Ke Li 0042

dblp:75/6627-42 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
5since 2021 · last 2026
0009-0001-2539-4531ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 5 · 3 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 An LLM-Guided Fuzzing of Proprietary Industrial Communication Protocols with Context Knowledge
Tianci Pan, Huan Qian, Yaowen Zheng, Haining Wang 0001, Peng Zhang 0044, Jiaxing Cheng, Ge Chu, Ke Li 0042, Ming Zhou 0010
INFOCOM8
2024 Save the Bruised Striver: A Reliable Live Patching Framework for Protecting Real-World PLCs
abstract
Industrial Control Systems (ICS), particularly programmable logic controllers (PLCs) responsible for managing underlying physical infrastructures, often operate for extended periods without interruption. Thus, it is challenging to patch security vulnerabilities of ICS in a timely manner after disclosure because it often necessitates waiting for a rare downtime window. While live patching has been introduced to avoid downtime and maintenance costs, conventional live patching methods are not viable for closed-source PLCs. Without the source code, it is difficult to understand the system behaviors and determine binary patch equivalence. To address these challenges, we present a Reliable Live Patching framework called RLPatch for applying live patches to third-party binary without source code. We design RLPatch to capture real-time conditions and dynamic behaviors of PLCs, which enables DevOps engineers to identify major non-recoverable fault (MNRF) vulnerabilities and generate hot patches. The core of RLPatch is an update agent that inserts breakpoints over the original MNRF code and then directs execution to the patches. To ensure system reliability, we use the unique constraints of PLCs to integrate the update processes with the scan cycle. We leverage RLPatch to patch 20 real vulnerabilities in three widely used Rockwell PLCs. We evaluate RLPatch in a real-world gas pipeline, demonstrating its reliability and effectiveness in practice.
Ming Zhou 0010, Haining Wang 0001, Ke Li 0042, Hongsong Zhu, Limin Sun 0001
EuroSys3
2024 Cascading Threat Analysis of IoT Devices in Trigger-Action Platforms
abstract
Internet of Things (IoT) platforms have become widely used recently. Facilitated by these IoT platforms, users can easily use programming paradigm to develop customized rules, connect their devices with online services, and realize system automation. However, the attack surface of each device is expanded as the device interactions increase with multiple rules enabled. In this work, we present a framework to analyze the cascading threat based on device interactions in the IFTTT (IF This Then That) platform. We first extract the trigger-action rules from the description text by using an NLP-based method. Then, we create a graph-based model by combining trigger-action rules with three components, to describe the flow information of device interactions. Finally, we propose a graph-searching-based method to discover the paths and starting points of application-level cascading attacks, uncovering the attack surface of devices. We conduct the evaluation on a data set of 305534 applets from the IFTTT platform. The results evidence that cascading attacks exist in IoT deployments but can be captured by our attack surface analysis.
Ke Li 0042, Haining Wang 0001, Ming Zhou 0010, Hongsong Zhu, Limin Sun 0001
IEEE Internet Things J.1
2022 Compromised IoT Devices Detection in Smart Home via Semantic Information
abstract
The safety and security of IoT devices in smart home systems is attracting booming attention, due to the cascading threat introduced by the interoperability of IoT devices. It is observed that semantic information of behaviors could be utilized to identify anomalies of IoT devices, and some prior works have attempted to detect single abnormal behavior based on the mined semantic patterns. However, the performance of these methods could be usually affected by some noisy data (e.g., user activities), suffering from false alarms of detection. In this work, we propose a semantic-aware framework of compromised IoT devices detection, which extracts the Mutual Information feature from the semantic information of IoT devices to eliminate interference of the noise. The proposed framework includes three modules: semantic analysis to generate event correlations, feature extraction to construct the feature vector, and detection model to train binary classifiers for detection. To collect real-world data for evaluation, we construct three testbeds of the following scenes: bedroom, living room and kitchen. The performance on the collected dataset shows that our method achieves high accuracy (the average is over 90.0%) on the compromised devices detection.
Ke Li 0042, Zhi Li 0018, Zhimin Gu, Ziying Wang, Limin Sun 0001
ICC1
2022 Inferring Device Interactions for Attack Path Discovery in Smart Home IoT
Mengjie Sun, Ke Li 0042, Yaowen Zheng, Hong Li 0004, Limin Sun 0001
WASA (1)2
2019 Side-Channel Information Leakage of Traffic Data in Instant Messaging
abstract
Instant Messaging has been widely applied for both corporate use and personal use in recent years. Major Instant Messaging service providers adopt the Push Technology to ensure the immediacy of message forwarding, which efficiently provides a great convenience for user. However, the immediacy feature causes side-channel information leakage even if some protection measures has been implemented, such as information encryption strategy. In particular, we observe that senders' traffic flows have a strong temporal correlation with those of corresponding recipients, since the messages are forwarded to recipients as soon as they are received by servers. Based on the observation, attackers can infer real-time communications between pairwise users and even the social connections of users. In this paper, we present a methodology framework to validate this side-channel information leakage, which identifies users of real-time communications by matching the pairwise time sequences of traffic flows. We evaluate the method on the collected real-world data. The experimental results show that users' communications can be identified with a high accuracy, and 6 groups of users are inferred to have strong connections based on the data collected from a local area networks.
Ke Li 0042, Hong Li 0004, Hongsong Zhu, Limin Sun 0001, Hui Wen 0001
IPCCC1