VLDB 2026 Research / reviewers in the wild / expert
Bing Mao 0001
dblp:98/5039-1
· DBLP profile ↗
61ranked-venue papers
0as first author
21since 2021 · last 2026
0000-0002-7066-2144ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 41 · 7 since 2021Software engineering, systems software and programming languages · 13 · 9 since 2021Systems, architecture and hardware · 4Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Computer networks · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Diverse Human Driving Vehicle Simulation in Background Traffic for Autonomous Driving TestsabstractRealistic background traffic is critical to the simulation platforms for autonomous driving (AD) testing. Given that most vehicles in reality are driven by human beings, introducing human driving (HD) vehicles to the background traffic is necessary to be able to discover more problems of the tested AD vehicle in the simulation stage. However, existing methods rely on ad-hoc rules or data-driven training to mimic partial human driver behaviors, which are not comprehensive and lack transparency. In this work, we design a smart human driving vehicle simulator HDSim which is empowered by cognitively inspired modeling and AI models. HDSim enables diverse, realistic, and scalable HD traffic simulation on AD testing platforms like CARLA in a non-intrusive manner. There are two novel components in HDSim. First, we introduce a driver model to guide the generation of diverse human driving styles by using different combinations of latent cognitive factors in a hierarchy. Second, we design a Perception-Mediated Behavior Influence (PMBI) mechanism to use LLM-assisted perceptual transformations to indirectly fuse driving actions with driving styles. Experiments show that HDSim traffic can help simulation platforms like CARLA to reveal 68% more failures of tested AD vehicles, and the explainability of reported accidents is also improved. Wendi Li, Hao Wu 0067, Bing Mao 0001, Fengyuan Xu, Sheng Zhong 0002 |
AAAI | 4 |
| 2026 | CLower: Detecting Compiler Pessimization Bugs through Redundant Memory AccessesabstractCompilers are expected to generate optimized code, but they sometimes introduce pessimizations, quality-degrading redundant instructions. These bugs not only incur performance overhead but also, critically, expand the attack surface by introducing unexpected side effects (e.g., redundant memory accesses) without breaking compilation correctness. Existing bug-finding methods are neither designed for nor effective at identifying such security-sensitive pessimizations. This paper presents CLower, a novel, black-box approach for automatically detecting compiler pessimizations via redundant memory accesses. CLower’s core insight is that any extra global memory accesses in a fully optimized binary, compared to the source, indicate a pessimization. To reliably distinguish compiler-introduced redundancy from source-level redundancy, we generate random C programs in which each global variable has a predetermined, controlled number of memory accesses. CLower then executes the instrumented binary and verifies whether superfluous accesses have been introduced during compilation. We applied CLower to GCC and LLVM, reporting 23 unique bugs (21 in GCC, 2 in Clang), with 16 confirmed as new pessimization bugs. Our evaluation shows that CLower accurately detects diverse, impactful pes-simization bugs, the majority of which (75%) also manifest for heap-allocated objects, demonstrating that the underlying compiler flaws are general and not limited to global memory. Furthermore, we identify a systematic conflict between compiler optimizations and pessimization bugs, which causes many such bugs to remain hidden in compiler versions. This study sheds light on the under-explored area of compiler pessimization and provides a practical tool for improving compiler quality. Jianhao Xu, Kunbo Zhang, Mathias Payer, Kangjie Lu, Bing Mao 0001 |
Proc. ACM Program. Lang. | 5 |
| 2025 | MIINT: Infuse Intuitive Data Correspondence for Model InterpretationabstractTo help humans understand the mechanism of machine learning models seamlessly, various works are dedicated to opening the black boxes of current learning methods. The mainstream of existing work attempts to calculate feature importance directly from input to output but still suffers from infidelity, inconsistency, instability, and complexity. To improve the performance of interpretable machine learning methods, we find that there are natural correlations between the prediction results and the features under specific tasks, called intuitive data correspondence. Specifically, in image classification tasks, image segmentation can be regarded as a kind of intuitive selection to sketch the relationship between the object and the classification result. Based on this heuristic observation, we propose MIINT to integrate intuitive data correspondence into the traditional post-hoc interpretable machine learning techniques with partial dependency. We conduct experiments on 2 classic image classification datasets, and the results show that MIINT has better fidelity, consistency, stability, and sparsity compared with the baseline method LIME: MIINT reduces infidelity and complexity by more than 10%, and increases consistency and stability by more than 10% and 25% respectively. Ligeng Chen, Bing Mao 0001 |
ICME | 3 |
| 2025 | Unleashing the Power of LLM to Infer State Machine From the Protocol ImplementationabstractState machines are essential for enhancing protocol analysis to identify vulnerabilities. However, inferring state machines from network protocol implementations is challenging due to complex code syntax and semantics. Traditional dynamic analysis methods often miss critical state transitions due to limited coverage, while static analysis faces path explosion issues. To overcome these challenges, we introduce a novel state machine inference approach utilizing Large Language Models (LLMs), named ProtocolGPT. This method employs retrieval augmented generation technology to enhance a pre-trained model with specific knowledge from protocol implementations. Through effective prompt engineering, we accurately identify and infer state machines. To the best of our knowledge, our approach represents the first state machine inference that leverages the source code of protocol implementations. Our evaluation of six protocol implementations shows that our method achieves a precision of over 90 %, outperforming the baselines by more than 30 %. Furthermore, integrating our approach with protocol fuzzing improves coverage by more than 20 % and uncovers two 0-day vulnerabilities compared to baseline methods. Haiyang Wei, Ligeng Chen, Zhengjie Du, Haohui Huang, Guang Cheng 0001, Fengyuan Xu, Linzhang Wang, Bing Mao 0001 |
IWQoS | 10 |
| 2025 | Uncovering Prompt Elements: Cloning System Prompts from Behavioral TracesabstractWe introduce prompt cloning, a new black-box attack that reconstructs functionally equivalent system prompts rather than extracts original system prompts. Unlike prompt stealing, prompt cloning exploits the insight that system prompts leave persistent behavioral traces in outputs, even under strong alignment and prompt-level defenses. Our method decomposes system behavior into semantically interpretable elements, selectively elicits them through carefully designed queries, and aggregates representative traces to synthesize high-fidelity cloned prompts. Extensive evaluations show that cloned prompts replicate functional behavior with up to 85% semantic similarity, outperforming base LLMs by up to 8%, and even exceeding original system prompts when transferred to different back-end models. We also conduct a large-scale study on GitHub repositories, revealing that single-prompt architectures remain widespread in open-source LLM applications, reinforcing the real-world relevance of our threat model. Our findings reveal that prompt cloning enables unauthorized replication of confidential LLM behavior and underscore the urgent need for defenses that go beyond hiding prompt text. Hao Wu 0067, Ligeng Chen, Bing Mao 0001 |
ASE | 5 |
| 2025 | CATI++: empirical study and evaluation for adjacent instruction enhanced type inferenceabstractAbstract Variable-type information is fundamental, and it greatly helps in understanding the program semantics. Previous work applies rule-based and machine learning-based methods to recover variable types from commercial off-the-shelf binaries, heavily relying on the data flow or control flow. However, according to our study, about half of the variables lacked or even had no data flow; this problem has not received much attention from previous work. We empirically explore the severity of this problem to the type inference task and analyze its root causes. Based on compilation properties, we find that the instructions surrounding the instructions that operate on variables provide good contextual information that can be used for co-encoding to overcome the above problem. In this paper, we present an effective machine learning-based method to infer variable types and overcome the challenge of limited data dependency via adjacent instructions co-encoding. Therefore, we implement a system called CATI++, which locates variables from stripped binaries and infers 19 types of variables. We evaluate CATI++ on different compilation options, all of which outperforms state-of-the-art methods. The ablation experiments verify that our scheme is not sensitive to compilation conditions, while our designed method effectively alleviates the problems caused by missing data dependency. Ligeng Chen, Zhongling He, Bing Mao 0001 |
Comput. J. | 4 |
| 2024 | Medusa: Unveil Memory Exhaustion DoS Vulnerabilities in Protocol ImplementationsabstractWeb services have brought great convenience to our daily lives. Meanwhile, they are vulnerable to Denial-of-Service (DoS) attacks. DoS attacks launched via vulnerabilities in the services can cause great harm. The vulnerabilities in protocol implementations are especially important because they are the keystones of web services. One vulnerable protocol implementation can affect all the web services built on top of it. Compared to the vulnerabilities that cause the target service to crash, resource exhaustion vulnerabilities are equally if not more important. This is because such vulnerabilities can deplete the system resources, leading to the unavailability of not only the vulnerable service but also other services running on the same machine. Despite the significance of this type of vulnerability, there has been limited research in this area. Zhengjie Du, Yuekang Li, Yaowen Zheng, Cen Zhang, Yi Liu 0069, Sheikh Mahbub Habib, Xinghua Li 0001, Linzhang Wang, Yang Liu 0003, Bing Mao 0001 |
WWW | 11 |
| 2023 | OCFI: Make Function Entry Identification Hard AgainabstractFunction entry identification is a crucial yet challenging task for binary disassemblers that has been the focus of research in the past decades. However, recent researches show that call frame information (CFI) provides accurate and almost complete function entries. With the aid of CFI, disassemblers have significant improvements in function entry detection. CFI is specifically designed for efficient stack unwinding, and every function has corresponding CFI in x64 and aarch64 architectures. Nevertheless, not every function and instruction unwinds the stack at runtime, and this observation has led to the development of techniques such as obfuscation to complicate function detection by disassemblers. Chengbin Pang, Tiantai Zhang, Xuelan Xu, Linzhang Wang, Bing Mao 0001 |
ISSTA | 5 |
| 2023 | WarpAttack: Bypassing CFI through Compiler-Introduced Double-FetchesabstractCode-reuse attacks are dangerous threats that attracted the attention of the security community for years. These attacks aim at corrupting important control-flow transfers for taking control of a process without injecting code. Nowadays, the combinations of multiple mitigations (e.g., ASLR, DEP, and CFI) drastically reduced this attack surface, making running code-reuse exploits more challenging.Unfortunately, security mitigations are combined with compiler optimizations, that do not distinguish between security-related and application code. Blindly deploying code optimizations over code-reuse mitigations may undermine their security guarantees. For instance, compilers may introduce double-fetch vulnerabilities that lead to concurrency issues such as Time-Of-Check to Time-Of-Use (TOCTTOU) attacks.In this work, we propose a new attack vector, called WarpAttack, that exploits compiler-introduced double-fetch optimizations to mount TOCTTOU attacks and bypass code-reuse mitigations. We study the mechanism underlying this attack and present a practical proof-of-concept exploit against the last version of Firefox. Additionally, we propose a lightweight analysis to locate vulnerable double-fetch code (with 3% false positives) and conduct research over six popular applications, five operating systems, and four architectures (32 and 64 bits) to study the diffusion of this threat. Moreover, we study the implication of our attack against six CFI implementations. Finally, we investigate possible research lines for addressing this threat and propose practical solutions to be deployed in existing projects. Jianhao Xu, Luca Di Bartolomeo, Flavio Toffalini, Bing Mao 0001, Mathias Payer |
SP | 4 |
| 2023 | Silent Bugs Matter: A Study of Compiler-Introduced Security Bugs
Jianhao Xu, Kangjie Lu, Zhengjie Du, Zhu Ding, Linke Li, Qiushi Wu, Mathias Payer, Bing Mao 0001 |
USENIX Security Symposium | 8 |
| 2023 | Generation-based fuzzing? Don't build a new generator, reuse!
Chengbin Pang, Hongbin Liu 0005, Neil Zhenqiang Gong, Bing Mao 0001, Jun Xu 0024 |
Comput. Secur. | 5 |
| 2023 | Nimbus++: Revisiting Efficient Function Signature Recovery with Depth Data AnalysisabstractFunction signature recovery is vital for many binary analysis tasks, led by control-flow integrity enhancement. To minimize human effort, existing works attempt to replace rule-based methods with learning-based methods. These works put a lot of work into improving the system’s performance, but this had the unintended consequence of increasing resource usage. However, recovering the function signature is more about providing information for subsequent tasks, e.g. reverse engineering, so both efficiency and performance are significant. To identify the fundamental factors that increase efficiency, we attempt to optimize data-driven systems throughout their lifecycle from a data perspective. To this end, we perform detailed data analysis on a carefully collected dataset. After analysis and exploration, selective input is adopted and a multi-task learning (MTL) structure is introduced for function feature recovery to make full use of mutual information, and the computing resource overhead is optimized based on the observation of information deviation and sub-task relationship. The resource usage of the entire process is significantly reduced by our suggested solution, named Nimbus++ for efficient function signature recovery, without sacrificing performance. Our test findings demonstrate that we even surpass the state-of-the-art method’s prediction accuracy across all function signature recovery tasks by about 1% with just about 12.5% of the processing time. Ligeng Chen, Bing Mao 0001 |
Int. J. Softw. Eng. Knowl. Eng. | 4 |
| 2023 | EVaDe: Efficient and Lightweight Mirai Variants Detection via Approximate Largest Submatrix SearchabstractThe Mirai botnet, notorious for launching significant Distributed Denial of Service (DDoS) attacks and crippling portions of internet services in late 2016, has emerged as a significant threat. Its threat is magnified by the open-source nature of the original Mirai code, which enables a propagation and evolution rate that surpasses traditional malware and frequently defies common sense. As the primary targets of Mirai attacks, Internet of Things (IoT) devices must promptly adapt to the evolving variations of the Mirai threat scenario. In practice, however, IoT devices are frequently constrained by insufficient security detection resources. Therefore, there is an urgent need for a lightweight framework capable of handling Mirai variants and dynamically updating its rule set in order to effectively counter the threat. In response to these challenges, we present Efficient and lightweight Mirai Variants Detection (EVaDe), a novel, lightweight framework for detecting Mirai. EVaDe unleashes the power of sample function mining to efficiently automate the generation of detection rules, requiring limited hardware resources while maintaining effectiveness against Mirai and its numerous variants. In addition, to improve the efficacy of rule generation, we propose a sophisticated algorithm designed to optimize the maximum submatrix problem, thereby facilitating the efficient and rapid extraction of malicious rules from the sample group. We validated the experiments on actual IoT devices with significantly compressed performance overheads. An average sample detection time of 5 ms to make sure the system can be deployed in real production. According to the result, the approach has an average detection rate of 95% for Mirai and its variants, which beats every other well-known piece of commercial antivirus software on the market by 3% to 56%. Xuguo Wang, Ligeng Chen, Bing Mao 0001 |
Int. J. Softw. Eng. Knowl. Eng. | 5 |
| 2022 | Windranger: A Directed Greybox Fuzzer driven by Deviation Basic BlocksabstractDirected grey-box fuzzing (DGF) is a security testing technique that aims to steer the fuzzer towards predefined target sites in the program. To gain directedness, DGF prioritizes the seeds whose execution traces are closer to the target sites. Therefore, evaluating the distance between the execution trace of a seed and the target sites (aka, the seed distance) is important for DGF. The first directed grey-box fuzzer, AFLGo, uses an approach of calculating the basic block level distances during static analysis and accumulating the distances of the executed basic blocks to compute the seed distance. Following AFLGo, most of the existing state-of-the-art DGF techniques use all the basic blocks on the execution trace and only the control flow information for seed distance calculation. However, not every basic block is equally important and there are certain basic blocks where the execution trace starts to deviate from the target sites (aka, deviation basic blocks). Zhengjie Du, Yuekang Li, Yang Liu 0003, Bing Mao 0001 |
ICSE | 4 |
| 2022 | Nimbus: Toward Speed Up Function Signature Recovery via Input Resizing and Multi-Task LearningabstractFunction signature recovery is important for many binary analysis tasks such as control-flow integrity enforcement, clone detection, and bug finding. Existing works try to substitute learning-based methods with rule-based methods to reduce human effort.They made considerable efforts to enhance the system’s performance, which also bring the side effect of higher resource consumption. However, recovering the function signature is more about providing information for subsequent tasks, and both efficiency and performance are significant.In this paper, we first propose a method called Nimbus for efficient function signature recovery that furthest reduces the whole-process resource consumption without performance loss. Thanks to information bias and task relation (i.e., the relation between parameter count and parameter type recovery), we utilize selective inputs and introduce multi-task learning (MTL) structure for function signature recovery to reduce computational resource consumption, and fully leverage mutual information. Our experimental results show that, with only about the one-eighth processing time of the state-of-the-art method, we even achieve about 1% more prediction accuracy over all function signature recovery tasks. Ligeng Chen, Bing Mao 0001 |
QRS | 4 |
| 2022 | AVMiner: Expansible and Semantic-Preserving Anti-Virus Labels Mining MethodabstractWith the increase in the variety and quantity of malware, there is an urgent need to speed up the diagnosis and analysis of malware. Extracting the malware family-related tokens from AV (Anti-Virus) labels, provided by online antivirus engines, paves the way for pre-diagnosing the malware. Automatically extracting vital information from AV labels will greatly enhance the detection ability of security enterprises and equip the research ability of security analysts. Recent works like AVCLASS and AVCLASS2 try to extract the attributes of malware from AV labels and establish the taxonomy based on expert knowledge. However, due to the uncertain trend of complicated malicious behaviors, the system needs the following abilities to face the challenge: preserving vital semantics, being expansible, and being free from expert knowledge. In this work, we present AVMiner, an expansible malware tagging system that can mine the most vital tokens from AV labels. AVMiner adopts natural language processing techniques and clustering methods to generate a sequence of tokens without expert knowledge ranked by importance. AVMiner can self-update when new samples come. Finally, we evaluate AVMiner on over 8,000 samples from well-known datasets with manually labeled ground truth, which outperforms previous works. Ligeng Chen, Zhongling He, Hao Wu 0067, Yuhang Gong, Bing Mao 0001 |
TrustCom | 5 |
| 2022 | Ground Truth for Binary Disassembly is Not Easy
Chengbin Pang, Tiantai Zhang, Ruotong Yu, Bing Mao 0001, Jun Xu 0024 |
USENIX Security Symposium | 4 |
| 2022 | DIComP: Lightweight Data-Driven Inference of Binary Compiler Provenance with High AccuracyabstractBinary analysis is pervasively utilized to assess software security and test vulnerabilities without accessing source codes. The analysis validity is heavily influenced by the inferring ability of information related to the code compilation. Among the compilation information, compiler type and optimization level, as the key factors determining how binaries look like, are still difficult to be inferred efficiently with existing tools. In this paper, we conduct a thorough empirical study on the binary's appearance under various compilation settings and propose a lightweight binary analysis tool based on the simplest machine learning method, called DIComP to infer the compiler and optimization level via most relevant features according to the observation. Our comprehensive evaluations demonstrate that DIComP can fully recognize the compiler provenance, and it is effective in inferring the optimization levels with up to 90% accuracy. Also, it is efficient to infer thousands of binaries at a millisecond level with our lightweight machine learning model (1MB). Ligeng Chen, Zhongling He, Hao Wu 0067, Fengyuan Xu, Bing Mao 0001 |
SANER | 6 |
| 2021 | SoK: All You Ever Wanted to Know About x86/x64 Binary Disassembly But Were Afraid to AskabstractDisassembly of binary code is hard, but necessary for improving the security of binary software. Over the past few decades, research in binary disassembly has produced many tools and frameworks, which have been made available to researchers and security professionals. These tools employ a variety of strategies that grant them different characteristics. The lack of systematization, however, impedes new research in the area and makes selecting the right tool hard, as we do not understand the strengths and weaknesses of existing tools. In this paper, we systematize binary disassembly through the study of nine popular, open-source tools. We couple the manual examination of their code bases with the most comprehensive experimental evaluation (thus far) using 3,788 binaries. Our study yields a comprehensive description and organization of strategies for disassembly, classifying them as either algorithm or else heuristic. Meanwhile, we measure and report the impact of individual algorithms on the results of each tool. We find that while principled algorithms are used by all tools, they still heavily rely on heuristics to increase code coverage. Depending on the heuristics used, different coverage-vs-correctness trade-offs come in play, leading to tools with different strengths and weaknesses. We envision that these findings will help users pick the right tool and assist researchers in improving binary disassembly. Chengbin Pang, Ruotong Yu, Yaohui Chen 0001, Eric Koskinen, Georgios Portokalidis, Bing Mao 0001, Jun Xu 0024 |
SP | 6 |
| 2021 | RoBin: Facilitating the Reproduction of Configuration-Related VulnerabilityabstractVulnerability reproduction paves a way in debugging software failures, which need intensive manual efforts. However, some key factors (e.g., software configuration, trigger method) are often missing, so we can not directly reproduce the failure without extra attempts. Even worse, highly customized configuration options of programs create a barrier for reproducing the vulnerabilities that only appear under some specific combinations of configurations. In this paper, we address the problem mentioned above - reproducing the configuration-related vulnerability. We try to solve it by proposing a binary similarity-based method to infer the specific building configurations via the binary from crash report. The main challenges are as follows: precise compilation option inference, program configuration inference, and source-code-to-binary matching. To achieve the goal, we implement RoBin, a binary similarity-based building configuration inference tool. To demonstrate the effectiveness, we test RoBin on 21 vulnerable cases upon 4 well-known open-source programs. It shows a strong ability in pinpointing the building configurations causing the vulnerability. The result can help developers reproduce and diagnose the vulnerability, and finally, patch the programs. Ligeng Chen, Zhongling He, Dongliang Mu, Bing Mao 0001 |
TrustCom | 5 |
| 2021 | POMP++: Facilitating Postmortem Program Diagnosis with Value-Set AnalysisabstractWith the emergence of hardware-assisted processor tracing, execution traces can be logged with lower runtime overhead and integrated into the core dump. In comparison with an ordinary core dump, such a new post-crash artifact provides software developers and security analysts with more clues to a program crash. However, existing works only rely on the resolved runtime information, which leads to the limitation in data flow recovery within long execution traces. In this work, we propose POMP++, an automated tool to facilitate the analysis of post-crash artifacts. More specifically, POMP++ introduces a reverse execution mechanism to construct the data flow that a program followed prior to its crash. Furthermore, POMP++ utilizes Value-set Analysis, which helps to verify memory alias relation, to improve the ability of data flow recovery. With the restored data flow, POMP++ then performs backward taint analysis and highlights program statements that actually contribute to the crash. We have implemented POMP++ for Linux system on x86-32 platform, and tested it against various crashes resulting from 31 distinct real-world security vulnerabilities. The evaluation shows that, our work can pinpoint the root causes in 29 cases, increase the number of recovered memory addresses by 12 percent and reduce the execution time by 60 percent compared with existing reverse execution. In short, POMP++ can accurately and efficiently pinpoint program statements that truly contribute to the crashes, making failure diagnosis significantly convenient. Dongliang Mu, Yunlan Du, Jianhao Xu, Jun Xu 0024, Xinyu Xing 0001, Bing Mao 0001, Peng Liu 0005 |
IEEE Trans. Software Eng. | 6 |
| 2020 | CATI: Context-Assisted Type Inference from Stripped BinariesabstractCode analysis is a powerful way to eliminate vulnerabilities. Closed-source programs lack crucial information vital for code analysis because that information is stripped on compilation to achieve smaller executable size. Restoration has always been a challenge for experts. Variable type information is fundamental in this process because it helps to provide a perspective on program semantic. In this paper, we present an efficient approach for inferring types, and we overcome the challenge of scattered information provided by static analysis on stripped binaries. We discover that neighboring instructions are likely to operate the same type of variables, which are leveraged to enrich the features that we rely on. Therefore, we implement a system called CATI, which locates variables from stripped binaries and infers 19 types from variables. Experiments show that it infers variable type with 71.2% accuracy on unseen binaries. Meanwhile, it takes approximately 6 seconds to process a typical binary. Ligeng Chen, Zhongling He, Bing Mao 0001 |
DSN | 3 |
| 2020 | HART: Hardware-Assisted Kernel Module Tracing on Arm
Yunlan Du, Zhenyu Ning, Jun Xu 0024, Yueh-Hsun Lin, Fengwei Zhang, Xinyu Xing 0001, Bing Mao 0001 |
ESORICS (1) | 8 |
| 2019 | PTrix: Efficient Hardware-Assisted Fuzzing for COTS BinaryabstractDespite its effectiveness in uncovering software defects, American Fuzzy Lop (AFL), one of the best grey-box fuzzers, is inefficient when fuzz-testing source-unavailable programs. AFL's binary-only fuzzing mode, QEMU-AFL, is typically 2-5× slower than its source- available fuzzing mode. The slowdown is largely caused by the heavy dynamic instrumentation. Recent fuzzing techniques use Intel Processor Tracing (PT), a light-weight tracing feature supported by recent Intel CPUs, to re- move the need of dynamic instrumentation. However, we found that these PT-based fuzzing techniques are even slower than QEMU-AFL when fuzzing real-world programs, making them less effective than QEMU-AFL. This poor performance is caused by the slow extraction of code coverage information from highly compressed PT traces. In this work, we present the design and implementation of PTrix, which fully unleashes the benefits of PT for fuzzing via three novel techniques. First, PTrix introduces a scheme to highly parallel the processing of PT trace and target program execution. Second, it directly takes decoded PT trace as feedback for fuzzing, avoiding the expensive reconstruction of code coverage information. Third, PTrix maintains the new feedback with stronger feedback than edge-based code coverage, which helps reach new code space and defects that AFL may not. We evaluated PTrix by comparing its performance with the state- of-the-art fuzzers. Our results show that, given the same amount of time, PTrix achieves a significantly higher fuzzing speed and reaches into code regions missed by the other fuzzers. In addition, PTrix identifies 35 new vulnerabilities in a set of previously well- fuzzed binaries, showing its ability to complement existing fuzzers. Yaohui Chen 0001, Dongliang Mu, Jun Xu 0024, Zhichuang Sun, Wenbo Shen, Xinyu Xing 0001, Long Lu, Bing Mao 0001 |
AsiaCCS | 8 |
| 2019 | RENN: Efficient Reverse Execution with Neural-Network-Assisted Alias AnalysisabstractReverse execution and coredump analysis have long been used to diagnose the root cause of software crashes. Each of these techniques, however, face inherent challenges, such as insufficient capability when handling memory aliases. Recent works have used hypothesis testing to address this drawback, albeit with high computational complexity, making them impractical for real world applications. To address this issue, we propose a new deep neural architecture, which could significantly improve memory alias resolution. At the high level, our approach employs a recurrent neural network (RNN) to learn the binary code pattern pertaining to memory accesses. It then infers the memory region accessed by memory references. Since memory references to different regions naturally indicate a non-alias relationship, our neural architecture can greatly reduce the burden of doing hypothesis testing to track down non-alias relation in binary code. Different from previous researches that have utilized deep learning for other binary analysis tasks, the neural network proposed in this work is fundamentally novel. Instead of simply using off-the-shelf neural networks, we designed a new recurrent neural architecture that could capture the data dependency between machine code segments. To demonstrate the utility of our deep neural architecture, we implement it as RENN, a neural network-assisted reverse execution system. We utilize this tool to analyze software crashes corresponding to 40 memory corruption vulnerabilities from the real world. Our experiments show that RENN can significantly improve the efficiency of locating the root cause for the crashes. Compared to a state-of-the-art technique, RENN has 36.25% faster execution time on average, detects an average of 21.35% more non-alias pairs, and successfully identified the root cause of 12.5% more cases. Dongliang Mu, Wenbo Guo 0002, Alejandro Cuevas, Yueqi Chen 0001, Jinxuan Gai, Xinyu Xing 0001, Bing Mao 0001, Chengyu Song |
ASE | 7 |
| 2019 | Automatic Detection and Repair Recommendation for Missing Checks
Lingyun Situ, Linzhang Wang, Yang Liu 0003, Bing Mao 0001, Xuandong Li |
J. Comput. Sci. Technol. | 4 |
| 2018 | Mapping to Bits: Efficiently Detecting Type Confusion ErrorsabstractThe features of modularity and inheritance in C++ facilitate the developers' usage, but also give rise to the problem of type confusion. As an ancestor class may have a different data layout from its descendant class, a dangerous downcasting operation from the ancestor to its descendant can lead to a critical attack, such as control flow hijacking, out-of-bounds access to neighbor memory area, etc. As reported in CVE, such vulnerabilities have been found in various common-used software, including Google Chrome, Firefox and Adobe Flash Player, and have a trend of increase in recent years. The urgency of addressing type confusion problems quickens the pace of researchers coming to corresponding solutions. However, the existing works either handle the problem partially, or suffer from the high performance and memory overhead, especially to the large-scale projects. Chengbin Pang, Yunlan Du, Bing Mao 0001, Shanqing Guo |
ACSAC | 3 |
| 2018 | To Detect Stack Buffer Overflow with Polymorphic CanariesabstractStack Smashing Protection (SSP) is a simple and highly efficient technique widely used in practice as the front line defense against stack buffer overflow attacks. Unfortunately, SSP is known to be vulnerable to the so-called byte-by-byte attack. Although several remedy schemes are proposed in the recent literature, their security is achieved at the price of practicality, because their complex logics ruin SSP's simplicity and high-efficiency. In this paper, we present an elegant solution named as Polymorphic SSP (P-SSP) that attains the same security without sacrificing SSP's strengths. We also propose three extensions of the basic scheme for better compatibility, stronger security, and local variable protection, respectively. We have implemented both a compiler plugin and a binary instrumentation tool for deploying P-SSP. Their respective runtime overheads are only 0.24% and 1.01%. We have also experimented with our extensions and compared their pros and cons with the basic scheme. Xuhua Ding, Chengbin Pang, Bing Mao 0001 |
DSN | 6 |
| 2018 | DCQCN+: Taming Large-Scale Incast Congestion in RDMA over Ethernet NetworksabstractRemote Direct Memory Access (RDMA) gains growing popularity in datacenter networks. The state-of-the-art congestion control scheme is DCQCN. However, DCQCN has performance problems when large-scale incast communication happens. DCQCN uses fixed period and steps for rate increase when probing for available bandwidth and this scheme is not scalable. Our key insight is that: senders should be aware of the scale of each incast, so that they can adjust their aggressiveness accordingly. The challenges come from different aspects. The scale of congestion is not easy to estimate while the control scheme should be cautiously designed. In this paper, we propose DCQCN+ to improve performance for large-scale incast congestion in RDMA networks. DCQCN+ adapts the rate control mechanisms to different scenarios. DCQCN+ can deal with incast congestion of at least 2,000 flows both in simulation and testbed. The scale is 10 times larger than that of DCQCN in simulation and 4 times larger in testbed. DCQCN+ also has 10 times smaller latency. Yixiao Gao, Chen Tian 0001, Jiaqi Zheng 0001, Bing Mao 0001, Guihai Chen |
ICNP | 5 |
| 2018 | Vanguard: Detecting Missing Checks for Prognosing Potential VulnerabilitiesabstractIt is challenging to have a general solution to precisely detect arbitrary vulnerabilities. Thus security research has focused on detecting specific types of vulnerabilities. Missing checks for untrusted inputs used in security-sensitive operations are one of the major causes of various serious vulnerabilities. Efficiently detecting missing checks is essential for identifying insufficient attack protections and prognosing potential vulnerabilities. This paper proposes a systematic static approach to detect missing checks for manipulable data used in security-sensitive operations in C/C++ programs. We first locate customized security-sensitive operations with lightweight static analysis; then judge assailability of sensitive data used in security-sensitive operations via static taint analysis; finally, assess the existence and risk degree of missing checks using static analysis. We have implemented the approach into an automated and cross-platform tool, named Vanguard, on top of Clang/LLVM 3.6.0. Experimental results on open-source projects have shown its effectiveness and efficiency. Furthermore, Vanguard has led us to uncover five known vulnerabilities and two unknown bugs. Lingyun Situ, Linzhang Wang, Yang Liu 0003, Bing Mao 0001, Xuandong Li |
Internetware | 4 |
| 2018 | Understanding the Reproducibility of Crowd-reported Security Vulnerabilities
Dongliang Mu, Alejandro Cuevas, Hang Hu 0002, Xinyu Xing 0001, Bing Mao 0001, Gang Wang 0011 |
USENIX Security Symposium | 6 |
| 2017 | What You See is Not What You Get! Thwarting Just-in-Time ROP with ChameleonabstractAddress space randomization has long been used for counteracting code reuse attacks, ranging from conventional ROP to sophisticated Just-in-Time ROP. At the high level, it shuffles program code in memory and thus prevents malicious ROP payload from performing arbitrary operations. While effective in mitigating attacks, existing randomization mechanisms are impractical for real-world applications and systems, especially considering the significant performance overhead and potential program corruption incurred by their implementation. In this paper, we introduce CHAMELEON, a practical defense mechanism that hinders code reuse attacks, particularly Just-in-Time ROP attacks. Technically speaking, CHAMELEON instruments program code, randomly shuffles code page addresses and minimizes the attack surface exposed to adversaries. While this defense mechanism follows in the footprints of address space randomization, our design principle focuses on using randomization to obstruct code page disclosure, making the ensuing attacks infeasible. We implemented a prototype of CHAMELEON on Linux operating system and extensively experimented it in different settings. Our theoretical and empirical evaluation indicates the effectiveness and efficiency of CHAMELEON in thwarting Just-in-Time ROP attacks. Ping Chen 0003, Jun Xu 0024, Zhisheng Hu, Xinyu Xing 0001, Bing Mao 0001, Peng Liu 0005 |
DSN | 6 |
| 2017 | NIVAnalyzer: A Tool for Automatically Detecting and Verifying Next-Intent Vulnerabilities in Android AppsabstractIn the Android system design, any app can start another app's public components to facilitate code reuse by sending an asynchronous message called Intent. In addition, Android also allows an app to have private components that should only be visible to the app itself. However, malicious apps can bypass this system protection and directly invoke private components in vulnerable apps through a class of newly discovered vulnerability, which is called next-intent vulnerability. In this paper, we design an intent flow analysis strategy which accurately tracks the intent in smali code to statically detect next-intent vulnerabilities efficiently and effectively on a large scale. We further propose an automated approach to dynamically verify the discovered vulnerabilities by generating exploit apps. Then we implement a tool named NIVAnalyzer and evaluate it on 20,000 apps downloaded from Google Play. As the result, we successfully confirms 190 vulnerable apps, some of which even have millions of downloads. We also confirmed that an open-source project and a third-party SDK, which are still used by other apps, have next intent vulnerabilities. Xingmin Cui, Ziming Zhao 0001, Shanqing Guo, Xin-Shun Xu, Chengyu Hu 0001, Tao Ban, Bing Mao 0001 |
ICST | 8 |
| 2017 | ROPOB: Obfuscating Binary Code via Return Oriented Programming
Dongliang Mu, Wenbiao Ding, Bing Mao 0001, Lei Shi 0001 |
SecureComm | 5 |
| 2017 | DiffGuard: Obscuring Sensitive Information in Canary Based Protections
Weiping Zhou, Dongliang Mu, Bing Mao 0001 |
SecureComm | 5 |
| 2017 | Postmortem Program Analysis with Hardware-Enhanced Post-Crash Artifacts
Jun Xu 0024, Dongliang Mu, Xinyu Xing 0001, Peng Liu 0005, Ping Chen 0003, Bing Mao 0001 |
USENIX Security Symposium | 6 |
| 2016 | Data Flow Analysis on Android Platform with Fragment Lifecycle Modeling
Jinbin Ouyang, Shanqing Guo, Bing Mao 0001 |
SecureComm | 4 |
| 2015 | Replacement Attacks: Automatically Impeding Behavior-Based Malware Specifications
Jiang Ming 0002, Zhi Xin, Pengwei Lan, Dinghao Wu, Peng Liu 0005, Bing Mao 0001 |
ACNS | 6 |
| 2015 | A Practical Approach for Adaptive Data Structure Layout RandomizationabstractAttackers often corrupt data structures to compromise software systems. As a countermeasure, data structure layout randomization has been proposed. Unfortunately, existing techniques require manual designation of randomize-able data structures without guaranteeing the correctness and keep the layout unchanged at runtime. We present a system, called SALADS, that automatically translates a program to a DSSR (Data Structure Self-Randomizing) program. At runtime, a DSSR program dynamically randomizes the layout of each security-sensitive data structure by itself autonomously. DSSR programs regularly re-randomize a data structure when it has been accessed several times after last randomization. More importantly, DSSR programs automatically determine the randomizability of instances and randomize each instance independently. We have implemented SALADS based on gcc-4.5.0 and generated DSSR user-level applications, OS kernels, and hypervisors. Our experiments show that the DSSR programs can defeat a wide range of attacks with reasonable performance overhead. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Ping Chen 0003, Jun Xu 0024, Zhiqiang Lin 0001, Dongyan Xu, Bing Mao 0001, Peng Liu 0005 |
ESORICS (1) | 5 |
| 2015 | Detection, Classification and Characterization of Android Malware Using API Data Dependency
Xuerui Pan, Bing Mao 0001 |
SecureComm | 5 |
| 2015 | TextLogger: inferring longer inputs on touch screen using motion sensorsabstractToday's smartphones are equipped with precise motion sensors like accelerometer and gyroscope, which can measure tiny motion and rotation of devices. While they make mobile applications more functional, they also bring risks of leaking users' privacy. Researchers have found that tap locations on screen can be roughly inferred from motion data of the device. They mostly utilized this side-channel for inferring short input like PIN numbers and passwords, with repeated attempts to boost accuracy. In this work, we study further for longer input inference, such as chat record and e-mail content, anything a user ever typed on a soft keyboard. Since people increasingly rely on smartphones for daily activities, their inputs directly or indirectly expose privacy about them. Thus, it is a serious threat if their input text is leaked. Dan Ping, Bing Mao 0001 |
WISEC | 3 |
| 2014 | System Call Redirection: A Practical Approach to Meeting Real-World Virtual Machine Introspection NeedsabstractExisting VMI techniques have high overhead, and require customized introspection programs/tools for different guest OS versions - lack of generality. In this paper, we present Shadow Context, a system for close-to-real time manual-effort-free VMI. Shadow Context can meet several important real-world VMI needs which existing VMI techniques cannot. Compared to other automatic introspection tool generation techniques, Shadow Contexthas two merits: (1) Its overhead is significantly less. It achieves close-to-real time VMI. (2) It significantly improves the practical usefulness of introspection tools by allowing one introspection program to inspect a variety of guest OS versions. These merits are achieved via a new concept called "Shadow Context" which allows the guest OSessystem call code to be reused inside a "shadowed" portion of the context of the out-of-guest inspection program. Besides, Shadow Context is secure enough to defend against a variety of real world attacks. Shadow Context is designed, implemented and systematically evaluated. Experimental results show that the performance overhead is about 75%with a median initialization time of 0.117 milliseconds. Ping Chen 0003, Peng Liu 0005, Bing Mao 0001 |
DSN | 4 |
| 2014 | Detecting Code Reuse in Android Applications Using Component-Based Control Flow Graph
Yibing Zhongyang, Zhi Xin, Bing Mao 0001, Li Xie 0001 |
SEC | 4 |
| 2014 | Defensor: Lightweight and Efficient Security-Enhanced Framework for AndroidabstractRecently the market of Android has shown an explosive development. Unfortunately the increasing popularity turns the Android platform into the main target of malware. At the same time, the limited security protection built-in Android makes the situation much worse. In this paper, we present a new framework named Defensor which takes the practicability and effectiveness into consideration. The core part of Defensor is built in Linux kernel, which results in a small size of TCB. Defensor is a system-wide lightweight inspecting framework. It can closely monitor the malicious behaviors within and across applications, such as sending SMS to premium rate numbers, stealing privacy from the compromised device and getting root privileges through root exploits. This type of monitor is mandatory. Any application installed on the phone and any component including malicious native code can't bypass it. Defensor can not only rebuild the high level behaviors from system calls, but also extract the context information that the behavior runs in. Context-based information likes background and foreground contributes a lot to the accuracy of malware detection. We have tested Defensor on real malware to prove its effectiveness. Finally, an experimental evaluation showing that the overhead introduced by Defensor is limited. Xuerui Pan, Yibing Zhongyang, Zhi Xin, Bing Mao 0001 |
TrustCom | 4 |
| 2014 | Detect Android Malware Variants Using Component Based Topology GraphabstractSmartphone has experienced explosive growth recently. At present, Android system is the most popular mobile platform and attracts lots of developers as well as malware authors. In order to evade detection, malware authors often apply obfuscation techniques to morph malware. Since traditional malware detectors are based on pure syntax, they may fail to detect obfuscated malware variants. We present a novel signature, topology graph based on Android components, which could model malicious payloads properly and resist against common obfuscation used by hackers. We performe stress test on security tools provided by Virus total with ten kinds of malware families from Android Malware Genome Project. Unfortunately, the result is not optimistic that obfuscated malware samples evade most of security tools. Nevertheless, 86.36% of obfuscated malware samples we tested are caught by our detector with tolerable false positive. The evaluation demonstrates that our approach is able to detect malware variants generated by common obfuscation techniques. Yibing Zhongyang, Zhi Xin, Bing Mao 0001 |
TrustCom | 4 |
| 2013 | DroidAlarm: an all-sided static analysis tool for Android privilege-escalation malwareabstractSince smartphones have stored diverse sensitive privacy information, including credit card and so on, a great deal of malware are desired to tamper them. As one of the most prevalent platforms, Android contains sensitive resources that can only be accessed via corresponding APIs, and the APIs can be invoked only when user has authorized permissions in the Android permission model. However, a novel threat called privilege escalation attack may bypass this watchdog. It's presented as that an application with less permissions can access sensitive resources through public interfaces of a more privileged application, which is especially useful for malware to hide sensitive functions by dispersing them into multiple programs. We explore privilege-escalation malware evolution techniques on samples from Android Malware Genome Project. And they have showed great effectiveness against a set of powerful antivirus tools provided by VirusTotal. The detection ratios present different and distinguished reduction, compared to an average 61% detection ratio before transformation. In order to conquer this threat model, we have developed a tool called DroidAlarm to conduct a full-spectrum analysis for identifying potential capability leaks and present concrete capability leak paths by static analysis on Android applications. And we can still alarm all these cases by exposing capability leak paths in them. Yibing Zhongyang, Zhi Xin, Bing Mao 0001, Li Xie 0001 |
AsiaCCS | 3 |
| 2013 | JITSafe: a framework against Just-in-time spraying attacksabstractA new code‐reuse attack, named Just‐in‐time (JIT) spraying attack, leverages the predictable generated JIT compiled code to launch an attack. It can circumvent the defenses such as data execution prevention and address space layout randomisation built‐in in the modern operation system, which were thought the insurmountable barrier so that the attackers cannot construct the traditional code injection attacks. In this study, the authors describe JITSafe, a framework that can be applied to existing JIT‐based virtual machines (VMs), in the purpose of preventing the attacker from reusing the JIT compiled code to construct the attack. The authors framework narrows the time window of the JIT compiled code in the executable pages, eliminates the immediate value and obfuscates the JIT compiled code. They demonstrate the effectiveness of JITSafe that it can successfully prevent existing JIT spraying attacks with low performance overhead. Ping Chen 0003, Bing Mao 0001 |
IET Inf. Secur. | 3 |
| 2012 | RIM: A Method to Defend from JIT Spraying AttackabstractAs a code reuse technique, JIT spraying attack becomes popular on the JITed VM (Virtual Machine) (e.g., Javascript Engine, Flash Engine). Using a bug in web applications, an attacker can reuse the code generated by the JIT (Just-In-Time) compiler, which is used to optimize the performance of web applications. JIT spraying attacks can circumvent DEP and ASLR -- protection mechanisms of modern operating systems. Based on the observation that JIT spraying attack mostly uses the immediate operand of the arithmetic instruction to build a shellcode, we propose RIM, a technique that obfuscates the arithmetic operations in the JITed code and prevents attackers from reusing the native code to construct a malicious code. We implement a prototype on Tamarin flash engine and demonstrate the effectiveness of RIM. Experimental results show that RIM's overhead is very low (less than 1%). And RIM greatly improves the security functionality of JIT compilers. Ping Chen 0003, Bing Mao 0001, Li Xie 0001 |
ARES | 3 |
| 2012 | CloudER: a framework for automatic software vulnerability location and patching in the cloudabstractIn a virtualization-based cloud infrastructure, customers of the cloud deploy virtual machines (VMs) with their own applications and customized runtime environments. The cloud provider supports the execution of these VMs without detailed knowledge of the guest applications and operating systems in the VMs. In addition to elastic resource provisioning for the VMs, a desirable "value-added" service the cloud provider can provide is the emergency response to runtime incidences of software bugs and vulnerabilities. The challenge is to facilitate the automatic runtime detection, location, and patching of the software vulnerability -- outside the VMs and without the source code. In this paper, we present CloudER, a cloud "emergency room" architecture that automatically detect, locate, and patch software vulnerabilities in cloud application binaries at runtime. CloudER leverages an existing taint-based system (Demand Emulation) for runtime anomaly detection, employs new algorithms for software vulnerability location and patch generation, and adapts a virtual machine introspection system (XenAccess) for dynamic patching. Our preliminary evaluation experiments with a number of real-world server applications show that CloudER achieves timely response to runtime software faults or attacks from outside the VMs. The main contributions of this paper are highlighted as follows: (1) CloudER is an integrated architecture that improves the runtime reliability of cloud applications. It covers the full life cycle of exploit detection, culprit instruction location, patch generation and application, and execution state recording and reset -- all performed from outside the protected VM and without the source code of the applications. (2) While leveraging existing techniques for taint-based exploit detection, CloudER involves new methods for culprit instruction location and binary patch generation. The methods cover some of the most common types of software vulnerabilities and the patches generated are of small size (tens of bytes). (3) CloudER incurs reasonable performance overhead to the application in comparison with running the application in an unprotected VM. The interruption to the production VM's execution (for culprit instruction location and patch generation) is less than half a minute in our experiments with real-world applications. Ping Chen 0003, Dongyan Xu, Bing Mao 0001 |
AsiaCCS | 3 |
| 2012 | RandHyp: Preventing Attacks via Xen Hypercall Interface
Ping Chen 0003, Bing Mao 0001, Li Xie 0001 |
SEC | 3 |
| 2011 | Automatic construction of jump-oriented programming shellcode (on the x86)abstractReturn-Oriented Programming (ROP) is a technique which leverages the instruction gadgets in existing libraries/executables to construct Turing complete programs. However, ROP attack is usually composed with gadgets which are ending in ret instruction without the corresponding call instruction. Based on this fact, several defense mechanisms have been proposed to detect the ROP malicious code. To circumvent these defenses, Return-Oriented Programming without returns has been proposed recently, which uses the gadgets ending in jmp instruction but with much diversity. In this paper, we propose an improved ROP techniques to construct the ROP shellcode without returns. Meanwhile we implement a tool to automatically construct the real-world Return-Oriented Programming without returns shellcode, which as demonstrated in our experiment can bypass most of the existing ROP defenses. Ping Chen 0003, Xiao Xing, Bing Mao 0001, Li Xie 0001, Xiaobin Shen 0001, Xinchun Yin |
AsiaCCS | 3 |
| 2011 | Replacement Attacks on Behavior Based Software Birthmark
Zhi Xin, Huiyu Chen, Xinche Wang, Peng Liu 0005, Sencun Zhu, Bing Mao 0001, Li Xie 0001 |
ISC | 6 |
| 2011 | JITDefender: A Defense against JIT Spraying Attacks
Ping Chen 0003, Bing Mao 0001, Li Xie 0001 |
SEC | 3 |
| 2010 | Return-Oriented Rootkit without Returns (on the x86)
Ping Chen 0003, Xiao Xing, Bing Mao 0001, Li Xie 0001 |
ICICS | 3 |
| 2010 | Misleading Malware Similarities Analysis by Automatic Data Structure Obfuscation
Zhi Xin, Huiyu Chen, Bing Mao 0001, Li Xie 0001 |
ISC | 4 |
| 2009 | BRICK: A Binary Tool for Run-Time Detecting and Locating Integer-Based VulnerabilityabstractInteger-based vulnerability is an extremely serious bug for programs written in languages such as C/C++. However,in practice, very few software security tools can efficiently detect and accurately locate such vulnerability. In addition, previous methods mainly depend on source code analysis and recompilation which are impractical when protecting the program without source code. In this paper,we present the design, implementation, and evaluation of BRICK (binary run-time integer-based vulnerability checker), a tool for run-time detecting and locating integer-based vulnerability. Given an integer-based vulnerability exploit, BRICK is able to catch the value which falls out of the range of its corresponding type, then find the root cause for this vulnerability, and finally locate the vulnerability code and give a warning, based on its checking scheme. BRICK is implemented on the dynamic binary instrumentation framework Valgrind and its type inference plug-in: Catchconv. Preliminary experimental results are quit promising: BRICK can detect and locate most of integer-based vulnerability in real software, and has very low false positives and negatives. Ping Chen 0003, Zhi Xin, Bing Mao 0001, Li Xie 0001 |
ARES | 4 |
| 2009 | Traffic Controller: A Practical Approach to Block Network Covert Timing ChannelabstractThis paper discusses the network covert timing channel. This channel modulates network packet's time properties to transfer information secretly. Much work has been done in inventing and utilizing network covert timing channels, however, there is not so much work in other areas such as detecting and handling covert channels. Covert channel detection is difficult, what's more, it often needs human analysis to confirm whether a suspect is a real covert channel. However, we figured out that we can try to control covert channels without knowing whether there are covert channels in using, which means our approach does not rely on the detection of covert channels at all. A network traffic controller is proposed to undermine the network covert timing channel communication mechanism. We will show how our method works and why our traffic control strategy is especially efficient to handle network covert timing channels. Ping Chen 0003, Yi Ge, Bing Mao 0001, Li Xie 0001 |
ARES | 4 |
| 2009 | IntFinder: Automatically Detecting Integer Bugs in x86 Binary Program
Ping Chen 0003, Xiaobin Shen 0001, Xinchun Yin, Bing Mao 0001, Li Xie 0001 |
ICICS | 6 |
| 2006 | A Practical Framework for Dynamically Immunizing Software Security VulnerabilitiesabstractMany security attacks are caused by software vulnerabilities such as buffer overflow. How to eliminate or mitigate these vulnerabilities, in particular with unstoppable software, is a great challenge for security researchers and practitioners. In this paper, we propose a practical framework to immunize software security vulnerabilities on the fly. We achieve the vulnerability immunization by using a security antibody, which can be implemented independently from the protected software and is used to defend against vulnerability exploitation attacks. And we employ in-core patching technique to attach the antibody quietly into running process, and hence we neither need to re-compile nor re-execute the protected software. The effectiveness of our framework depends on the effectiveness of the antibody that is implemented by redirecting flaw functions into secure ones. As a proof of concept, we have built a prototype and applied it to prevent the software from buffer overflow attacks. Preliminary experimental results show that our framework is practical and efficient for the dynamical immunization of software security vulnerabilities. Zhiqiang Lin 0001, Bing Mao 0001, Li Xie 0001 |
ARES | 2 |
| 2006 | Transparent Run-Time Prevention of Format-String Attacks Via Dynamic Taint and Flexible Validation
Zhiqiang Lin 0001, Nai Xia, Guole Li, Bing Mao 0001, Li Xie 0001 |
ISC | 4 |
| 2004 | The design and implementation of a runtime system for graph-oriented parallel and distributed programming
Jiannong Cao 0001, Ying Liu 0007, Li Xie 0001, Bing Mao 0001, Kang Zhang 0001 |
J. Syst. Softw. | 4 |