EDBT 2026 Demo / reviewers in the wild / expert
Zhiyong Shan
dblp:02/4241
· DBLP profile ↗
13ranked-venue papers
9as first author
2since 2021 · last 2022
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 first-author · 1 since 2021Systems, architecture and hardware · 3 · 2 first-authorSoftware engineering, systems software and programming languages · 3 · 2 first-author · 1 since 2021Computer networks · 2 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
6 papers |
Web and mobile security · 49% Malware analysis · 32% Systems and software security · 12% | |
| Software engineering, system software, and programming languages
4 papers |
Operating systems · 42% Program analysis · 19% Debugging and program repair · 19% | |
| Computer architecture, parallel and distributed computing, and storage systems
2 papers |
Cloud and datacenter computing · 49% Hardware reliability and fault tolerance · 36% Distributed systems · 9% |
Topics — the 21 heaviest of 24, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Web and mobile security
mobile application security |
0.6 | 1 | 2022 | Scraping Sticky Leftovers: App User Information Left on Servers After Account Deletion · SP 2022 |
Cloud and datacenter computing
virtualization |
0.4 | 2 | 2015 | FTXen: Making hypervisor resilient to hardware faults on relaxed cores · HPCA 2015 Shuttle: Facilitating Inter-Application Interactions for OS-Level Virtualization · IEEE Trans. Computers 2014 |
Web and mobile security
mobile security |
0.4 | 1 | 2019 | Device Administrator Use and Abuse in Android: Detection and Characterization · MobiCom 2019 |
Malware analysis › mobile malware detection
android malware detection |
0.3 | 1 | 2018 | Self-hiding behavior in Android apps: detection and characterization · ICSE 2018 |
Web and mobile security › mobile application security
mobile app analysis |
0.3 | 1 | 2018 | Self-hiding behavior in Android apps: detection and characterization · ICSE 2018 |
Debugging and program repair
fault localization |
0.2 | 1 | 2016 | Finding resume and restart errors in Android applications · OOPSLA 2016 |
Program analysis
static analysis |
0.2 | 1 | 2016 | Finding resume and restart errors in Android applications · OOPSLA 2016 |
Software testing
test generation |
0.2 | 1 | 2016 | Finding resume and restart errors in Android applications · OOPSLA 2016 |
Malware analysis › malware detection
behavior-based malware detection |
0.2 | 2 | 2014 | Growing Grapes in Your Computer to Defend Against Malware · IEEE Trans. Inf. Forensics Secur. 2014 Malware Clearance for Secure Commitment of OS-Level Virtual Machines · IEEE Trans. Dependable Secur. Comput. 2013 |
Hardware reliability and fault tolerance › software fault tolerance
hypervisor-based fault tolerance |
0.2 | 1 | 2015 | FTXen: Making hypervisor resilient to hardware faults on relaxed cores · HPCA 2015 |
Hardware reliability and fault tolerance › soft errors
soft error resilience |
0.2 | 1 | 2015 | FTXen: Making hypervisor resilient to hardware faults on relaxed cores · HPCA 2015 |
Operating systems › system security › operating system security › protection mechanism
isolation |
0.2 | 1 | 2014 | Shuttle: Facilitating Inter-Application Interactions for OS-Level Virtualization · IEEE Trans. Computers 2014 |
Operating systems
virtualization |
0.2 | 1 | 2014 | Shuttle: Facilitating Inter-Application Interactions for OS-Level Virtualization · IEEE Trans. Computers 2014 |
Cloud and datacenter computing › virtualization
containerization |
0.2 | 1 | 2014 | Shuttle: Facilitating Inter-Application Interactions for OS-Level Virtualization · IEEE Trans. Computers 2014 |
Operating systems › virtualization
OS-level virtualization |
0.2 | 1 | 2013 | Malware Clearance for Secure Commitment of OS-Level Virtual Machines · IEEE Trans. Dependable Secur. Comput. 2013 |
Malware analysis
malware behavior analysis |
0.1 | 1 | 2012 | Enforcing Mandatory Access Control in Commodity OS to Disable Malware · IEEE Trans. Dependable Secur. Comput. 2012 |
Cryptographic primitives and cryptanalysis
message authentication codes |
0.1 | 1 | 2012 | Enforcing Mandatory Access Control in Commodity OS to Disable Malware · IEEE Trans. Dependable Secur. Comput. 2012 |
Systems and software security
operating system security |
0.1 | 1 | 2012 | Enforcing Mandatory Access Control in Commodity OS to Disable Malware · IEEE Trans. Dependable Secur. Comput. 2012 |
Distributed systems
fault tolerance |
0.1 | 1 | 2014 | Shuttle: Facilitating Inter-Application Interactions for OS-Level Virtualization · IEEE Trans. Computers 2014 |
Distributed systems › fault tolerance
intrusion tolerance |
0.1 | 1 | 2014 | Shuttle: Facilitating Inter-Application Interactions for OS-Level Virtualization · IEEE Trans. Computers 2014 |
Network security › intrusion detection and prevention
intrusion detection |
0.0 | 1 | 2013 | Malware Clearance for Secure Commitment of OS-Level Virtual Machines · IEEE Trans. Dependable Secur. Comput. 2013 |
Methods — techniques the papers use, named apart from their topics
static analysis · 2.1dynamic analysis · 1.5reverse engineering · 1.1natural language processing · 1.1clustering · 0.5information flow analysis · 0.3behavior-based detection · 0.3input generation · 0.2fault injection · 0.2combinatorial optimization · 0.2security label configuration · 0.1intrusion detection · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Automated Testing to Detect Status Data Loss in Android ApplicationsabstractWhen user installs an Android app, it is expected that the data should be persistent at all states, which requires saving the instance data for all the activities. An app can be paused or sent to the background due to other interruptions or user intervention. It is difficult for the programmer to test this issue for all the activities. This results the issue of data loss, the information/details entered by user in the app are not saved when there is any interruption. This results in degrading the user experience because user should enter the information each time there is an interruption. This research proposes a tool, DroidDLP, a Data Loss Preventor in Android, which will detect the information loss from a given android application. We have tested 395 applications and found 12 applications with the issue of data loss. This approach is proved highly accurate and reliable to find the apps with this defect, which can be used by android developers to avoid such errors. Anusha Konduru, Zhiyong Shan |
SERA | 2 |
| 2022 | Scraping Sticky Leftovers: App User Information Left on Servers After Account DeletionabstractSixty-five percent of mobile apps require user accounts for offering full-fledged functionality. Account information includes private data, e.g., address, phone number, credit card. Our concern is “leftover” account data kept on the server after account deletion, which can be a significant privacy violation. Specifically, we analyzed 1,435 popular apps from Google Play (and 771 associated websites), of which 678 have their own sign-up process, to answer questions such as: Can accounts be deleted at all? Following account deletion, will user data remain on the app’s servers? If so, for how long? Do apps keep their promise to remove data? Answering these questions, and more generally, understanding and tackling the leftover account problem, is challenging. A fundamental obstacle is that leftover data is manipulated and retained in a private space, on the app’s backend servers; we devised a novel, reverse-engineering approach to infer leftover data from app–server communication. Another obstacle is the distributed nature of this data: program analysis as well as information retrieval are required on both the app and its website. We have developed an end-to-end solution (static analysis, dynamic analysis, natural language processing) to the leftover account problem. First, our toolchain checks whether an app, or its website, support account deletion; next, it checks whether the app/website have a data retention policy, and whether the account is left on servers after deletion, or after the specified retention period; finally, it automatically cleans up leftover accounts. We found that 64.45% of apps do not offer any means for users to delete accounts; 2.5% of apps still keep account data on app servers even after accounts are deleted by users. Only 5% of apps specify a retention period; some of these apps violate their own policy by still retaining data months after the period has ended. Experiments show that our approach is effective, with an F-measure $\gt 88$%, and efficient, with a typical analysis time of 279 seconds per app/website. Preethi Santhanam, Hoang Dang, Zhiyong Shan, Iulian Neamtiu |
SP | 3 |
| 2019 | Device Administrator Use and Abuse in Android: Detection and CharacterizationabstractDevice Administrator (DA) capabilities for mobile devices, e.g., remote locking/wiping, or enforcing password strength, were originally introduced to help organizations manage phone fleets or enable parental control. However, DA capabilities have been subverted and abused: malicious apps have used DA to create ransomware or lock users out, while benign apps have used DA to prevent or hinder uninstallation; in certain cases the only remedy is to factory-reset the phone. We call these apps "Deathless Device Administrator" (DDA), i.e., apps that cannot be uninstalled. We provide the first systematic study of Android DA capabilities, DDA apps, DDA-attack resistance across Android versions, and DDA-induced families in malicious apps. To enable scalable studies of questionable DA behavior, we developed DAAX, a static analyzer which exposes potential DA abuse effectively and efficiently. In a corpus of 39,459 apps (20,467 malicious and 18,992 benign) DAAX has found 4,135 DA apps and 691 potential DDA apps. The static analysis results on the 4,135 apps were cross-checked via dynamic analysis on at least 3 phones, confirming 578 true DDAs, including apps currently on Google Play. The study has shown that DAAX is effective (84.8% F-measure) and efficient (analysis typically takes 205 seconds per app). Zhiyong Shan, Raina Samuel, Iulian Neamtiu |
MobiCom | 1 |
| 2018 | Self-hiding behavior in Android apps: detection and characterizationabstractApplications (apps) that conceal their activities are fundamentally deceptive; app marketplaces and end-users should treat such apps as suspicious. However, due to its nature and intent, activity concealing is not disclosed up-front, which puts users at risk. In this paper, we focus on characterization and detection of such techniques, e.g., hiding the app or removing traces, which we call "self hiding behavior" (SHB). SHB has not been studied per se - rather it has been reported on only as a byproduct of malware investigations. We address this gap via a study and suite of static analyses targeted at SH in Android apps. Specifically, we present (1) a detailed characterization of SHB, (2) a suite of static analyses to detect such behavior, and (3) a set of detectors that employ SHB to distinguish between benign and malicious apps. We show that SHB ranges from hiding the app's presence or activity to covering an app's traces, e.g., by blocking phone calls/text messages or removing calls and messages from logs. Using our static analysis tools on a large dataset of 9,452 Android apps (benign as well as malicious) we expose the frequency of 12 such SH behaviors. Our approach is effective: it has revealed that malicious apps employ 1.5 SHBs per app on average. Surprisingly, SH behavior is also employed by legitimate ("benign") apps, which can affect users negatively in multiple ways. When using our approach for separating malicious from benign apps, our approach has high precision and recall (combined F-measure = 87.19%). Our approach is also efficient, with analysis typically taking just 37 seconds per app. We believe that our findings and analysis tool are beneficial to both app marketplaces and end-users. Zhiyong Shan, Iulian Neamtiu, Raina Samuel |
ICSE | 1 |
| 2016 | Finding resume and restart errors in Android applicationsabstractSmartphone apps create and handle a large variety of ``instance'' data that has to persist across runs, such as the current navigation route, workout results, antivirus settings, or game state. Due to the nature of the smartphone platform, an app can be paused, sent into background, or killed at any time. If the instance data is not saved and restored between runs, in addition to data loss, partially-saved or corrupted data can crash the app upon resume or restart. While smartphone platforms offer API support for data-saving and data-retrieving operations, the use of this API is ad-hoc: left to the programmer, rather than enforced by the compiler. We have observed that several categories of bugs---including data loss, failure to resume/restart or resuming/restarting in the wrong state---are due to incorrect handling of instance data and are easily triggered by just pressing the `Home' or `Back' buttons. To help address this problem, we have constructed a tool chain for Android (the KREfinder static analysis and the KREreproducer input generator) that helps find and reproduce such incorrect handling. We have evaluated our approach by running the static analysis on 324 apps, of which 49 were further analyzed manually. Results indicate that our approach is (i) effective, as it has discovered 49 bugs, including in popular Android apps, and (ii) efficient, completing on average in 61 seconds per app. More generally, our approach helps determine whether an app saves too much or too little state. Zhiyong Shan, Tanzirul Azim, Iulian Neamtiu |
OOPSLA | 1 |
| 2015 | FTXen: Making hypervisor resilient to hardware faults on relaxed coresabstractAs CMOS technology scales, the Increasingly smaller transistor components are susceptible to a variety of in-field hardware errors. Traditional redundancy techniques to deal with the increasing error rates are expensive and energy inefficient. To address this emerging challenge, many researchers have recently proposed the idea of relaxed hardware design and exposing errors to software. For such relaxed hardware to become a reality, it is crucially important for system software, such as the virtual machine hypervisor, to be resilient to hardware faults. To address the above fundamental software challenge in enabling relaxed hardware design, we are making a major effort in restructuring an important part of system software, namely the virtual machine hypervisor, to be resilient to faulty cores. A fault in a relaxed core can only affect those virtual machines (and applications) running on that core, but the hypervisor and other virtual machines remain intact and continue providing services. We have redesigned every component of Xen, a large, popular virtual machine hypervisor, to achieve such error resiliency. This paper presents our design and implementation of the restructured Xen (we refer to it as FTXen). Our experimental evaluation on real systems shows that FTXen adds minimum application overhead, and scales well to different ratios of reliable and relaxed cores. Our results with random fault injection show that FTXen can successfully survive all injected hardware faults. Xinxin Jin, Tianwei Sheng, Rishan Chen, Zhiyong Shan, Yuanyuan Zhou 0001 |
HPCA | 5 |
| 2014 | Shuttle: Facilitating Inter-Application Interactions for OS-Level VirtualizationabstractOS-level virtualization generates a minimal start-up and run-time overhead on the host OS and thus suits applications that require both good isolation and high efficiency. However, multiple-member applications required for forming a system may need to occasionally communicate across this isolation barrier to cooperate with each other while they are separated in different VMs to isolate intrusion or fault. Such application scenarios are often critical to enterprise-class servers, HPC clusters and intrusion/fault-tolerant systems, etc. We make the first effort to support the inter-application interactions in an OS-level virtualization system without causing a significant compromise on VM isolation. We identify all interactive operations that impact inter-application interactions, including inter-process communications, application invocations, resource name transfers, and application dependencies. We propose Shuttle, a novel approach for facilitating inter-application interactions within and across OS-level virtual machines. Our results demonstrate that Shuttle can correctly address all necessary inter-application interactions while providing good isolation capability for all sample applications on different versions of Windows OS. Zhiyong Shan, Xin Wang 0001, Tzi-cker Chiueh |
IEEE Trans. Computers | 1 |
| 2014 | Growing Grapes in Your Computer to Defend Against MalwareabstractBehavior-based detection is promising to resolve the pressing security problem of malware. However, the great challenge lies in how to detect malware in a both accurate and light-weight manner. In this paper, we propose a novel behavior-based detection method, named growing grapes, aiming to enable accurate online detection. It consists of a clustering engine and detection engine. The clustering engine groups the objects, e.g., processes and files, of a suspicious program together into a cluster, just like growing grapes. The detection engine recognizes the cluster as malicious if the behaviors of the cluster match a predefined behavior template formed by a set of discrete behaviors. The approach is accurate since it identifies a malware based on multiple behaviors and the source of the processes requesting the behaviors. The approach is also light-weight as it uses OS-level information flows instead of data flows that generally impose significant performance impact on the system. To further improve the performance, a novel method of organizing the behavior template and template database is proposed, which not only makes the template matching process very quick, but also makes the storage space small and fixed. Furthermore, the detection accuracy and performance are optimized to the best degree using a combinatorial optimization algorithm, which properly selects and combines multiple behaviors to form a template for malware detection. Finally, the approach novelly identifies malicious OS objects in a cluster fashion rather than one by one as done in traditional methods, which help users to thoroughly eliminate the changes of a malware without malware family knowledge. Compared with commercial antimalware tools, extensive experiments show that our approach can detect new malware samples with higher detection rate and lower false positive rate while imposing low overhead on the system. Zhiyong Shan, Xin Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2013 | Malware Clearance for Secure Commitment of OS-Level Virtual MachinesabstractA virtual machine(VM) can be simply created upon use and disposed upon the completion of the tasks or the detection of error. The disadvantage of this approach is that if there is no malicious activity, the user has to redo all of the work in her actual workspace since there is no easy way to commit (i.e., merge) only the benign updates within the VM back to the host environment. In this work, we develop a VM commitment system called Secom to automatically eliminate malicious state changes when merging the contents of an OS-level VM to the host. Secom consists of three steps: grouping state changes into clusters, distinguishing between benign and malicious clusters, and committing benign clusters. Secom has three novel features. First, instead of relying on a huge volume of log data, it leverages OS-level information flow and malware behavior information to recognize malicious changes. As a result, the approach imposes a smaller performance overhead. Second, different from existing intrusion detection and recovery systems that detect compromised OS objects one by one, Secom classifies objects into clusters and then identifies malicious objects on a cluster by cluster basis. Third, to reduce the false-positive rate when identifying malicious clusters, it simultaneously considers two malware behaviors that are of different types and the origin of the processes that exhibit these behaviors, rather than considers a single behavior alone as done by existing malware detection methods. We have successfully implemented Secom on the feather-weight virtual machine system, a Windows-based OS-level virtualization system. Experiments show that the prototype can effectively eliminate malicious state changes while committing a VM with small performance degradation. Moreover, compared with the commercial antimalware tools, the Secom prototype has a smaller number of false negatives and thus can more thoroughly clean up malware side effects. In addition, the number of false positives of the Secom prototype is also lower than that achieved by the online behavior-based approach of the commercial tools. Zhiyong Shan, Xin Wang 0001, Tzi-cker Chiueh |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2012 | Facilitating inter-application interactions for OS-level virtualizationabstractOS-level virtualization generates a minimal start-up and run-time overhead on the host OS and thus suits applications that require both good isolation and high efficiency. However, multiple-member applications required for forming a system may need to occasionally communicate across this isolation barrier to cooperate with each other while they are separated in different VMs to isolate intrusion or fault. Such application scenarios are often critical to enterprise-class servers, HPC clusters and intrusion/fault-tolerant systems, etc. We make the first effort to support the inter-application interactions in an OS-level virtualization system without causing a significant compromise on VM isolation. We identify all interactive operations that impact inter-application interactions, including inter-process communications, application invocations, resource name transfers and application dependencies. We propose Shuttle, a novel approach for facilitating inter-application interactions within and across OS-level virtual machines. Our results demonstrate that Shuttle can correctly address all necessary inter-application interactions while providing good isolation capability to all sample applications on different versions of Windows OS. Zhiyong Shan, Xin Wang 0001, Tzi-cker Chiueh, Xiaofeng Meng 0001 |
VEE | 1 |
| 2012 | Enforcing Mandatory Access Control in Commodity OS to Disable MalwareabstractEnforcing a practical Mandatory Access Control (MAC) in a commercial operating system to tackle malware problem is a grand challenge but also a promising approach. The firmest barriers to apply MAC to defeat malware programs are the incompatible and unusable problems in existing MAC systems. To address these issues, we manually analyze 2,600 malware samples one by one and two types of MAC enforced operating systems, and then design a novel MAC enforcement approach, named Tracer, which incorporates intrusion detection and tracing in a commercial operating system. The approach conceptually consists of three actions: detecting, tracing, and restricting suspected intruders. One novelty is that it leverages light-weight intrusion detection and tracing techniques to automate security label configuration that is widely acknowledged as a tough issue when applying a MAC system in practice. The other is that, rather than restricting information flow as a traditional MAC does, it traces intruders and restricts only their critical malware behaviors, where intruders represent processes and executables that are potential agents of a remote attacker. Our prototyping and experiments on Windows show that Tracer can effectively defeat all malware samples tested via blocking malware behaviors while not causing a significant compatibility problem. Zhiyong Shan, Xin Wang 0001, Tzi-cker Chiueh |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2011 | Tracer: enforcing mandatory access control in commodity OS with the support of light-weight intrusion detection and tracingabstractEnforcing a practical Mandatory Access Control (MAC) in a commercial operating system to tackle malware problem is a grand challenge but also a promising approach. The firmest barriers to apply MAC to defeat malware programs are the incompatible and unusable problems in existing MAC systems. To address these issues, we start our work by analyzing the technical details of 2,600 malware samples one by one and performing experiments over two types of MAC enforced operating systems. Based on the preliminary studies, we design a novel MAC model incorporating intrusion detection and tracing in a commercial operating system, named Tracer, in order to disable malware on hosts while offering good compatibility to existing software and good usability to common users who are not system experts. The model conceptually consists of three actions: detecting, tracing and restricting suspected intruders. One novelty is that it leverages light-weight intrusion detection and tracing techniques to automate security label configuration that is widely acknowledged as a tough issue when applying a MAC system in practice. The other is that, rather than restricting information flow as a traditional MAC does, it traces intruders and restricts only their critical malware behaviors, where intruders represent processes and executables that are potential agents of a remote attacker. Our prototyping and experiments on Windows show that Tracer can effectively defeat all malware samples tested via blocking malware behaviors while not causing a significant compatibility problem. Zhiyong Shan, Xin Wang 0001, Tzi-cker Chiueh |
AsiaCCS | 1 |
| 2009 | Operating System Mechanisms for TPM-Based Lifetime Measurement of Process IntegrityabstractImplementing runtime integrity measurement in an acceptable way is a big challenge. We tackle this challenge by developing a framework called Patos. This paper discusses the design and implementation concepts of our operating system mechanisms for runtime process integrity measurement, which is an important part of the Patos framework and is named Patos-RIP. Patos-RIP is developed into the main-stream Linux operating system and utilizes TPM as hardware support for tamper-resistance. From the beginning a process is created to the moment the process dies, Patos-RIP conducts integrity measurement at appropriate points of time when the process runs, so as to ensure that the integrity of a process is not compromised during its whole lifetime. This way, Patos-RIP can improve trustworthiness of processes by effectively detecting runtime tampering attacks on processes' integrity. Wenchang Shi, Zhaohui Liang, Bin Liang 0002, Zhiyong Shan |
MASS | 5 |