Songtao Yang 0001

dblp:150/3809-1 · DBLP profile ↗
← Back
8ranked-venue papers
1as first author
7since 2021 · last 2026
0000-0001-5903-8554ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 5 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 CiRCLE: Recovering Complex Data Structures in Binaries Beyond Fragmentation
Junlin Zhou, Songtao Yang 0001, Chao Zhang 0008
SP3
2025 VulShield: Protecting Vulnerable Code Before Deploying Patches
Yuan Li 0061, Chao Zhang 0008, Jinhao Zhu, Penghui Li 0001, Songtao Yang 0001, Wende Tan
NDSS6
2025 CCTAG: Configurable and Combinable Tagged Architecture
Zhanpeng Liu, Wende Tan, Yuan Li 0061, Xinhui Han, Songtao Yang 0001, Chao Zhang 0008
NDSS7
2023 1dFuzz: Reproduce 1-Day Vulnerabilities with Directed Differential Fuzzing
abstract
1-day vulnerabilities are common in practice and have posed severe threats to end users, as adversaries could learn from released patches to find them and exploit them. Reproducing 1-day vulnerabilities is also crucial for defenders, e.g., to block attack traffic against 1-day vulnerabilities. A core question that affects the effectiveness of recognizing and triggering 1-day vulnerabilities is what is the unique feature of a security patch. After conducting a large-scale empirical study, we point out that a common and unique feature of patches is the trailing call sequence (TCS) and present a novel directed differential fuzzing solution 1dFuzz to efficiently reproduce 1-day vulnerabilities in this paper. Based on the TCS feature, we present a locator 1dLoc able to find candidate patch locations via static analysis, a novel TCS-based distance metric for directed fuzzing, and a novel sanitizer 1dSan able to catch PoCs for 1-day vulnerabilities during fuzzing. We have systematically evaluated 1dFuzz on a set of real-world software vulnerabilities in 11 different settings. Results show that 1dFuzz significantly outperforms state-of-the-art (SOTA) baselines and could find up to 2.26x more 1-day vulnerabilities with a 43% shorter time.
Songtao Yang 0001, Yubo He, Kaixiang Chen, Zheyu Ma, Xiapu Luo, Jianjun Chen 0005, Chao Zhang 0008
ISSTA1
2023 TAICHI: Transform Your Secret Exploits Into Mine From a Victim's Perspective
abstract
Acquiring and analyzing exploits, which take advantage of vulnerabilities to conduct malicious actions, are crucial for victims (and defenders) when responding to system compromising incidents. However, exploits are sensitive and valuable assets that are not available to victims. The most common resource available for victims to investigate is network traffic, which covers the exploitation period. Thus reconstructing exploits from network traffic is demanded. In practice, the reconstruction process is performed manually, thus inefficient and non-scalable. In this article, we present an automated solutionTAICHIto reconstruct exploits from network traffic, able to generate replica exploits and facilitate timely incident analysis. By nature, a working exploit has to satisfy (1)path constraintswhich ensure the program path same as the original exploit's is explored and the same vulnerability is triggered, and (2)exploit constraintswhich ensure the same exploitation strategy is applied, e.g., to bypass deployed defenses or to stitch multiple gadgets together. We propose a hybrid solution to this problem by integrating techniques including multi-version execution (MVE), dynamic taint analysis (DTA), and concolic execution. We have implemented a prototype ofTAICHIon x86 and x86-64 Linux and tested it on the Cyber Grand Challenge (CGC) dataset, several Capture the Flag (CTF) challenges, and Metasploit exploit modules targeting real world applications. The evaluation results showed thatTAICHIcould reconstruct exploits efficiently with a high success rate. Moreover, it could be applied to production environments without disrupting running services, and could reconstruct exploits even if only one round of exploitation traffic is available.
Zhongyu Pei, Xingman Chen, Songtao Yang 0001, Hai-Xin Duan, Chao Zhang 0008
IEEE Trans. Dependable Secur. Comput.3
2022 PACMem: Enforcing Spatial and Temporal Memory Safety via ARM Pointer Authentication
abstract
Memory safety is a key security property that stops memory corruption vulnerabilities. Different types of memory safety enforcement solutions have been proposed and adopted by sanitizers or mitigations to catch and stop such bugs, at the development or deployment phase. However, existing solutions either provide partial memory safety or have overwhelmingly high performance overheads.
Yuan Li 0061, Wende Tan, Zhizheng Lv, Songtao Yang 0001, Mathias Payer, Ying Liu 0024, Chao Zhang 0008
CCS4
2021 ROLoad: Securing Sensitive Operations with Pointee Integrity
abstract
Sensitive operations (e.g. control-flow transfers) are attractive targets for attackers. To protect them from being hijacked, we propose a new solution ROLoad to guarantee the integrity of their operands, which are loaded from (potentially corrupted) memory. We extend the RISC-V instruction set, implement an FPGA-based prototype of ROLoad, and then demonstrate two specific defense applications. Results show that this solution only costs few extra hardware resources (< 3.32%). However, it could enable many lightweight (e.g. with overheads less than 0.31%) defenses, and provide broader and stronger security guarantees than existing hardware solutions, e.g. ARM BTI and Intel CET.
Wende Tan, Yuan Li 0061, Chao Zhang 0008, Xingman Chen, Songtao Yang 0001, Ying Liu 0024
DAC5
2020 Finding Cracks in Shields: On the Security of Control Flow Integrity Mechanisms
abstract
Control-flow integrity (CFI) is a promising technique to mitigate control-flow hijacking attacks. In the past decade, dozens of CFI mechanisms have been proposed by researchers. Despite the claims made by themselves, the security promises of these mechanisms have not been carefully evaluated, and thus are questionable.
Yuan Li 0061, Chao Zhang 0008, Xingman Chen, Songtao Yang 0001, Ying Liu 0024
CCS5