VLDB 2026 Research / reviewers in the wild / expert
Zhi Wang 0004
dblp:95/6543-4
· DBLP profile ↗
47ranked-venue papers
5as first author
11since 2021 · last 2023
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 33 · 4 first-author · 5 since 2021Systems, architecture and hardware · 9 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 4 · 1 since 2021Computer networks · 3 · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Performance of Software-based Encrypted MPI Communication over Container ClustersabstractWe study the performance of software-based secure communication infrastructure for HPC Message Passing Interface (MPI) applications in container clusters. Specifically, extensive experiments are performed using micro-and application benchmarks to evaluate the encrypted MPI communication performance. Container built-in encrypted communication schemes including Docker Swarm and Kubernetes Antrea and Calico, as well as CryptMPI, a secure MPI library, are evaluated and compared. Our results confirm the findings in earlier studies that for some MPI applications, running in the container environment with unencrypted communication introduces only minor overheads over running on the bare metal system. However, when the communications are encrypted, all of the container built-in software-based encrypted communication mechanisms that we evaluated incur very large overheads in all of our experiments for both micro-benchmarks and application benchmarks. On the other hand, CryptMPI, which encrypts and decrypts messages in the MPI library, achieves much higher performance than the container built-in encryption schemes. Mohsen Gavahi, Abu Naser, Mehran Sadeghi Lahijani, Cong Wu 0003, Zhi Wang 0004, Xin Yuan 0001 |
IPCCC | 5 |
| 2023 | A Systematic Study of Android Non-SDK (Hidden) Service API SecurityabstractAndroid allows apps to communicate with its system services via system service helpers so that these apps can use various functions provided by the system services. Meanwhile, the system services rely on their service helpers to enforce security checks for protection. Unfortunately, the security checks in the service helpers may be bypassed via directly exploiting the non-SDK (hidden) APIs, degrading the stability and posing severe security threats such as privilege escalation, automatic function execution without users’ interactions, crashes, and DoS attacks. Google has proposed various approaches to address this problem, e.g., case-by-case fixing the bugs or even proposing a blacklist to block all the non-SDK APIs. However, the developers can still figure out new ways of exploiting these hidden APIs to evade the non-SDKs restrictions. In this article, we systematically study the vulnerabilities due to the hidden API exploitation and analyze the effectiveness of Google’s countermeasures. We aim to answer if there are still vulnerable hidden APIs that can be exploited in newest Android 12. We develop a static analysis tool called${{\sf ServiceAudit}}$to automatically mine the inconsistent security enforcement between service helper classes and the hidden service APIs. We apply${{\sf ServiceAudit}}$to Android 6$\sim$12. Our tool discovers 112 vulnerabilities in Android 6 with a higher precision than existing approaches. Moreover, in Android 11 and 12, we identify more than 25 hidden APIs with inconsistent protections; however, only one of the vulnerable APIs can lead to severe security problem in Android 11, and none of them work on Android 12. Yi He 0020, Yacong Gu, Purui Su, Kun Sun 0001, Yajin Zhou, Zhi Wang 0004, Qi Li 0002 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2022 | SGXLock: Towards Efficiently Establishing Mutual Distrust Between Host Application and Enclave for SGX
Jiaqi Li 0023, Guorui Xu, Yajin Zhou, Zhi Wang 0004, Cong Wang 0001, Kui Ren 0001 |
USENIX Security Symposium | 5 |
| 2022 | RapidPatch: Firmware Hotpatching for Real-Time Embedded Devices
Yi He 0020, Zhenhua Zou, Kun Sun 0001, Zhuotao Liu, Ke Xu 0002, Qian Wang 0002, Chao Shen 0001, Zhi Wang 0004, Qi Li 0002 |
USENIX Security Symposium | 8 |
| 2022 | Time-travel Investigation: Toward Building a Scalable Attack Detection Framework on EthereumabstractEthereum has been attracting lots of attacks, hence there is a pressing need to perform timely investigation and detect more attack instances. However, existing systems suffer from the scalability issue due to the following reasons. First, the tight coupling between malicious contract detection and blockchain data importing makes them infeasible to repeatedly detect different attacks. Second, the coarse-grained archive data makes them inefficient to replay transactions. Third, the separation between malicious contract detection and runtime state recovery consumes lots of storage. In this article, we propose a scalable attack detection framework named EthScope , which overcomes the scalability issue by neatly re-organizing the Ethereum state and efficiently locating suspicious transactions. It leverages the fine-grained state to support the replay of arbitrary transactions and proposes a well-designed schema to optimize the storage consumption. The performance evaluation shows that EthScope can solve the scalability issue, i.e., efficiently performing a large-scale analysis on billions of transactions, and a speedup of around \( \text{2,300}\times \) when replaying transactions. It also has lower storage consumption compared with existing systems. Further analysis shows that EthScope can help analysts understand attack behaviors and detect more attack instances. Siwei Wu, Lei Wu 0012, Yajin Zhou, Runhuai Li, Zhi Wang 0004, Xiapu Luo, Cong Wang 0001, Kui Ren 0001 |
ACM Trans. Softw. Eng. Methodol. | 5 |
| 2021 | ECMO: Peripheral Transplantation to Rehost Embedded Linux KernelsabstractDynamic analysis based on the full-system emulator QEMU is widely used for various purposes.However, it is challenging to run firmware images of embedded devices in QEMU, especially the process to boot the Linux kernel (we call this process rehosting the Linux kernel in this paper). That's because embedded devices usually use different system-on-chips (SoCs) from multiple vendors and only a limited number of SoCs are currently supported in QEMU. Muhui Jiang, Lin Ma 0009, Yajin Zhou, Qiang Liu 0034, Cen Zhang, Zhi Wang 0004, Xiapu Luo, Lei Wu 0012, Kui Ren 0001 |
CCS | 6 |
| 2021 | Encrypted All-reduce on Multi-core ClustersabstractWe consider the encrypted all-reduce operation on multi-core clusters. We derive performance bounds for the encrypted all-reduce operation and develop efficient algorithms that are theoretically optimal in that they asymptotically achieve the performance bounds. We empirically evaluate our encrypted all-reduce algorithms on production clusters. The results show that with the right algorithm, encryption can be incorporated in the all-reduce operation on large messages without significant overheads on modern multi-core clusters whose compute node has a large number of cores. Mohsen Gavahi, Abu Naser, Cong Wu 0003, Mehran Sadeghi Lahijani, Zhi Wang 0004, Xin Yuan 0001 |
IPCCC | 5 |
| 2021 | Efficient Algorithms for Encrypted All-gather OperationabstractAs more High-Performance Computing (HPC) applications that process sensitive data are moving to run on the public cloud, there is a need for the cloud infrastructure to provide privacy and integrity support. In this work, we investigate how to add encryption to all-gather to protect internode communication. This task is challenging since encryption is often more expensive than communication in contemporary HPC systems. We derive performance bounds for encrypted allgather, and develop new algorithms that meet the theoretical lower bounds. Our empirical evaluation on production systems demonstrates that the new algorithms achieve substantially better performance than the naive approach. Mehran Sadeghi Lahijani, Abu Naser, Cong Wu 0003, Mohsen Gavahi, Viet Tung Hoang, Zhi Wang 0004, Xin Yuan 0001 |
IPDPS | 6 |
| 2021 | An ear canal deformation based continuous user authentication using earablesabstractBiometric-based authentication is gaining increasing attention for wearables and mobile applications. Meanwhile, the growing adoption of sensors in wearables also provides opportunities to capture novel wearable biometrics. In this work, we propose EarDynamic, an ear canal deformation based user authentication using ear wearables (earables). EarDynamic provides continuous and passive user authentication and is transparent to users. It leverages ear canal deformation that combines the unique static geometry and dynamic motions of the ear canal when the user is speaking for authentication. It utilizes an acoustic sensing approach to capture the ear canal deformation with the built-in microphone and speaker of the earables. Specifically, it first emits well-designed inaudible beep signals and records the reflected signals from the ear canal. It then analyzes the reflected signals and extracts fine-grained acoustic features that correspond to the ear canal deformation for user authentication. Our experimental evaluation shows that EarDynamic can achieve a recall of 97.38% and an F1 score of 96.84%. Zi Wang 0003, Sheng Tan, Linghan Zhang, Yili Ren, Zhi Wang 0004, Jie Yang 0003 |
MobiCom | 5 |
| 2021 | Towards Understanding and Demystifying Bitcoin Mixing ServicesabstractOne reason for the popularity of Bitcoin is due to its anonymity. Although several heuristics have been used to break the anonymity, new approaches are proposed to enhance its anonymity at the same time. One of them is the mixing service. Unfortunately, mixing services have been abused to facilitate criminal activities, e.g., money laundering. As such, there is an urgent need to systematically understand Bitcoin mixing services. Lei Wu 0012, Yajin Zhou, Haoyu Wang 0001, Xiapu Luo, Zhi Wang 0004, Fan Zhang 0010, Kui Ren 0001 |
WWW | 6 |
| 2021 | CATTmew: Defeating Software-Only Physical Kernel IsolationabstractAll the state-of-the-art rowhammer attacks can break the MMU-enforced inter-domain isolation because the physical memory owned by each domain is adjacent to each other. To mitigate these attacks, physical domain isolation, introduced by CATT, physically separates each domain by dividing the physical memory into multiple partitions and keeping each partition occupied by only one domain. CATT implemented physical kernel isolation as the first generic and practical software-only defense to protect kernel from being rowhammered as kernel is one of the most appealing targets. In this paper, we develop a novel exploit that could effectively defeat the CATT implementation and gain both root and kernel privileges, indicating that the physical kernel isolation is not secure in practice. Our exploit can work without exhausting the page cache or the system memory, or relying on the information of the virtual-to-physical address mapping. The exploit is motivated by our key observation that the modern OSes have double-owned kernel buffers (e.g., video buffers and SCSI Generic buffers) owned concurrently by the kernel and user domains. The existence of such buffers invalidates the physical separation enforced by CATT and makes the rowhammer-based attack possible again. Existing conspicuous rowhammer attacks achieving the root/kernel privilege escalation exhaust the page cache or even the whole system memory. Instead, we propose a new technique, named Memory Ambush. It is able to place the hammerable double-owned kernel buffers physically adjacent to the target objects (e.g., page tables) with only a small amount of memory. As a result, our exploit is stealthier and has fewer memory footprints. We also replace the inefficient rowhammer algorithm that blindly picks up addresses to hammer with an efficient one. Our algorithm selects suitable addresses based on an existing timing channel. We implement our exploit on the Linux kernel version 4.10.0. Our experiment results indicate that a successful attack could be done within 1 minute. The occupied memory is as low as 88 MB. Yueqiang Cheng, Zhi Zhang 0001, Surya Nepal, Zhi Wang 0004 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2020 | VibLive: A Continuous Liveness Detection for Secure Voice User Interface in IoT EnvironmentabstractThe voice user interface (VUI) has been progressively used to authenticate users to numerous devices and applications. Such massive adoption of VUIs in IoT environments like individual homes and businesses arises extensive privacy and security concerns. Latest VUIs adopting traditional voice authentication methods are vulnerable to spoofing attacks, where a malicious party spoofs the VUIs with pre-recorded or synthesized voice commands of the genuine user. In this paper, we design VibLive, a continuous liveness detection system for secure VUIs in IoT environments. The underlying principle of VibLive is to catch the dissimilarities between bone-conducted vibrations and air-conducted voices when human speaks for liveness detection. VibLive is a text-independent system that verifies live users and detects spoofing attacks without requiring users to enroll specific passphrases. Moreover, VibLive is practical and transparent as it requires neither additional operations nor extra hardwares, other than a loudspeaker and a microphone that are commonly equipped on VUIs. Our evaluation with 25 participants under different IoT intended experiment settings shows that VibLive is highly effective with over 97% detection accuracy. Results also show that VibLive is robust to various use scenarios. Linghan Zhang, Sheng Tan, Zi Wang 0003, Yili Ren, Zhi Wang 0004, Jie Yang 0003 |
ACSAC | 5 |
| 2020 | COIN Attacks: On Insecurity of Enclave Untrusted Interfaces in SGXabstractIntel SGX is a hardware-based trusted execution environment (TEE), which enables an application to compute on confidential data in a secure enclave. SGX assumes a powerful threat model, in which only the CPU itself is trusted; anything else is untrusted, including the memory, firmware, system software, etc. An enclave interacts with its host application through an exposed, enclave-specific, (usually) bi-directional interface. This interface is the main attack surface of the enclave. The attacker can invoke the interface in any order and inputs. It is thus imperative to secure it through careful design and defensive programming. Mustakimur Khandaker, Yueqiang Cheng, Zhi Wang 0004, Tao Wei 0002 |
ASPLOS | 3 |
| 2020 | High-density Multi-tenant Bare-metal CloudabstractVirtualization is the cornerstone of the infrastructure-as-a-service (IaaS) cloud, where VMs from multiple tenants share a single physical server. This increases the utilization of data-center servers, allowing cloud providers to provide cost-efficient services. However, the multi-tenant nature of this service leads to serious security concerns, especially in regard to side-channel attacks. In addition, virtualization incurs non-negligible overhead in the performance of CPU, memory, and I/O. To this end, the bare-metal cloud has become an emerging type of service in the public clouds, where a cloud user can rent dedicated physical servers. The bare-metal cloud provides users with strong isolation, full and direct access to the hardware, and more predicable performance. However, the existing single-tenant bare-metal service has poor scalability, low cost efficiency, and weak adaptability because it can only lease entire physical servers to users and have no control over user programs after the server is leased. In this paper, we propose the design of a new high-density multi-tenant bare-metal cloud called BM-Hive. In BM-Hive, each bare-metal guest runs on its own compute board, a PCIe extension board with the dedicated CPU and memory modules. Moreover, BM-Hive features a hardware-software hybrid virtio I/O system that enables the guest to directly access the cloud network and storage services. BM-Hive can significantly improve the cost efficiency of the bare-metal service by hosting up to 16 bare-metal guests in a single physical server. In addition, BM-Hive strictly isolates the bare-metal guests at the hardware level for better security and isolation. We have deployed BM-Hive in one of the largest public cloud infrastructures. It currently serves tens of thousands of users at the same time. Our evaluation of BM-Hive demonstrates its strong performance over VMs. Zhi Wang 0004, Yibin Shen |
ASPLOS | 3 |
| 2020 | PThammer: Cross-User-Kernel-Boundary Rowhammer through Implicit AccessesabstractRowhammer is a hardware vulnerability in DRAM memory, where repeated access to memory can induce bit flips in neighboring memory locations. Being a hardware vulnerability, rowhammer bypasses all of the system memory protection, allowing adversaries to compromise the integrity and confidentiality of data. Rowhammer attacks have shown to enable privilege escalation, sandbox escape, and cryptographic key disclosures.Recently, several proposals suggest exploiting the spatial proximity between the accessed memory location and the location of the bit flip for a defense against rowhammer. These all aim to deny the attacker's permission to access memory locations near sensitive data.In this paper, we question the core assumption underlying these defenses. We present PThammer, a confused-deputy attack that causes accesses to memory locations that the attacker is not allowed to access. Specifically, PThammer exploits the address translation process of modern processors, inducing the processor to generate frequent accesses to protected memory locations. We implement PThammer, demonstrating that it is a viable attack, resulting in a system compromise (e.g., kernel privilege escalation). We further evaluate the effectiveness of proposed software-only defenses showing that PThammer can overcome those. Zhi Zhang 0001, Yueqiang Cheng, Dongxi Liu, Surya Nepal, Zhi Wang 0004, Yuval Yarom |
MICRO | 5 |
| 2020 | Automatic Hot Patch Generation for Android Kernels
Zhengzi Xu, Longri Zheng, Liangzhao Xia, Chenfu Bao, Zhi Wang 0004, Yang Liu 0003 |
USENIX Security Symposium | 6 |
| 2019 | Fast and Scalable VMM Live Upgrade in Large Cloud InfrastructureabstractHigh availability is the most important and challenging problem for cloud providers. However, virtual machine monitor (VMM), a crucial component of the cloud infrastructure, has to be frequently updated and restarted to add security patches and new features, undermining high availability. There are two existing live update methods to improve the cloud availability: kernel live patching and Virtual Machine (VM) live migration. However, they both have serious drawbacks that impair their usefulness in the large cloud infrastructure: kernel live patching cannot handle complex changes (e.g., changes to persistent data structures); and VM live migration may incur unacceptably long delays when migrating millions of VMs in the whole cloud, for example, to deploy urgent security patches. Zhi Wang 0004, Qi Li 0002, Junkang Fu, Yang Zhang 0016, Yibin Shen |
ASPLOS | 3 |
| 2019 | An Empirical Study of Cryptographic Libraries for MPI CommunicationsabstractAs High Performance Computing (HPC) applications with data security requirements are increasingly moving to execute in the public cloud, there is a demand that the cloud infrastructure for HPC should support privacy and integrity. Incorporating privacy and integrity mechanisms in the communication infrastructure of today's public cloud is challenging because recent advances in the networking infrastructure in data centers have shifted the communication bottleneck from the network links to the network end points and because encryption is computationally intensive. In this work, we consider incorporating encryption to support privacy and integrity in the Message Passing Interface (MPI) library, which is widely used in HPC applications. We empirically study four contemporary cryptographic libraries, OpenSSL, BoringSSL, Libsodium, and CryptoPP using micro-benchmarks and NAS parallel benchmarks to evaluate their overheads for encrypting MPI messages on two different networking technologies, 10Gbps Ethernet and 40Gbps InfiniBand. The results indicate that (1) the performance differs drastically across cryptographic libraries, and (2) effectively supporting privacy and integrity in MPI communications on high speed data center networks is challenging-even with the most efficient cryptographic library, encryption can still introduce very significant overheads in some scenarios such as a single MPI communication operation on InfiniBand, but (3) the overall overhead may not be prohibitive for practical uses since there can be multiple concurrent communications. Abu Naser, Mohsen Gavahi, Cong Wu 0003, Viet Tung Hoang, Zhi Wang 0004, Xin Yuan 0001 |
CLUSTER | 5 |
| 2019 | Adaptive Call-Site Sensitive Control Flow IntegrityabstractLow-level languages like C/C++ are widely used in various applications for their performance and flexibility. Unfortunately, these languages are prone to memory corruption vulnerabilities, leading to control-flow hijacking attacks. Control flow integrity (CFI) is a general principle to enforce run-time control flow of a program to a pre-computed control-flow graph (CFG). While the traditional context-insensitive CFI falls short in protecting critical control transfers, recent context-sensitive CFI research shows promising improvements but has various limitations. We present Control Flow Integrity with Look Back (CFI-LB), a call-site sensitive CFI in which a conventional source-target control transfer is strengthened by a look back into its call-sites (return addresses). CFI-LB features the adaptive call-site sensitivity in which each indirect call has its own level of sensitivity and the multi-scope CFG to improve the security even if a precise context-sensitive static CFG is not available, especially for large programs such as GCC and NGINX. One of the CFGs is constructed by our localized concolic execution, which significantly extends the dynamic CFG with very low false positives. In addition, CFI-LB is the first CFI system explicitly designed to protect its reference monitors from race conditions. We have built a prototype of CFI-LB. The evaluation with SPEC CPU2006 benchmarks and NGINX indicates that CFI-LB has a low-performance overhead (less than 5% on average for the full protection) while increasing the security. Mustakimur Khandaker, Abu Naser, Wenqing Liu, Zhi Wang 0004, Yajin Zhou, Yueqiang Cheng |
EuroS&P | 4 |
| 2019 | Origin-sensitive Control Flow Integrity
Mustakimur Khandaker, Wenqing Liu, Abu Naser, Zhi Wang 0004, Jie Yang 0003 |
USENIX Security Symposium | 4 |
| 2019 | Design and Implementation of SecPod, A Framework for Virtualization-Based Security SystemsabstractThe OS kernel is critical to the security of a computer system. Many systems have been proposed to improve its security. A fundamental weakness of those systems is that page tables, the data structures that control the memory protection, are not isolated from the vulnerable kernel, and thus subject to tampering. To address that, researchers have relied on virtualization for reliable kernel memory protection. Unfortunately, such memory protection requires to monitor every update to the guest's page tables. This fundamentally conflicts with the recent advances in the hardware virtualization support. In this paper, we present the design and implementation of SecPod, a practical and extensible framework for virtualization-based security systems that can provide both strong isolation and the compatibility with modern hardware. SecPod has two key techniques:paging delegationdelegates and audits the kernel's paging operations to a secure space;execution trappingintercepts the (compromised) kernel's attempts to subvert SecPod by misusing privileged instructions. We have implemented a prototype of SecPod based on KVM. Our experiments show that SecPod is both effective and efficient. Xiaoguang Wang 0003, Yong Qi 0001, Zhi Wang 0004, Yajin Zhou |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2018 | InstaGuard: Instantly Deployable Hot-patches for Vulnerable System Programs on Android
Yaohui Chen 0001, Long Lu, Yueh-Hsun Lin, Hayawardh Vijayakumar, Zhi Wang 0004, Xinming Ou |
NDSS | 6 |
| 2017 | Pinpointing VulnerabilitiesabstractMemory-based vulnerabilities are a major source of attack vectors. They allow attackers to gain unauthorized access to computers and their data. Previous research has made significant progress in detecting attacks. However, developers still need to locate and fix these vulnerabilities, a mostly manual and time-consuming process. They face a number of challenges. Particularly, the manifestation of an attack does not always coincide with the exploited vulnerabilities, and many attacks are hard to reproduce in the lab environment, leaving developers with limited information to locate them. In this paper, we propose Ravel, an architectural approach to pinpoint vulnerabilities from attacks. Ravel consists of an online attack detector and an offline vulnerability locator linked by a record & replay mechanism. Specifically, Ravel records the execution of a production system and simultaneously monitors it for attacks. If an attack is detected, the execution is replayed to reveal the targeted vulnerabilities by analyzing the program's memory access patterns under attack. We have built a prototype of Ravel based on the open-source FreeBSD operating system. The evaluation results in security and performance demonstrate that Ravel can effectively pinpoint various types of memory vulnerabilities and has low performance overhead. Mustakimur Khandaker, Zhi Wang 0004 |
AsiaCCS | 3 |
| 2017 | Secure In-Cache Execution
Mustakimur Khandaker, Zhi Wang 0004 |
RAID | 3 |
| 2017 | Adaptive Android Kernel Live Patching
Zhi Wang 0004, Liangzhao Xia, Chenfu Bao, Tao Wei 0002 |
USENIX Security Symposium | 3 |
| 2016 | Remix: On-demand Live RandomizationabstractCode randomization is an effective defense against code reuse attacks. It scrambles program code to prevent attackers from locating useful functions or gadgets. The key to secure code randomization is achieving high entropy. A practical approach to boost entropy is on-demand live randomization that works on running processes. However, enabling live randomization is challenging in that it often requires manual efforts to solve ambiguity in identifying function pointers. Zhi Wang 0004, David B. Whalley, Long Lu |
CODASPY | 2 |
| 2015 | Hybrid User-level Sandboxing of Third-party Android AppsabstractUsers of Android phones increasingly entrust personal information to third-party apps. However, recent studies reveal that many apps, even benign ones, could leak sensitive information without user awareness or consent. Previous solutions either require to modify the Android framework thus significantly impairing their practical deployment, or could be easily defeated by malicious apps using a native library. Yajin Zhou, Kunal Patel, Lei Wu 0012, Zhi Wang 0004, Xuxian Jiang |
AsiaCCS | 4 |
| 2015 | Xede: Practical Exploit Early Detection
Meining Nie, Purui Su, Qi Li 0002, Zhi Wang 0004, Lingyun Ying, Dengguo Feng |
RAID | 4 |
| 2015 | SecPod: a Framework for Virtualization-based Security Systems
Xiaoguang Wang 0003, Zhi Wang 0004, Yong Qi 0001, Yajin Zhou |
USENIX ATC | 3 |
| 2015 | Harvesting developer credentials in Android appsabstractDevelopers often integrate third-party services into their apps. To access a service, an app must authenticate itself to the service with a credential. However, credentials in apps are often not properly or adequately protected, and might be easily extracted by attackers. A leaked credential could pose serious privacy and security threats to both the app developer and app users. Yajin Zhou, Lei Wu 0012, Zhi Wang 0004, Xuxian Jiang |
WISEC | 3 |
| 2014 | ARMlock: Hardware-based Fault Isolation for ARMabstractSoftware fault isolation (SFI) is an effective mechanism to confine untrusted modules inside isolated domains to protect their host applications. Since its debut, researchers have proposed different SFI systems for many purposes such as safe execution of untrusted native browser plugins. However, most of these systems focus on the x86 architecture. Inrecent years, ARM has become the dominant architecture for mobile devices and gains in popularity in data centers.Hence there is a compellingneed for an efficient SFI system for the ARM architecture. Unfortunately, existing systems either have prohibitively high performance overhead or place various limitations on the memory layout and instructions of untrusted modules. Yajin Zhou, Xiaoguang Wang 0003, Zhi Wang 0004 |
CCS | 4 |
| 2014 | Systematic audit of third-party android phonesabstractAndroid has become the leading smartphone platform with hundreds of devices from various manufacturers available on the market today. All these phones closely resemble each other with similar hardware and software features. Manufacturers must therefore customize the official Android system to differentiate their devices. Unfortunately, such heavily customization by third-party manufacturers often leads to serious vulnerabilities that do not exist in the official Android system. In this paper, we propose a comparative approach to systematically audit software in third-party phones by comparing them side-by-side to the official system. Specifically, we first retrieve pre-loaded apps and libraries from the phone and build a matching base system from the Android open source project repository. We then compare corresponding apps and libraries for potential vulnerabilities. To facilitate this process, we have designed and implemented DexDiff, a system that can pinpoint fine structural differences between two Android binaries and also present the changes in their surrounding contexts. Our experiments show that DexDiff is efficient and scalable. For example, it spends less than two and half minutes to process two 16.5MB (in total) files. DexDiff is also able to reveal a new vulnerability and details of the invasive CIQ mobile intelligence software. Michael Mitchell, Guanyu Tian, Zhi Wang 0004 |
CODASPY | 3 |
| 2014 | DIVILAR: diversifying intermediate language for anti-repackaging on android platformabstractApp repackaging remains a serious threat to the emerging mobile app ecosystem. Previous solutions have mostly focused on the postmortem detection of repackaged apps by measuring similarity among apps. In this paper, we propose DIVILAR, a virtualization-based protection scheme to enable self-defense of Android apps against app repackaging. Specifically, it re-encodes an Android app in a diversified virtual instruction set and uses a specialized execute engine for these virtual instructions to run the protected app. However, this extra layer of execution may cause significant performance overhead, rendering the solution unacceptable for daily use. To address this challenge, we leverage a light-weight hooking mechanism to hook into Dalvik VM, the execution engine for Dalvik bytecode, and piggy-back the decoding of virtual instructions to that of Dalvik bytecode. By compositing virtual and Dalvik instruction execution, we can effectively eliminate this extra layer of execution and significantly reduce the performance overhead. We have implemented a prototype of DIVILAR. Our evaluation shows that DIVILAR is resilient against existing static and dynamic analysis, including these specific to VM-based protection. Further performance evaluation demonstrates its efficiency for daily use (an average of 16.2 and 8.9 increase to the start time and run time, respectively). Wu Zhou 0001, Zhi Wang 0004, Yajin Zhou, Xuxian Jiang |
CODASPY | 2 |
| 2013 | Taming Hosted Hypervisors with (Mostly) Deprivileged Execution
Chiachih Wu, Zhi Wang 0004, Xuxian Jiang |
NDSS | 2 |
| 2012 | Isolating commodity hosted hypervisors with HyperLockabstractHosted hypervisors (e.g., KVM) are being widely deployed. One key reason is that they can effectively take advantage of the mature features and broad user bases of commodity operating systems. However, they are not immune to exploitable software bugs. Particularly, due to the close integration with the host and the unique presence underneath guest virtual machines, a hosted hypervisor -- if compromised -- can also jeopardize the host system and completely take over all guests in the same physical machine. Zhi Wang 0004, Chiachih Wu, Michael C. Grace, Xuxian Jiang |
EuroSys | 1 |
| 2012 | Systematic Detection of Capability Leaks in Stock Android Smartphones
Michael C. Grace, Yajin Zhou, Zhi Wang 0004, Xuxian Jiang |
NDSS | 3 |
| 2012 | Hey, You, Get Off of My Market: Detecting Malicious Apps in Official and Alternative Android Markets
Yajin Zhou, Zhi Wang 0004, Wu Zhou 0001, Xuxian Jiang |
NDSS | 2 |
| 2011 | Process out-grafting: an efficient "out-of-VM" approach for fine-grained process execution monitoringabstractRecent rapid malware growth has exposed the limitations of traditional in-host malware-defense systems and motivated the development of secure virtualization-based out-of-VM solutions. By running vulnerable systems as virtual machines (VMs) and moving security software from inside the VMs to outside, the out-of-VM solutions securely isolate the anti-malware software from the vulnerable system. However, the presence of semantic gap also leads to the compatibility problem in not supporting existing defense software. In this paper, we present process out-grafting, an architectural approach to address both isolation and compatibility challenges in out-of-VM approaches for fine-grained process-level execution monitoring. Specifically, by relocating a suspect process from inside a VM to run side-by-side with the out-of-VM security tool, our technique effectively removes the semantic gap and supports existing user-mode process monitoring tools without any modification. Moreover, by forwarding the system calls back to the VM, we can smoothly continue the execution of the out-grafted process without weakening the isolation of the monitoring tool. We have developed a KVM-based prototype and used it to natively support a number of existing tools without any modification. The evaluation results including measurement with benchmark programs show it is effective and practical with a small performance overhead. Deepa Srinivasan, Zhi Wang 0004, Xuxian Jiang, Dongyan Xu |
CCS | 2 |
| 2011 | Comprehensive and Efficient Protection of Kernel Control DataabstractProtecting kernel control data (e.g., function pointers and return addresses) has been a serious issue plaguing rootkit defenders. In particular, rootkit authors only need to compromise one piece of control data to launch their attacks, while defenders need to protect thousands of such values widely scattered across kernel memory space. Worse, some of this data (e.g., return addresses) is volatile and can be dynamically generated at run time. Existing solutions, however, offer either incomplete protection or excessive performance overhead. To overcome these limitations, we present indexed hooks, a scheme that greatly facilitates kernel control-flow enforcement by thoroughly transforming and restricting kernel control data to take only legal jump targets (allowed by the kernel's control-flow graph). By doing so, we can severely limit the attackers' possibility of exploiting them as an infection vector to launch rootkit attacks. To validate our approach, we have developed a compiler-based prototype that implements this technique in the FreeBSD 8.0 kernel, transforming 49 025 control transfer instructions (~7.25% of the code base) to use indexed hooks instead of direct pointers. Our evaluation results indicate that our approach is generic, effective, and can be implemented on commodity hardware with a low performance overhead (<;5% based on benchmarks). Jinku Li, Zhi Wang 0004, Tyler K. Bletsch, Deepa Srinivasan, Michael C. Grace, Xuxian Jiang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2010 | HyperSentry: enabling stealthy in-context measurement of hypervisor integrityabstractThis paper presents HyperSentry, a novel framework to enable integrity measurement of a running hypervisor (or any other highest privileged software layer on a system). Unlike existing solutions for protecting privileged software, HyperSentry does not introduce a higher privileged software layer below the integrity measurement target, which could start another race with malicious attackers in obtaining the highest privilege in the system. Instead, HyperSentry introduces a software component that is properly isolated from the hypervisor to enable stealthy and in-context measurement of the runtime integrity of the hypervisor. While stealthiness is necessary to ensure that a compromised hypervisor does not have a chance to hide the attack traces upon detecting an up-coming measurement, in-context measurement is necessary to retrieve all the needed inputs for a successful integrity measurement. Ahmed M. Azab, Peng Ning, Zhi Wang 0004, Xuxian Jiang, Xiaolan Zhang 0001, Nathan C. Skalsky |
CCS | 3 |
| 2010 | Defeating return-oriented rootkits with "Return-Less" kernelsabstractTargeting the operating system (OS) kernel, kernel rootkits pose a formidable threat to computer systems and their users. Recent efforts have made significant progress in blocking them from injecting malicious code into the OS kernel for execution. Unfortunately, they cannot block the emerging so-called return-oriented rootkits (RORs). Without the need of injecting their own malicious code, these rootkits can discover and chain together "return-oriented gadgets" (that consist of only legitimate kernel code) for rootkit computation. Jinku Li, Zhi Wang 0004, Xuxian Jiang, Michael C. Grace, Sina Bahram |
EuroSys | 2 |
| 2010 | Transparent Protection of Commodity OS Kernels Using Hardware Virtualization
Michael C. Grace, Zhi Wang 0004, Deepa Srinivasan, Jinku Li, Xuxian Jiang, Zhenkai Liang, Siarhei Liakh |
SecureComm | 2 |
| 2010 | HyperSafe: A Lightweight Approach to Provide Lifetime Hypervisor Control-Flow IntegrityabstractVirtualization is being widely adopted in today's computing systems. Its unique security advantages in isolating and introspecting commodity OSes as virtual machines (VMs) have enabled a wide spectrum of applications. However, a common, fundamental assumption is the presence of a trustworthy hypervisor. Unfortunately, the large code base of commodity hypervisors and recent successful hypervisor attacks (e.g., VM escape) seriously question the validity of this assumption. In this paper, we present HyperSafe, a lightweight approach that endows existing Type-I bare-metal hypervisors with a unique self-protection capability to provide lifetime control flow integrity. Specifically, we propose two key techniques. The first one, non-bypassable memory lockdown, reliably protects the hypervisor's code and static data from being compromised even in the presence of exploitable memory corruption bugs (e.g., buffer overflows), therefore successfully providing hypervisor code integrity. The second one, restricted pointer indexing, introduces one layer of indirection to convert the control data into pointer indexes. These pointer indexes are restricted such that the corresponding call/return targets strictly follow the hypervisor control flow graph, hence expanding protection to control-flow integrity. We have built a prototype and used it to protect two open-source Type-I hypervisors: BitVisor and Xen. The experimental results with synthetic hypervisor exploits and benchmarking programs show HyperSafe can reliably enable the hypervisor self-protection and provide the integrity guarantee with a small performance overhead. Zhi Wang 0004, Xuxian Jiang |
IEEE Symposium on Security and Privacy | 1 |
| 2010 | DKSM: Subverting Virtual Machine Introspection for Fun and ProfitabstractVirtual machine (VM) introspection is a powerful technique for determining the specific aspects of guest VM execution from outside the VM. Unfortunately, existing introspection solutions share a common questionable assumption. This assumption is embodied in the expectation that original kernel data structures are respected by the untrusted guest and thus can be directly used to bridge the well-known semantic gap. In this paper, we assume the perspective of the attacker, and exploit this questionable assumption to subvert VM introspection. In particular, we present an attack called DKSM (Direct Kernel Structure Manipulation), and show that it can effectively foil existing VM introspection solutions into providing false information. By assuming this perspective, we hope to better understand the challenges and opportunities for the development of future reliable VM introspection solutions that are not vulnerable to the proposed attack. Sina Bahram, Xuxian Jiang, Zhi Wang 0004, Mike Grace, Jinku Li, Deepa Srinivasan, Junghwan Rhee, Dongyan Xu |
SRDS | 3 |
| 2009 | Countering kernel rootkits with lightweight hook protectionabstractKernel rootkits have posed serious security threats due to their stealthy manner. To hide their presence and activities, many rootkits hijack control flows by modifying control data or hooks in the kernel space. A critical step towards eliminating rootkits is to protect such hooks from being hijacked. However, it remains a challenge because there exist a large number of widely-scattered kernel hooks and many of them could be dynamically allocated from kernel heap and co-located together with other kernel data. In addition, there is a lack of flexible commodity hardware support, leading to the socalled protection granularity gap -- kernel hook protection requires byte-level granularity but commodity hardware only provides page level protection. Zhi Wang 0004, Xuxian Jiang, Weidong Cui, Peng Ning |
CCS | 1 |
| 2009 | ReFormat: Automatic Reverse Engineering of Encrypted Messages
Zhi Wang 0004, Xuxian Jiang, Weidong Cui, Xinyuan Wang 0005, Mike Grace |
ESORICS | 1 |
| 2008 | Countering Persistent Kernel Rootkits through Systematic Hook Discovery
Zhi Wang 0004, Xuxian Jiang, Weidong Cui, Xinyuan Wang 0005 |
RAID | 1 |