VLDB 2026 Research / reviewers in the wild / expert
Haotian Zhang 0006
dblp:83/4184-6
· DBLP profile ↗
5ranked-venue papers
1as first author
4since 2021 · last 2023
0000-0003-0844-3730ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Intelligent Zigbee Protocol Fuzzing via Constraint-Field Dependency Inference
Mengfei Ren 0001, Haotian Zhang 0006, Xiaolei Ren 0001, Jiang Ming 0002, Yu Lei 0001 |
ESORICS (2) | 2 |
| 2023 | On the Feasibility of Malware Unpacking via Hardware-assisted Loop Profiling
Binlin Cheng, Erika A. Leal, Haotian Zhang 0006, Jiang Ming 0002 |
USENIX Security Symposium | 3 |
| 2022 | One size does not fit all: security hardening of MIPS embedded systems via static binary debloating for shared librariesabstractEmbedded systems have become prominent targets for cyberattacks. To exploit firmware’s memory corruption vulnerabilities, cybercriminals harvest reusable code gadgets from the large shared library codebase (e.g., uClibc). Unfortunately, unlike their desktop counterparts, embedded systems lack essential computing resources to enforce security hardening techniques. Recently, we have witnessed a surge of software debloating as a new defense mechanism against code-reuse attacks; it erases unused code to significantly diminish the possibilities of constructing reusable gadgets. Because of the single firmware image update style, static library debloating shows promise to fortify embedded systems without compromising performance and forward compatibility. However, static library debloating on stripped binaries (e.g., firmware’s shared libraries) is still an enormous challenge. In this paper, we show that this challenge is not insurmountable for MIPS firmware. We develop a novel system, named uTrimmer, to identify and wipe out unused basic blocks from shared libraries’ binary code, without causing additional runtime overhead or memory consumption. We propose a new method to identify address-taken blocks/functions, which further help us maintain an inter-procedural control flow graph to conservatively include library code that could be potentially used by firmware. By capturing address access patterns for position-independent code, we circumvent the challenge of determining code-pointer targets and safely eliminate unused code. We run uTrimmer to debloat shared libraries for SPEC CPU2017 benchmarks, popular firmware applications (e.g., Apache, BusyBox, and OpenSSL), and a real-world wireless router firmware image. Our experiments show that not only does uTrimmer deliver functional programs, but also it can cut the exposed code surface and eliminate various reusable code gadgets remarkably. uTrimmer’s debloating capability can compete with the static linking results. Haotian Zhang 0006, Mengfei Ren 0001, Yu Lei 0001, Jiang Ming 0002 |
ASPLOS | 1 |
| 2021 | Obfuscation-Resilient Executable Payload Extraction From Packed Malware
Binlin Cheng, Jiang Ming 0002, Erika A. Leal, Haotian Zhang 0006, Jianming Fu, Guojun Peng, Jean-Yves Marion |
USENIX Security Symposium | 4 |
| 2020 | PatchScope: Memory Object Centric Patch DiffingabstractSoftware patching is one of the most significant mechanisms to combat vulnerabilities. To demystify underlying patch details, the techniques of patch differential analysis (a.k.a. patch diffing) are proposed to find differences between patched and unpatched programs' binary code. Considering the sophisticated security patches, patch diffing is expected to not only correctly locate patch changes but also provide sufficient explanation for understanding patch details and the fixed vulnerabilities. Unfortunately, none of the existing patch diffing techniques can meet these requirements. In this study, we first perform a large-scale study on code changes of security patches for better understanding their patterns. We then point out several challenges and design principles for patch diffing. To address the above challenges, we design a dynamic patch diffing technique PatchScope. Our technique is motivated by two key observations: 1) the way that a program processes its input reveals a wealth of semantic information, and 2) most memory corruption patches regulate the handling of malformed inputs via updating the manipulations of input-related data structures. The core of PatchScope is a new semantics-aware program representation, memory object access sequence, which characterizes how a program references data structures to manipulate inputs. The representation can not only deliver succinct patch differences but also offer rich patch context information such as input-patch correlations. Such information can interpret patch differences and further help security analysts understand patch details, locate vulnerability root causes, and even detect buggy patches. Lei Zhao 0012, Yuncong Zhu, Jiang Ming 0002, Haotian Zhang 0006, Heng Yin 0001 |
CCS | 5 |