VLDB 2026 Research / reviewers in the wild / expert
Bo Yu 0008
dblp:75/2868-8
· DBLP profile ↗
23ranked-venue papers
5as first author
16since 2021 · last 2026
0000-0001-6576-5555ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 1 first-author · 4 since 2021Computer networks · 8 · 3 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | FirmCross: Detecting Taint-style Vulnerabilities in Modern C-Lua Hybrid Web Services of Linux-based Firmware
Runhao Liu 0001, Jiarun Dai, Haoyu Xiao, Yeqi Mou, Lukai Xu, Bo Yu 0008 |
NDSS | 7 |
| 2026 | Comprehensive Measurement of IPv6 Inbound Source Address Validation Deployment via Global Counter Side-Channel
Ling Hu 0001, Zhihuang Liu, Xionglve Li, Bingnan Hou, Zhiyuan Jiang, Bo Yu 0008, Zhiping Cai |
IEEE Trans. Netw. | 7 |
| 2025 | SyzOrch: An Orchestration Framework for Resource-Aware and Composable Kernel FuzzingabstractKernel fuzzing plays a critical role in uncovering vulnerabilities, reproducing bugs, and testing patches in operating systems. While integrating external resources such as symbolic execution engines, static analyzers, and language models has proven effective in areas such as enhancing path exploration, optimizing seed generation, and improving seed mutation, existing approaches remain tightly coupled and task-specific, hindering the reuse, migration, scheduling, and composition of these external resources. This limitation further restricts the ability of researchers to explore flexible hybrid fuzzing strategies and hinders industry efforts to build stronger and more adaptable kernel fuzzers. We present SyzOrch to address this limitation. SyzOrch (1) decouples the kernel fuzzing workflow; (2) provides event-driven coordination between external resources and the fuzzer; (3) abstracts heterogeneous external resources through a generalized behavior model; and (4) supports user-defined dynamic control via a programmable DSL runner. We evaluate SyzOrch across diverse kernel fuzzing scenarios and show that it achieves a 30% speedup of directed kernel fuzzing by migrating existing techniques, improves coverage by 8.6% through hybrid composition with multiple external resources, and discovers previously unknown kernel bugs, including one assigned a CNNVD identifier. These results demonstrate SyzOrch’s effectiveness in orchestrating external resources to enhance kernel fuzzing. Lukai Xu, Bo Yu 0008, Boyu Chang, Shouling Ji, Danjun Liu, Lei Zhou 0023, Yaojia Yang |
ISSRE | 3 |
| 2025 | Grey Rhino Warning: IPv6 is Becoming Fertile Ground for Reflection Amplification AttacksabstractDistributed Denial-of-Service (DDoS) attacks represent a cost-effective and potent threat to network stability. While extensively studied in IPv4 networks, DDoS implications in IPv6 remain underexplored. The vast IPv6 address space renders brute-force scanning and amplifier testing for all active addresses impractical. Innovatively, this work investigates ASlevel vulnerabilities to reflection amplification attacks in IPv6. One prerequisite for amplification presence is that it is located in a vulnerable autonomous system (AS) without inbound source address validation (ISAV) deployment. Hence, the analysis focuses on two critical aspects: global detection of ISAV deployment and identification of amplifiers within vulnerable ASes. Specifically, we develop a methodology combining ICMP Time Exceeded mechanisms for ISAV detection, employ IPv6 address scanning for amplifier identification, and utilize dual vantage points for amplification verification. Experimental results reveal that 4,460 ASes (61.36% of measured networks) lack ISAV deployment. Through scanning approximately 47 M active addresses, we have identified reflection amplifiers in 3,507 ASes. The analysis demonstrates that current IPv6 networks are fertile ground for reflection amplification attacks, alarming network security. Ling Hu 0001, Tao Yang 0041, Bingnan Hou, Zhiping Cai, Bo Yu 0008 |
IWQoS | 6 |
| 2025 | ROVReco: An ROV deployment recommendation approach with GNN based on routing betweenness
Jinshu Su, Bo Yu 0008 |
Comput. Networks | 4 |
| 2024 | SCFuzz: Complexity Aware State Selection Algorithm for Network Protocol FuzzingabstractCurrent network protocol fuzzing approaches primarily utilize stateful fuzzing approaches, optimizing around the stateful characteristics of network protocols. However, they still fall short in exploring the state space of network protocol implementations, due to the inadequate consideration of the code logic of network protocol implementations, leading to insufficient discovery of program exceptions. In this paper, we propose a state-complexity-guided fuzzing approach for network protocol implementation fuzzing. Our method automatically calculates the complexity of protocol states and selects states based on their complexity to guide the fuzzing process toward a comprehensive exploration of the state space. We have developed a new fuzzing tool, SCFuzz, and evaluated its effectiveness on five real-world programs. The evaluation results show that SCFuzz has achieved a 2.8x increase in discovering long state-transition paths and a 21.2x increase in discovering program exceptions compared to baseline tools. Yeqi Mou, Bo Yu 0008 |
GLOBECOM | 3 |
| 2024 | Large Language Model guided State Selection Approach for Fuzzing Network ProtocolabstractFuzzing network protocols is challenging due to their various factors including protocol state and state transitions. To achieve better state coverage when fuzzing network protocol with grey-box fuzzing, several approaches are proposed to select valuable states and optimize the fuzzing process. Based on the ability of extensive knowledge integration and reasoning, large language models (LLMs) are also imported to generate more effective test cases for protocol fuzzing. However, these approaches leave poor state and code coverage on real-world services protocol evaluation since they use either random selection or heuristics. To address this issue, we present LLMgSSA, a Large Language Model guided State Selection Approach, which navigates the LLM to reason about protocol state selection. In the approach, LLMgSSA first extracts the features of the current protocol and state space and determines valuable states by interacting with the LLM. It then collects and analyzes the current status of each covered state and combines the inference results of the LLM for the final state selection. To evaluate the effectiveness of LLMgSSA, we have conducted extensive experiments with five real-world protocols from ProFuzzBench. Experimental results show that, compared to three state-of-the-art fuzzers, ChataFL, AFLnet, and NSFuzz, LLMgSSA can increase state transitions, covered states, branch coverage, and line coverage by up to 70.6%, 35.3%, 13.1%, and 13.1% respectively. Bo Yu 0008, Qihong Song, Chengnuo Cai |
IPCCC | 1 |
| 2024 | SSFuzz: State Sensitive Fuzzing for Network Protocol ImplementationsabstractProtocol implementations are stateful and reactive systems, where the protocol process communicates with the client through a session. Complex state changes of implementations limit the efficiency of fuzzing. Current methods typically send a mutated message sequence to the protocol implementation, then terminate the session and evaluate the message sequence based on the feedback. We observe the following issues: (1) The state changes of the protocol implementation are random because of mutated messages, and message schedule methods that do not consider the real-time state of the target are blind; (2) The value of a message can vary significantly in different states, making seeds value evaluation method based on the entire message sequence insufficiently precise. (3) Existing fuzzing approaches actively terminate sessions after a test, resulting in resource wastage.To solve these problem, we propose SSFuzz, a state sensitive fuzzing approach for protocol implementations. First, it monitors the state transitions and path feedback of the protocol implementation in real-time. Second, it dynamically schedules messages based on real-time state transitions during testing. According to the state transitions and path feedback after processing a message, it then conducts more precise evaluation of the messages. Last, we achieve testing multiple states within one session by reusing session. We believe that our approach better adapts to the characteristics of protocol implementations. We validated our approach on 9 widely used protocol implementations from ProFuzzBench. Compared to the state-of-the-art network protocol greybox fuzzing tool AFLnet, SSFuzz can increase discovered branch coverage on average 1.31% and discovers 25.28% more unique crashes within 24 hours. Chengnuo Cai, Lei Zhou 0023, Bo Yu 0008 |
ISPA | 3 |
| 2024 | ConfigKG: Identify Routing Security Issues from Configurations Based on Knowledge GraphabstractInadequate network configurations can lead to serious security issues. Current research, however, overlooks the integrity of the network in identifying security issues from configurations. Specifically, it lacks sufficient integration of multi-level information and lacks a certain level of scalability when facing different network situations. This paper introduces ConfigKG, a general, extensible, and comprehensible framework for identifying security issues from configurations in a network. ConfigKG utilizes configuration files to create a knowledge graph, which assists in reasoning and mining network information. Through this process, ConfigKG models networks in knowledge graphs. Drawing from properly configured routing protocol scenarios, this study translates the standard network state into a series of graph-based rules that are applied across network planes. By evaluating these rules, ConfigKG can determine the network state and find errors in configurations. This article focuses solely on identifying security issues in the configuration of routing protocols, as routing security is the primary concern related to configuration problems. An experimental scenario was conducted to assess ConfigKG, which successfully constructs a knowledge graph and accurately models the network, enabling finding security issues through rule set checks. During the experiment, ConfigKG effectively identifies misconfigurations in OSPF and BGP, as well as prefix hijacking. Additionally, ConfigKG demonstrates scalability by accommodating additional mining algorithms and rule sets, allowing for customized adjustments based on detailed requirements. Jinshu Su, Bo Yu 0008 |
TrustCom | 4 |
| 2023 | Firm VEA: Vulnerability Discovery Optimisation for IoT Firmware via Version Evolution AnalysisabstractWith the development and widespread application of IoT technology, the impact of N -day vulnerabilities on IoT firmware has become increasingly serious. Detection technology for IoT firmware vulnerabilities plays an increasingly important role in IoT security. However, existing approaches for firmware vulnerability detection did not consider the issue of vulnerabilities between components, which are introduced in a supply chain's business process, such as library reuse and collaboration development. Meanwhile, they did not consider the component changes across the evolution of firmware versions, which is not conducive to analysts timely patching and managing vulnerable components, resulting in the duplication of analysis of components and inefficient analysis. Thus, feasible methods for analysing version evolution and discovering component vulnerabilities are urgently needed. In this paper, we design and implement Firm VEA, which discovers lOT component vulnerabilities via version evolution analysis. To evaluate our approach, we collect 10161 real-world firmware with 1053 firmware components (shortened as FC) from 11 different vendors, which cover various architectures such as MIPS, ARM, X86, PowerPC, and various OSs such as Linux, and FreeBSD (32/64-bit). The experiments show that FirmVEA can analyze the relationship between complex components, expose components and vulnerabilities change in adjacent firmware versions, and is on average 10 times more efficient than the state-of-the-art tool FACT while ensuring no loss of accuracy, making it suitable for large-scale IoT firmware N-day vulnerability analysis. Bo Yu 0008, Yongyi Zhang |
GLOBECOM | 1 |
| 2023 | FirmCVI: Taint Analysis-Based Component Version Identification Method for Large-Scale IoT FirmwareabstractIn recent years, numerous attacks on IoT device firmware caused by component vulnerabilities have occurred, they has attracted a great deal of attention from security researchers. Thus, identifying the component and version information in IoT device firmware is of great significance for conducting large-scale IoT device firmware vulnerability correlation analysis, security risk assessment and emergency response of the IoT. Existing methods may not dig deeper into the features of version information, resulting in missing recognition information, leading to insufficient recognition accuracy. Alternatively, existing methods rely on features such as CFG, which makes it difficult to accurately match components between different versions, leading to recognition errors. For these reasons, in this paper, we propose a taint analysis-based version identification method for IoT firmware components. Firstly, we use the feature information extracted from the binary file as the source point for taint analysis, then we perform reverse flow analysis based on the data flow of function calls, and then we find the memory address of the version information as the sink to identify the version information of the component. To evaluate our approach, we collected 312,330 firmware components from 10161 real firmware from 11 different vendors covering various architectures such as MIPS, ARM, X86, and PowerPC and various operating systems such as Linux and FreeBSD (32/64 bit). The experiments demonstrate that the FirmCVI does not require manually building a large-scale database, and achieves an average identification accuracy of up to 96.07% for IoT device firmware component versions, false positives within 5%. And the average time taken to identify component versions is about 0.19 seconds, which is 10 times more efficient than existing version identification tools. It provides powerful data and technical support for IOT device firmware vulnerability correlation analysis. Bo Yu 0008 |
ICPADS | 2 |
| 2023 | Automatic discovery of stateful variables in network protocol software based on replay analysisabstractNetwork protocol software is usually characterized by complicated functions and a vast state space. In this type of program, a massive number of stateful variables that are used to represent the evolution of the states and store some information about the sessions are prone to potential flaws caused by violations of protocol specification requirements and program logic. Discovering such variables is significant in discovering and exploiting vulnerabilities in protocol software, and still needs massive manual verifications. In this paper, we propose a novel method that could automatically discover the use of stateful variables in network protocol software. The core idea is that a stateful variable features information of the communication entities and the software states, so it will exist in the form of a global or static variable during program execution. Based on recording and replaying a protocol program’s execution, varieties of variables in the life cycle can be tracked with the technique of dynamic instrument. We draw up some rules from multiple dimensions by taking full advantage of the existing vulnerability knowledge to determine whether the data stored in critical memory areas have stateful characteristics. We also implement a prototype system that can discover stateful variables automatically and then perform it on nine programs in ProFuzzBench and two complex real-world software programs. With the help of available open-source code, the evaluation results show that the average true positive rate (TPR) can reach 82% and the average precision can be approximately up to 96%. Bo Yu 0008, Runhao Liu 0001, Jinshu Su |
Frontiers Inf. Technol. Electron. Eng. | 2 |
| 2022 | WThreadAFL: Deterministic Greybox Fuzzing for Multi-thread Network ServersabstractMulti-thread network servers have non-deterministic behaviors during fuzzing process, which constrains the performance of the fuzzer. In this work, we present WThreadAFL, a new greybox fuzzer for fuzzing multi-thread network servers. WThreadAFL addresses the non-deterministic problem based on a lightweight thread identification approach. We distinguish between worker thread and background thread via thread-context instrumentation, and only update coverage feedback of the worker thread. The experimental results on four popular server benchmarks show that, WThreadAFL behaves more deterministic than network protocol greybox fuzzer AFLNET, which increases the stability metric by 1.9%-25.7% and cuts down coverage variable edges by 19.0%-39.8% within 24 hours. Jianjun Lu, Bo Yu 0008 |
APNet | 2 |
| 2022 | A Component Vulnerability Matching Approach for IoT FirmwareabstractComponent vulnerability matching offers an approach for discovering vulnerabilities existing in IoT firmware. In this work, A component composition analysis and reliability assessment (C2ARA) is developed to improve the component vulnerability matching. The C2ARA method employs a knowledge graph for discovering the components and their relationships from the extracted file system of the firmware. The key to the proposed method is to discover vulnerabilities from the component composition extracted from IoT firmware file systems, rather than only the information provided by CVE databases and firmware vendor. The results of the experiment with a large-scale dataset demonstrate the effectiveness of the C2ARA method. Bo Yu 0008, Yongyi Zhang, Runhao Liu 0001, Zhoushi Sheng |
APNet | 1 |
| 2022 | Anatomist: Enhanced Firmware Vulnerability Discovery Based on Program State Abnormality Determination with Whole-System Replay
Runhao Liu 0001, Bo Yu 0008, Jianbin Ye |
ISC | 2 |
| 2022 | SEEKER: A Root Cause Analysis Method Based on Deterministic Replay for Multi-Type Network Protocol VulnerabilitiesabstractVarious types of network protocol software vulnerabilities often result in considerable damage. However, existing root cause analysis methods, which rely on symbolic path tracing and the hardware processor tracing (PT) function, cannot be applied in protocol software. They are also limited by the restricted resources of embedded platforms and symbolic execution ability. Additionally, manually analysing vulnerabilities is typically labour intensive. To solve this problem, we propose SEEKER, the first root cause analysis method based on deterministic replay for multi-type network protocol vulnerabilities to automatically generate vulnerability analysis reports. By proposing a multilayer semantic model, SEEKER extracts fine-grained semantics, compares the extracted semantics with predefined vulnerability rules and finally generates an analysis report.We implemented and evaluated SEEKER against 7 vulnerability types, across 4 real-world software programs, covering 2 different platforms. The experimental results show that SEEKER can identify the root causes of multi-type vulnerabilities and even find 3 new 0-day vulnerabilities. Meanwhile, SEEKER demonstrates impressive adaptability and scalability. It can analyse one execution path that involves up to 135,437,793 instructions and upwards of 15,893,356 memory access requests. Runhao Liu 0001, Bo Yu 0008, Jianbin Ye |
TrustCom | 2 |
| 2020 | EcoFuzz: Adaptive Energy-Saving Greybox Fuzzing as a Variant of the Adversarial Multi-Armed Bandit
Tai Yue, Pengfei Wang 0010, Yong Tang 0005, Enze Wang, Bo Yu 0008, Kai Lu 0001, Xu Zhou 0004 |
USENIX Security Symposium | 5 |
| 2019 | Poster: Fuzzing IoT Firmware via Multi-stage Message GenerationabstractIn this work, we present IoTHunter, the first grey-box fuzzer for fuzzing stateful protocols in IoT firmware. IoTHunter addresses the state scheduling problem based on a multi-stage message generation mechanism on runtime monitoring of IoT firmware. We evaluate IoTHunter with a set of real-world programs, and the result shows that IoTHunter outperforms black-box fuzzer boofuzz, which has a 2.2x, 2.0x, and 2.5x increase for function coverage, block coverage, and edge coverage, respectively. IoTHunter also found five new vulnerabilities in the firmware of home router Mikrotik, which have been reported to the vendor. Bo Yu 0008, Pengfei Wang 0010, Tai Yue, Yong Tang 0005 |
CCS | 1 |
| 2018 | Automated Vulnerability Detection in Embedded Devices
Danjun Liu, Yong Tang 0005, Wei Xie 0007, Bo Yu 0008 |
IFIP Int. Conf. Digital Forensics | 5 |
| 2018 | A survey of malware behavior description and analysisabstractBehavior-based malware analysis is an important technique for automatically analyzing and detecting malware, and it has received considerable attention from both academic and industrial communities. By considering how malware behaves, we can tackle the malware obfuscation problem, which cannot be processed by traditional static analysis approaches, and we can also derive the as-built behavior specifications and cover the entire behavior space of the malware samples. Although there have been several works focusing on malware behavior analysis, such research is far from mature, and no overviews have been put forward to date to investigate current developments and challenges. In this paper, we conduct a survey on malware behavior description and analysis considering three aspects: malware behavior description, behavior analysis methods, and visualization techniques. First, existing behavior data types and emerging techniques for malware behavior description are explored, especially the goals, principles, characteristics, and classifications of behavior analysis techniques proposed in the existing approaches. Second, the inadequacies and challenges in malware behavior analysis are summarized from different perspectives. Finally, several possible directions are discussed for future research. Bo Yu 0008, Yong Tang 0005, Liu Liu 0004 |
Frontiers Inf. Technol. Electron. Eng. | 1 |
| 2017 | A New Malware Classification Approach Based on Malware Dynamic Analysis
Bo Yu 0008, Yong Tang 0005, Liu Liu 0004, Yi Wang 0036 |
ACISP (2) | 2 |
| 2017 | Matching Function-Call Graph of Binary Codes and Its Applications (Short Paper)
Yong Tang 0005, Yi Wang 0036, Shuning Wei, Bo Yu 0008 |
ISPEC | 4 |
| 2017 | Automatic malware classification and new malware detection using machine learningabstractThe explosive growth of malware variants poses a major threat to information security. Traditional anti-virus systems based on signatures fail to classify unknown malware into their corresponding families and to detect new kinds of malware programs. Therefore, we propose a machine learning based malware analysis system, which is composed of three modules: data processing, decision making, and new malware detection. The data processing module deals with gray-scale images, Opcode n -gram, and import functions, which are employed to extract the features of the malware. The decision-making module uses the features to classify the malware and to identify suspicious malware. Finally, the detection module uses the shared nearest neighbor (SNN) clustering algorithm to discover new malware families. Our approach is evaluated on more than 20 000 malware instances, which were collected by Kingsoft, ESET NOD32, and Anubis. The results show that our system can effectively classify the unknown malware with a best accuracy of 98.9%, and successfully detects 86.7% of the new malware. Liu Liu 0004, Bo Yu 0008, Qiuxi Zhong |
Frontiers Inf. Technol. Electron. Eng. | 3 |