EDBT 2026 Demo / reviewers in the wild / expert
Ronghai Yang
dblp:130/6977
· DBLP profile ↗
9ranked-venue papers
6as first author
3since 2021 · last 2024
0009-0007-9733-9949ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 6 first-author · 3 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | SWIDE: A Semantic-aware Detection Engine for Successful Web Injection AttacksabstractWeb attacks, a primary vector for system breaches, pose a significant challenge within the cybersecurity landscape. The growing intensity of web attack attempts has led to "alert fatigue" where enterprises are inundated by excessive alerts. Although extensive research is being conducted on automated methods for detecting web attacks, it remains an open problem to identify whether the attacks are successful. Towards this end, we present SWIDE (Successful Web Injection Detection Engine), an engine to pinpoint successful web injection attacks (e.g., PHP command injection, SQL injection). This enables enterprises to focus exclusively on those crucial threats. Our methodology builds on two insights: Firstly, while attackers tend to apply payload obfuscation techniques to evade detection, all successful web injection attacks must comply with the programming language syntax to be executable; Secondly, these attacks inevitably produce observable effects, such as returning execution result or creating backdoors for future access by the attacker. Consequently, we leverage advanced syntactic and semantic analysis to 1) detect malicious syntax features in obfuscated payloads and 2) perform semantic analysis of the payload to recover the intention of the attack. With a two-stage design, namely, attack identification and confirmation mechanisms, SWIDE can accurately identify successful attacks, even amidst intricate obfuscations. Unlike proof-of-concept studies, SWIDE has been deployed and validated in real-world environments through collaborations with a cybersecurity firm. Serving 5,045 enterprise users, our system identifies that roughly 15% of enterprises have suffered from successful attacks on a weekly basis - an alarmingly high rate. Moreover, we perform a detailed analysis of six months' data and discover 60 zero-day vulnerabilities exploited in the wild, including 12 high-risk ones acknowledged by relevant authorities. These findings underscore the practical effectiveness of SWIDE. Ronghai Yang, Xianbo Wang, Kaixuan Luo, Jiayuan Xin, Wing Cheong Lau |
CCS | 1 |
| 2021 | An Empirical Study on Mobile Payment Credential Leaks and Their Exploits
Shangcheng Shi, Xianbo Wang, Kyle Zeng, Ronghai Yang, Wing Cheong Lau |
SecureComm (2) | 4 |
| 2021 | Scalable Detection of Promotional Website Defacements in Black Hat SEO Campaigns
Ronghai Yang, Xianbo Wang, Siming Pang, Wing Cheong Lau |
USENIX Security Symposium | 1 |
| 2020 | Search & Catch: Detecting Promotion Infection in the Underground through Search EnginesabstractPromotion infection is an attack where adversaries exploit website weakness to inject illicit content into web pages for promoting illicit products, e.g., gambling and unlicensed drugs, etc. As the development of online underground economy, promotion infection is widely utilized by adversaries. To escape legal supervision, adversaries have exploited ingenious anti-regulatory techniques, making it challenging to access the infected webpage, let alone the collection of a large scale corpus. Limited by the small size of corpus, the effectiveness of the literature in detecting promotion infection is not proven yet. Towards this end, we propose a novel and efficient approach to (semi-)automatically collect infected webpages. Our insight is that the goal of infection is to promote the underground business, mainly through search engines. Exploiting this observation, we propose the search-engine dork technique to crawl the infected webpages by querying underground advertisings (i.e., a list of black keywords) on search engines. Running with an initial 58 seed black keywords, we have collected 22,939 infected pages ranging 2,563 domains, and along the way automatically gathered 8,374 new black keywords. This large scale dataset thereby enables us to build a machine-learning model to distinguish infected webpages from normal ones. The experimental results show that the model, thanks to the large-scale and high-quality dataset, can provide high detection rate and low false alarm rate. Ronghai Yang, Jia Liu 0017, Liang Gu |
TrustCom | 1 |
| 2018 | IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based Fuzzing
Jiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo, Zhiqiang Lin 0001, XiaoFeng Wang 0001, Wing Cheong Lau, Menghan Sun, Ronghai Yang, Kehuan Zhang |
NDSS | 9 |
| 2018 | Vetting Single Sign-On SDK Implementations via Symbolic Reasoning
Ronghai Yang, Wing Cheong Lau, Jiongyi Chen, Kehuan Zhang |
USENIX Security Symposium | 1 |
| 2017 | Breaking and Fixing Mobile App Authentication with OAuth2.0-based Protocols
Ronghai Yang, Wing Cheong Lau, Shangcheng Shi |
ACNS | 1 |
| 2016 | Model-based Security Testing: An Empirical Study on OAuth 2.0 ImplementationsabstractMotivated by the prevalence of OAuth-related vulnerabilities in the wild, large-scale security testing of real-world OAuth 2.0 implementations have received increasing attention lately [31,37,42]. However, these existing works either rely on manual discovery of new vulnerabilities in OAuth 2.0 implementations or perform automated testing for specific, previously-known vulnerabilities across a large number of OAuth implementations. In this work, we propose an adaptive model-based testing framework to perform automated, large-scale security assessments for OAuth 2.0 implementations in practice. Key advantages of our approach include (1) its ability to identify existing vulnerabilities and discover new ones in an automated manner; (2) improved testing coverage as all possible execution paths within the scope of the model will be checked and (3) its ability to cater for the implementation differences of practical OAuth systems/ applications, which enables the analyst to offload the manual efforts for large-scale testing of OAuth implementations. We have designed and implemented OAuthTester to realize our proposed framework. Using OAuthTester, we examine the implementations of 4 major Identity Providers as well as 500 top-ranked US and Chinese websites which use the OAuth-based Single-Sign-On service provided by the formers. Our empirical findings demonstrate the efficacy of adaptive model-based testing on OAuth 2.0 deployments at scale. More importantly, OAuthTester not only manages to rediscover various existing vulnerabilities but also identify several previously unknown security flaws and new exploits for a large number of eal-world applications implementing OAuth 2.0. Ronghai Yang, Wing Cheong Lau, Kehuan Zhang, Pili Hu |
AsiaCCS | 1 |
| 2015 | Solving Large Graph Problems in MapReduce-Like Frameworks via Optimized Parameter Configuration
Huanle Xu, Ronghai Yang, Zhibo Yang 0002, Wing Cheong Lau |
ICA3PP (2) | 2 |