EDBT 2026 Demo / reviewers in the wild / expert
Yong Tang 0005
dblp:01/2880-5
· DBLP profile ↗
12ranked-venue papers
1as first author
3since 2021 · last 2023
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2Computer networks · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | VulHawk: Cross-architecture Vulnerability Detection with Entropy-based Binary Code Search
Zhenhao Luo, Pengfei Wang 0010, Yong Tang 0005, Wei Xie 0007, Xu Zhou 0004, Danjun Liu, Kai Lu 0001 |
NDSS | 4 |
| 2021 | XHunter: Understanding XXE Vulnerability via Automatic Analysis
Wei Xie 0007, Yong Tang 0005, Enze Wang |
SecureComm (2) | 4 |
| 2021 | HashMTI: Scalable Mutation-based Taint Inference with Hash RecordsabstractMutation-based taint inference (MTI) is a novel technique for taint analysis. Compared with traditional techniques that track propagations of taint tags, MTI infers a variable is tainted if its values change due to input mutations, which is lightweight and conceptually sound. However, there are 3 challenges to its efficiency and scalability: (1) it cannot efficiently record variable values to monitor their changes; (2) it consumes a large amount of memory monitoring variable values, especially on complex programs; and (3) its excessive memory overhead leads to a low hit ratio of CPU cache, which slows down the speed of taint inference. This paper presents an efficient and scalable solution named HashMTI. We first explain the above challenges based on 4 observations. Motivated by these challenges, we propose a hash record scheme to efficiently monitor changes in variable values and significantly reduce the memory overhead. The scheme is based on our specially selected and optimized hash functions that possess 3 crucial properties. Moreover, we propose the DoubleMutation strategy, which applies additional mutations to mitigate the limitation of the hash record and detect more taint information. We implemented a prototype of HashMTI and evaluated it on 18 real-world programs and 4 LAVA-M programs. Compared with the baseline OrigMTI, HashMTI significantly reduces the overhead while having similar accuracy. It achieves a speedup of 2.5X to 23.5X and consumes little memory which is on average 70.4 times less than that of OrigMTI. Yong Tang 0005, Pengfei Wang 0010, Shuning Wei, Tai Yue |
SANER | 2 |
| 2020 | EcoFuzz: Adaptive Energy-Saving Greybox Fuzzing as a Variant of the Adversarial Multi-Armed Bandit
Tai Yue, Pengfei Wang 0010, Yong Tang 0005, Enze Wang, Bo Yu 0008, Kai Lu 0001, Xu Zhou 0004 |
USENIX Security Symposium | 3 |
| 2019 | Poster: Fuzzing IoT Firmware via Multi-stage Message GenerationabstractIn this work, we present IoTHunter, the first grey-box fuzzer for fuzzing stateful protocols in IoT firmware. IoTHunter addresses the state scheduling problem based on a multi-stage message generation mechanism on runtime monitoring of IoT firmware. We evaluate IoTHunter with a set of real-world programs, and the result shows that IoTHunter outperforms black-box fuzzer boofuzz, which has a 2.2x, 2.0x, and 2.5x increase for function coverage, block coverage, and edge coverage, respectively. IoTHunter also found five new vulnerabilities in the firmware of home router Mikrotik, which have been reported to the vendor. Bo Yu 0008, Pengfei Wang 0010, Tai Yue, Yong Tang 0005 |
CCS | 4 |
| 2019 | Toward efficient and accurate function-call graph matching of binary codesabstractSummary Reverse engineering, software plagiarism detection, and malware analysis have always been important issues in software and security fields. For a binary code, the function‐call graph (FCG) reflects its capability, structure, and intrinsic relations, which motivates us to study FCG matching and its applications in those problems systematically. In this work, we propose an FCG matching algorithm based on Hungarian algorithm that solves the maximum weight matching problem in polynomial time and makes matching between graphs of large scale possible. Also, optimizations including node pairs pruning and forward matching are proposed to improve the efficiency and accuracy of FCG matching algorithm. Finally, a series of experiments are conducted to show that FCG matching is an effective method and has huge application potentiality in software and security analysis. DongXing Huang, Yong Tang 0005, Yi Wang 0036, Shuning Wei |
Concurr. Comput. Pract. Exp. | 2 |
| 2018 | Automated Vulnerability Detection in Embedded Devices
Danjun Liu, Yong Tang 0005, Wei Xie 0007, Bo Yu 0008 |
IFIP Int. Conf. Digital Forensics | 2 |
| 2018 | A survey of malware behavior description and analysisabstractBehavior-based malware analysis is an important technique for automatically analyzing and detecting malware, and it has received considerable attention from both academic and industrial communities. By considering how malware behaves, we can tackle the malware obfuscation problem, which cannot be processed by traditional static analysis approaches, and we can also derive the as-built behavior specifications and cover the entire behavior space of the malware samples. Although there have been several works focusing on malware behavior analysis, such research is far from mature, and no overviews have been put forward to date to investigate current developments and challenges. In this paper, we conduct a survey on malware behavior description and analysis considering three aspects: malware behavior description, behavior analysis methods, and visualization techniques. First, existing behavior data types and emerging techniques for malware behavior description are explored, especially the goals, principles, characteristics, and classifications of behavior analysis techniques proposed in the existing approaches. Second, the inadequacies and challenges in malware behavior analysis are summarized from different perspectives. Finally, several possible directions are discussed for future research. Bo Yu 0008, Yong Tang 0005, Liu Liu 0004 |
Frontiers Inf. Technol. Electron. Eng. | 4 |
| 2017 | A New Malware Classification Approach Based on Malware Dynamic Analysis
Bo Yu 0008, Yong Tang 0005, Liu Liu 0004, Yi Wang 0036 |
ACISP (2) | 3 |
| 2017 | Deja Q Encore RIBE: Anonymous Revocable Identity-Based Encryption with Short ParametersabstractRevocable Identity-Based Encryption (RIBE) allows feasible key revoke to enable dynamic user management in certificateless system. The existing RIBE schemes fail to keep receivers anonymity, or short parameters, or adaptive security. Hence, we overcome the drawbacks of previous schemes and contribute to an Anonymous RIBE (ARIBE) scheme with two advantages: (1) the provable full security under the adaptive-ID attack in the standard model and (2) the sufficient efficiency in optimal parameters-the secret subkey and the update subkey are one group element each and decryption only requires two pairings. To our best knowledge, our construction is the first IBE scheme that simultaneously achieves efficient revocability, anonymity and full security in the exponent-inversion IBE family. Qianqian Xing, Xiaofeng Wang 0002, Yong Tang 0005, Yi Wang 0055 |
GLOBECOM | 4 |
| 2017 | Vulnerability Detection in IoT Firmware: A SurveyabstractWith the development of Internet of Things(IoT), more and more smart devices are connected into the Internet. The security and privacy issues of IoT devices have received increasingly academic and industrial attentions. Vulnerability detection is the key technology to protect IoT devices from zero-day attacks. However, traditional methods and tools of vulnerability detection cannot be directly used in analyzing IoT firmware. This paper firstly reviews related works on vulnerability detection in IoT firmware, previous researches are classified into four types i.e. static analysis, symbolic execution, fuzzing on emulators and comprehensive testing. Then, this paper points out that the specificity of vulnerability detection in IoT firmware is to detect logical flaws in embedded binaries which are built on the MIPS architecture. Finally, this paper proposes a method based on fuzzing and static analysis to detect authentication bypass flaws in IoT embedded binary servers. The proposed method is proved to be effective by verifying known CVEs as well as discovering unknown ones. Wei Xie 0007, Yikun Jiang, Yong Tang 0005, Yuanming Gao |
ICPADS | 3 |
| 2017 | Matching Function-Call Graph of Binary Codes and Its Applications (Short Paper)
Yong Tang 0005, Yi Wang 0036, Shuning Wei, Bo Yu 0008 |
ISPEC | 1 |