EDBT 2026 Demo / reviewers in the wild / expert
Jinku Li
dblp:06/8291
· DBLP profile ↗
27ranked-venue papers
3as first author
17since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 2 first-author · 14 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1 · 1 first-authorComputer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The Dark Side of Flexibility: Detecting Risky Permission Chaining Attacks in Serverless Applications
Xunqi Liu, Nanzi Yang, Jinku Li, Jianfeng Ma 0001, Kangjie Lu |
NDSS | 4 |
| 2026 | Moderation is the Best Policy: Dynamic Defense Against Gradient-Based Data Reconstruction Attacks in Federated LearningabstractFederated learning (FL) is a privacy-preserving distributed machine learning framework. However, recent studies have shown that implementing gradient-based data reconstruction attacks (DRA) can still lead to the leakage of user privacy through frequently uploaded model parameters in FL. Existing works leverage differential privacy (DP) to prevent privacy leakage, but the lack of effective scheduling of the privacy budget results in significant accuracy loss in the trained models. In this paper, we propose a novel dynamic privacy preserving federated learning framework, named NDPP-FL, capable of delivering robust defenses against DRA while significantly mitigating performance loss. Our key insight is to regard the privacy budget as a non-replenishable resource and dynamically schedule it based on privacy leakage risks to provide self-adaptive privacy protection for clients across varying communication rounds. Specifically, based on the amount of information between the local dataset and the transmitted parameters, we first design a parameter channel information leakage model. Then, during each update iteration, we introduce saliency perturbations based on the Hessian matrix to enhance defensive capabilities. Meanwhile, to improve the performance of NDPP-FL, sample-adaptive clipping and decaying noise perturbations are adopted in the construction. Furthermore, extensive experiments demonstrate that our framework performs excellently in terms of model accuracy and resilience against DRA. Qinyang Miao, Wen Sun 0004, Dan Zhu 0001, Jinku Li, Yajin Zhou, Cristina Alcaraz |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Dangers Behind Access Control: Understanding and Exploiting Implicit Permissions in KubernetesabstractAs the de-facto standard for container orchestration, Kubernetes is extensively adopted by numerous companies and cloud vendors, making its security critical. In this paper, we define a new attack surface called implicit permission: The execution of explicitly granted permissions in Kubernetes dynamically leads to implicit operations on other resources, enabling new permissions beyond the explicitly granted ones. Such implicit permissions create security vulnerabilities that attackers can exploit to compromise an entire cluster. Nanzi Yang, Wenbo Shen, Jinku Li, Kangjie Lu |
CCS | 4 |
| 2025 | Hit The Bullseye On The First Shot: Improving LLMs Using Multi-Sample Self-Reward Feedback for Vulnerability RepairabstractIn recent years, large language models (LLMs) have emerged as powerful tools to assist developers in various coding tasks, including the challenging domain of vulnerability repair. While these models have demonstrated significant potential in generating patches for software vulnerabilities, current approaches often suffer from limitations in precision, requiring multiple attempts to produce accurate fixes. In this paper, we propose MUSSEL (Multi-Sample Self-Reward Feedback), a novel framework designed to address the issue of one-shot vulnerability patching. Inspired by insights from human learning mechanisms, our approach aims to enhance the efficiency and accuracy of LLMs in generating precise patches for software vulnerabilities. We introduce a multi-stage training process, beginning with supervised fine-tuning using domain-specific data to impart foundational knowledge in vulnerability repair to the LLM. Subsequently, we employ self-reward feedback learning to refine the model’s patch generation capabilities, leveraging correct and incorrect patches iteratively to improve performance. We also introduce a novel prompt design tailored to better align with the capabilities of LLMs during inference. Our results demonstrate that MUSSEL consistently outperforms state-of-the-art solutions in one-shot queries. Notably, even with a small beam size, MUSSEL exhibits remarkable efficiency, requiring minimal GPU memory resources. Furthermore, MUSSEL’s effectiveness across diverse CWEs underscores its significant security implications. Yue Zhang 0025, Jinku Li |
ASE | 3 |
| 2025 | SCCA: A Multi-Agent Code Security Analysis Framework for AI-Assisted Code GenerationabstractThis paper presents SCCA, a novel multi-agent security analysis framework for AI-assisted code generation environments. Our system combines three specialized agents—AST-based structural analysis, LLM-enhanced vulnerability detection, and data flow security assessment—to overcome limitations of traditional security tools. We evaluate the framework using different LLM configurations (e.g., Claude-4, GPT-4o) across diverse project types, demonstrating the impact of LLM selection on the quality of security analysis. Results show our framework with Claude-4 achieves superior performance in vulnerability detection and explanation quality, with the multi-agent approach significantly outperforming traditional methods. Furthermore, our framework produces structured reports specifically designed for automated remediation, enabling high remediation success rates without human intervention. This work provides a foundation for addressing the unique security challenges of AI-generated code in modern development environments. Yue Zhang 0025, Jinku Li, Boyang Ma |
MASS | 3 |
| 2025 | RansomSentry: Runtime Detection of Android Ransomware With Compiler-Based InstrumentationabstractIn recent years, mobile ransomware attacks have become increasingly prevalent, especially in Android systems. Android ransomware extorts users by maliciously locking infected devices or encrypting user files on the devices. To address this problem, we proposeRansomSentry, a runtime detection system with compiler-based instrumentation against both lock-screen and crypto ransomware in Android. Specifically,RansomSentryleverages a modified Androiddex2oatcompiler to instrument the sensitive APIs invoked by ransomware during the installation of a target app, and monitors the app's screen-related and file access operations at runtime to detect attacks. Compared to previous solutions,RansomSentrydoes not require to change the app's APK file and bytecode, thus it will pass the original integrity check of the app, which makes it readily deployed by users. Further, such a dynamic approach is naturally immune to code or data obfuscation and can provide real-time protection. To validate our approach, we implement a prototype ofRansomSentryand collect 2,376 recent Android ransomware samples to evaluate it. The evaluation results show that our prototype can effectively detect ransomware attacks with an acceptable performance overhead. Boyang Ma, Linxuan Zhou, Chong Liao, Yajin Zhou, Jinku Li, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Towards Understanding and Defeating Abstract Resource Attacks for Container PlatformsabstractOS-level virtualization (a.k.a. container) has become a fundamental technology in cloud computing due to the efficiency provided by the shared-kernel design. However, this design results in containers sharing thousands of kernel variables and data structures (termedabstract resources), which are prevalent but under-protected. Without exploiting other kernel vulnerabilities, a non-privileged container can easily exhaust abstract resources to cause DoS attacks against other containers. Even worse, our experiments demonstrate that abstract resource attacks are a broad class of attacks that affect Linux, FreeBSD, Fuchsia, and all shared-kernel container environments on the top four cloud vendors. To defend against the abstract resource attack, we automatically analyze vulnerable abstract resources in the Linux kernel and detect 501 container-exhaustible resources. To confine these abstract resources dynamically, we propose two new techniques: the flexible in-kernel attachment for flexible resource consumption attachment and the tree-based resource accounting for efficient usage retrieval. Based on these two techniques, we design and implement aflexibleabstract resource confinement framework, named Flask, to achieve flexible and efficient abstract resource confinement. Our evaluation shows Flask can efficiently limit abstract resource usage with less than 0.6% performance overhead. Wenbo Shen, Yutian Yang, Nanzi Yang, Jinku Li, Kangjie Lu, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2024 | Boosting Practical Control-Flow Integrity with Complete Field Sensitivity and Origin AwarenessabstractControl-flow integrity (CFI) is a strong and efficient defense mechanism against memory-corruption attacks.The practical versions of CFI, which have been integrated into compilers, employ static analysis to collect all possibly valid target functions of indirect calls.They are however less effective because the static analysis is imprecise.While more precise CFI techniques have been proposed, such as dynamic CFI, they are not yet practical due to issues on performance, compatibility, and deployability.We believe that to be practical, CFI based on static analysis is still the promising direction.However, these years have not seen much progress on the effectiveness of such practical CFI.This paper aims to boost the effectiveness of practical CFI by dramatically optimizing the target-function sets (aka equivalence class or EC) of indirect calls.We first identify two fundamental limitations that lead to the imprecision of static indirect-call analysis: incomplete field sensitivity due to variable field indexes and the unawareness of the origins of point-to targets.We then propose two novel analysis techniques, complete field sensitivity and origin awareness, which handle variable field indexes and distinguish target origins.The techniques dramatically reduce the size of target functions.To enforce the origin awareness, we further employ Intel Memory Protection Keys to safely store the origin information.We implement our techniques as a system called ECCut.The evaluation results show that compared to the mainline LLVM CFI, ECCut achieves a substantial reduction of 94.8% and 90.3% in the average and the largest EC sizes.While compared to the state-of-the-art origin-aware CFI (i.e., OS-CFI), ECCut reduces the average and the largest EC sizes by 90.2% and 89.3% respectively.Additionally, Zehui Cheng 0005, Jinku Li, Jianfeng Ma 0001, Kangjie Lu |
CCS | 3 |
| 2024 | Lifting the Grey Curtain: Analyzing the Ecosystem of Android Scam AppsabstractMobile applications (apps) are extensively involved in online scams. Previous studies mainly targetmaliciousapps that either compromise victims' devices (e.g., malware and ransomware), or lead to privacy leakage and abuse (e.g., creepware). Recently, an emerging kind of appmakes profits by providing scam services rather than compromising devices or abusing privacy. We name these apps asscamwaredue to their deceptive behavior, which poses a new threat to (mobile) users. However, the characteristics and the ecosystem of scamware remain mysterious. This paper takes the first step toward systematically studying scamware. In total, 1262 ground-truth scamware are collected from December 1, 2020, to May 1, 2022. Specifically, we first investigate the social tricks used by scamware, and then analyze the participants and their relationships to demystify the ecosystem behind scamware. Finally, we reveal the scamware development features to facilitate the detection of scamware. Our study also gives some interesting findings,e.g., 1) the crowd-sourcing strategy is adopted to develop scamware,i.e., thescammersare the core members, while other participants are hired as peripherals; and 2) the online app generators have been abused to facilitate development; and 3) the money mule based payment is prevalent, and the case study shows the money flow is around $ 2593346 per day. We believe that our findings will facilitate the community and law enforcement agencies to mitigate this threat, and we will release the source code of our tools to engage the community. Zhuo Chen 0023, Lei Wu 0012, Yubo Hu, Yajin Zhou, Zhushou Tang, Yexuan Chen, Jinku Li, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 9 |
| 2023 | TypeSqueezer: When Static Recovery of Function Signatures for Binary Executables Meets Dynamic AnalysisabstractControl-Flow Integrity (CFI) is considered a promising solution in thwarting advanced code-reuse attacks. While the problem of backward-edge protection in CFI is nearly closed, effective forward-edge protection is still a major challenge. The keystone of protecting the forward edge is to resolve indirect call targets, which although can be done quite accurately using type-based solutions given the program source code, it faces difficulties when carried out at the binary level. Since the actual type information is unavailable in COTS binaries, type-based indirect call target matching typically resorts to approximate function signatures inferred using the arity and argument width of indirect callsites and calltargets. Doing so with static analysis, therefore, forces the existing solutions to assume the arity/width boundaries in a too-permissive way to defeat sophisticated attacks. Jinku Li, Debin Gao, Jianfeng Ma 0001 |
CCS | 2 |
| 2023 | Travelling the Hypervisor and SSD: A Tag-Based Approach Against Crypto Ransomware with Fine-Grained Data RecoveryabstractRansomware has evolved from an economic nuisance to a national security threat nowadays, which poses a significant risk to users. To address this problem, we propose RansomTag, a tag-based approach against crypto ransomware with fine-grained data recovery. Compared to state-of-the-art SSD-based solutions, RansomTag makes progress in three aspects. First, it decouples the ransomware detection functionality from the firmware of the SSD and integrates it into a lightweight hypervisor of Type I. Thus, it can leverage the powerful computing capability of the host system and the rich context information, which is introspected from the operating system, to achieve accurate detection of ransomware attacks and defense against potential targeted attacks on SSD characteristics. Further, RansomTag is readily deployed onto desktop personal computers due to its parapass-through architecture. Second, RansomTag bridges the semantic gap between the hypervisor and the SSD through the tag-based approach proposed by us. Third, RansomTag is able to keep 100% of the user data overwritten or deleted by ransomware, and restore any single or multiple user files to any versions based on timestamps. To validate our approach, we implement a prototype of RansomTag and collect 3,123 recent ransomware samples to evaluate it. The evaluation results show that our prototype effectively protects user data with minimal scale data backup and acceptable performance overhead. In addition, all the attacked files can be completely restored in fine-grained. Boyang Ma, Jinku Li, Fengwei Zhang, Wenbo Shen, Yajin Zhou, Jianfeng Ma 0001 |
CCS | 3 |
| 2023 | Take Over the Whole Cluster: Attacking Kubernetes via Excessive Permissions of Third-party ApplicationsabstractAs the dominant container orchestration system, Kubernetes is widely used by many companies and cloud vendors. It runs third-party add-ons and applications (termed third-party apps) on its control plane to manage the whole cluster. The security of these third-party apps is critical to the whole cluster but has not been systematically studied so far. Nanzi Yang, Wenbo Shen, Jinku Li, Xunqi Liu, Jianfeng Ma 0001 |
CCS | 3 |
| 2023 | DeUEDroid: Detecting Underground Economy Apps Based on UTG SimilarityabstractIn recent years, the underground economy is proliferating in the mobile system. These underground economy apps (UEware for short) make profits from providing non-compliant services, especially in sensitive areas (e.g., gambling, porn, loan). Unlike traditional malware, most of them (over 80%) do not have malicious payloads. Due to their unique characteristics, existing detection approaches cannot effectively and efficiently mitigate this emerging threat. To address this problem, we propose a novel approach to effectively and efficiently detect UEware by considering their UI transition graphs (UTGs). Based on the proposed approach, we design and implement a system, named DeUEDroid, to perform the detection. To evaluate DeUEDroid, we collect 25, 717 apps and build up the first large-scale ground-truth dataset (1, 700 apps) of UEware. The evaluation result based on the ground-truth dataset shows that DeUEDroid can cover new UI features and statically construct precise UTG. It achieves 98.22% detection F1-score and 98.97% classification accuracy, a significantly better performance than the traditional approaches. The evaluation result involving 24, 017 apps demonstrates the effectiveness and efficiency of UEware detection in real-world scenarios. Furthermore, the result also reveals that UEware are prevalent, i.e., 54% apps in the wild and 11% apps in the app stores are UEware. Our work sheds light on the future work of analyzing and detecting UEware. To engage the community, we have made our prototype system and the dataset available online. Zhuo Chen 0023, Yubo Hu, Lei Wu 0012, Yajin Zhou, Yiling He, Xianhao Liao, Ke Wang 0042, Jinku Li, Zhan Qin |
ISSTA | 9 |
| 2023 | Demystifying Pointer Authentication on Apple M1
Zechao Cai, Jiaxun Zhu, Wenbo Shen, Yutian Yang, Jinku Li, Kui Ren 0001 |
USENIX Security Symposium | 7 |
| 2023 | Attacks are Forwarded: Breaking the Isolation of MicroVM-based Containers Through Operation Forwarding
Jietao Xiao, Nanzi Yang, Wenbo Shen, Jinku Li, Zhiqiang Dong, Jianfeng Ma 0001 |
USENIX Security Symposium | 4 |
| 2022 | LibCapsule: Complete Confinement of Third-Party Libraries in Android ApplicationsabstractAndroid application (or app) developers increasingly integrate third-party libraries to enrich the functionality of their apps. However, current permission model on Android cannot constrain the behaviors of in-app third-party libraries for allowing them to operate with the same permissions as their host app. This brings serious security and privacy concerns to users. In this article, we proposeLibCapsule, a user-level solution to confine third-party libraries from potential permission abuses. Compared to previous systems,LibCapsuleis able to providecompleteconfinement of third-party libraries in Android apps, including the static Java code, dynamically loaded code and native code of third-party libraries. We have developed a prototype ofLibCapsule, and collected 204 popular third-party libraries as well as 2,021 apps to evaluate it. The evaluation results indicate thatLibCapsuleis capable of enforcing complete and fine-grained regulation on third-party libraries according to customized security policies with a low performance overhead. To engage the whole community, we will release the dataset of third-party libraries and apps in our evaluation. Xuewu Yang, Huamao Wu, Yajin Zhou, Jinku Li, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | Demons in the Shared Kernel: Abstract Resource Attacks Against OS-level VirtualizationabstractDue to its faster start-up speed and better resource utilization efficiency, OS-level virtualization has been widely adopted and has become a fundamental technology in cloud computing. Compared to hardware virtualization, OS-level virtualization leverages the shared-kernel design to achieve high efficiency and runs multiple user-space instances (a.k.a., containers) on the shared kernel. However, in this paper, we reveal a new attack surface that is intrinsic to OS-level virtualization, affecting Linux, FreeBSD, and Fuchsia. The root cause is that the shared-kernel design in OS-level virtualization results containers in sharing thousands of kernel variables and data structures directly and indirectly. Without exploiting any kernel vulnerabilities, a non-privileged container can easily exhaust the shared kernel variables and data structure instances to cause DoS attacks against other containers. Compared with the physical resources, these kernel variables or data structure instances (termed abstract resources) are more prevalent but under-protected. To show the importance of confining abstract resources, we conduct abstract resource attacks that target different aspects of the OS kernel. The results show that attacking abstract resources is highly practical and critical. We further conduct a systematic analysis to identify vulnerable abstract resources in the Linux kernel, which successfully detects 1,010 abstract resources and 501 of them can be repeatedly consumed dynamically. We also conduct the attacking experiments in the self-deployed shared-kernel container environments on the top 4 cloud vendors. The results show that all environments are vulnerable to abstract resource attacks. We conclude that containing abstract resources is hard and give out multiple strategies for mitigating the risks. Nanzi Yang, Wenbo Shen, Jinku Li, Yutian Yang, Kangjie Lu, Jietao Xiao, Chenggang Qin, Jianfeng Ma 0001, Kui Ren 0001 |
CCS | 3 |
| 2020 | RansomSpector: An introspection-based approach to detect crypto ransomware
Boyang Ma, Jinku Li, Fengwei Zhang, Jipeng Su, Jianfeng Ma 0001 |
Comput. Secur. | 3 |
| 2020 | AdCapsule: Practical Confinement of Advertisements in Android ApplicationsabstractNowadays, app developers tend to integrate advertisement libraries (or ad libraries) into their apps to get revenue from ad networks. However, researches have shown that both ad libraries and ad contents could raise serious security and privacy concerns. In this paper, we propose AdCapsule, a user-level solution to practically confine advertisements, including ad libraries and ad contents. Our solution does not need to change the Android framework, nor requires the root privilege, thus can be readily deployed. Specifically, we propose the permission sandbox, which isolates the permissions used by ad libraries from the host app, and the file sandbox, which separates the file operations of advertisements. The ad library and ad content cannot read or write any file outside this sandbox. We have implemented a prototype of AdCapsule. Our evaluation results indicate that AdCapsule can successfully enforce security policies to block attempts of accessing private information or manipulating files of the host app, and the performance overhead introduced by AdCapsule is low. Xiaonan Zhu, Jinku Li, Yajin Zhou, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2020 | Flow Adversarial Networks: Flowrate Prediction for Gas-Liquid Multiphase Flows Across Different DomainsabstractThe solution of how to accurately and timely predict the flowrate of gas-liquid mixtures is the key to help petroleum and other related industries to reduce costs, improve efficiency, and optimize management. Although numerous studies have been carried out over the past decades, the problem is still significantly challenging due to the complexity of multiphase flows. This paper attempts to seek new possibilities for multiphase flow measurement and novel application scenarios for state-of-the-art machine learning (ML) techniques. Convolutional neural networks (CNNs) are applied to predict the flowrate of multiphase flows for the first time and can achieve promising performance. In addition, considering the difference between data distributions of training and testing samples and its negative impact on prediction accuracy of the CNN models on testing samples, we propose flow adversarial networks (FANs) that can distill both domain-invariant and flowrate-discriminative features from the raw input. The method is evaluated on dynamic experimental data of different multiphase flows on different flow conditions and operating environments. The experimental results demonstrate that FANs can effectively prevent the accuracy degradation caused by the gap between training and testing samples and have better performance than state-of-the-art approaches in the flowrate prediction field. Delin Hu, Jinku Li, Yinyan Liu, Yi Li 0032 |
IEEE Trans. Neural Networks Learn. Syst. | 2 |
| 2019 | Towards a First Step to Understand the Cryptocurrency Stealing Attack on Ethereum
Xinrui Hou, Runhuai Li, Yajin Zhou, Xiapu Luo, Jinku Li, Kui Ren 0001 |
RAID | 6 |
| 2018 | Fine-CFI: Fine-Grained Control-Flow Integrity for Operating System KernelsabstractThe operating system kernel is often the security foundation for the whole system. To prevent attacks, control-flow integrity (CFI) has been proposed to ensure that any control transfer during the program's execution never deviates from its control-flow graph (CFG). Existing CFI solutions either work in user space or are coarse-grained; thus they cannot be readily deployed in kernels or are vulnerable to state-of-the-art attacks. In this paper, we present Fine-CFI, a system that enforces fine-grained CFI for operating system kernels. Unlike previous systems, Fine-CFI constructs the kernel's fine-grained CFG with a retrofitted context-sensitive and field-sensitive pointer analysis, then enforces CFI with this CFG. At the same time, Fine-CFI provides comprehensive protection to the control data in the kernel's interrupt context. Combining the above two kinds of protection, we can thus defeat those formidable ret2usr and kernel code-reuse attacks. We have developed a compiler-based prototype and implemented this technique in Linux 3.14 kernel. Our evaluation indicates that Fine-CFI prevents all the gadgets found by an open-source gadget-finding tool from being misused, as well as all the attacks from the RIPE benchmark and malicious attempts to modify control data in the interrupt context; and it also reduces the number of indirect control-flow targets by 99.998%, thus largely raising the bar for attackers. Our evaluation also shows that the performance overhead introduced by Fine-CFI is less than 10% on average. Jinku Li, Xiaomeng Tong, Fengwei Zhang, Jianfeng Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2014 | Verifying Secure Interface Composition for Component-Based System DesignsabstractInformation flow security has been considered as a critical requirement on software systems, especially when heterogeneous components from different parties cooperate to achieve end-to-end enforcement on data confidentiality. Enforcing the information flow security properties on complicated systems faces a great challenge because the properties cannot be preserved under composition and most of the current approaches are not scalable enough. To address this problem, there have been several recent efforts on the compositional information flow analyses developed for different abstraction levels. But these approaches have rarely been considered to incorporate with the process of system design. Integrating the security enforcement with the model-based development process can provide the designer with ability to verify information flow security in the early stage of system development. We propose a compositional information flow verification which is integrated with model-based system design in Sys ML by an automated model translation from semi-formal behavior and structure models to interface automata. Our compositional approach is general to support the complex security lattices and a variety of in distinguish ability relations. The evaluation results show the usability of our approach on practical system designs and the scalability of the compositional verification. Cong Sun 0001, Ning Xi 0002, Jinku Li, Qingsong Yao, Jianfeng Ma 0001 |
APSEC (1) | 3 |
| 2011 | Comprehensive and Efficient Protection of Kernel Control DataabstractProtecting kernel control data (e.g., function pointers and return addresses) has been a serious issue plaguing rootkit defenders. In particular, rootkit authors only need to compromise one piece of control data to launch their attacks, while defenders need to protect thousands of such values widely scattered across kernel memory space. Worse, some of this data (e.g., return addresses) is volatile and can be dynamically generated at run time. Existing solutions, however, offer either incomplete protection or excessive performance overhead. To overcome these limitations, we present indexed hooks, a scheme that greatly facilitates kernel control-flow enforcement by thoroughly transforming and restricting kernel control data to take only legal jump targets (allowed by the kernel's control-flow graph). By doing so, we can severely limit the attackers' possibility of exploiting them as an infection vector to launch rootkit attacks. To validate our approach, we have developed a compiler-based prototype that implements this technique in the FreeBSD 8.0 kernel, transforming 49 025 control transfer instructions (~7.25% of the code base) to use indexed hooks instead of direct pointers. Our evaluation results indicate that our approach is generic, effective, and can be implemented on commodity hardware with a low performance overhead (<;5% based on benchmarks). Jinku Li, Zhi Wang 0004, Tyler K. Bletsch, Deepa Srinivasan, Michael C. Grace, Xuxian Jiang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2010 | Defeating return-oriented rootkits with "Return-Less" kernelsabstractTargeting the operating system (OS) kernel, kernel rootkits pose a formidable threat to computer systems and their users. Recent efforts have made significant progress in blocking them from injecting malicious code into the OS kernel for execution. Unfortunately, they cannot block the emerging so-called return-oriented rootkits (RORs). Without the need of injecting their own malicious code, these rootkits can discover and chain together "return-oriented gadgets" (that consist of only legitimate kernel code) for rootkit computation. Jinku Li, Zhi Wang 0004, Xuxian Jiang, Michael C. Grace, Sina Bahram |
EuroSys | 1 |
| 2010 | Transparent Protection of Commodity OS Kernels Using Hardware Virtualization
Michael C. Grace, Zhi Wang 0004, Deepa Srinivasan, Jinku Li, Xuxian Jiang, Zhenkai Liang, Siarhei Liakh |
SecureComm | 4 |
| 2010 | DKSM: Subverting Virtual Machine Introspection for Fun and ProfitabstractVirtual machine (VM) introspection is a powerful technique for determining the specific aspects of guest VM execution from outside the VM. Unfortunately, existing introspection solutions share a common questionable assumption. This assumption is embodied in the expectation that original kernel data structures are respected by the untrusted guest and thus can be directly used to bridge the well-known semantic gap. In this paper, we assume the perspective of the attacker, and exploit this questionable assumption to subvert VM introspection. In particular, we present an attack called DKSM (Direct Kernel Structure Manipulation), and show that it can effectively foil existing VM introspection solutions into providing false information. By assuming this perspective, we hope to better understand the challenges and opportunities for the development of future reliable VM introspection solutions that are not vulnerable to the proposed attack. Sina Bahram, Xuxian Jiang, Zhi Wang 0004, Mike Grace, Jinku Li, Deepa Srinivasan, Junghwan Rhee, Dongyan Xu |
SRDS | 5 |