EDBT 2026 Demo / reviewers in the wild / expert
Xi Chen 0038
dblp:16/3283-38
· DBLP profile ↗
9ranked-venue papers
3as first author
0since 2021 · last 2017
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-authorSystems, architecture and hardware · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
6 papers |
Systems and software security · 90% Hardware security and side channels · 8% Privacy and data protection · 2% | |
| Software engineering, system software, and programming languages
5 papers |
Program analysis · 71% Software maintenance and evolution · 18% Programming languages and type systems · 10% |
Topics — the 19 heaviest of 19, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Program analysis
binary analysis |
0.6 | 3 | 2017 | DSIbin: identifying dynamic data structures in C/C++ binaries · ASE 2017 StackArmor: Comprehensive Protection From Stack-based Memory Error Vulnerabilities for Binaries · NDSS 2015 A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary Level · IEEE Symposium on Security and Privacy 2016 |
Systems and software security
exploitation |
0.5 | 2 | 2017 | The Dynamics of Innocent Flesh on the Bone: Code Reuse Ten Years Later · CCS 2017 A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary Level · IEEE Symposium on Security and Privacy 2016 |
Systems and software security › return-oriented programming defense
code reuse attack defense |
0.3 | 2 | 2017 | A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary Level · IEEE Symposium on Security and Privacy 2016 The Dynamics of Innocent Flesh on the Bone: Code Reuse Ten Years Later · CCS 2017 |
Systems and software security › exploitation
code reuse attack |
0.3 | 1 | 2017 | The Dynamics of Innocent Flesh on the Bone: Code Reuse Ten Years Later · CCS 2017 |
Systems and software security › memory safety › memory isolation
in-process isolation |
0.3 | 1 | 2017 | No Need to Hide: Protecting Safe Regions on Commodity Hardware · EuroSys 2017 |
Systems and software security › memory safety
memory isolation |
0.3 | 1 | 2017 | No Need to Hide: Protecting Safe Regions on Commodity Hardware · EuroSys 2017 |
Systems and software security › exploitation › code reuse attack
return-oriented programming |
0.3 | 1 | 2017 | The Dynamics of Innocent Flesh on the Bone: Code Reuse Ten Years Later · CCS 2017 |
Hardware security and side channels
side-channel attack |
0.3 | 1 | 2017 | No Need to Hide: Protecting Safe Regions on Commodity Hardware · EuroSys 2017 |
Program analysis › heap analysis
data structure identification |
0.3 | 1 | 2017 | DSIbin: identifying dynamic data structures in C/C++ binaries · ASE 2017 |
Software maintenance and evolution
reverse engineering |
0.3 | 1 | 2017 | DSIbin: identifying dynamic data structures in C/C++ binaries · ASE 2017 |
Systems and software security
binary analysis |
0.2 | 1 | 2016 | An In-Depth Analysis of Disassembly on Full-Scale x86/x64 Binaries · USENIX Security Symposium 2016 |
Systems and software security › binary analysis
binary type recovery |
0.2 | 1 | 2016 | POSTER: Identifying Dynamic Data Structures in Malware · CCS 2016 |
Systems and software security › memory safety
control-flow integrity |
0.2 | 1 | 2016 | A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary Level · IEEE Symposium on Security and Privacy 2016 |
Systems and software security › software protection
binary protection |
0.2 | 1 | 2015 | StackArmor: Comprehensive Protection From Stack-based Memory Error Vulnerabilities for Binaries · NDSS 2015 |
Systems and software security
memory safety |
0.2 | 1 | 2015 | StackArmor: Comprehensive Protection From Stack-based Memory Error Vulnerabilities for Binaries · NDSS 2015 |
Program analysis
static analysis |
0.2 | 2 | 2017 | DSIbin: identifying dynamic data structures in C/C++ binaries · ASE 2017 POSTER: Identifying Dynamic Data Structures in Malware · CCS 2016 |
Programming languages and type systems
type inference |
0.2 | 2 | 2017 | DSIbin: identifying dynamic data structures in C/C++ binaries · ASE 2017 POSTER: Identifying Dynamic Data Structures in Malware · CCS 2016 |
Privacy and data protection
randomization |
0.1 | 1 | 2017 | No Need to Hide: Protecting Safe Regions on Commodity Hardware · EuroSys 2017 |
Program analysis › binary analysis
disassembly |
0.1 | 1 | 2016 | An In-Depth Analysis of Disassembly on Full-Scale x86/x64 Binaries · USENIX Security Symposium 2016 |
Methods — techniques the papers use, named apart from their topics
use-def analysis · 0.5memory abstraction · 0.5machine learning · 0.5liveness analysis · 0.5empirical analysis · 0.5binary instrumentation · 0.4type merging · 0.3survey · 0.3speculative nested-struct detection · 0.3segmentation · 0.3randomization · 0.3historical analysis · 0.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2017 | The Dynamics of Innocent Flesh on the Bone: Code Reuse Ten Years LaterabstractIn 2007, Shacham published a seminal paper on Return-Oriented Programming (ROP), the first systematic formulation of code reuse. The paper has been highly influential, profoundly shaping the way we still think about code reuse today: an attacker analyzes the "geometry" of victim binary code to locate gadgets and chains these to craft an exploit. This model has spurred much research, with a rapid progression of increasingly sophisticated code reuse attacks and defenses over time. After ten years, the common perception is that state-of-the-art code reuse defenses are effective in significantly raising the bar and making attacks exceedingly hard. Victor van der Veen, Dennis Andriesse, Manolis Stamatogiannakis, Xi Chen 0038, Herbert Bos, Cristiano Giuffrida |
CCS | 4 |
| 2017 | CodeArmor: Virtualizing the Code Space to Counter Disclosure AttacksabstractCode diversification is an effective strategy to prevent modern code-reuse exploits. Unfortunately, diversification techniques are inherently vulnerable to information disclosure. Recent diversification-aware ROP exploits have demonstrated that code disclosure attacks are a realistic threat, with an attacker able to read or execute arbitrary code memory and gather enough gadgets to bypass state-of-the-art code diversification defenses. In this paper, we present CodeArmor, a binary-level system to harden code diversification against all the existing read-based and execution-based code disclosure attacks. To counter such attacks, CodeArmor virtualizes the code space to completely decouple code pointer values from the concrete location of their targets in the memory address space. Using a combination of run-time randomization and pervasively deployed honey gadgets, code space virtualization probabilistically ensures that only code references that can legitimately be issued by the program are effectively translated to the concrete code space. This strategy significantly reduces the attack surface, limiting the attacker to only code pointer gadgets that can be leaked from data memory. In addition, unlike existing leakage-resistant code diversification techniques that provide similar security guarantees, CodeArmor requires no access to source code, hypervisors, or special hardware support. Our experimental results show that CodeArmor significantly raises the bar against existing and future attacks, at the cost of relatively low average performance overhead (6.9% on SPEC and 14.5% on popular server programs, and even lower-roughly halving such average overheads-when operating aggressive inlining optimizations at the binary level). Xi Chen 0038, Herbert Bos, Cristiano Giuffrida |
EuroS&P | 1 |
| 2017 | No Need to Hide: Protecting Safe Regions on Commodity HardwareabstractAs modern 64-bit x86 processors no longer support the segmentation capabilities of their 32-bit predecessors, most research projects assume that strong in-process memory isolation is no longer an affordable option. Instead of strong, deterministic isolation, new defense systems therefore rely on the probabilistic pseudo-isolation provided by randomization to "hide" sensitive (or safe) regions. However, recent attacks have shown that such protection is insufficient; attackers can leak these safe regions in a variety of ways. Koen Koning, Xi Chen 0038, Herbert Bos, Cristiano Giuffrida, Elias Athanasopoulos |
EuroSys | 2 |
| 2017 | DSIbin: identifying dynamic data structures in C/C++ binariesabstractReverse engineering binary code is notoriously difficult and, especially, understanding a binary's dynamic data structures. Existing data structure analyzers are limited wrt. program comprehension: they do not detect complex structures such as skip lists, or lists running through nodes of different types such as in the Linux kernel's cyclic doubly-linked list. They also do not reveal complex parent-child relationships between structures. The tool DSI remedies these shortcomings but requires source code, where type information on heap nodes is available. We present DSIbin, a combination of DSI and the type excavator Howard for the inspection of C/C++ binaries. While a naive combination already improves upon related work, its precision is limited because Howard's inferred types are often too coarse. To address this we auto-generate candidates of refined types based on speculative nested-struct detection and type merging; the plausibility of these hypotheses is then validated by DSI. We demonstrate via benchmarking that DSIbin detects data structures with high precision. Thomas Rupprecht, Xi Chen 0038, David H. White 0001, Jan H. Boockmann, Gerald Lüttgen, Herbert Bos |
ASE | 2 |
| 2016 | POSTER: Identifying Dynamic Data Structures in MalwareabstractAs the complexity of malware grows, so does the necessity of employing program structuring mechanisms during development. While control flow structuring is often obfuscated, the dynamic data structures employed by the program are typically untouched. We report on work in progress that exploits this weakness to identify dynamic data structures present in malware samples for the purposes of aiding reverse engineering and constructing malware signatures, which may be employed for malware classification. Using a prototype implementation, which combines the type recovery tool Howard and the identification tool Data Structure Investigator (DSI), we analyze data structures in Carberp and AgoBot malware. Identifying their data structures illustrates a challenging problem. To tackle this, we propose a new type recovery for binaries based on machine learning, which uses Howard's types to guide the search and DSI's memory abstraction for hypothesis evaluation. Thomas Rupprecht, Xi Chen 0038, David H. White 0001, Jan Tobias Mühlberg, Herbert Bos, Gerald Lüttgen |
CCS | 2 |
| 2016 | A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary LevelabstractCurrent binary-level Control-Flow Integrity (CFI) techniques are weak in determining the set of valid targets for indirect control flow transfers on the forward edge. In particular, the lack of source code forces existing techniques to resort to a conservative address-taken policy that overapproximates this set. In contrast, source-level solutions can accurately infer the targets of indirect calls and thus detect malicious control-flow transfers more precisely. Given that source code is not always available, however, offering similar quality of protection at the binary level is important, but, unquestionably, more challenging than ever: recent work demonstrates powerful attacks such as Counterfeit Object-oriented Programming (COOP), which made the community believe that protecting software against control-flow diversion attacks at the binary level is rather impossible. In this paper, we propose binary-level analysis techniques to significantly reduce the number of possible targets for indirect branches. More specifically, we reconstruct a conservative approximation of target function prototypes by means of use-def analysis at possible callees. We then couple this with liveness analysis at each indirect callsite to derive a many-to-many relationship between callsites and target callees with a much higher precision compared to prior binary-level solutions. Experimental results on popular server programs and on SPEC CPU2006 show that TypeArmor, a prototype implementation of our approach, is efficient - with a runtime overhead of less than 3%. Furthermore, we evaluate to what extent TypeArmor can mitigate COOP and other advanced attacks and show that our approach can significantly reduce the number of targets on the forward edge. Moreover, we show that TypeArmor breaks published COOP exploits, providing concrete evidence that strict binary-level CFI can still mitigate advanced attacks, despite the absence of source information or C++ semantics. Victor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski, Xi Chen 0038, Sanjay Rawat 0001, Herbert Bos, Thorsten Holz, Elias Athanasopoulos, Cristiano Giuffrida |
IEEE Symposium on Security and Privacy | 5 |
| 2016 | An In-Depth Analysis of Disassembly on Full-Scale x86/x64 Binaries
Dennis Andriesse, Xi Chen 0038, Victor van der Veen, Asia Slowinska, Herbert Bos |
USENIX Security Symposium | 2 |
| 2016 | On the detection of custom memory allocators in C binariesabstractMany reverse engineering techniques for data structures rely on the knowledge of memory allocation routines. Typically, they interpose on the system’s malloc and free functions, and track each chunk of memory thus allocated as a data structure. However, many performance-critical applications implement their own custom memory allocators. Examples include webservers, database management systems, and compilers like gcc and clang. As a result, current binary analysis techniques for tracking data structures fail on such binaries. We present MemBrush, a new tool to detect memory allocation and deallocation functions in stripped binaries with high accuracy. We evaluated the technique on a large number of real world applications that use custom memory allocators. We demonstrate that MemBrush can detect allocators/deallocators with a high accuracy which is 52 out of 59 for allocators, and 29 out of 31 for deallocators in SPECINT 2006. As we show, we can furnish existing reverse engineering tools with detailed information about the memory management API, and as a result perform an analysis of the actual application specific data structures designed by the programmer. Our system uses dynamic analysis and detects memory allocation and deallocation routines by searching for functions that comply with a set of generic characteristics of allocators and deallocators. Xi Chen 0038, Asia Slowinska, Herbert Bos |
Empir. Softw. Eng. | 1 |
| 2015 | StackArmor: Comprehensive Protection From Stack-based Memory Error Vulnerabilities for Binaries
Xi Chen 0038, Asia Slowinska, Dennis Andriesse, Herbert Bos, Cristiano Giuffrida |
NDSS | 1 |