Xi Chen 0038

dblp:16/3283-38 · DBLP profile ↗
← Back
9ranked-venue papers
3as first author
0since 2021 · last 2017
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 2 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-authorSystems, architecture and hardware · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
6 papers
Systems and software security · 90% Hardware security and side channels · 8% Privacy and data protection · 2%
Software engineering, system software, and programming languages
5 papers
Program analysis · 71% Software maintenance and evolution · 18% Programming languages and type systems · 10%

Topics — the 19 heaviest of 19, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Program analysis
binary analysis
0.632017
DSIbin: identifying dynamic data structures in C/C++ binaries · ASE 2017
StackArmor: Comprehensive Protection From Stack-based Memory Error Vulnerabilities for Binaries · NDSS 2015
A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary Level · IEEE Symposium on Security and Privacy 2016
Systems and software security
exploitation
0.522017
The Dynamics of Innocent Flesh on the Bone: Code Reuse Ten Years Later · CCS 2017
A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary Level · IEEE Symposium on Security and Privacy 2016
Systems and software security › return-oriented programming defense
code reuse attack defense
0.322017
A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary Level · IEEE Symposium on Security and Privacy 2016
The Dynamics of Innocent Flesh on the Bone: Code Reuse Ten Years Later · CCS 2017
Systems and software security › exploitation
code reuse attack
0.312017
The Dynamics of Innocent Flesh on the Bone: Code Reuse Ten Years Later · CCS 2017
Systems and software security › memory safety › memory isolation
in-process isolation
0.312017
No Need to Hide: Protecting Safe Regions on Commodity Hardware · EuroSys 2017
Systems and software security › memory safety
memory isolation
0.312017
No Need to Hide: Protecting Safe Regions on Commodity Hardware · EuroSys 2017
Systems and software security › exploitation › code reuse attack
return-oriented programming
0.312017
The Dynamics of Innocent Flesh on the Bone: Code Reuse Ten Years Later · CCS 2017
Hardware security and side channels
side-channel attack
0.312017
No Need to Hide: Protecting Safe Regions on Commodity Hardware · EuroSys 2017
Program analysis › heap analysis
data structure identification
0.312017
DSIbin: identifying dynamic data structures in C/C++ binaries · ASE 2017
Software maintenance and evolution
reverse engineering
0.312017
DSIbin: identifying dynamic data structures in C/C++ binaries · ASE 2017
Systems and software security
binary analysis
0.212016
An In-Depth Analysis of Disassembly on Full-Scale x86/x64 Binaries · USENIX Security Symposium 2016
Systems and software security › binary analysis
binary type recovery
0.212016
POSTER: Identifying Dynamic Data Structures in Malware · CCS 2016
Systems and software security › memory safety
control-flow integrity
0.212016
A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary Level · IEEE Symposium on Security and Privacy 2016
Systems and software security › software protection
binary protection
0.212015
StackArmor: Comprehensive Protection From Stack-based Memory Error Vulnerabilities for Binaries · NDSS 2015
Systems and software security
memory safety
0.212015
StackArmor: Comprehensive Protection From Stack-based Memory Error Vulnerabilities for Binaries · NDSS 2015
Program analysis
static analysis
0.222017
DSIbin: identifying dynamic data structures in C/C++ binaries · ASE 2017
POSTER: Identifying Dynamic Data Structures in Malware · CCS 2016
Programming languages and type systems
type inference
0.222017
DSIbin: identifying dynamic data structures in C/C++ binaries · ASE 2017
POSTER: Identifying Dynamic Data Structures in Malware · CCS 2016
Privacy and data protection
randomization
0.112017
No Need to Hide: Protecting Safe Regions on Commodity Hardware · EuroSys 2017
Program analysis › binary analysis
disassembly
0.112016
An In-Depth Analysis of Disassembly on Full-Scale x86/x64 Binaries · USENIX Security Symposium 2016

Methods — techniques the papers use, named apart from their topics

use-def analysis · 0.5memory abstraction · 0.5machine learning · 0.5liveness analysis · 0.5empirical analysis · 0.5binary instrumentation · 0.4type merging · 0.3survey · 0.3speculative nested-struct detection · 0.3segmentation · 0.3randomization · 0.3historical analysis · 0.3
YearPublicationVenuePosition
2017 The Dynamics of Innocent Flesh on the Bone: Code Reuse Ten Years Later
abstract
In 2007, Shacham published a seminal paper on Return-Oriented Programming (ROP), the first systematic formulation of code reuse. The paper has been highly influential, profoundly shaping the way we still think about code reuse today: an attacker analyzes the "geometry" of victim binary code to locate gadgets and chains these to craft an exploit. This model has spurred much research, with a rapid progression of increasingly sophisticated code reuse attacks and defenses over time. After ten years, the common perception is that state-of-the-art code reuse defenses are effective in significantly raising the bar and making attacks exceedingly hard.
Victor van der Veen, Dennis Andriesse, Manolis Stamatogiannakis, Xi Chen 0038, Herbert Bos, Cristiano Giuffrida
CCS4
2017 CodeArmor: Virtualizing the Code Space to Counter Disclosure Attacks
abstract
Code diversification is an effective strategy to prevent modern code-reuse exploits. Unfortunately, diversification techniques are inherently vulnerable to information disclosure. Recent diversification-aware ROP exploits have demonstrated that code disclosure attacks are a realistic threat, with an attacker able to read or execute arbitrary code memory and gather enough gadgets to bypass state-of-the-art code diversification defenses. In this paper, we present CodeArmor, a binary-level system to harden code diversification against all the existing read-based and execution-based code disclosure attacks. To counter such attacks, CodeArmor virtualizes the code space to completely decouple code pointer values from the concrete location of their targets in the memory address space. Using a combination of run-time randomization and pervasively deployed honey gadgets, code space virtualization probabilistically ensures that only code references that can legitimately be issued by the program are effectively translated to the concrete code space. This strategy significantly reduces the attack surface, limiting the attacker to only code pointer gadgets that can be leaked from data memory. In addition, unlike existing leakage-resistant code diversification techniques that provide similar security guarantees, CodeArmor requires no access to source code, hypervisors, or special hardware support. Our experimental results show that CodeArmor significantly raises the bar against existing and future attacks, at the cost of relatively low average performance overhead (6.9% on SPEC and 14.5% on popular server programs, and even lower-roughly halving such average overheads-when operating aggressive inlining optimizations at the binary level).
Xi Chen 0038, Herbert Bos, Cristiano Giuffrida
EuroS&P1
2017 No Need to Hide: Protecting Safe Regions on Commodity Hardware
abstract
As modern 64-bit x86 processors no longer support the segmentation capabilities of their 32-bit predecessors, most research projects assume that strong in-process memory isolation is no longer an affordable option. Instead of strong, deterministic isolation, new defense systems therefore rely on the probabilistic pseudo-isolation provided by randomization to "hide" sensitive (or safe) regions. However, recent attacks have shown that such protection is insufficient; attackers can leak these safe regions in a variety of ways.
Koen Koning, Xi Chen 0038, Herbert Bos, Cristiano Giuffrida, Elias Athanasopoulos
EuroSys2
2017 DSIbin: identifying dynamic data structures in C/C++ binaries
abstract
Reverse engineering binary code is notoriously difficult and, especially, understanding a binary's dynamic data structures. Existing data structure analyzers are limited wrt. program comprehension: they do not detect complex structures such as skip lists, or lists running through nodes of different types such as in the Linux kernel's cyclic doubly-linked list. They also do not reveal complex parent-child relationships between structures. The tool DSI remedies these shortcomings but requires source code, where type information on heap nodes is available. We present DSIbin, a combination of DSI and the type excavator Howard for the inspection of C/C++ binaries. While a naive combination already improves upon related work, its precision is limited because Howard's inferred types are often too coarse. To address this we auto-generate candidates of refined types based on speculative nested-struct detection and type merging; the plausibility of these hypotheses is then validated by DSI. We demonstrate via benchmarking that DSIbin detects data structures with high precision.
Thomas Rupprecht, Xi Chen 0038, David H. White 0001, Jan H. Boockmann, Gerald Lüttgen, Herbert Bos
ASE2
2016 POSTER: Identifying Dynamic Data Structures in Malware
abstract
As the complexity of malware grows, so does the necessity of employing program structuring mechanisms during development. While control flow structuring is often obfuscated, the dynamic data structures employed by the program are typically untouched. We report on work in progress that exploits this weakness to identify dynamic data structures present in malware samples for the purposes of aiding reverse engineering and constructing malware signatures, which may be employed for malware classification. Using a prototype implementation, which combines the type recovery tool Howard and the identification tool Data Structure Investigator (DSI), we analyze data structures in Carberp and AgoBot malware. Identifying their data structures illustrates a challenging problem. To tackle this, we propose a new type recovery for binaries based on machine learning, which uses Howard's types to guide the search and DSI's memory abstraction for hypothesis evaluation.
Thomas Rupprecht, Xi Chen 0038, David H. White 0001, Jan Tobias Mühlberg, Herbert Bos, Gerald Lüttgen
CCS2
2016 A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary Level
abstract
Current binary-level Control-Flow Integrity (CFI) techniques are weak in determining the set of valid targets for indirect control flow transfers on the forward edge. In particular, the lack of source code forces existing techniques to resort to a conservative address-taken policy that overapproximates this set. In contrast, source-level solutions can accurately infer the targets of indirect calls and thus detect malicious control-flow transfers more precisely. Given that source code is not always available, however, offering similar quality of protection at the binary level is important, but, unquestionably, more challenging than ever: recent work demonstrates powerful attacks such as Counterfeit Object-oriented Programming (COOP), which made the community believe that protecting software against control-flow diversion attacks at the binary level is rather impossible. In this paper, we propose binary-level analysis techniques to significantly reduce the number of possible targets for indirect branches. More specifically, we reconstruct a conservative approximation of target function prototypes by means of use-def analysis at possible callees. We then couple this with liveness analysis at each indirect callsite to derive a many-to-many relationship between callsites and target callees with a much higher precision compared to prior binary-level solutions. Experimental results on popular server programs and on SPEC CPU2006 show that TypeArmor, a prototype implementation of our approach, is efficient - with a runtime overhead of less than 3%. Furthermore, we evaluate to what extent TypeArmor can mitigate COOP and other advanced attacks and show that our approach can significantly reduce the number of targets on the forward edge. Moreover, we show that TypeArmor breaks published COOP exploits, providing concrete evidence that strict binary-level CFI can still mitigate advanced attacks, despite the absence of source information or C++ semantics.
Victor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski, Xi Chen 0038, Sanjay Rawat 0001, Herbert Bos, Thorsten Holz, Elias Athanasopoulos, Cristiano Giuffrida
IEEE Symposium on Security and Privacy5
2016 An In-Depth Analysis of Disassembly on Full-Scale x86/x64 Binaries
Dennis Andriesse, Xi Chen 0038, Victor van der Veen, Asia Slowinska, Herbert Bos
USENIX Security Symposium2
2016 On the detection of custom memory allocators in C binaries
abstract
Many reverse engineering techniques for data structures rely on the knowledge of memory allocation routines. Typically, they interpose on the system’s malloc and free functions, and track each chunk of memory thus allocated as a data structure. However, many performance-critical applications implement their own custom memory allocators. Examples include webservers, database management systems, and compilers like gcc and clang. As a result, current binary analysis techniques for tracking data structures fail on such binaries. We present MemBrush, a new tool to detect memory allocation and deallocation functions in stripped binaries with high accuracy. We evaluated the technique on a large number of real world applications that use custom memory allocators. We demonstrate that MemBrush can detect allocators/deallocators with a high accuracy which is 52 out of 59 for allocators, and 29 out of 31 for deallocators in SPECINT 2006. As we show, we can furnish existing reverse engineering tools with detailed information about the memory management API, and as a result perform an analysis of the actual application specific data structures designed by the programmer. Our system uses dynamic analysis and detects memory allocation and deallocation routines by searching for functions that comply with a set of generic characteristics of allocators and deallocators.
Xi Chen 0038, Asia Slowinska, Herbert Bos
Empir. Softw. Eng.1
2015 StackArmor: Comprehensive Protection From Stack-based Memory Error Vulnerabilities for Binaries
Xi Chen 0038, Asia Slowinska, Dennis Andriesse, Herbert Bos, Cristiano Giuffrida
NDSS1