Chao Feng 0002

dblp:97/164-2 · DBLP profile ↗
← Back
13ranked-venue papers
0as first author
10since 2021 · last 2026
0000-0003-0884-5457ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 5 since 2021Software engineering, systems software and programming languages · 4 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 OSmartPro: a large language model-assisted option fuzzing approach
abstract
Abstract Program options provide flexible software functionality control but complicate fuzz testing, as triggering many behaviors require specific option combinations. Although existing option-aware fuzzing approaches attempt to mutate options as inputs or leverage AI technologies to extract option relationships from documentation, these methods have limitations. Documentation is often incomplete, and some option dependencies are embedded deeply within program logic via data or control flows, making these methods challenging to detect all possible dependencies. This paper introduces OSmartPro , an advanced option-fuzzing approach that directly extracts options and infers option dependencies from source code. Given LLM’s capabilities to interpret program semantics, OSmartPro employs LLM-assisted static analysis to handle diverse option-parsing structures and extract comprehensive options. Through control and data dependency analysis, it constructs option impact graph , which it uses to guide fuzzing strategies. The tool successfully extracted complete options from all 59 programs in our test set, uncovering undocumented options in over 66% of them. Additionally, OSmartPro inferred 14,701 option combinations, identified 45.03% more execution paths compared to AFL++, and uncovered 54 zero-day vulnerabilities, of which 18 awarded CVE IDs. Lastly, in a benchmark comparison against four option-aware fuzzers, OSmartPro achieved higher line coverage in 66.7% (20 out of 30) of the programs.
Kelin Wang, Mengda Chen, Liang He 0011, Purui Su, Jiongyi Chen, Yan Cai 0001, Chao Feng 0002, Chaojing Tang, Guojun Peng
Cybersecur.9
2025 Practical Object-Level Sanitizer with Aggregated Memory Access and Custom Allocator
abstract
To mitigate potential memory safety vulnerabilities, recently there have been significant advances in sanitizers for pre-production bug detection. However, the limited inability to balance performance and detection accuracy still holds. The main reason is due to excessive reliance on shadow memory and a large number of memory access checks at runtime, incurring a significant performance overhead (if fine-grained memory safety detection is performed, the overhead will be even greater). In this paper, we propose a novel Object-Level Address Sanitizer OLASan to reduce performance overhead further while implementing accurate memory violations (including intra-object overflow) detection. Unlike previous sanitizers ignoring the correlation between memory access and objects, OLASan aggregates multiple memory accesses of same object at function level to perform on-demand targeted sanitization, thus avoiding examining most memory accesses at runtime. Specifically, OLASan characterizes various memory access patterns to identify those which can be aggregated, and implements memory safety checks with customized memory tagging. We implement OLASan atop the LLVM framework and evaluate it on SPEC CPU benchmarks. Evaluations show that OLASan outperforms the state-of-the-art methods with 51.18%, 25.20% and 6.52% less runtime overhead than ASan, ASan-- and GiantSan respectively. Moreover, aided by customized memory tagging, OLASan achieves zero false negatives for the first time when testing Juliet suites. Finally, we confirm that OLASan also offers comparable detection capabilities on real bugs.
Ruilin Li 0002, Chao Feng 0002, Chaojing Tang
ICSE4
2024 OSmart: Whitebox Program Option Fuzzing
abstract
Program options are ubiquitous and serve as a fundamental mechanism for configuring and customizing software behaviors. Given their widespread use, testing program options becomes essential to ensure that the software behaves as expected across various configurations. Existing option-aware fuzzers either mutate options as if they were standard program inputs or employ NLP techniques to deduce relationships among options from the documentation. However, there has not been a whitebox approach that generates option combinations by capturing the inherent execution logic of the program.
Kelin Wang, Mengda Chen, Liang He 0011, Purui Su, Yan Cai 0001, Jiongyi Chen, Chao Feng 0002, Chaojing Tang
CCS8
2023 Towards Automatic and Precise Heap Layout Manipulation for General-Purpose Programs
Runhao Li, Jiongyi Chen, Wenfeng Lin, Chao Feng 0002, Chaojing Tang
NDSS5
2023 Automated Exploitable Heap Layout Generation for Heap Overflows Through Manipulation Distance-Guided Fuzzing
Jiongyi Chen, Runhao Li, Chao Feng 0002, Ruilin Li 0002, Chaojing Tang
USENIX Security Symposium4
2022 Default: Mutual Information-based Crash Triage for Massive Crashes
abstract
With the considerable success achieved by modern fuzzing infrastructures, more crashes are produced than ever before. To dig out the root cause, rapid and faithful crash triage for large numbers of crashes has always been attractive. However, hindered by the practical difficulty of reducing analysis imprecision without compromising efficiency, this goal has not been accomplished.
Jiongyi Chen, Chao Feng 0002, Ruilin Li 0002, Wenrui Diao, Kehuan Zhang, Jing Lei 0001, Chaojing Tang
ICSE3
2022 Game of Hide-and-Seek: Exposing Hidden Interfaces in Embedded Web Applications of IoT Devices
abstract
Recent years have seen increased attacks targeting embedded web applications of IoT devices. An important target of such attacks is the hidden interface of embedded web applications, which employs no protection but exposes security-critical actions and sensitive information to illegitimate users. With the severity and the pervasiveness of this issue, it is crucial to identify the vulnerable hidden interfaces, shed light on best practices and raise public awareness.
Wei Xie 0007, Jiongyi Chen, Chao Feng 0002, Enze Wang, Kai Lu 0001
WWW4
2022 Automated detection on the security of the linked-list operations
Hongyu Kuang, Jian Wang 0020, Ruilin Li 0002, Chao Feng 0002, Yunfei Su
Frontiers Comput. Sci.4
2022 Pusher: an augmented fuzzer based on the connection between input and comparison operand
Jiaxi Ye, Ruilin Li 0002, Chao Feng 0002, Yunfei Su, Chaojing Tang
Frontiers Comput. Sci.4
2021 Reducing Test Cases with Attention Mechanism of Neural Networks
Jiongyi Chen, Chao Feng 0002, Ruilin Li 0002, Yunfei Su, Jing Lei 0001, Chaojing Tang
USENIX Security Symposium3
2018 Discover deeper bugs with dynamic symbolic execution and coverage-based fuzz testing
abstract
Coverage‐based fuzz testing and dynamic symbolic execution are both popular program testing techniques. However, on their own, both techniques suffer from scalability problems when considering the complexity of modern software. Hybrid testing methods attempt to mitigate these problems by leveraging dynamic symbolic execution to assist fuzz testing. Unfortunately, the efficiency of such methods is still limited by specific program structures and the schedule of seed files. In this study, the authors introduce a novel lazy symbolic pointer concretisation method and a symbolic loop bucket optimisation to mitigate path explosion caused by dynamic symbolic execution in hybrid testing. They also propose a distance‐based seed selection method to rearrange the seed queue of the fuzzer engine in order to achieve higher coverage. They implemented a prototype and evaluate its ability to find vulnerabilities in software and cover new execution paths. They show on different benchmarks that it can find more crashes than other off‐the‐shelf vulnerability detection tools. They also show that the proposed method can discover 43% more unique paths than vanilla fuzz testing.
Chao Feng 0002, Adrian Herrera, Vitaly Chipounov, George Candea, Chaojing Tang
IET Softw.2
2018 An Exploitability Analysis Technique for Binary Vulnerability Based on Automatic Exception Suppression
abstract
To quickly verify and fix vulnerabilities, it is necessary to judge the exploitability of the massive crash generated by the automated vulnerability mining tool. While the current manual analysis of the crash process is inefficient and time-consuming, the existing automated tools can only handle execute exceptions and some write exceptions but cannot handle common read exceptions. To address this problem, we propose a method of determining the exploitability based on the exception type suppression. This method enables the program to continue to execute until an exploitable exception is triggered. The method performs a symbolic replay of the crash sample, constructing and reusing data gadget, to bypass the complex exception, thereby improving the efficiency and accuracy of vulnerability exploitability analysis. The testing of typical CGC/RHG binary software shows that this method can automatically convert a crash that cannot be judged by existing analysis tools into a different crash type and judge the exploitability successfully.
Zhiyuan Jiang, Chao Feng 0002, Chaojing Tang
Secur. Commun. Networks2
2016 Detecting integer overflow in Windows binary executables based on symbolic execution
abstract
The integer overflow vulnerabilities exist in Windows binary executables still take up a large proportion of software security vulnerabilities. As integer overflow could lead to a serious buffer overflow sometimes, so once the integer overflow to buffer overflow vulnerability is exploited by attackers, our computer system may be exposed to critical threaten. In this paper, we present the design and implementation of a dynamic method to detect integer overflow to buffer overflow vulnerabilities. Our method first utilizes static analysis to find integer sensitive code region with the help of the characteristics of integer overflow to buffer overflow vulnerability. Then we leverage selective symbolic execution to explore these code regions and check the secure condition on each sink point to find secure bugs. Once we find a suspicious integer overflow to buffer overflow point, our method can generate POC automatically so that we can validate this overflow warning easily and accurately. We evaluate our method on 104 integer overflow to buffer overflow programs in Juliet test suite, and the result shows that our method does not produce any false positive and false negative. We also test our method on real-world binary software and the result shows our method could detect the vulnerability efficiently and generate POCs successfully.
Chao Feng 0002, Chaojing Tang
SNPD2