Yueqi Chen 0001

dblp:16/6884-1 · DBLP profile ↗
← Back
18ranked-venue papers
2as first author
10since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 14 · 2 first-author · 9 since 2021Software engineering, systems software and programming languages · 3Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Quantum Methods for Boundary Checking in Classical Programs
abstract
Boundary violations—array out-of-bounds accesses, integer overflows, and stray pointer offsets—remain a leading cause of software failure. Classical analyses such as abstract interpretation and symbolic execution try to detect such errors, yet the exponential growth of program states forces them to trade precision for scalability. We introduce QCheck, the first quantum framework aimed at boundary checking of classical programs.
Yicheng Guang, Pietro Zanotta, Yueqi Chen 0001, Ramin Ayanzadeh
MobiSys4
2025 Lancet: A Formalization Framework for Crash and Exploit Pathology
Qinrun Dai, Kirby Linvill, Yueqi Chen 0001, Gowtham Kaki
USENIX Security Symposium3
2024 TGRop: Top Gun of Return-Oriented Programming Automation
Nanyu Zhong, Yueqi Chen 0001, Yanyan Zou 0002, Xinyu Xing 0001, Jinwei Dong, Bingcheng Xian, Jiaxu Zhao 0004, Binghong Liu, Wei Huo 0005
ESORICS (3)2
2024 SeaK: Rethinking the Design of a Secure Allocator for OS Kernel
Zicheng Wang 0010, Yicheng Guang, Yueqi Chen 0001, Zhenpeng Lin, Michael V. Le, Dang K. Le, Dan Williams 0001, Xinyu Xing 0001, Zhongshu Gu, Hani Jamjoom
USENIX Security Symposium3
2024 Towards Unveiling Exploitation Potential With Multiple Error Behaviors for Kernel Bugs
abstract
Nowadays, fuzz testing has significantly expedited the vulnerability discovery of Linux kernel. Security analysts use the manifested error behaviors to infer the exploitability of one bug and thus prioritize the patch development. However, only using an error behavior in the report, security analysts might underestimate the exploitability of the kernel bug because it could manifest various error behaviors indicating different exploitation potentials. In this work, we conduct an empirical study on multiple error behaviors of kernel bugs to understand 1) the prevalence of multiple error behaviors and the possible impact of multiple error behaviors towards the exploitation potential; 2) the factors that manifest multiple error behaviors with different exploitation potential. We collectedall the fixed kernel bugsreported on Syzbot from September 2017 to January 2022, including 3,352 bug reports. We observed that multiple error behaviors manifested by kernel bugs are prevalent in the real world, and more error behaviors help unveil the exploitability of kernel bugs. Then we organized Linux kernel experts to analyze a sample of kernel bug dataset (484 bug reports, unique 162 bugs) and identified 6 key contributing factors to the mutiple error behaviors. Finally, based on the empirical findings, we propose an object-driven fuzzing technique to explore all possible error behaviors that a kernel bug might bring about. To evaluate the utility of our proposed technique, we implement our fuzzing toolGREBEand apply it to 60 real-world Linux kernel bugs. On average,GREBEcould manifest 2+ additional error behaviors for each of the kernel bugs. For 26 kernel bugs,GREBEdiscovers higher exploitation potential. We report to kernel vendors some of the bugs – the exploitability of which was wrongly assessed and the corresponding patch has not yet been carefully applied – resulting in their rapid patch adoption.
Ziqin Liu, Zhenpeng Lin, Yueqi Chen 0001, Yuhang Wu 0003, Yalong Zou, Dongliang Mu, Xinyu Xing 0001
IEEE Trans. Dependable Secur. Comput.3
2023 PET: Prevent Discovered Errors from Being Triggered in the Linux Kernel
Zicheng Wang 0010, Yueqi Chen 0001, Qingkai Zeng 0002
USENIX Security Symposium2
2023 Mitigating Security Risks in Linux with KLAUS: A Method for Evaluating Patch Correctness
Yuhang Wu 0003, Zhenpeng Lin, Yueqi Chen 0001, Dang K. Le, Dongliang Mu, Xinyu Xing 0001
USENIX Security Symposium3
2022 An In-depth Analysis of Duplicated Linux Kernel Bug Reports
Dongliang Mu, Yuhang Wu 0003, Yueqi Chen 0001, Zhenpeng Lin, Chensheng Yu, Xinyu Xing 0001, Gang Wang 0011
NDSS3
2022 GREBE: Unveiling Exploitation Potential for Linux Kernel Bugs
abstract
Nowadays, dynamic testing tools have significantly expedited the discovery of bugs in the Linux kernel. When unveiling kernel bugs, they automatically generate reports, specifying the errors the Linux encounters. The error in the report implies the possible exploitability of the corresponding kernel bug. As a result, many security analysts use the manifested error to infer a bug’s exploitability and thus prioritize their exploit development effort. However, using the error in the report, security researchers might underestimate a bug’s exploitability. The error exhibited in the report may depend upon how the bug is triggered. Through different paths or under different contexts, a bug may manifest various error behaviors implying very different exploitation potentials. This work proposes a new kernel fuzzing technique to explore all the possible error behaviors that a kernel bug might bring about. Unlike conventional kernel fuzzing techniques concentrating on kernel code coverage, our fuzzing technique is more directed towards the buggy code fragment. It introduces an object-driven kernel fuzzing technique to explore various contexts and paths to trigger the reported bug, making the bug manifest various error behaviors. With the newly demonstrated errors, security researchers could better infer a bug’s possible exploitability. To evaluate our proposed technique’s effectiveness, efficiency, and impact, we implement our fuzzing technique as a tool GREBE and apply it to 60 real-world Linux kernel bugs. On average, GREBE could manifest 2+ additional error behaviors for each of the kernel bugs. For 26 kernel bugs, GREBE discovers higher exploitation potential. We report to kernel vendors some of the bugs – the exploitability of which was wrongly assessed and the corresponding patch has not yet been carefully applied – resulting in their rapid patch adoption.
Zhenpeng Lin, Yueqi Chen 0001, Yuhang Wu 0003, Dongliang Mu, Chensheng Yu, Xinyu Xing 0001
SP2
2022 Playing for K(H)eaps: Understanding and Improving Linux Kernel Exploit Reliability
Kyle Zeng, Yueqi Chen 0001, Haehyun Cho, Xinyu Xing 0001, Adam Doupé, Yan Shoshitaishvili, Tiffany Bao
USENIX Security Symposium2
2020 A Systematic Study of Elastic Objects in Kernel Exploitation
abstract
Recent research has proposed various methods to perform kernel exploitation and bypass kernel protection. For example, security researchers have demonstrated an exploitation method that utilizes the characteristic of elastic kernel objects to bypass KASLR, disclose stack/heap cookies, and even perform arbitrary read in the kernel. While this exploitation method is considered a commonly adopted approach to disclosing critical kernel information, there is no evidence indicating a strong need for developing a new defense mechanism to limit this exploitation method. It is because the effectiveness of this exploitation method is demonstrated only on anecdotal kernel vulnerabilities. It is unclear whether such a method is useful for a majority of kernel vulnerabilities.
Yueqi Chen 0001, Zhenpeng Lin, Xinyu Xing 0001
CCS1
2020 SpecuSym: speculative symbolic execution for cache timing leak detection
abstract
CPU cache is a limited but crucial storage component in modern processors, whereas the cache timing side-channel may inadvertently leak information through the physically measurable timing variance. Speculative execution, an essential processor optimization, and a source of such variances, can cause severe detriment on deliberate branch mispredictions. Despite static analysis could qualitatively verify the timing-leakage-free property under speculative execution, it is incapable of producing endorsements including inputs and speculated flows to diagnose leaks in depth. This work proposes a new symbolic execution based method, SpecuSym, for precisely detecting cache timing leaks introduced by speculative execution. Given a program (leakage-free in non-speculative execution), SpecuSym systematically explores the program state space, models speculative behavior at conditional branches, and accumulates the cache side effects along with subsequent path explorations. During the dynamic execution, SpecuSym constructs leak predicates for memory visits according to the specified cache model and conducts a constraint-solving based cache behavior analysis to inspect the new cache behaviors. We have implemented SpecuSym atop KLEE and evaluated it against 15 open-source benchmarks. Experimental results show that SpecuSym successfully detected from 2 to 61 leaks in 6 programs under 3 different cache settings and identified false positives in 2 programs reported by recent work.
Shengjian Guo, Yueqi Chen 0001, Yueqiang Cheng, Huibo Wang, Zhiqiang Zuo 0002
ICSE2
2020 Exposing cache timing side-channel leaks through out-of-order symbolic execution
abstract
As one of the fundamental optimizations in modern processors, the out-of-order execution boosts the pipeline throughput by executing independent instructions in parallel rather than in their program orders. However, due to the side effects introduced by such microarchitectural optimization to the CPU cache, secret-critical applications may suffer from timing side-channel leaks. This paper presents a symbolic execution-based technique, named SymO 3 , for exposing cache timing leaks under the context of out-of-order execution. SymO 3 proposes new components that address the modeling, reduction, and reasoning challenges of accommodating program analysis to the software code out-of-order analysis. We implemented SymO 3 upon KLEE and conducted three evaluations on it. Experimental results show that SymO 3 successfully uncovers a set of cache timing leaks in five real-world programs. Also, SymO 3 finds that, in general, program transformation from compiler optimizations shrink the surface to timing leaks. Furthermore, augmented with a speculative execution modeling, SymO 3 identifies five more leaky programs based on the compound analysis.
Shengjian Guo, Yueqi Chen 0001, Jiyong Yu, Zhiqiang Zuo 0002, Yueqiang Cheng, Huibo Wang
Proc. ACM Program. Lang.2
2019 SLAKE: Facilitating Slab Manipulation for Exploiting Vulnerabilities in the Linux Kernel
abstract
To determine the exploitability for a kernel vulnerability, a secu- rity analyst usually has to manipulate slab and thus demonstrate the capability of obtaining the control over a program counter or performing privilege escalation. However, this is a lengthy process because (1) an analyst typically has no clue about what objects and system calls are useful for kernel exploitation and (2) he lacks the knowledge of manipulating a slab and obtaining the desired layout. In the past, researchers have proposed various techniques to facilitate exploit development. Unfortunately, none of them can be easily applied to address these challenges. On the one hand, this is because of the complexity of the Linux kernel. On the other hand, this is due to the dynamics and non-deterministic of slab variations. In this work, we tackle the challenges above from two perspectives. First, we use static and dynamic analysis techniques to explore the kernel objects, and the corresponding system calls useful for exploitation. Second, we model commonly-adopted exploitation methods and develop a technical approach to facilitate the slab layout adjustment. By extending LLVM as well as Syzkaller, we implement our techniques and name their combination after SLAKE. We evaluate SLAKE by using 27 real-world kernel vulnerabilities, demonstrating that it could not only diversify the ways to perform kernel exploitation but also sometimes escalate the exploitability of kernel vulnerabilities.
Yueqi Chen 0001, Xinyu Xing 0001
CCS1
2019 RENN: Efficient Reverse Execution with Neural-Network-Assisted Alias Analysis
abstract
Reverse execution and coredump analysis have long been used to diagnose the root cause of software crashes. Each of these techniques, however, face inherent challenges, such as insufficient capability when handling memory aliases. Recent works have used hypothesis testing to address this drawback, albeit with high computational complexity, making them impractical for real world applications. To address this issue, we propose a new deep neural architecture, which could significantly improve memory alias resolution. At the high level, our approach employs a recurrent neural network (RNN) to learn the binary code pattern pertaining to memory accesses. It then infers the memory region accessed by memory references. Since memory references to different regions naturally indicate a non-alias relationship, our neural architecture can greatly reduce the burden of doing hypothesis testing to track down non-alias relation in binary code. Different from previous researches that have utilized deep learning for other binary analysis tasks, the neural network proposed in this work is fundamentally novel. Instead of simply using off-the-shelf neural networks, we designed a new recurrent neural architecture that could capture the data dependency between machine code segments. To demonstrate the utility of our deep neural architecture, we implement it as RENN, a neural network-assisted reverse execution system. We utilize this tool to analyze software crashes corresponding to 40 memory corruption vulnerabilities from the real world. Our experiments show that RENN can significantly improve the efficiency of locating the root cause for the crashes. Compared to a state-of-the-art technique, RENN has 36.25% faster execution time on average, detects an average of 21.35% more non-alias pairs, and successfully identified the root cause of 12.5% more cases.
Dongliang Mu, Wenbo Guo 0002, Alejandro Cuevas, Yueqi Chen 0001, Jinxuan Gai, Xinyu Xing 0001, Bing Mao 0001, Chengyu Song
ASE4
2019 Towards the Detection of Inconsistencies in Public Security Vulnerability Reports
Wenbo Guo 0002, Yueqi Chen 0001, Xinyu Xing 0001, Gang Wang 0011
USENIX Security Symposium3
2019 KEPLER: Facilitating Control-flow Hijacking Primitive Evaluation for Linux Kernel Vulnerabilities
Wei Wu 0010, Yueqi Chen 0001, Xinyu Xing 0001
USENIX Security Symposium2
2018 FUZE: Towards Facilitating Exploit Generation for Kernel Use-After-Free Vulnerabilities
Wei Wu 0010, Yueqi Chen 0001, Jun Xu 0024, Xinyu Xing 0001, Xiaorui Gong
USENIX Security Symposium2