VLDB 2026 Research / reviewers in the wild / expert
Wenchang Shi
dblp:74/2181
· DBLP profile ↗
62ranked-venue papers
0as first author
22since 2021 · last 2026
0000-0002-5160-1223ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 33 · 12 since 2021Software engineering, systems software and programming languages · 13 · 5 since 2021Systems, architecture and hardware · 6 · 2 since 2021Computer networks · 5 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 since 2021Databases, data management, data science and information retrieval · 3 · 1 since 2021Artificial intelligence and machine learning · 1Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PriSat: Prioritized satisfaction of critical path and data conditions for directed greybox fuzzing
Yang Zi, Wenchang Shi, Linjie Pan 0003, Pan Bian, Wei You 0001 |
Comput. Secur. | 3 |
| 2026 | AtomXross: Toward General Cross-Chain TransactionabstractAs blockchain technology advances, an increasing number of applications require interactions between smart contracts across multiple blockchains. However, existing cross-chain solutions exhibit limited scalability due to heterogeneous blockchain environments and diverse application requirements. A fundamental challenge lies in the absence of a unified resource definition for cross-chain processes, impeding moderate resource allocation and effective conflict resolution. Specifically, when extended to general cross-chain transactions involving invocations among multiple contracts, these methods lack the capability to correctly handle state transitions for all related contracts. This paper proposes AtomXross, a novel cross-chain scheme that supports arbitrary combinations of smart contracts during the cross-chain process. We build a scalable cross-chain architecture based on a relay chain and a cluster of cross-chain nodes to provide better scalability. We propose a unified definition for cross-chain resources within the system and implement an adaptive resource management mechanism on the relay chain, enabling it to record the invocation relationships of contract functions. When a cross-chain transaction involves multiple contract calls, AtomXross can index the calls and generate the corresponding call tree. To address the challenges posed by potential mutual invocations between smart contracts, we design an atomic transaction protocol based on buckle-lock, an ordered two-tier pessimistic locking mechanism. AtomXross ensures that cross-chain transactions do not conflict with each other while remaining compatible with non-cross-chain calls that may occur at any time. Furthermore, we propose a universal programming template for on-chain smart contracts, which enables ordinary smart contracts to acquire cross-chain capabilities. We implement AtomXross based on Hyperledger Fabric and FiscoBCOS. In comparison to WeCross, AtomXross lowers the gas cost on system initialization and incurs only a 14% increase in transaction latency while supporting inter-contract calls. Yanran Zhang, Yifu Geng, Qin Wang 0008, Qianhong Wu, Wenchang Shi, Willy Susilo |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | Fight Fire with Fire: Combating Adversarial Patch Attacks using Pattern-randomized Defensive PatchesabstractObject detection has found extensive applications in various tasks, but it is also susceptible to adversarial patch attacks. The ideal defense should be effective, efficient, easy to deploy, and capable of withstanding adaptive attacks. In this paper, we adopt a counterattack strategy to propose a novel and general methodology for defending adversarial attacks. Two types of defensive patches, canary and woodpecker, are specially-crafted and injected into the model input to proactively probe or counteract potential adversarial patches. In this manner, adversarial patch attacks can be effectively detected by simply analyzing the model output, without the need to alter the target model. Moreover, we employ randomized canary and woodpecker injection patterns to defend against defense-aware attacks. The effectiveness and practicality of the proposed method are demonstrated through comprehensive experiments. The results illustrate that canary and woodpecker achieve high performance, even when confronted with unknown attack methods, while incurring limited time overhead. Furthermore, our method also exhibits sufficient robustness against defense-aware attacks, as evidenced by adaptive attack experiments. Jianan Feng, Changqing Miao, Jianjun Huang 0001, Wei You 0001, Wenchang Shi, Bin Liang 0002 |
SP | 6 |
| 2025 | BridgeRouter: Automated Capability Upgrading of Out-Of-Bounds Write Vulnerabilities to Arbitrary Memory Write Primitives in the Linux KernelabstractMemory corruption vulnerabilities pose a significant threat to the Linux kernel, with out-of-bounds (OOB) vulnerabilities receiving particular attention due to their prevalence. The existing kernel OOB exploitation techniques either require strong capabilities from the vulnerabilities, demand that the vulnerable and victim objects reside in the same memory allocator cache, or rely on extensive page table manipulation. These constraints restrict their applicability and lead to low success rates in completing a full exploitation chain. In this paper, we propose a practical approach that enables arbitrary memory writes from kernel OOB vulnerabilities with limited capabilities. Our method leverages two special kinds of kernel objects to upgrade the capability from an uncontrolled overwrite to a controlled overwrite, ultimately achieving arbitrary memory write. We develop a system to automatically identify and utilize these two kinds of kernel objects. Evaluations on a crafted vulnerability and 14 representative real-world vulnerabilities, along with a comparison against two state-of-the-art works, demonstrate the broad applicability of our approach. Dongchen Xie, Dongnan He, Wei You 0001, Jianjun Huang 0001, Bin Liang 0002, Shuitao Gan, Wenchang Shi |
SP | 7 |
| 2024 | Define-Use Guided Path Exploration for Better Forced ExecutionabstractThe evolution of recent malware, characterized by the escalating use of cloaking techniques, poses a significant challenge in the analysis of malware behaviors. Researchers proposed forced execution to penetrate malware’s self-protection mechanisms and expose hidden behaviors, by forcefully setting certain branch outcomes. Existing studies focus on enhancing the forced executor to provide light-weight crash-free execution models. However, insufficient attention has been directed toward the path exploration strategy, an aspect equally crucial to the effectiveness. Linear search employed in state-of-the-art forced execution tools exhibits inherent limitations that lead to unnecessary path exploration and incomplete behavior exposure. In this paper, we propose a novel and practical path exploration strategy that focuses on the coverage of defineuse relations in the subject binary. We develop a fuzzing approach for exploring these define-use relations in a progressive and self-supervised way. Our experimental results show that the proposed solution outperforms the existing forced execution tools in both memory dependence coverage and malware behavior exposure. Dongnan He, Dongchen Xie, Wei You 0001, Bin Liang 0002, Jianjun Huang 0001, Wenchang Shi, Zhuo Zhang 0002, Xiangyu Zhang 0001 |
ISSTA | 7 |
| 2024 | SICode: Embedding-Based Subgraph Isomorphism Identification for Bug DetectionabstractGiven a known buggy code snippet, searching for similar patterns in a target project to detect unknown bugs is a reasonable approach. In practice, a search unit, such as a function, may appear quite different from the buggy snippet but actually contains a similar buggy substructure. Utilizing subgraph isomorphism identification can effectively hunt potential bugs by checking whether an approximate copy of the buggy subgraph exists within the target code graphs. Regrettably, subgraph isomorphism identification is an NP-complete problem. Yuanjun Gong, Jianglei Nie, Wei You 0001, Wenchang Shi, Jianjun Huang 0001, Bin Liang 0002, Jian Zhang 0001 |
ICPC | 4 |
| 2023 | A Good Fishman Knows All the Angles: A Critical Evaluation of Google's Phishing Page ClassifierabstractPhishing is one of the most popular cyberspace attacks. Phishing detection has been integrated into mainstream browsers to provide online protection. The phishing detector of Google Chrome reports millions of phishing attacks per week. However, it has been proven to be vulnerable to evasion attacks. Currently, Google has upgraded Chrome/Chromium's phishing detector, introducing a CNN-based image classifier. The robustness of the new-generation detector is unclear. If it can be bypassed, its billions of users will be exposed to sophisticated attackers. This paper presents a critical evaluation of Google's phishing detector by targeted evasion testing, and investigates corresponding defensive techniques. First, we propose a three-stage evasion method against the phishing image classifier. The experiments show that it can be completely bypassed with adversarial phishing pages generated using the proposed method. Meanwhile, the phishing pages still preserve their visual utility. Second, we introduce two defense techniques to enhance the phishing detection model. The results show that even using lightweight defense methods can significantly improve the model robustness. Our research reveals that Google's new-generation phishing classifier is very vulnerable to targeted evasion attacks. A sophisticated phishers can know how to fool the classifier. Billions of Chrome users are being exposed to potential phishing attacks. To improve its robustness, necessary security enhancements should be introduced. Changqing Miao, Jianan Feng, Wei You 0001, Wenchang Shi, Jianjun Huang 0001, Bin Liang 0002 |
CCS | 4 |
| 2023 | Who Are Querying For Me? Egress Measurement For Open DNS ResolversabstractThe dependencies and centralization in DNS infrastructure increase the risk of single-point failure and the scope of collateral damage. In the DNS recursive resolution, dependencies between different resolvers also exist due to situations such as forwarding. Currently, research on dependencies in recursive resolution is still insufficient. In this work, we take a deep insight into the recursive resolution implemented by open resolvers to investigate their dependencies, including the concentration of dependencies, and the influence of 3rd-party providers. We find that most open resolvers in the wild are dependent on a small number of egress resolvers to communicate with the authoritative name servers. 90% of the open resolvers are influenced by 8.41% of the egress resolvers. Besides, egress resolvers from 3rd-party providers are able to influence more than 44% of the open resolvers. The concentration makes a large amount of DNS traffic concentrated in a small number of egress resolvers/providers, which will reduce the redundancy of DNS and threaten user privacy. Meng Luo 0006, Liling Xin, Yepeng Yao, Zhengwei Jiang, Qiuyun Wang, Wenchang Shi |
CSCWD | 6 |
| 2023 | Subsidy Bridge: Rewarding Cross-Blockchain Relayers with Subsidy
Yifu Geng, Qin Wang 0008, Wenchang Shi, Qianhong Wu |
ICICS | 4 |
| 2023 | BDTS: Blockchain-Based Data Trading System
Erya Jiang, Qin Wang 0008, Qianhong Wu, Sanxi Li, Wenchang Shi, Yingxin Bi, Wenyi Tang |
ICICS | 6 |
| 2023 | Operand-Variation-Oriented Differential Analysis for Fuzzing Binding Calls in PDF ReadersabstractBinding calls of embedded scripting engines introduce a serious attack surface in PDF readers. To effectively test binding calls, the knowledge of parameter types is necessary. Unfortunately, due to the absence or incompleteness of documentation and the lack of sufficient samples, automatic type reasoning for binding call parameters is a big challenge. In this paper, we propose a novel operand-variation-oriented differential analysis approach, which automatically extracts features from execution traces as oracles for inferring parameter types. In particular, the parameter types of a binding call are inferred by executing the binding call with different values of different types and investigating which types cause an expected effect on the instruction operands. The inferred type information is used to guide the test generation in fuzzing. Through the evaluation on two popular PDF readers (Adobe Reader and Foxit Reader), we demonstrated the accuracy of our type reasoning method and the effectiveness of the inferred type information for improving fuzzing in both code coverage and vulnerability discovery. We found 38 previously unknown security vulnerabilities, 26 of which were certified with CVE numbers. Suyue Guo, Xinyu Wan, Wei You 0001, Bin Liang 0002, Wenchang Shi, Jianjun Huang 0001, Jian Zhang 0001 |
ICSE | 5 |
| 2023 | Interactions of Framing and Timing in Nudging Online Game Security
Leilei Qu, Ruojin Xiao, Wenchang Shi |
Comput. Secur. | 3 |
| 2022 | PXCrypto: A Regulated Privacy-Preserving Cross-Chain Transaction Scheme
Yanran Zhang, Qin Wang 0008, Qianhong Wu, Wenchang Shi |
ICA3PP | 6 |
| 2022 | Hunting bugs with accelerated optimal graph vertex matchingabstractVarious techniques based on code similarity measurement have been proposed to detect bugs. Essentially, the code fragment can be regarded as a kind of graph. Performing code graph similarity comparison to identify the potential bugs is a natural choice. However, the logic of a bug often involves only a few statements in the code fragment, while others are bug-irrelevant. They can be considered as a kind of noise, and can heavily interfere with the code similarity measurement. In theory, performing optimal vertex matching can address the problem well, but the task is NP-complete and cannot be applied to a large-scale code base. In this paper, we propose a two-phase strategy to accelerate code graph vertex matching for detecting bugs. In the first phase, a vertex matching embedding model is trained and used to rapidly filter a limited number of candidate code graphs from the target code base, which are likely to have a high vertex matching degree with the seed, i.e., the known buggy code. As a result, the number of code graphs needed to be further analyzed is dramatically reduced. In the second phase, a high-order similarity embedding model based on graph convolutional neural network is built to efficiently get the approximately optimal vertex matching between the seed and candidates. On this basis, the code graph similarity is calculated to identify the potential buggy code. The proposed method is applied to five open source projects. In total, 31 unknown bugs were successfully detected and confirmed by developers. Comparative experiments demonstrate that our method can effectively mitigate the noise problem, and the detection efficiency can be improved dozens of times with the two-phase strategy. Yuanjun Gong, Bin Liang 0002, Jianjun Huang 0001, Wei You 0001, Wenchang Shi, Jian Zhang 0001 |
ISSTA | 6 |
| 2022 | Measurement for encrypted open resolvers: Applications and security
Meng Luo 0006, Yepeng Yao, Liling Xin, Zhengwei Jiang, Qiuyun Wang, Wenchang Shi |
Comput. Networks | 6 |
| 2022 | Your Behaviors Reveal What You Need: A Practical Scheme Based on User Behaviors for Personalized Security Nudges
Leilei Qu, Ruojin Xiao, Wenchang Shi, Keman Huang, Bin Liang 0002 |
Comput. Secur. | 3 |
| 2021 | SoFi: Reflection-Augmented Fuzzing for JavaScript EnginesabstractJavaScript engines have been shown prone to security vulnerabilities, which can lead to serious consequences due to their popularity. Fuzzing is an effective testing technique to discover vulnerabilities. The main challenge of fuzzing JavaScript engines is to generate syntactically and semantically valid inputs such that deep functionalities can be explored. However, due to the dynamic nature of JavaScript and the special features of different engines, it is quite challenging to generate semantically meaningful test inputs. Xiaofei Xie, Yuekang Li, Feng Li 0045, Yang Liu 0003, Wenchang Shi, Wei Huo 0005 |
CCS | 10 |
| 2021 | SEPAL: Towards a Large-scale Analysis of SEAndroid Policy CustomizationabstractNowadays, SEAndroid has been widely deployed in Android devices to enforce security policies and provide flexible mandatory access control (MAC), for the purpose of narrowing down attack surfaces and restricting risky operations. Generally, the original SEAndroid security policy rules are carefully and strictly written and maintained by the Android community. However, in practice, mobile device manufacturers usually have to customize these policy rules and add their own new rules to satisfy their functionality extensions, which breaks the integrity of SEAndroid and causes serious security issues. Still, up to now, it is a challenging task to identify these security issues due to the large and ever-increasing number of policy rules, as well as the complexity of policy semantics. Dongsong Yu, Guangliang Yang 0001, Guozhu Meng, Xiaorui Gong, Xiaobo Xiang, Kai Chen 0012, Wenke Lee, Wenchang Shi |
WWW | 12 |
| 2021 | Detecting multiphase linear ranking functions for single-path linear-constraint loops
Wenchang Shi |
Int. J. Softw. Tools Technol. Transf. | 3 |
| 2021 | Detecting the Capacitance-Based Gamepad for Protecting Mobile Game FairnessabstractMobile game has become a big industry, whose success heavily depends on the game fairness. Recently, a new type of physical cheating instrument, the capacitance-based gamepad (CBG), has been wildly used in popular mobile games. CBG players can obtain an unfairly overwhelming control advantage (e.g., more sensitive clicking and sliding) over benign players. Moreover, as a physical peripheral, CBG is completely transparent to the game application and the underlying system. This makes it inherently immune to existing cheating detection techniques. In this study, by disassembling the CBG device, we find a leverageable physical limitation that the distributions of generated clicking and sliding are more concentrated around a limited area or a boundary respectively. Accordingly, a novel method is proposed to detect the CBG-based cheating. Specifically, to detect the CBG clicking, we employ the entropy to measure the uncertainty of the clicking coordinates; and to detect the CBG sliding, we introduce the convex hull identification algorithm to recognize the potential sliding boundary. We have applied our detection method to four popular mobile games. The evaluation results demonstrate the effectiveness of the proposed method. We believe that the proposed method can be easily adopted by the manufacturers to fight against the CBG-based cheating and protect the game fairness. Shilei Bai, Bin Liang 0002, Jianjun Huang 0001, Wei You 0001, Wenchang Shi |
IEEE Trans. Computers | 7 |
| 2021 | Detecting Adversarial Image Examples in Deep Neural Networks with Adaptive Noise ReductionabstractRecently, many studies have demonstrated deep neural network (DNN) classifiers can be fooled by the adversarial example, which is crafted via introducing some perturbations into an original sample. Accordingly, some powerful defense techniques were proposed. However, existing defense techniques often require modifying the target model or depend on the prior knowledge of attacks. In this paper, we propose a straightforward method for detecting adversarial image examples, which can be directly deployed into unmodified off-the-shelf DNN models. We consider the perturbation to images as a kind of noise and introduce two classic image processing techniques, scalar quantization and smoothing spatial filter, to reduce its effect. The image entropy is employed as a metric to implement an adaptive noise reduction for different kinds of images. Consequently, the adversarial example can be effectively detected by comparing the classification results of a given sample and its denoised version, without referring to any prior knowledge of attacks. More than 20,000 adversarial examples against some state-of-the-art DNN models are used to evaluate the proposed method, which are crafted with different attack techniques. The experiments show that our detection method can achieve a high overall F1 score of 96.39 percent and certainly raises the bar for defense-aware attacks. Bin Liang 0002, Miaoqiang Su, Xirong Li 0001, Wenchang Shi, XiaoFeng Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Hunting Vulnerable Smart Contracts via Graph Embedding Based Bytecode MatchingabstractSmart contract vulnerabilities have attracted lots of concerns due to the resultant financial losses. Matching-based detection methods extrapolating known vulnerabilities to unknown have proven to be effective in other platforms. However, directly adopting the technique to smart contracts is obstructed by two issues, i.e., diversity of bytecode generation resulting from the rapid evolution of compilers and interference of noise code easily caused by the homogeneous business logics. To address the problems, we propose contract bytecode-oriented normalization and slicing techniques to augment bytecode matching. Specifically, we conduct data- and instruction-level normalizations to uniform the bytecode generated by different compilers, and enforce contract-specific slicing by tracking data- and control-flows with simulated bytecode executions to prune the noise code as far as possible. Based on the above techniques, we design an unsupervised graph embedding algorithm to encode the code graphs into quantitatively comparable vectors. The potentially vulnerable smart contracts can be identified by measuring the similarities between their vectors and known vulnerable ones. Our evaluations have shown the efficiency (0.47 seconds per contract on average), effectiveness (160 verified true positives) and high precision (91.95% for top-ranked). It is worth noting that, we also identify dozens of honeypot contracts, further demonstrating the capability of our method. Jianjun Huang 0001, Songming Han, Wei You 0001, Wenchang Shi, Bin Liang 0002, JingZheng Wu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2020 | A Paid Message Forwarding Scheme Based on Social Network
Yifu Geng, Wenchang Shi, Qianhong Wu |
Inscrypt | 3 |
| 2020 | Experimental Comparisons of Verifiable Delay Functions
Zihan Yang 0002, Qianhong Wu, Wenchang Shi, Bin Liang 0002 |
ICICS | 4 |
| 2020 | SinkFinder: harvesting hundreds of unknown interesting function pairs with just one seedabstractMastering the knowledge about security-sensitive functions that can potentially result in bugs is valuable to detect them. However, identifying this kind of functions is not a trivial task. Introducing machine learning-based techniques to do the task is a natural choice. Unfortunately, the approach also requires considerable prior knowledge, e.g., sufficient labelled training samples. In practice, the requirement is often hard to meet. Pan Bian, Bin Liang 0002, Jianjun Huang 0001, Wenchang Shi, Xidong Wang, Jian Zhang 0001 |
ESEC/SIGSOFT FSE | 4 |
| 2020 | MVP: Detecting Vulnerabilities using Patch-Enhanced Vulnerability Signatures
Yang Xiao 0011, Bihuan Chen 0001, Chendong Yu, Zhengzi Xu, Zimu Yuan, Feng Li 0045, Binghong Liu, Yang Liu 0003, Wei Huo 0005, Wenchang Shi |
USENIX Security Symposium | 11 |
| 2020 | On the fine-grained fingerprinting threat to software-defined networks
Jianwei Hou, Minjian Zhang 0001, Wenchang Shi, Bin Liang 0002 |
Future Gener. Comput. Syst. | 4 |
| 2020 | Cecoin: A decentralized PKI mitigating MitM attacks
Jikun Huang, Qin Wang 0008, Xizhao Luo, Bin Liang 0002, Wenchang Shi |
Future Gener. Comput. Syst. | 6 |
| 2020 | A Survey on Digital Forensics in Internet of ThingsabstractInternet of Things (IoT) is increasingly permeating peoples' lives, gradually revolutionizing our way of life. Due to the tight connection between people and IoT, now civil and criminal investigations or internal probes must take IoT into account. From the forensic perspective, the IoT environment contains a rich set of artifacts that could benefit investigations, while the forensic investigation in IoT paradigm may have to alter to accommodate characteristics of IoT. Therefore, in this article, we analyze the impact of IoT on digital forensics and systematize the research efforts made by previous researchers from 2010 to 2018. We sketch the landscape of IoT forensics and examine the state of IoT forensics under a 3-D framework. The 3-D framework consists of a temporal dimension, a spatial dimension, and a technical dimension. The temporal dimension walks through the standard digital forensic process while the spatial dimension explores where to identify sources of evidence in IoT environment. These two dimensions attempt to provide principles and guidelines for standardizing digital investigations in the context of IoT. The technical dimension guides a way to the exploration of tools and techniques to ensure the enforcement of digital forensics in the ever-evolving IoT environment. Put together, we present a holistic overview of digital forensics in IoT. We also highlight open issues and outline promising suggestions to inspire future study. Jianwei Hou, Yuewei Li, Jingyang Yu, Wenchang Shi |
IEEE Internet Things J. | 4 |
| 2020 | Identifying parasitic malware as outliers by code clusteringabstractInjecting malicious code into benign programs is popular in spreading malware. Unfortunately, for detection, the prior knowledge about the malware, e.g., the behavior or implementation patterns, isn’t always available. Our observation shows that the logic of the host program is normally unclear to parasitic malware developers, resulting in very few interactions between the host and the payloads in lots of parasitic malware. Thus we can expose the injected part by grouping the code based on the interactive relations. Particularly, we partition a target program into modules, extract the relations, cluster the modules and further inspect the outliers to identify such malware. In this paper, we design a two-stage code clustering-based approach to detecting two representative types of malware, the UEFI rootkits and the piggybacked Android applications. Parasitic malware is reported when (1) any outlier in a UEFI firmware shows a relatively long distance to the largest cluster, or (2) the largest outlier distance exceeds zero in an Android application, i.e., multiple cluster exist after re-clustering outliers. We evaluate the approach on 35 pairs of benign/infected UEFI samples we do our best to get and achieve an overall F1 score. of 100%. Applying the learned threshold to 50 other benign firmwares, we identify them without false positives. In addition, our evaluation on 1079 pairs of Android applications, shows an F1 score of 90.66% when the third-party libraries are eliminated and a score of 87.36% if we keep the popular third-party libraries, demonstrating the effectiveness of the approach. Jianjun Huang 0001, Bin Liang 0002, Wenchang Shi, Yifang Wu, Shilei Bai |
J. Comput. Secur. | 4 |
| 2020 | Do not jail my app: Detecting the Android plugin environments by time lag contradictionabstractMany Android apps today face problems such as the large application package (APK) size, frequent updates, and so on. The Android plugin technology provides a solution for app developers, allowing a running app to dynamically load and execute a separate APK file without installing it in the system. These dynamically loaded APKs are called plugins. In Android app markets, many multi-instance apps abuse this technology to load normal social apps as plugins. While satisfying the users’ demand for logging into multiple accounts simultaneously, it brings new security threats to the legitimate apps. Sensitive API invocations can be hijacked and private data becomes accessible to malicious multi-instance apps. Therefore, identifying the running environments becomes necessary. In this paper, we propose a novel detection mechanism, named PluginAssassin, to identify whether an app is running as a plugin. PluginAssassin uses the time ratio of different activity launching procedures to determine the running environment, conforming to the observed time lag contradiction phenomenon. We also present a mitigation mechanism for the [Formula: see text] attack specific to our approach. We collect 50 multi-instance apps from two app markets and implement PluginAssassin in five popular social apps. We assess the effectiveness on three devices and the experimental results show that PluginAssassin can detect plugin environments effectively. Yifang Wu, Jianjun Huang 0001, Bin Liang 0002, Wenchang Shi |
J. Comput. Secur. | 4 |
| 2020 | TaintMan: An ART-Compatible Dynamic Taint Analysis Framework on Unmodified and Non-Rooted Android DevicesabstractDynamic taint analysis (DTA), as a mainstream information flow tracking technique, has been widely used in mobile security. On the Android platform, the existing DTA approaches are typically implemented by instrumenting the Dalvik virtual machine (DVM) interpreter or the Android emulator with taint enforcement code. The most prominent problem of the interpreter-based approaches is that they cannot work in the new Android RunTime (ART) environment introduced since the 5.0 release. For the emulator-based approaches, the most prominent problem is that they cannot be deployed on real devices. In addition, almost all the existing Android DTA approaches only concern the explicit information flow caused by data dependence, while completely ignore the impact of implicit information flow caused by control dependence. These problems limit their adoption in the latest Android system and make them ineffective in detecting the state-of-the-art malware whose privacy-breaching behaviors are inactivated in the analyzed environment (e.g., the emulator) or conducted via implicit information flow. In this paper, we present TaintMan, an ART-compatible DTA framework that can be deployed on unmodified and non-rooted Android devices. In TaintMan, the taint enforcement code is statically instrumented into both the target application and the system class libraries to track data flow and common control flow. A specially designed execution environment reconstruction technique, named reference hijacking, is proposed to force the target application to reference the instrumented system class libraries. By enforcing on-demand instrumentation and on-demand tracking, the performance overhead is significantly reduced. We have developed TaintMan and deployed it on two popular stock smartphones (HTC One S equipped with Android-4.0 and Motorola MOTO G equipped with Android-5.0). The evaluation with malware samples and real-world applications shows that TaintMan can effectively detect privacy leakage behaviors with an acceptable performance overhead. Wei You 0001, Bin Liang 0002, Wenchang Shi, Xiangyu Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2020 | Corrections to "Detecting Bugs by Discovering Expectations and Their Violations"abstractIn the above named work (ibid., vol. 45, no. 10, pp. 984???1001, Oct. 2019), the corresponding author should have been listed as Bin Liang. The footnote information is corrected here. Pan Bian, Bin Liang 0002, Wenchang Shi, Yan Cai 0001 |
IEEE Trans. Software Eng. | 5 |
| 2019 | An Approach to Cloud Execution Failure Diagnosis Based on Exception Logs in OpenStackabstractCloud is getting ubiquitous and scales up rapidly. It is critical to effectively detect and efficiently repair system anomalies for a robust cloud. Many efforts have been made to facilitate analysis of system problems with the readily-available and massive cloud logs. However, most tools can still not automatically recognize failures related to a specific cloud operating system task. To diagnose execution failures of a cloud, it is inevitable to monitor corresponding system tasks. In this paper, we propose a lightweight approach to identify cloud behaviors related to failed executions of the cloud operating system for failure diagnosis, by exploiting logs of ERROR logging level in a cloud. Instead of working on execution sequences extracted from logs for all system tasks, we focus on automated recognition of exception logs generated by a system task. These logs are critical snippets of execution traces for failure diagnosis of a cloud. In our work, exception logs are extracted and associated with the respective system task. Efforts can be reduced by comparing patterns of new error cloud behaviors with cloud behaviors met before. With experiments on OpenStack, a popular open source cloud operating system, we demonstrate that our work is effective and efficient for execution failure diagnosis of a cloud. Our approach can also be used as a complementary method for log-based troubleshooting tools concentrating on execution sequences. Wenchang Shi, Bin Liang 0002 |
CLOUD | 2 |
| 2019 | Learning-Based Anomaly Cause Tracing with Synthetic Analysis of Logs from Multiple Cloud Service ComponentsabstractIt is critical for a reliable cloud to effectively find out root causes of the cloud service anomalies for efficacious treatment. System logs are widely used for anomaly detection and analysis. Many efforts have been made to handle massive cloud logs automatically. However, existing work can still not effectually make comprehensive use of logs from multiple cloud service components to locate the causes of cloud service anomalies automatically. In this paper, we propose a learning-based approach for fine-grained deep cloud service anomaly cause tracing by synthetically utilizing logs from multiple service components of a cloud. We focus on uncovering root causes of anomalies corresponding to system executions of each user operation rather than roughly taking various system tasks as a whole. Log patterns are learned from past experience of system runs with anomalies occurred before, where the mined log event sequences to represent system behaviors related to each user operation are treated as natural language sequences. When an anomaly is to be diagnosed, the corresponding log patterns can be recognized for root cause identification. We implemented and evaluated our approach in OpenStack. Experimental results show that our approach can effectively trace the root causes for anomalies in cloud environments. Han Anu, Wenchang Shi, Bin Liang 0002 |
COMPSAC (1) | 3 |
| 2019 | DTGuard: A Lightweight Defence Mechanism Against a New DoS Attack on SDN
Jianwei Hou, Wenchang Shi, Bin Liang 0002 |
ICICS | 3 |
| 2019 | An Approach to Recommendation of Verbosity Log Levels Based on Logging IntentionabstractVerbosity levels of logs are designed to discriminate highly diverse runtime events, which facilitates system failure identification through simple keyword search (e.g., fatal, error). Verbosity levels should be properly assigned to logging statements, as inappropriate verbosity levels would confuse users and cause a lot of redundant maintenance effort. However, to achieve such a goal is not an easy task due to the lack of practical specifications and guidelines towards verbosity log level usages. The existing research has built a classification model on log related quantitative metrics such as log density to improve logging level practice. Though such quantitative metrics can reveal logging characteristics, their contributions on logging level decision are limited, since valuable logging intention information buried in logging code context can not be captured. In this paper, we propose an automatic approach to help developers determine the appropriate verbosity log levels. More specially, our approach discriminates different verbosity log level usages based on code context features that contain underlying logging intention. To validate our approach, we implement a prototype tool, VerbosityLevelDirector, and perform a case study to measure its effectiveness on four well-known open source software projects. Evaluation results show that VerbosityLevelDirector achieves high performance on verbosity level discrimination and outperforms the baseline approaches on all those projects. Furthermore, through applying noise handling technique, our approach can detect previously unknown inappropriate verbosity level configurations in the code repository. We have reported 21 representative logging level errors with modification advice to issue tracking platforms of the examined software projects and received positive feedback from their developers. The above results confirm that our work can help developers make a better logging level decision in real-world engineering. Han Anu, Wenchang Shi, Jianwei Hou, Bin Liang 0002 |
ICSME | 3 |
| 2019 | A survey on internet of things security from data perspectives
Jianwei Hou, Leilei Qu, Wenchang Shi |
Comput. Networks | 3 |
| 2019 | Detecting Bugs by Discovering Expectations and Their ViolationsabstractCode mining has been proven to be a promising approach to inferring implicit programming rules for finding software bugs. However, existing methods may report large numbers of false positives and false negatives. In this paper, we propose a novel approach called EAntMiner to improve the effectiveness of code mining. EAntMiner elaborately reduces noises from statements irrelevant to interesting rules and different implementation forms of the same logic. During preprocessing, we employ program slicing to decompose the original source repository into independent sub-repositories. In each sub-repository, statements irrelevant to critical operations (automatically extracted from source code) are excluded and various semantics-equivalent implementations are normalized into a canonical form as far as possible. Moreover, to tackle the challenge that some bugs are difficult to be detected by mining frequent patterns as rules, we further developed a kNN-based method to identify them. We have implemented EAntMiner and evaluated it on four large-scale C systems. EAntMiner successfully detected 105 previously unknown bugs that have been confirmed by corresponding development communities. A set of comparative evaluations also demonstrate that EAntMiner can effectively improve the precision of code mining. Pan Bian, Bin Liang 0002, Wenchang Shi, Yan Cai 0001 |
IEEE Trans. Software Eng. | 5 |
| 2018 | Deep Text Classification Can be FooledabstractIn this paper, we present an effective method to craft text adversarial samples, revealing one important yet underestimated fact that DNN-based text classifiers are also prone to adversarial sample attack. Specifically, confronted with different adversarial scenarios, the text items that are important for classification are identified by computing the cost gradients of the input (white-box attack) or generating a series of occluded test samples (black-box attack). Based on these items, we design three perturbation strategies, namely insertion, modification, and removal, to generate adversarial samples. The experiment results show that the adversarial samples generated by our method can successfully fool both state-of-the-art character-level and word-level DNN-based text classifiers. The adversarial samples can be perturbed to any desirable classes without compromising their utilities. At the same time, the introduced perturbation is difficult to be perceived. Bin Liang 0002, Miaoqiang Su, Pan Bian, Xirong Li 0001, Wenchang Shi |
IJCAI | 6 |
| 2018 | NAR-miner: discovering negative association rules from code for bug detectionabstractInferring programming rules from source code based on data mining techniques has been proven to be effective to detect software bugs. Existing studies focus on discovering positive rules in the form of A ⇒ B, indicating that when operation A appears, operation B should also be here. Unfortunately, the negative rules (A ⇒ ¬ B), indicating the mutual suppression or conflict relationships among program elements, have not gotten the attention they deserve. In fact, violating such negative rules can also result in serious bugs. Pan Bian, Bin Liang 0002, Wenchang Shi, Jianjun Huang 0001, Yan Cai 0001 |
ESEC/SIGSOFT FSE | 3 |
| 2017 | Identity-Based Data Outsourcing With Comprehensive Auditing in CloudsabstractCloud storage system provides facilitative file storage and sharing services for distributed clients. To address integrity, controllable outsourcing, and origin auditing concerns on outsourced files, we propose an identity-based data outsourcing (IBDO) scheme equipped with desirable features advantageous over existing proposals in securing outsourced data. First, our IBDO scheme allows a user to authorize dedicated proxies to upload data to the cloud storage server on her behalf, e.g., a company may authorize some employees to upload files to the company's cloud account in a controlled way. The proxies are identified and authorized with their recognizable identities, which eliminates complicated certificate management in usual secure distributed computing systems. Second, our IBDO scheme facilitates comprehensive auditing, i.e., our scheme not only permits regular integrity auditing as in existing schemes for securing outsourced data, but also allows to audit the information on data origin, type, and consistence of outsourced files. Security analysis and experimental evaluation indicate that our IBDO scheme provides strong security with desirable efficiency. Qianhong Wu, Wenchang Shi, Robert H. Deng, Jiankun Hu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2016 | AntMiner: mining more bugs by reducing noise interferenceabstractDetecting bugs with code mining has proven to be an effective approach. However, the existing methods suffer from reporting serious false positives and false negatives. In this paper, we developed an approach called AntMiner to improve the precision of code mining by carefully preprocessing the source code. Specifically, we employ the program slicing technique to decompose the original source repository into independent sub-repositories, taking critical operations (automatically extracted from source code) as slicing criteria. In this way, the statements irrelevant to a critical operation are excluded from the corresponding sub-repository. Besides, various semantics-equivalent representations are normalized into a canonical form. Eventually, the mining process can be performed on a refined code database, and false positives and false negatives can be significantly pruned. We have implemented AntMiner and applied it to detect bugs in the Linux kernel. It reported 52 violations that have been either confirmed as real bugs by the kernel development community or fixed in new kernel versions. Among them, 41 cannot be detected by a widely used representative analysis tool Coverity. Besides, the result of a comparative analysis shows that our approach can effectively improve the precision of code mining and detect subtle bugs that have previously been missed. Bin Liang 0002, Pan Bian, Wenchang Shi, Wei You 0001, Yan Cai 0001 |
ICSE | 4 |
| 2016 | Reference hijacking: patching, protecting and analyzing on unmodified and non-rooted android devicesabstractMany efforts have been paid to enhance the security of Android. However, less attention has been given to how to practically adopt the enhancements on off-the-shelf devices. In particular, securing Android devices often requires modifying their write-protected underlying system component files (especially the system libraries) by flashing or rooting devices, which is unacceptable in many realistic cases. In this paper, a novel technique, called reference hijacking, is presented to address the problem. By introducing a specially designed reset procedure, a new execution environment is constructed for the target application, in which the reference to the underlying system libraries will be redirected to the security-enhanced alternatives. The technique can be applicable to both the Dalvik and Android Runtime (ART) environments and to almost all mainstream Android versions (2.x to 5.x). To demonstrate the capability of reference hijacking, we develop three prototype systems, PatchMan, ControlMan, and TaintMan, to enforce specific security enhancements, involving patching vulnerabilities, protecting inter-component communications, and performing dynamic taint analysis for the target application. These three prototypes have been successfully deployed on a number of popular Android devices from different manufacturers, without modifying the underlying system. The evaluation results show that they are effective and do not introduce noticeable overhead. They strongly support that reference hijacking can substantially improve the practicability of many security enhancement efforts for Android. Wei You 0001, Bin Liang 0002, Wenchang Shi, Shuyang Zhu, Sikefu Xie, Xiangyu Zhang 0001 |
ICSE | 3 |
| 2016 | Cracking Classifiers for Evasion: A Case Study on the Google's Phishing Pages FilterabstractVarious classifiers based on the machine learning techniques have been widely used in security applications. Meanwhile, they also became an attack target of adversaries. Many existing studies have paid much attention to the evasion attacks on the online classifiers and discussed defensive methods. However, the security of the classifiers deployed in the client environment has not got the attention it deserves. Besides, earlier studies only concentrated on the experimental classifiers developed for research purposes only. The security of widely-used commercial classifiers still remains unclear. In this paper, we use the Google's phishing pages filter (GPPF), a classifier deployed in the Chrome browser which owns over one billion users, as a case to investigate the security challenges for the client-side classifiers. We present a new attack methodology targeting on client-side classifiers, called classifiers cracking. With the methodology, we successfully cracked the classification model of GPPF and extracted sufficient knowledge can be exploited for evasion attacks, including the classification algorithm, scoring rules and features, etc. Most importantly, we completely reverse engineered 84.8% scoring rules, covering most of high-weighted rules. Based on the cracked information, we performed two kinds of evasion attacks to GPPF, using 100 real phishing pages for the evaluation purpose. The experiments show that all the phishing pages (100%) can be easily manipulated to bypass the detection of GPPF. Our study demonstrates that the existing client-side classifiers are very vulnerable to classifiers cracking attacks. Bin Liang 0002, Miaoqiang Su, Wei You 0001, Wenchang Shi, Gang Yang 0001 |
WWW | 4 |
| 2016 | Versatile lightweight key distribution for big data privacy in vehicular ad hoc networksabstractSummary Vehicular ad hoc networks (VANETs) continually produce large scale of data shared among vehicles nearby to improve driving experience and safety. The vehicular communications contain a large amount of private information. It is well known that group key management is a fundamental cryptographic primitive for providing secure group communication. Although many proposals with regard to group key management have been introduced, they cannot well support secure subgroup and intergroup communications in VANETs. In this paper, we exploit the specific features of vehicular communications and propose two group key distribution schemes providing efficient solutions to these two problems. Our schemes do not require interaction between users. Storage and computation analyses show that compared with existing schemes, our proposals are more efficient and versatile. Based on these basic schemes, we present extensions for multipartite groups, by which the efficiency is greatly improved in this scenario. We also provide the extensions for two‐level multipartite groups, which enable fine‐grained real‐world applications. The experimental results confirm that our group key distribution schemes are practical in security, computation, and communication. Copyright © 2015 John Wiley & Sons, Ltd. Linxiao Wang, Qianhong Wu, Wenchang Shi, Bin Liang 0002 |
Concurr. Comput. Pract. Exp. | 5 |
| 2015 | Asymmetric Cross-cryptosystem Re-encryption Applicable to Efficient and Secure Mobile Access to Outsourced DataabstractWith the increasing development of pervasive computing and wireless bandwidth communication, more mobile devices are used to access sensitive data stored in remote servers. In such applications, a practical issue emerges such as how to exploit the sufficient resource of a server so that the file owners can enforce fine-grained access control over the remotely stored files, while enable resource-limited mobile devices to easily access the protected data, especially if the storage server maintained by a third party is untrusted. This challenge mainly arises from the asymmetric capacity among the participants, i.e., the capacity limited mobile devices and the resource abundant server (and file owners equipped with fixed computers). To meet the security requirements in mobile access to sensitive data, we propose a new encryption paradigm, referred to as asymmetric cross-cryptosystem re-encryption (ACCRE) by leveraging the asymmetric capacity of the participants. In ACCRE, relatively light-weight identity-based encryption (IBE) is deployed in mobile devices, while resource-consuming but versatile identity-based broadcast encryption (IBBE) is deployed in servers and fixed computers of the file owners. The core of ACCRE is a novel ciphertext conversion mechanism that allows an authorized proxy to convert a complicated IBBE ciphertext into a simple IBE ciphertext affordable to mobile devices, without leaking any sensitive information to the proxy. Following this paradigm, we propose an efficient ACCRE scheme with its security formally reduced to the security of the underlying IBE and IBBE schemes. Thorough theoretical analyses and extensive experiments confirm that the scheme takes very small cost for mobile devices to access encrypted data and is practical to secure mobile computing applications. Qianhong Wu, Willy Susilo, Joseph K. Liu, Wenchang Shi |
AsiaCCS | 6 |
| 2015 | Android Implicit Information Flow DemystifiedabstractIn this paper, a comprehensive analysis of implicit information flow (IIF) on the Android bytecode is presented to identify all potential IIF forms, determine their exploitability, and mitigate the potential threat. By applying control-transfer-oriented semantic analysis of the bytecode language, we identify five IIF forms, some of which are not studied by existing IIF literature. We develop proof-of-concepts (PoCs) for each IIF form to demonstrate their exploitability. The experimental results show that all these PoCs can effectively and efficiently transmit sensitive data, as well as successfully evade the detection of a state-of-the-art privacy monitor TaintDroid. To mitigate the threat of IIF, we propose a solution to defending against IIF leveraging a special control dependence tracking technique and implement a prototype system. The evaluation shows that the prototype can effectively detect information leak by all the identified IIF forms and also real-world malware with an acceptable overhead. In summary, our study gives in-depth insight into Android IIF from both offensive and defensive perspectives, and provides a foundation for further research on Android IIF. Wei You 0001, Bin Liang 0002, Jingzhe Li, Wenchang Shi, Xiangyu Zhang 0001 |
AsiaCCS | 4 |
| 2015 | Expanding an Operating System's Working Space with a New Mode to Support Trust Measurement
Chenglong Wei, Wenchang Shi, Bin Liang 0002 |
ISPEC | 2 |
| 2014 | Tracing and revoking leaked credentials: accountability in leaking sensitive outsourced dataabstractMost existing proposals for access control over outsourced data mainly aim at guaranteeing that the data are only accessible to authorized requestors who have the access credentials. This paper proposes TRLAC, an a posteriori approach for tracing and revoking leaked credentials, to complement existing a priori solutions. The tracing procedure of TRLAC can trace, in a black-box manner, at least one traitor who illegally distributed a credential, without any help from the cloud service provider. Once the dishonest users have been found, a revocation mechanism can be called to deprive them of access rights. We formally prove the security of TRLAC, and empirically shows that the introduction of the tracing feature incurs little costs to outsourcing. Qianhong Wu, Sherman S. M. Chow, Josep Domingo-Ferrer, Wenchang Shi |
AsiaCCS | 6 |
| 2014 | Scriptless Timing Attacks on Web Browser PrivacyabstractThe existing Web timing attack methods are heavily dependent on executing client-side scripts to measure the time. However, many techniques have been proposed to block the executions of suspicious scripts recently. This paper presents a novel timing attack method to sniff users' browsing histories without executing any scripts. Our method is based on the fact that when a resource is loaded from the local cache, its rendering process should begin earlier than when it is loaded from a remote website. We leverage some Cascading Style Sheets (CSS) features to indirectly monitor the rendering of the target resource. Three practical attack vectors are developed for different attack scenarios and applied to six popular desktop and mobile browsers. The evaluation shows that our method can effectively sniff users' browsing histories with very high precision. We believe that modern browsers protected by script-blocking techniques are still likely to suffer serious privacy leakage threats. Bin Liang 0002, Wei You 0001, Liangkun Liu, Wenchang Shi, Mario Heiderich |
DSN | 4 |
| 2014 | Who Is Touching My Cloud
Qianhong Wu, Lei Zhang 0009, Wenchang Shi |
ESORICS (1) | 7 |
| 2014 | Provably Secure Certificateless Authenticated Asymmetric Group Key Agreement
Lei Zhang 0009, Qianhong Wu, Jianwei Liu 0001, Wenchang Shi |
ISPEC | 6 |
| 2014 | HDROP: Detecting ROP Attacks Using Performance Monitoring Counters
Wenchang Shi, Jinhui Yuan, Bin Liang 0002 |
ISPEC | 3 |
| 2014 | Efficient Sub-/Inter-Group Key Distribution for ad hoc Networks
Linxiao Wang, Qianhong Wu, Wenchang Shi, Bin Liang 0002 |
NSS | 5 |
| 2014 | Ciphertext-policy hierarchical attribute-based encryption with short ciphertexts
Qianhong Wu, Josep Domingo-Ferrer, Lei Zhang 0009, Jianwei Liu 0001, Wenchang Shi |
Inf. Sci. | 7 |
| 2013 | Secure One-to-Group Communications Escrow-Free ID-Based Asymmetric Group Key Agreement
Lei Zhang 0009, Qianhong Wu, Josep Domingo-Ferrer, Sherman S. M. Chow, Wenchang Shi |
Inscrypt | 6 |
| 2011 | Detecting stealthy malware with inter-structure and imported signaturesabstractRecent years have witnessed an increasing threat from kernel rootkits. A common feature of such attack is hiding malicious objects to conceal their presence, including processes, sockets, and kernel modules. Scanning memory with object signatures to detect the stealthy rootkit has been proven to be a powerful approach only when it is hard for adversaries to evade. However, it is difficult, if not impossible, to select fields from a single data structure as robust signatures with traditional techniques. In this paper, we propose the concepts of inter-structure signature and imported signature, and present techniques to detect stealthy malware based on these concepts. The key idea is to use cross-reference relationships of multiple data structures as signatures to detect stealthy malware, and to import some extra information into regions attached to target data structures as signatures. We have inferred four invariants as signatures to detect hidden processes, sockets, and kernel modules in Linux respectively and implemented a prototype detection system called DeepScanner. Meanwhile, we have also developed a hypervisor-based monitor to protect imported signatures. Our experimental result shows that our DeepScanner can effectively and efficiently detect stealthy objects hidden by seven real-world rootkits without any false positives and false negatives, and an adversary can hardly evade DeepScanner if he/she does not break the normal functions of target objects and the system. Bin Liang 0002, Wei You 0001, Wenchang Shi, Zhaohui Liang |
AsiaCCS | 3 |
| 2009 | Operating System Mechanisms for TPM-Based Lifetime Measurement of Process IntegrityabstractImplementing runtime integrity measurement in an acceptable way is a big challenge. We tackle this challenge by developing a framework called Patos. This paper discusses the design and implementation concepts of our operating system mechanisms for runtime process integrity measurement, which is an important part of the Patos framework and is named Patos-RIP. Patos-RIP is developed into the main-stream Linux operating system and utilizes TPM as hardware support for tamper-resistance. From the beginning a process is created to the moment the process dies, Patos-RIP conducts integrity measurement at appropriate points of time when the process runs, so as to ensure that the integrity of a process is not compromised during its whole lifetime. This way, Patos-RIP can improve trustworthiness of processes by effectively detecting runtime tampering attacks on processes' integrity. Wenchang Shi, Zhaohui Liang, Bin Liang 0002, Zhiyong Shan |
MASS | 2 |
| 2006 | Portal monitoring based anti-malware framework: design and implementationabstractMost malware are introduced into a computer system by applications that communicate with the outside world. These applications (called portals) are key components for system security. This paper presents an efficient anti-malware framework under Linux by monitoring the behavior of these portals and isolating the files they induced. The files created or modified by the monitored applications will be marked with a suspicious label; when a file with suspicious label is accessed, a predefined scanning tool or other mechanisms in user-land will be invoked to check the file. The file labeling and access mediation are done in kernel, thus is mandatory and transparent to user applications; the scanning mechanisms are implemented in user land, thus flexible for user to customize. Experiment result under Linux shows the framework can prevent malware's intrusion with small performance penalty. Wenchang Shi |
IPCCC | 2 |
| 2005 | Enforcing the Principle of Least Privilege with a State-Based Privilege Control Model
Bin Liang 0002, Wenchang Shi |
ISPEC | 3 |
| 2005 | Security On-demand Architecture with Multiple Modules Support
Wenchang Shi, Hongliang Liang, Qinghua Shang, Chunyang Yuan, Bin Liang 0002 |
ISPEC | 2 |