling tenant-defined SDN apps in IaaS clouds
abstract
The need of customized network functions for enterprises in Infrastructure-as-a-Service (IaaS) clouds is emerging. However, existing network functions in IaaS clouds are very limited, inflexible, and hard to control by the tenants. Recently, the introduction of Software-Defined Networking (SDN) technology brings the hope of flexible control of network flows and creation of diverse network functions. Unfortunately, enterprises lose access to the SDN controller when they move to clouds. Moreover, the cloud SDN controller is only managed by the provider administrators for security and performance reasons. To allow enterprise tenants to develop and deploy their own SDN apps in the cloud, in this paper, we introduce a new cloud usage paradigm: Bring Your Own Controller (BYOC). BYOC offers each tenant an individual SDN controller, where tenants can deploy SDN apps to manage their network. To manage these tenant SDN controllers, we propose BYOC-Visor, a new SDN-based virtualization platform. BYOC-VISOR addresses several security and performance challenges which are specific to IaaS clouds. We show that BYOC-Visor supports different controller platforms and diverse SDN security applications such as firewall, IDS, and access control. We implement a prototype system and the performance evaluation results show that our system has low overhead.
Haopei Wang, Abhinav Srivastava, Lei Xu 0024, Sungmin Hong, Guofei Gu
INFOCOM5
2017 Precisely and Scalably Vetting JavaScript Bridge in Android Hybrid Apps
Guangliang Yang 0001, Abner Mendoza, Jialong Zhang 0001, Guofei Gu
RAID4
2017 Attacking the Brain: Races in the SDN Control Plane
Lei Xu 0024, Jeff Huang 0001, Sungmin Hong, Jialong Zhang 0001, Guofei Gu
USENIX Security Symposium5
2017 Malton: Towards On-Device Non-Invasive Mobile Malware Analysis for ART
Lei Xue 0001, Yajin Zhou, Ting Chen 0002, Xiapu Luo, Guofei Gu
USENIX Security Symposium5
2017 Identifying User-Input Privacy in Mobile Applications at a Large Scale
abstract
Identifying sensitive user inputs is a prerequisite for privacy protection in mobile applications. When it comes to today's program analysis systems, however, only those data that go through well-defined system Application Program Interface (system controlled resources) can be automatically labeled. In this paper, we show that this conventional approach is far from adequate, as most sensitive inputs are actually entered by the user at an app's runtime. In this paper, we inspect 13,072 top apps from Google Play, and find that 38.69% of them involve sensitive user inputs. Just like system controlled resources, these data are also exposed to a series of privacy leakage threats. For these sensitive user inputs, manually marking them involves a lot of efforts, impeding a large-scale, automated analysis of apps to defend against potential privacy leakage. To address this important issue, we present UIPicker, an adaptable framework for automatic identification of sensitive user inputs as the first step. UIPicker is designed to detect the semantic information within the application layout resources and the program code, and further analyze it for the locations where security-critical information may show up. This approach can support a variety of existing security analysis on mobile apps. We evaluate our approach over randomly selected popular apps on Google Play. UIPicker is able to accurately label sensitive user inputs most of the time, with 94.0% precision and 96.0% recall.
Yuhong Nan, Zhemin Yang, Min Yang 0002, Shunfan Zhou, Yuan Zhang 0009, Guofei Gu, XiaoFeng Wang 0001, Limin Sun 0001
IEEE Trans. Inf. Forensics Secur.6
2017 Flow Wars: Systemizing the Attack Surface and Defenses in Software-Defined Networks
abstract
Emerging software defined network (SDN) stacks have introduced an entirely new attack surface that is exploitable from a wide range of launch points. Through an analysis of the various attack strategies reported in prior work, and through our own efforts to enumerate new and variant attack strategies, we have gained two insights. First, we observe that different SDN controller implementations, developed independently by different groups, seem to manifest common sets of pitfalls and design weakness that enable the extensive set of attacks compiled in this paper. Second, through a principled exploration of the underlying design and implementation weaknesses that enables these attacks, we introduce a taxonomy to offer insight into the common pitfalls that enable SDN stacks to be broken or destabilized when fielded within hostile computing environments. This paper first captures our understanding of the SDN attack surface through a comprehensive survey of existing SDN attack studies, which we extend by enumerating 12 new vectors for SDN abuse. We then organize these vulnerabilities within the well-known confidentiality, integrity, and availability model, assess the severity of these attacks by replicating them in a physical SDN testbed, and evaluate them against three popular SDN controllers. We also evaluate the impact of these attacks against published SDN defense solutions. Finally, we abstract our findings to offer the research and development communities with a deeper understanding of the common design and implementation pitfalls that are enabling the abuse of SDN networks.
Changhoon Yoon, Seungsoo Lee 0001, Heedo Kang, Taejune Park, Seungwon Shin 0001, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu
IEEE/ACM Trans. Netw.8
2016 Enhancing Network Security through Software Defined Networking (SDN)
abstract
Software Defined Networking (SDN) is an emerging technology that attracts significant attention from both industry and academia recently. By decoupling the control logic from the closed and proprietary implementations of traditional network devices, it enables researchers and practitioners to design new innovative network functions/protocols in a much more flexible, powerful, and easier way. We believe SDN provides new research opportunities to security, and it can greatly impact network security research in many different ways. However, till today, SDN has not been well recognized by the security community yet. In this systematic survey on SDN security, we investigate how the new features provided by SDN can help enhance network security and information security process. By systematically reasoning the opportunities introduced by SDN to network security, we hope to provide new insights for future research in this important area.
Seungwon Shin 0001, Lei Xu 0024, Sungmin Hong, Guofei Gu
ICCCN4
2016 Hunting for invisibility: Characterizing and detecting malicious web infrastructures through server visibility analysis
abstract
Nowadays, cyber criminals often build web infrastructures rather than a single server to conduct their malicious activities. In order to continue their malevolent activities without being detected, cyber criminals make efforts to conceal the core servers (e.g., C&C servers, exploit servers, and drop-zone servers) in the malicious web infrastructure. Such deliberate invisibility of those concealed malicious servers, however, makes them particularly distinguishable from benign web servers that are usually promoted to be public. In this paper, we conduct the first large-scale measurement study to investigate the visibility of both malicious and benign servers. From our intensive analysis of over 100,000 benign servers, 45,000 malicious servers and 40,000 redirections, we identify a set of distinct features of malicious web infrastructures from their locations, structures, roles, and relationships perspectives, and propose a lightweight yet effective detection system called VisHunter. VisHunter identifies malicious redirections from visible servers to invisible servers at the entryway of malicious web infrastructures. We evaluate VisHunter on both online public data and large-scale enterprise network traffic, and demonstrate that VisHunter can achieve an average 96.2% detection rate with only 0.9% false positive rate on the real enterprise network traffic.
Jialong Zhang 0001, Xin Hu 0001, Jiyong Jang, Ting Wang 0006, Guofei Gu, Marc Ph. Stoecklin
INFOCOM5
2016 Towards SDN-Defined Programmable BYOD (Bring Your Own Device) Security
Sungmin Hong, Robert Baykov, Lei Xu 0024, Srinath Nadimpalli, Guofei Gu
NDSS5
2016 PRIDE: A practical intrusion detection system for resource constrained wireless mesh networks
Amin Hassanzadeh, Zhaoyan Xu, Radu Stoleru, Guofei Gu, Michalis Polychronakis
Comput. Secur.4
2016 Rethinking Permission Enforcement Mechanism on Mobile Systems
abstract
To protect sensitive resources from unauthorized use, modern mobile systems, such as Android and iOS, design a permission-based access control model. However, current model could not enforce fine-grained control over the dynamic permission use contexts, causing two severe security problems. First, any code package in an application could use the granted permissions, inducing attackers to embed malicious payloads into benign apps. Second, the permissions granted to a benign application may be utilized by an attacker through vulnerable application interactions. Although ad hoc solutions have been proposed, none could systematically solve these two issues within a unified framework. This paper presents the first such framework to provide context-sensitive permission enforcement that regulates permission use policies according to system-wide application contexts, which cover both intra-application context and inter-application context. We build a prototype system on Android, named FineDroid, to track such context during the application execution. To flexibly regulate the context-sensitive permission rules, FineDroid features a policy framework that could express generic application contexts. We demonstrate the benefits of FineDroid by instantiating several security extensions based on the policy framework, for three potential users: end users, administrators, and developers. Furthermore, FineDroid is showed to introduce a minor overhead.
Yuan Zhang 0009, Min Yang 0002, Guofei Gu, Hao Chen 0003
IEEE Trans. Inf. Forensics Secur.3
2015 FloodGuard: A DoS Attack Prevention Extension in Software-Defined Networks
abstract
This paper addresses one serious SDN-specific attack, i.e., data-to-control plane saturation attack, which overloads the infrastructure of SDN networks. In this attack, an attacker can produce a large amount of table-miss packet_in messages to consume resources in both control plane and data plane. To mitigate this security threat, we introduce an efficient, lightweight and protocol-independent defense framework for SDN networks. Our solution, called FloodGuard, contains two new techniques/modules: proactive flow rule analyzer and packet migration. To preserve network policy enforcement, proactive flow rule analyzer dynamically derives proactive flow rules by reasoning the runtime logic of the SDN/OpenFlow controller and its applications. To protect the controller from being overloaded, packet migration temporarily caches the flooding packets and submits them to the OpenFlow controller using rate limit and round-robin scheduling. We evaluate FloodGuard through a prototype implementation tested in both software and hardware environments. The results show that FloodGuard is effective with adding only minor overhead into the entire SDN/OpenFlow infrastructure.
Haopei Wang, Lei Xu 0024, Guofei Gu
DSN3
2015 Systematic Mining of Associated Server Herds for Malware Campaign Discovery
abstract
HTTP is a popular channel for malware to communicate with malicious servers (e.g., Command & Control, drive-by download, drop-zone), as well as to attack benign servers. By utilizing HTTP requests, malware easily disguises itself under a large amount of benign HTTP traffic. Thus, identifying malicious HTTP activities is challenging. We leverage an insight that cyber criminals are increasingly using dynamic malicious infrastructures with multiple servers to be efficient and anonymous in (i) malware distribution (using redirectors and exploit servers), (ii) control (using C&C servers) and (iii) monetization (using payment servers), and (iv) being robust against server takedowns (using multiple backups for each type of servers). Instead of focusing on detecting individual malicious domains, we propose a complementary approach to identify a group of closely related servers that are potentially involved in the same malware campaign, which we term as Associated Server Herd (ASH). Our solution, SMASH (Systematic Mining of Associated Server Herds), utilizes an unsupervised framework to infer malware ASHs by systematically mining the relations among all servers from multiple dimensions. We build a prototype system of SMASH and evaluate it with traces from a large ISP. The result shows that SMASH successfully infers a large number of previously undetected malicious servers and possible zero-day attacks, with low false positives. We believe the inferred ASHs provide a better global view of the attack campaign that may not be easily captured by detecting only individual servers.
Jialong Zhang 0001, Sabyasachi Saha, Guofei Gu, Sung-Ju Lee 0001, Marco Mellia
ICDCS3
2015 What is wrecking your data plan? A measurement study of mobile web overhead
abstract
The growing popularity of smartphones and continuous user demand for a rich web experience has resulted in an exponential surge in cellular bandwidth requirements. Cellular providers have struggled to keep pace with the new requirements while users often face a monetary cost associated with the data downloaded to their device. While many modern websites have adapted to the new mobile habitat, they often take shortcuts to transition from their desktop to mobile versions, many times carrying redundant content that is never utilized. Moreover, mobile users are effectively paying for certain undesirable content, such as advertisements, in the form of their bandwidth costs. In this paper, we study the composition and complexity of modern websites, from both a mobile and desktop perspective, to identify sources of wasted bandwidth. We developed a custom crawler-based framework to perform an in-depth analysis of the top 100,000 popular sites ranked by Alexa. Our results show that 23% or more of the content size on an average website is unnecessary, unused or redundant. Our results serve as a motivation for developing optimized websites and enhancing the web infrastructure to better suit the mobile environment with emphasis on reducing bandwidth costs, while also improving performance and efficiency.
Abner Mendoza, Kapil Singh, Guofei Gu
INFOCOM3
2015 Poisoning Network Visibility in Software-Defined Networks: New Attacks and Countermeasures
Sungmin Hong, Lei Xu 0024, Haopei Wang, Guofei Gu
NDSS4
2015 Using Provenance Patterns to Vet Sensitive Behaviors in Android Apps
Chao Yang 0022, Guangliang Yang 0001, Ashish Gehani, Vinod Yegneswaran, Dawood Tariq, Guofei Gu
SecureComm6
2015 FineDroid: Enforcing Permissions with System-Wide Application Execution Context
Yuan Zhang 0009, Min Yang 0002, Guofei Gu, Hao Chen 0003
SecureComm3
2015 UIPicker: User-Input Privacy Identification in Mobile Applications
Yuhong Nan, Min Yang 0002, Zhemin Yang, Shunfan Zhou, Guofei Gu, XiaoFeng Wang 0001
USENIX Security Symposium5
2015 A First Step Toward Network Security Virtualization: From Concept To Prototype
abstract
Network security management is becoming more and more complicated in recent years, considering the need of deploying more and more network security devices/middle-boxes at various locations inside the already complicated networks. A grand challenge in this situation is that current management is inflexible and the security resource utilization is not efficient. The flexible deployment and utilization of proper security devices at reasonable places at needed time with low management cost is extremely difficult. In this paper, we present a new concept of network security virtualization, which virtualizes security resources/functions to network administrators/users, and thus maximally utilizing existing security devices/middle-boxes. In addition, it enables security protection to desirable networks with minimal management cost. To verify this concept, we further design and implement a prototype system, NETSECVISOR, which can utilize existing pre-installed (fixed-location) security devices and leverage software-defined networking technology to virtualize network security functions. At its core, NETSECVISOR contains: 1) a simple script language to register security services and policies; 2) a set of routing algorithms to determine optimal routing paths for different security policies based on different needs; and 3) a set of security response functions/strategies to handle security incidents. We deploy NETSECVISOR in both virtual test networks and a commercial switch environment to evaluate its performance and feasibility. The evaluation results show that our prototype only adds a very small overhead while providing desired network security virtualization to network users/administrators.
Seungwon Shin 0001, Haopei Wang, Guofei Gu
IEEE Trans. Inf. Forensics Secur.3
2015 Malware Propagation in Large-Scale Networks
abstract
Malware is pervasive in networks, and poses a critical threat to network security. However, we have very limited understanding of malware behavior in networks to date. In this paper, we investigate how malware propagates in networks from a global perspective. We formulate the problem, and establish a rigorous two layer epidemic model for malware propagation from network to network. Based on the proposed model, our analysis indicates that the distribution of a given malware follows exponential distribution, power law distribution with a short exponential tail, and power law distribution at its early, late and final stages, respectively. Extensive experiments have been performed through two real-world global scale malware data sets, and the results confirm our theoretical findings.
Shui Yu 0001, Guofei Gu, Ahmed Barnawi, Song Guo 0001, Ivan Stojmenovic
IEEE Trans. Knowl. Data Eng.2
2014 A taste of tweets: reverse engineering Twitter spammers
abstract
In this paper, through reverse engineering Twitter spammers' tastes (their preferred targets to spam), we aim at providing guidelines for building more effective social honeypots, and generating new insights to defend against social spammers. Specifically, we first perform a measurement study by deploying "benchmark" social honeypots on Twitter with diverse and fine-grained social behavior patterns to trap spammers. After five months' data collection, we make a deep analysis on how Twitter spammers find their targets. Based on the analysis, we evaluate our new guidelines for building effective social honeypots by implementing "advanced" honeypots. Particularly, within the same time period, using those advanced honeypots can trap spammers around 26 times faster than using "traditional" honeypots.
Chao Yang 0022, Jialong Zhang 0001, Guofei Gu
ACSAC3
2014 AUTOPROBE: Towards Automatic Active Malicious Server Probing Using Dynamic Binary Analysis
abstract
Malware continues to be one of the major threats to Internet security. In the battle against cybercriminals, accurately identifying the underlying malicious server infrastructure (e.g., C&C servers for botnet command and control) is of vital importance. Most existing passive monitoring approaches cannot keep up with the highly dynamic, ever-evolving malware server infrastructure. As an effective complementary technique, active probing has recently attracted attention due to its high accuracy, efficiency, and scalability (even to the Internet level). In this paper, we propose Autoprobe, a novel system to automatically generate effective and efficient fingerprints of remote malicious servers. Autoprobe addresses two fundamental limitations of existing active probing approaches: it supports pull-based C&C protocols, used by the majority of malware, and it generates fingerprints even in the common case when C&C servers are not alive during fingerprint generation. Using real-world malware samples we show that Autoprobe can successfully generate accurate C&C server fingerprints through novel applications of dynamic binary analysis techniques. By conducting Internet-scale active probing, we show that Autoprobe can successfully uncover hundreds of malicious servers on the Internet, many of them unknown to existing blacklists. We believe Autoprobe is a great complement to existing defenses, and can play a unique role in the battle against cybercriminals.
Zhaoyan Xu, Antonio Nappa, Robert Baykov, Guangliang Yang 0001, Juan Caballero, Guofei Gu
CCS6
2014 SRID: State Relation Based Intrusion Detection for False Data Injection Attacks in SCADA
Zhaoyan Xu, Jialong Zhang 0001, Lei Xu 0024, Haopei Wang, Guofei Gu
ESORICS (2)6
2014 DroidMiner: Automated Mining and Characterization of Fine-grained Malicious Behaviors in Android Applications
Chao Yang 0022, Zhaoyan Xu, Guofei Gu, Vinod Yegneswaran, Phillip A. Porras
ESORICS (1)3
2014 CyberProbe: Towards Internet-Scale Active Detection of Malicious Servers
Antonio Nappa, Zhaoyan Xu, M. Zubair Rafique, Juan Caballero, Guofei Gu
NDSS5
2014 GoldenEye: Efficiently and Effectively Unveiling Malware's Targeted Environment
Zhaoyan Xu, Jialong Zhang 0001, Guofei Gu, Zhiqiang Lin 0001
RAID3
2014 Abusing Browser Address Bar for Fun and Profit - An Empirical Investigation of Add-On Cross Site Scripting Attacks
Yinzhi Cao, Chao Yang 0022, Vaibhav Rastogi, Yan Chen 0004, Guofei Gu
SecureComm (1)5
2014 Characterizing Google Hacking: A First Large-Scale Quantitative Study
Jialong Zhang 0001, Jayant Notani, Guofei Gu
SecureComm (1)3
2014 Permission Use Analysis for Vetting Undesirable Behaviors in Android Apps
abstract
The android platform adopts permissions to protect sensitive resources from untrusted apps. However, after permissions are granted by users at install time, apps could use these permissions (sensitive resources) with no further restrictions. Thus, recent years have witnessed the explosion of undesirable behaviors in Android apps. An important part in the defense is the accurate analysis of Android apps. However, traditional syscall-based analysis techniques are not well-suited for Android, because they could not capture critical interactions between the application and the Android system. This paper presents VetDroid, a dynamic analysis platform for generally analyzing sensitive behaviors in Android apps from a novel permission use perspective. VetDroid proposes a systematic permission use analysis technique to effectively construct permission use behaviors, i.e., how applications use permissions to access (sensitive) system resources, and how these acquired permission-sensitive resources are further utilized by the application. With permission use behaviors, security analysts can easily examine the internal sensitive behaviors of an app. Using real-world Android malware, we show that VetDroid can clearly reconstruct fine-grained malicious behaviors to ease malware analysis. We further apply VetDroid to 1249 top free apps in Google Play. VetDroid can assist in finding more information leaks than TaintDroid, a state-of-the-art technique. In addition, we show how we can use VetDroid to analyze fine-grained causes of information leaks that TaintDroid cannot reveal. Finally, we show that VetDroid can help to identify subtle vulnerabilities in some (top free) applications otherwise hard to detect.
Yuan Zhang 0009, Min Yang 0002, Zhemin Yang, Guofei Gu, Peng Ning, Binyu Zang
IEEE Trans. Inf. Forensics Secur.4
2013 AVANT-GUARD: scalable and vigilant switch flow management in software-defined networks
abstract
Among the leading reference implementations of the Software Defined Networking (SDN) paradigm is the OpenFlow framework, which decouples the control plane into a centralized application. In this paper, we consider two aspects of OpenFlow that pose security challenges, and we propose two solutions that could address these concerns. The first challenge is the inherent communication bottleneck that arises between the data plane and the control plane, which an adversary could exploit by mounting a "control plane saturation attack" that disrupts network operations. Indeed, even well-mined adversarial models, such as scanning or denial-of-service (DoS) activity, can produce more potent impacts on OpenFlow networks than traditional networks. To address this challenge, we introduce an extension to the OpenFlow data plane called "connection migration", which dramatically reduces the amount of data-to-control-plane interactions that arise during such attacks. The second challenge is that of enabling the control plane to expedite both detection of, and responses to, the changing flow dynamics within the data plane. For this, we introduce "actuating triggers" over the data plane's existing statistics collection services. These triggers are inserted by control layer applications to both register for asynchronous call backs, and insert conditional flow rules that are only activated when a trigger condition is detected within the data plane's statistics module. We present Avant-Guard, an implementation of our two data plane extensions, evaluate the performance impact, and examine its use for developing more scalable and resilient SDN security services.
Seungwon Shin 0001, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu
CCS4
2013 AppIntent: analyzing sensitive data transmission in android for privacy leakage detection
abstract
Android phones often carry personal information, attracting malicious developers to embed code in Android applications to steal sensitive data. With known techniques in the literature, one may easily determine if sensitive data is being transmitted out of an Android phone. However, transmission of sensitive data in itself does not necessarily indicate privacy leakage; a better indicator may be whether the transmission is by user intention or not. When transmission is not intended by the user, it is more likely a privacy leakage. The problem is how to determine if transmission is user intended. As a first solution in this space, we present a new analysis framework called AppIntent. For each data transmission, AppIntent can efficiently provide a sequence of GUI manipulations corresponding to the sequence of events that lead to the data transmission, thus helping an analyst to determine if the data transmission is user intended or not. The basic idea is to use symbolic execution to generate the aforementioned event sequence, but straightforward symbolic execution proves to be too time-consuming to be practical. A major innovation in AppIntent is to leverage the unique Android execution model to reduce the search space without sacrificing code coverage. We also present an evaluation of AppIntent with a set of 750 malicious apps, as well as 1,000 top free apps from Google Play. The results show that AppIntent can effectively help separate the apps that truly leak user privacy from those that do not.
Zhemin Yang, Min Yang 0002, Yuan Zhang 0009, Guofei Gu, Peng Ning, Xiaoyang Sean Wang
CCS4
2013 Vetting undesirable behaviors in android apps with permission use analysis
abstract
Android platform adopts permissions to protect sensitive resources from untrusted apps. However, after permissions are granted by users at install time, apps could use these permissions (sensitive resources) with no further restrictions. Thus, recent years have witnessed the explosion of undesirable behaviors in Android apps. An important part in the defense is the accurate analysis of Android apps. However, traditional syscall-based analysis techniques are not well-suited for Android, because they could not capture critical interactions between the application and the Android system.
Yuan Zhang 0009, Min Yang 0002, Bingquan Xu, Zhemin Yang, Guofei Gu, Peng Ning, Xiaoyang Sean Wang, Binyu Zang
CCS5
2013 Model checking invariant security properties in OpenFlow
abstract
The OpenFlow (OF) switching specification represents an innovative and open standard for enabling the dynamic programming of flow control policies in production networks. Unfortunately, thus far researchers have paid little attention to the development of methods for verifying that dynamic flow policies inserted within an OpenFlow network do not violate the network's underlying security policy. We introduce Flover, a model checking system which verifies that the aggregate of flow policies instantiated within an OpenFlow network does not violate the network's security policy. We have implemented Flover using the Yices SMT solver, which we then integrated into NOX, a popular OpenFlow network controller. Flover provides NOX a formal validation of the OpenFlow network's security posture.
Sooel Son, Seungwon Shin 0001, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu
ICC5
2013 AUTOVAC: Automatically Extracting System Resource Constraints and Generating Vaccines for Malware Immunization
abstract
Malware often contains many system-resource-sensitive condition checks to avoid any duplicate infection, make sure to obtain required resources, or try to infect only targeted computers, etc. If we are able to extract the system resource constraints from malware code, and manipulate the environment state as vaccines, we would then be able to immunize a computer from infections. Towards this end, this paper provides the first systematic study and presents a prototype system, AUTOVAC, for automatically extracting the system resource constraints from malware code and generating vaccines based on the system resource conditions. Specifically, through monitoring the data propagation from system-resource-related system calls, AUTOVAC automatically identifies the environment related state of a computer. Through analyzing the environment state, AUTOVAC automatically generates vaccines. Such vaccines can be then injected into other computers, thereby being immune from future infections from the same malware or its polymorphic variants. We have evaluated AUTOVAC on a large set of real-world malware samples and successfully extracted working vaccines for many families including high-profile Conficker, Sality and Zeus. We believe AUTOVAC represents an appealing technique to complement existing malware defenses.
Zhaoyan Xu, Jialong Zhang 0001, Guofei Gu, Zhiqiang Lin 0001
ICDCS3
2013 PRIDE: Practical Intrusion Detection in Resource Constrained Wireless Mesh Networks
Amin Hassanzadeh, Zhaoyan Xu, Radu Stoleru, Guofei Gu, Michalis Polychronakis
ICICS4
2013 FRESCO: Modular Composable Security Services for Software-Defined Networks
Seungwon Shin 0001, Phillip A. Porras, Vinod Yegneswaran, Martin W. Fong, Guofei Gu, Mabry Tyson
NDSS5
2013 NEIGHBORWATCHER: A Content-Agnostic Comment Spam Inference System
Jialong Zhang 0001, Guofei Gu
NDSS2
2013 Editorial for Computer Networks special issue on ''Botnet Activity: Analysis, Detection and Shutdown''
Ronaldo M. Salles, Guofei Gu, Morton Swimmer
Comput. Networks2
2013 EFFORT: A new host-network cooperated framework for efficient and effective bot malware detection
Seungwon Shin 0001, Zhaoyan Xu, Guofei Gu
Comput. Networks3
2013 Empirical Evaluation and New Design for Fighting Evolving Twitter Spammers
abstract
To date, as one of the most popular online social networks (OSNs), Twitter is paying its dues as more and more spammers set their sights on this microblogging site. Twitter spammers can achieve their malicious goals such as sending spam, spreading malware, hosting botnet command and control (C&C) channels, and launching other underground illicit activities. Due to the significance and indispensability of detecting and suspending those spam accounts, many researchers along with the engineers at Twitter Inc. have devoted themselves to keeping Twitter as spam-free online communities. Most of the existing studies utilize machine learning techniques to detect Twitter spammers. “While the priest climbs a post, the devil climbs ten.” Twitter spammers are evolving to evade existing detection features. In this paper, we first make a comprehensive and empirical analysis of the evasion tactics utilized by Twitter spammers. We further design several new detection features to detect more Twitter spammers. In addition, to deeply understand the effectiveness and difficulties of using machine learning features to detect spammers, we analyze the robustness of 24 detection features that are commonly utilized in the literature as well as our proposed ones. Through our experiments, we show that our new designed features are much more effective to be used to detect (even evasive) Twitter spammers. According to our evaluation, while keeping an even lower false positive rate, the detection rate using our new feature set is also significantly higher than that of existing work. To the best of our knowledge, this work is the first empirical study and evaluation of the effect of evasion tactics utilized by Twitter spammers and is a valuable supplement to this line of research.
Chao Yang 0022, Robert Chandler Harkreader, Guofei Gu
IEEE Trans. Inf. Forensics Secur.3
2012 PeerPress: utilizing enemies' P2P strength against them
abstract
We propose a new, active scheme for fast and reliable detection of P2P malware by exploiting the enemies' strength against them. Our new scheme works in two phases: host-level dynamic binary analysis to automatically extract built-in remotely-accessible/controllable mechanisms (referred to as Malware Control Birthmarks or MCB) in P2P malware, followed by network-level informed probing for detection. Our new design demonstrates a novel combination of the strengths from both host-based and network-based approaches. Compared with existing detection solutions, it is fast, reliable, and scalable in its detection scope. Furthermore, it can be applicable to more than just P2P malware, more broadly any malware that opens a service port for network communications (e.g., many Trojans/backdoors). We develop a prototype system, PeerPress, and evaluate it on many representative real-world P2P malware (including Storm, Conficker, and more recent Sality). The results show that it can effectively detect the existence of malware when MCBs are extracted, and the detection occurs in an early stage during which other tools (e.g., BotHunter) typically do not have sufficient information to detect. We further discuss its limitations and implications, and we believe it is a great complement to existing passive detection solutions.
Zhaoyan Xu, Lingfeng Chen, Guofei Gu, Christopher Krügel
CCS3
2012 Automatic generation of vaccines for malware immunization
abstract
Inspired by the biological vaccines, we explore the possibility of developing similar vaccines for malware immunization. We provide the first systematic study towards this direction and present a prototype system, AGAMI, for automatic generation of vaccines for malware immunization. With a novel use of several dynamic malware analysis techniques, we show that it is possible to extract a lightweight vaccine from current malware, and after injecting such vaccine on clean machines, they can be immune from future infection from the same malware family. We evaluate AGAMI on a large set of real-world malware samples and successfully extract working vaccines for many families such as Conficker and Zeus. We believe it is an appealing complementary technique to existing malware defense solutions.
Zhaoyan Xu, Jialong Zhang 0001, Guofei Gu, Zhiqiang Lin 0001
CCS3
2012 Detecting money-stealing apps in alternative Android markets
abstract
The prevalence of malware in Android marketplaces is a growing and significant problem. Among the most worrisome concerns are with regarding to malicious Android applications that attempt to steal money from unsuspecting users. These malicious applications get uploaded under the guise of benign applications, typically to third-party alternative market places that lack proper security vetting procedures, and are subsequently downloaded and executed by unsuspecting victims. In this work, we propose "Money-Guard", a systematic approach to detect stealthy moneystealing applications in popular Android markets. Our technique relies on detecting two key behavioral heuristics that seem to be common across many money-stealing Android malware: hardcoded exfiltration and notification suppression. In our preliminary analysis of 47 SMS-based money stealing applications, we confirm that 41 of these applications follow the above pattern, and describe a light weight detection approach that will identify this behavioral pattern.
Chao Yang 0022, Vinod Yegneswaran, Phillip A. Porras, Guofei Gu
CCS4
2012 CloudWatcher: Network security monitoring using OpenFlow in dynamic cloud networks (or: How to provide security monitoring as a service in clouds?)
abstract
Cloud computing is becoming a popular paradigm. Many recent new services are based on cloud environments, and a lot of people are using cloud networks. Since many diverse hosts and network configurations coexist in a cloud network, it is essential to protect each of them in the cloud network from threats. To do this, basically, we can employ existing network security devices, but applying them to a cloud network requires more considerations for its complexity, dynamism, and diversity. In this paper, we propose a new framework, CloudWatcher, which provides monitoring services for large and dynamic cloud networks. This framework automatically detours network packets to be inspected by pre-installed network security devices. In addition, all these operations can be implemented by writing a simple policy script, thus, a cloud network administrator is able to protect his cloud network easily. We have implemented the proposed framework, and evaluated it on different test network environments.
Seungwon Shin 0001, Guofei Gu
ICNP2
2012 EFFORT: Efficient and effective bot malware detection
abstract
To detect bots, a lot of detection approaches have been proposed at host or network level so far and both approaches have clear advantages and disadvantages. In this paper, we propose EFFORT, a new host-network cooperated detection framework attempting to overcome shortcomings of both approaches while still keeping both advantages, i.e., effectiveness and efficiency. Based on intrinsic characteristics of bots, we propose a multi-module approach to correlate information from different host- and network-level aspects and design a multi-layered architecture to efficiently coordinate modules to perform heavy monitoring only when necessary. We have implemented our proposed system and evaluated on real-world benign and malicious programs running on several diverse real-life office and home machines for several days. The final results show that our system can detect all 15 real-world bots (e.g., Waledac, Storm) with low false positives (0.68%) and with minimal overhead. We believe EFFORT raises a higher bar and this host-network cooperated design represents a timely effort and a right direction in the malware battle.
Seungwon Shin 0001, Zhaoyan Xu, Guofei Gu
INFOCOM3
2012 PoisonAmplifier: A Guided Approach of Discovering Compromised Websites through Reversing Search Poisoning Attacks
Jialong Zhang 0001, Chao Yang 0022, Zhaoyan Xu, Guofei Gu
RAID4
2012 Analyzing spammers' social networks for fun and profit: a case study of cyber criminal ecosystem on twitter
abstract
In this paper, we perform an empirical analysis of the cyber criminal ecosystem on Twitter. Essentially, through analyzing inner social relationships in the criminal account community, we find that criminal accounts tend to be socially connected, forming a small-world network. We also find that criminal hubs, sitting in the center of the social graph, are more inclined to follow criminal accounts. Through analyzing outer social relationships between criminal accounts and their social friends outside the criminal account community, we reveal three categories of accounts that have close friendships with criminal accounts. Through these analyses, we provide a novel and effective criminal account inference algorithm by exploiting criminal accounts' social relationships and semantic coordinations.
Chao Yang 0022, Robert Chandler Harkreader, Jialong Zhang 0001, Seungwon Shin 0001, Guofei Gu
WWW5
2012 A Large-Scale Empirical Study of Conficker
abstract
Conficker is the most recent widespread, well-known worm/bot. According to several reports, it has infected about 7 million to 15 million hosts and the victims are still increasing even now. In this paper, we analyze Conficker infections at a large scale, about 25 million victims, and study various interesting aspects about this state-of-the-art malware. By analyzing Conficker, we intend to understand current and new trends in malware propagation, which could be very helpful in predicting future malware trends and providing insights for future malware defense. We observe that Conficker has some very different victim distribution patterns compared to many previous generation worms/botnets, suggesting that new malware spreading models and defense strategies are likely needed. We measure the potential power of Conficker to estimate its effects on the networks/hosts when it performs malicious operations. Furthermore, we intend to determine how well a reputation-based blacklisting approach can perform when faced with new malware threats such as Conficker. We cross-check several DNS blacklists and IP/AS reputation data from Dshield and FIRE and our evaluation shows that unlike a previous study which shows that a blacklist-based approach can detect most bots, these reputation-based approaches did relatively poorly for Conficker. This raises a question of how we can improve and complement existing reputation-based techniques to prepare for future malware defense? Based on this, we look into some insights for defenders. We show that neighborhood watch is a surprisingly effective approach in the case of Conficker. This suggests that security alert sharing/correlation (particularly among neighborhood networks) could be a promising approach and play a more important role for future malware defense.
Seungwon Shin 0001, Guofei Gu, A. L. Narasimha Reddy, Christopher P. Lee 0001
IEEE Trans. Inf. Forensics Secur.2
2012 Active User-Side Evil Twin Access Point Detection Using Statistical Techniques
abstract
In this paper, we consider the problem of “evil twin” attacks in wireless local area networks (WLANs). An evil twin is essentially a rogue (phishing) Wi-Fi access point (AP) that looks like a legitimate one (with the same SSID). It is set up by an adversary, who can eavesdrop on wireless communications of users' Internet access. Existing evil twin detection solutions are mostly for wireless network administrators to verify whether a given AP is in an authorized list or not, instead of for a wireless client to detect whether a given AP is authentic or evil. Such administrator-side solutions are limited, expensive, and not available for many scenarios. Thus, a lightweight, effective, and user-side solution is highly desired. In this work, we propose a novel user-side evil twin detection technique that outperforms traditional administrator-side detection methods in several aspects. Unlike previous approaches, our technique does not need a known authorized AP/host list, thus it is suitable for users to identify and avoid evil twins. Our technique does not strictly rely on training data of target wireless networks, nor depend on the types of wireless networks. We propose to exploit fundamental communication structures and properties of such evil twin attacks in wireless networks and to design new active, statistical and anomaly detection algorithms. Our preliminary evaluation in real-world widely deployed 802.11b and 802.11 g wireless networks shows very promising results. We can identify evil twins with a very high detection rate while maintaining a very low false positive rate.
Chao Yang 0022, Yimin Song, Guofei Gu
IEEE Trans. Inf. Forensics Secur.3
2011 SEMAGE: a new image-based two-factor CAPTCHA
abstract
We present SEMAGE (SEmantically MAtching imaGEs), a new image-based CAPTCHA that capitalizes on the human ability to define and comprehend image content and to establish semantic relationships between them. A SEMAGE challenge asks a user to select semantically related images from a given image set. SEMAGE has a two-factor design where in order to pass a challenge the user is required to figure out the content of each image and then understand and identify semantic relationship between a subset of them. Most of the current state-of-the-art image-based systems like Assira [20] only require the user to solve the first level, i.e., image recognition. Utilizing the semantic correlation between images to create more secure and user-friendly challenges makes SEMAGE novel. SEMAGE does not suffer from limitations of traditional image-based approaches such as lacking customization and adaptability. SEMAGE unlike the current text-based systems is also very user-friendly with a high fun factor. These features make it very attractive to web service providers. In addition, SEMAGE is language independent and highly flexible for customizations (both in terms of security and usability levels). SEMAGE is also mobile devices friendly as it does not require the user to type anything. We conduct a first-of-its-kind large-scale user study involving 174 users to gauge and compare accuracy and usability of SEMAGE with existing state-of-the-art CAPTCHA systems like reCAPTCHA (text-based) [6] and Asirra (image-based) [20]. The user study further reinstates our points and shows that users achieve high accuracy using our system and consider our system to be fun and easy.
Shardul Vikram, Yinan Fan, Guofei Gu
ACSAC3
2011 WebPatrol: automated collection and replay of web-based malware scenarios
abstract
Traditional remote-server-exploiting malware is quickly evolving and adapting to the new web-centric computing paradigm. By leveraging the large population of (insecure) web sites and exploiting the vulnerabilities at client-side modern (complex) browsers (and their extensions), web-based malware becomes one of the most severe and common infection vectors nowadays. While traditional malware collection and analysis are mainly focusing on binaries, it is important to develop new techniques and tools for collecting and analyzing web-based malware, which should include a complete web-based malicious logic to reflect the dynamic, distributed, multi-step, and multi-path web infection trails, instead of just the binaries executed at end hosts. This paper is a first attempt in this direction to automatically collect web-based malware scenarios (including complete web infection trails) to enable fine-grained analysis. Based on the collections, we provide the capability for offline "live" replay, i.e., an end user (e.g., an analyst) can faithfully experience the original infection trail based on her current client environment, even when the original malicious web pages are not available or already cleaned. Our evaluation shows that WebPatrol can collect/cover much more complete infection trails than state-of-the-art honeypot systems such as PHoneyC [11] and Capture-HPC [1]. We also provide several case studies on the analysis of web-based malware scenarios we have collected from a large national education and research network, which contains around 35,000 web sites.
Kevin Zhijie Chen, Guofei Gu, Jianwei Zhuge, Jose Nazario, Xinhui Han
AsiaCCS2
2011 Boosting the scalability of botnet detection using adaptive traffic sampling
abstract
Botnets pose a serious threat to the health of the Internet. Most current network-based botnet detection systems require deep packet inspection (DPI) to detect bots. Because DPI is a computational costly process, such detection systems cannot handle large volumes of traffic typical of large enterprise and ISP networks. In this paper we propose a system that aims to efficiently and effectively identify a small number of suspicious hosts that are likely bots. Their traffic can then be forwarded to DPI-based botnet detection systems for fine-grained inspection and accurate botnet detection. By using a novel adaptive packet sampling algorithm and a scalable spatial-temporal flow correlation approach, our system is able to substantially reduce the volume of network traffic that goes through DPI, thereby boosting the scalability of existing botnet detection systems. We implemented a proof-of-concept version of our system, and evaluated it using real-world legitimate and botnet-related network traces. Our experimental results are very promising and suggest that our approach can enable the deployment of botnet-detection systems in large, high-speed networks.
Junjie Zhang 0004, Xiapu Luo, Roberto Perdisci, Guofei Gu, Wenke Lee, Nick Feamster
AsiaCCS4
2011 Cross-Analysis of Botnet Victims: New Insights and Implications
Seungwon Shin 0001, Raymond Lin, Guofei Gu
RAID3
2011 Die Free or Live Hard? Empirical Evaluation and New Design for Fighting Evolving Twitter Spammers
Chao Yang 0022, Robert Chandler Harkreader, Guofei Gu
RAID3
2011 Checksum-Aware Fuzzing Combined with Dynamic Taint Analysis and Symbolic Execution
abstract
Fuzz testing has proven successful in finding security vulnerabilities in large programs. However, traditional fuzz testing tools have a well-known common drawback: they are ineffective if most generated inputs are rejected at the early stage of program running, especially when target programs employ checksum mechanisms to verify the integrity of inputs. This article presents TaintScope, an automatic fuzzing system using dynamic taint analysis and symbolic execution techniques, to tackle the above problem. TaintScope has several novel features: (1) TaintScope is a checksum-aware fuzzing tool. It can identify checksum fields in inputs, accurately locate checksum-based integrity checks by using branch profiling techniques, and bypass such checks via control flow alteration. Furthermore, it can fix checksum values in generated inputs using combined concrete and symbolic execution techniques. (2) TaintScope is a taint-based fuzzing tool working at the x86 binary level. Based on fine-grained dynamic taint tracing, TaintScope identifies the “hot bytes” in a well-formed input that are used in security-sensitive operations (e.g., invoking system/library calls), and then focuses on modifying such bytes with random or boundary values. (3) TaintScope is also a symbolic-execution-based fuzzing tool. It can symbolically evaluate a trace, reason about all possible values that can execute the trace, and then detect potential vulnerabilities on the trace. We evaluate TaintScope on a number of large real-world applications. Experimental results show that TaintScope can accurately locate the checksum checks in programs and dramatically improve the effectiveness of fuzz testing. TaintScope has already found 30 previously unknown vulnerabilities in several widely used applications, including Adobe Acrobat, Flash Player, Google Picasa, and Microsoft Paint. Most of these severe vulnerabilities have been confirmed by Secunia and oCERT, and assigned CVE identifiers (such as CVE-2009-1882, CVE-2009-2688). Vendor patches have been released or are in preparation based on our reports.
Tielei Wang, Tao Wei 0002, Guofei Gu
ACM Trans. Inf. Syst. Secur.3
2010 Conficker and beyond: a large-scale empirical study
abstract
Conficker [26] is the most recent widespread, well-known worm/bot. According to several reports [16, 28], it has infected about 7 million to 15 million hosts and the victims are still increasing even now. In this paper, we analyze Conficker infections at a large scale, including about 25 millions victims, and study various interesting aspects about this state-of-the-art malware. By analyzing Conficker, we intend to understand current and new trends in malware propagation, which could be very helpful in predicting future malware trends and providing insights for future malware defense. We observe that Conficker has some very different victim distribution patterns compared to many previous generation worms/botnets, suggesting that new malware spreading models and defense strategies are likely needed. Furthermore, we intend to determine how well a reputation-based blacklisting approach can perform when faced with new malware threats such as Conficker. We cross-check several DNS blacklists and IP/AS reputation data from Dshield [6] and FIRE [7], and our evaluation shows that unlike a previous study [18] which shows that a blacklist-based approach can detect most bots, these reputation-based approaches did relatively poorly for Conficker. This raised the question, how can we improve and complement existing reputation-based techniques to prepare for future malware defense? Finally, we look into some insights for defenders. We show that neighborhood watch is a surprisingly effective approach in the Conficker case. This suggests that security alert sharing/correlation (particularly among neighborhood networks) could be a promising approach and play a more important role for future malware defense.
Seungwon Shin 0001, Guofei Gu
ACSAC2
2010 Who is peeping at your passwords at Starbucks? - To catch an evil twin access point
abstract
In this paper, we consider the problem of “evil twin” attacks in wireless local area networks (WLANs). An evil twin is essentially a phishing (rogue) Wi-Fi access point (AP) that looks like a legitimate one (with the same SSID name). It is set up by an adversary, who can eavesdrop on wireless communications of users' Internet access. Existing evil twin detection solutions are mostly for wireless network administrators to verify whether a given AP is in an authorized list or not, instead of for a wireless client to detect whether a given AP is authentic or evil. Such administrator-side solutions are limited, expensive, and not available for many scenarios. For example, for traveling users who use wireless networks at airports, hotels, or cafes, they need to protect themselves from evil twin attacks (instead of relying on those wireless network providers, which typically may not provide strong security monitoring/management service). Thus, a lightweight and effective solution for these users is highly desired. In this work, we propose a novel user-side evil twin detection technique that outperforms traditional administrator-side detection methods in several aspects. Unlike previous approaches, our technique does not need a known authorized AP/host list, thus it is suitable for users to identify and avoid evil twins. Our technique does not strictly rely on training data of target wireless networks, nor depend on the types of wireless networks. We propose to exploit fundamental communication structures and properties of such evil twin attacks in wireless networks and to design new active, statistical and anomaly detection algorithms. Our preliminary evaluation in real-world widely deployed 802.11b and 802.11g wireless networks shows very promising results. We can identify evil twins with a very high detection rate while keeping a very low false positive rate.
Yimin Song, Chao Yang 0022, Guofei Gu
DSN3
2010 TaintScope: A Checksum-Aware Directed Fuzzing Tool for Automatic Software Vulnerability Detection
abstract
Fuzz testing has proven successful in finding security vulnerabilities in large programs. However, traditional fuzz testing tools have a well-known common drawback: they are ineffective if most generated malformed inputs are rejected in the early stage of program running, especially when target programs employ checksum mechanisms to verify the integrity of inputs. In this paper, we present TaintScope, an automatic fuzzing system using dynamic taint analysis and symbolic execution techniques, to tackle the above problem. TaintScope has several novel contributions: 1) TaintScope is the first checksum-aware fuzzing tool to the best of our knowledge. It can identify checksum fields in input instances, accurately locate checksum-based integrity checks by using branch profiling techniques, and bypass such checks via control flow alteration. 2) TaintScope is a directed fuzzing tool working at X86 binary level (on both Linux and Window). Based on fine-grained dynamic taint tracing, TaintScope identifies which bytes in a well-formed input are used in security-sensitive operations (e.g., invoking system/library calls) and then focuses on modifying such bytes. Thus, generated inputs are more likely to trigger potential vulnerabilities. 3) TaintScope is fully automatic, from detecting checksum, directed fuzzing, to repairing crashed samples. It can fix checksum values in generated inputs using combined concrete and symbolic execution techniques. We evaluate TaintScope on a number of large real-world applications. Experimental results show that TaintScope can accurately locate the checksum checks in programs and dramatically improve the effectiveness of fuzz testing. TaintScope has already found 27 previously unknown vulnerabilities in several widely used applications, including Adobe Acrobat, Google Picasa, Microsoft Paint, and ImageMagick. Most of these severe vulnerabilities have been confirmed by Secunia and oCERT, and assigned CVE identifiers (such as CVE-2009-1882, CVE-2009-2688). Corresponding patches from vendors are released or in progress based on our reports.
Tielei Wang, Tao Wei 0002, Guofei Gu
IEEE Symposium on Security and Privacy3
2009 Active Botnet Probing to Identify Obscure Command and Control Channels
abstract
We consider the problem of identifying obscure chat-like botnet command and control (C & C) communications, which are indistinguishable from human-human communication using traditional signature-based techniques. Existing passive-behavior-based anomaly detection techniques are limited because they either require monitoring multiple bot-infected machines that belong to the same botnet or require extended monitoring times. In this paper, we explore the potential use of active botnet probing techniques in a network middle-box as a means to augment and complement existing passive botnet C & C detection strategies, especially for small botnets with obfuscated C & C content and infrequent C & C interactions. We present an algorithmic framework that uses hypothesis testing to separate botnet C & C dialogs from human-human conversations with desired accuracy and implement a prototype system called BotProbe. Experimental results on multiple real-world IRC bots demonstrate that our proposed active methods can successfully identify obscure and obfuscated botnet communications. A real-world user study on about one hundred participants also shows that the technique has a low false positive rate on human-human conversations. We discuss the limitations of BotProbe and hope this preliminary feasibility study on the use of active techniques in botnet research can inspire new thoughts and directions within the malware research community.
Guofei Gu, Vinod Yegneswaran, Phillip A. Porras, Jennifer Stoll, Wenke Lee
ACSAC1
2008 Principled reasoning and practical applications of alert fusion in intrusion detection systems
abstract
It is generally believed that by combining several diverse intrusion detectors (i.e., forming an IDS ensemble), we may achieve better performance. However, there has been very little work on analyzing the effectiveness of an IDS ensemble. In this paper, we study the following problem: how to make a good fusion decision on the alerts from multiple detectors in order to improve the final performance. We propose a decision-theoretic alert fusion technique based on the likelihood ratio test (LRT). We report our experience from empirical studies, and formally analyze its practical interpretation based on ROC curve analysis. Through theoretical reasoning and experiments using multiple IDSs on several data sets, we show that our technique is more flexible and also outperforms other existing fusion techniques such as AND, OR, majority voting, and weighted voting.
Guofei Gu, Alvaro A. Cárdenas, Wenke Lee
AsiaCCS1
2008 BotSniffer: Detecting Botnet Command and Control Channels in Network Traffic
Guofei Gu, Junjie Zhang 0004, Wenke Lee
NDSS1
2008 BotMiner: Clustering Analysis of Network Traffic for Protocol- and Structure-Independent Botnet Detection
Guofei Gu, Roberto Perdisci, Junjie Zhang 0004, Wenke Lee
USENIX Security Symposium1
2007 A Taxonomy of Botnet Structures
abstract
We propose a taxonomy of botnet structures, based on their utility to the botmaster. We propose key metrics to measure their utility for various activities (e.g., spam, ddos). Using these performance metrics, we consider the ability of different response techniques to degrade or disrupt botnets. In particular, our models show that targeted responses are particularly effective against scale free botnets and efforts to increase the robustness of scale free networks comes at a cost of diminished transitivity. Botmasters do not appear to have any structural solutions to this problem in scale free networks. We also show that random graph botnets (e.g., those using P2P formations) are highly resistant to both random and targeted responses. We evaluate the impact of responses on different topologies using simulation and demonstrate the utility of our proposed metrics by performing novel measurements of a P2P network. Our analysis shows how botnets may be classified according to structure and given rank or priority using our proposed metrics. This may help direct responses and suggests which general remediation strategies are more likely to succeed.
David Dagon, Guofei Gu, Christopher P. Lee 0001, Wenke Lee
ACSAC2
2007 BotHunter: Detecting Malware Infection Through IDS-Driven Dialog Correlation
Guofei Gu, Phillip A. Porras, Vinod Yegneswaran, Martin W. Fong, Wenke Lee
USENIX Security Symposium1
2006 DSO: Dependable Signing Overlay
Guofei Gu, Prahlad Fogla, Wenke Lee, Douglas M. Blough
ACNS1
2006 Measuring intrusion detection capability: an information-theoretic approach
abstract
A fundamental problem in intrusion detection is what metric(s) can be used to objectively evaluate an intrusion detection system (IDS) in terms of its ability to correctly classify events as normal or intrusive. Traditional metrics (e.g., true positive rate and false positive rate) measure different aspects, but no single metric seems sufficient to measure the capability of intrusion detection systems. The lack of a single unified metric makes it difficult to fine-tune and evaluate an IDS. In this paper, we provide an in-depth analysis of existing metrics. Specifically, we analyze a typical cost-based scheme [6], and demonstrate that this approach is very confusing and ineffective when the cost factor is not carefully selected. In addition, we provide a novel information-theoretic analysis of IDS and propose a new metric that highly complements cost-based analysis. When examining the intrusion detection process from an information-theoretic point of view, intuitively, we should have less uncertainty about the input (event data) given the IDS output (alarm data). Thus, our new metric, CI D (Intrusion Detection Capability), is defined as the ratio of the mutual information between the IDS input and output to the entropy of the input. CI D has the desired property that: (1) It takes into account all the important aspects of detection capability naturally, i.e., true positive rate, false positive rate, positive predictive value, negative predictive value, and base rate; (2) it objectively provides an intrinsic measure of intrusion detection capability; and (3) it is sensitive to IDS operation parameters such as true positive rate and false positive rate, which can demonstrate the effect of the subtle changes of intrusion detection systems. We propose CI D as an appropriate performance measure to maximize when fine-tuning an IDS. The obtained operation point is the best that can be achieved by the IDS in terms of its intrinsic ability to classify input data. We use numerical examples as well as experiments of actual IDSs on various data sets to show that by using CI D, we can choose the best (optimal) operating point for an IDS and objectively compare different IDSs.
Guofei Gu, Prahlad Fogla, David Dagon, Wenke Lee, Boris Skoric
AsiaCCS1
2006 Towards an Information-Theoretic Framework for Analyzing Intrusion Detection Systems
Guofei Gu, Prahlad Fogla, David Dagon, Wenke Lee, Boris Skoric
ESORICS1
2006 InfoShield: a security architecture for protecting information usage in memory
abstract
Cyber theft is a serious threat to Internet security. It is one of the major security concerns by both network service providers and Internet users. Though sensitive information can be encrypted when stored in non-volatile memory such as hard disks, for many e-commerce and network applications, sensitive information is often stored as plaintext in main memory. Documented and reported exploits facilitate an adversary stealing sensitive information from an application's memory. These exploits include illegitimate memory scan, information theft oriented buffer overflow, invalid pointer manipulation, integer overflow, password stealing Trojans and so forth. Today's computing system and its hardware cannot address these exploits effectively in a coherent way. This paper presents a unified and lightweight solution, called InfoShield that can strengthen application protection against theft of sensitive information such as passwords, encryption keys, and other private data with a minimal performance impact. Unlike prior whole memory encryption and information flow based efforts, InfoShield protects the usage of information. InfoShield ensures that sensitive data are used only as defined by application semantics, preventing misuse of information. Comparing with prior art, InfoShield handles a broader range of information theft scenarios in a unified framework with less overhead. Evaluation using popular network client-server applications shows that InfoShield is sound for practical use and incurs little performance loss because InfoShield only protects absolute, critical sensitive information. Based on the profiling results, only 0.3% of memory accesses and 0.2% of executed codes are affected by InfoShield.
Joshua B. Fryman, Guofei Gu, Hsien-Hsin S. Lee, Youtao Zhang, Jun Yang 0002
HPCA3
2006 Using an Ensemble of One-Class SVM Classifiers to Harden Payload-based Anomaly Detection Systems
abstract
Unsupervised or unlabeled learning approaches for network anomaly detection have been recently proposed. In particular, recent work on unlabeled anomaly detection focused on high speed classification based on simple payload statistics. For example, PAYL, an anomaly IDS, measures the occurrence frequency in the payload of n-grams. A simple model of normal traffic is then constructed according to this description of the packets' content. It has been demonstrated that anomaly detectors based on payload statistics can be "evaded" by mimicry attacks using byte substitution and padding techniques. In this paper we propose a new approach to construct high speed payload-based anomaly IDS intended to be accurate and hard to evade. We propose a new technique to extract the features from the payload. We use a feature clustering algorithm originally proposed for text classification problems to reduce the dimensionality of the feature space. Accuracy and hardness of evasion are obtained by constructing our anomaly-based IDS using an ensemble of one-class SVM classifiers that work on different feature spaces.
Roberto Perdisci, Guofei Gu, Wenke Lee
ICDM2
2004 Worm Detection, Early Warning and Response Based on Local Victim Information
abstract
Worm detection systems have traditionally focused on global strategies. In the absence of a global worm detection system, we examine the effectiveness of local worm detection and response strategies. This paper makes three contributions: (1) we propose a simple two-phase local worm victim detection algorithm, DSC (Destination-Source Correlation), based on worm behavior in terms of both infection pattern and scanning pattern. DSC can detect zero-day scanning worms with a high detection rate and very low false positive rate. (2) We demonstrate the effectiveness of early worm warning based on local victim information. For example, warning occurs with 0.19% infection of all vulnerable hosts on Internet when using a /12 monitored network. (3) Based on local victim information, we investigate and evaluate the effectiveness of an automatic real-time local response in terms of slowing down the global Internet worms propagation. (2) and (3) are general results, not specific to certain detection algorithm like DSC. We demonstrate (2) and (3) with both analytical models and packet-level network simulator experiments.
Guofei Gu, Monirul Islam Sharif, Xinzhou Qin, David Dagon, Wenke Lee, George F. Riley
ACSAC1
2004 HoneyStat: Local Worm Detection Using Honeypots
David Dagon, Xinzhou Qin, Guofei Gu, Wenke Lee, Julian B. Grizzard, John G. Levine, Henry L. Owen
RAID3
2003 PLI: A New Framework to Protect Digital Content for P2P Networks
Guofei Gu, Bin B. Zhu, Shipeng Li 0001, Shiyong Zhang
ACNS1