Shichao Lv

dblp:176/7476 · DBLP profile ↗
← Back
44ranked-venue papers
3as first author
32since 2021 · last 2026
0000-0002-0549-0999ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 18 · 2 first-author · 10 since 2021Security and privacy · 10 · 9 since 2021Software engineering, systems software and programming languages · 6 · 6 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2026 HoneyGPT: Breaking the trilemma in honeypots with large language models
Jianzhou You, Haining Wang 0001, Tianwei Yuan, Shichao Lv, Yang Wang 0006, Limin Sun 0001
Comput. Networks5
2026 A tolerance analysis framework for microservice-based systems against cascading failures
abstract
Abstract Microservice has become a dominant approach for building large-scale Internet applications. The microservice-based system (MS) consists of thousands of services, and its complex interactions make it highly susceptible to unforeseen cascading failures. Cascading failure models are commonly used to analyze the system’s tolerance, while the existing models overlook MS’s features and fail to incorporate real-world events, leading to bias in simulation results. To address these, we proposed a comprehensive tolerance analysis framework of MS named the MSTAF. Specifically, we extracted the real-world failure-triggering scenarios and constructed the Workload-based Cascading Failure Model (WL-CFM) to model the load initialization and redistribution. Then, we implemented the Business Loss Assessment Method (BLAM) to quantify the impact by calculating the workload loss. To validate our MSTAF, we conducted experiments on the WL-CFM and BMAL and performed an analysis on the TrainTicket (TT). The results confirm the MSTAF’s superiority. Specifically, the WL-CFM outperforms baselines, reducing simulation error by 10– 48%. The BMAL demonstrates greater accuracy, with deviations from the ground truth ranging from $$-45$$ - 45 % to + 7%. Overall, the MSTAF offers valuable insights for enhancing tolerance and provides an effective solution for developers and researchers.
Chunyang Zheng, Shuaizong Si, Xiaoxi Wang, Jinfa Wang, Shichao Lv, Limin Sun 0001
Cybersecur.6
2026 Nonlinear Optimal Control for Mismatched Disturbance Rejection and Its Application to AGV
abstract
This paper addresses the challenge of mismatched disturbance rejection in nonlinear discrete-time systems by proposing a novel model predictive control algorithm based on optimal control theory, which significantly enhances disturbance rejection performance. The algorithm constructs a concise yet effective performance index capable of handling both matched and mismatched disturbances by incorporating a disturbance observer, thereby simultaneously fulfilling the dual objectives of trajectory tracking and disturbance attenuation. To improve computational efficiency, a solution method grounded in optimal control theory is devised, enabling rapid online controller computation. This approach ensures superior real-time performance while delivering more efficient tracking and disturbance rejection. The effectiveness of the proposed algorithm is validated through simulations and experimental tests on an automated guided vehicle platform. Results show that the algorithm achieves outstanding performance in both disturbance rejection and computational efficiency, markedly surpassing conventional methods. It can effectively withstand unknown disturbances while meeting the real-time and reliability demands of practical engineering applications, demonstrating broad prospects for deployment in real-world systems.
Xunmin Yin, Chuanzhi Lv, Shichao Lv, Xuezhen Cheng, Huanshui Zhang
IEEE Trans Autom. Sci. Eng.3
2026 TLCFI-PLC: Trampoline-Based Lightweight Control Flow Integrity Scheme for Protecting PLC
Kaixiang Liu, Junjiao Liu, Zhiwen Pan, Shichao Lv, Xin Chen 0123, Zhi Li 0018, Yuqi Chen 0001, Limin Sun 0001
IEEE Trans. Inf. Forensics Secur.4
2026 Vercation: Precise Vulnerable Open-Source Software Version Identification Based on Static Analysis and LLM
abstract
Open-source software (OSS) has experienced a surge in popularity, attributed to its collaborative development model and cost-effective nature. However, the adoption of specific software versions in development projects may introduce security risks when these versions bring along vulnerabilities. Current methods of identifying vulnerable versions typically analyze and extract the code features involved in vulnerability patches using static analysis with pre-defined rules. They then use code clone detection to identify the vulnerable versions. These methods are hindered by imprecision due to (1) the exclusion of vulnerability-irrelevant code in the analysis and (2) the inadequacy of code clone detection. This paper presents VERCATION, an approach designed to identify vulnerable versions of OSS written in C/C++. VERCATION combines program slicing with a Large Language Model (LLM) to identify vulnerability-relevant code from vulnerability patches. It then backtracks historical commits to gather previous modifications of identified vulnerability-relevant code. We propose code clone detection based on expanded and normalized ASTs to compare the differences between pre-modification and post-modification code, thereby locating the vulnerability-introducing commit (vic) and enabling the identification of the vulnerable versions between the vulnerability-fixing commit and thevic. We curate a dataset linking 122 OSS vulnerabilities and 1,211 versions to evaluate VERCATION. On this dataset, our approach achieves an F1 score of 93.1%, outperforming current state-of-the-art methods. More importantly, VERCATION detected 202 incorrect vulnerable OSS versions in NVD reports.
Yiran Cheng, Ting Zhang 0011, Lwin Khin Shar, Shouguo Yang, Chaopeng Dong, David Lo 0001, Shichao Lv, Zhiqiang Shi, Limin Sun 0001
IEEE Trans. Software Eng.7
2025 PNetGPT: Proprietary Protocol Network Traffic Generation with Pre-trained Transformer
abstract
Generative pre-trained transformers are exceedingly effective as generative models and classifiers, widely used in natural language processing and computer vision. This work contributes to the exploration of generative pre-trained transformer-based models in the proprietary protocol network traffic. However, building a pre-trained model for proprietary protocol network traffic is non-trivial due to the heterogeneous unknown formats and the extreme scarcity of proprietary protocol network traffic datasets. In this paper, we present PNetGPT, a pre-trained transformer-based model for generating proprietary protocol network traffic. We have constructed the inaugural dataset of 2 real-world proprietary protocols. After training on this dataset, PNetGPT possesses the capacity to generate high-quality proprietary protocol network traffic to support various applications of proprietary protocols, including reverse analysis, protocol fuzzy testing, intrusion detection, etc. We evaluated PNetGPT with two real proprietary protocols and demonstrated state-of-the-art (SOTA) performance in handling heterogeneous unknown formats. The code and datasets are available at: https://github.com/Snail1502/PNetGPT
Zedong Li, Dongliang Fang, Xin Chen 0123, Zhanwei Song, Zhi Li 0018, Shichao Lv, Limin Sun 0001
ICASSP7
2025 Moye: A Wallbreaker for Monolithic Firmware
abstract
As embedded devices become increasingly popular, monolithic firmware, known for its execution efficiency and simplicity, is widely used in resource-constrained devices. Different from ordinary firmware, the monolithic firmware image is packed without the file that indicates its format, which challenges the reverse engineering of monolithic firmware. Function identification is the prerequisite of monolithic firmware's analysis. Prior works on function identification are less effectiveness when applied to monolithic firmware due to their heavy reliance on file formats. In this paper, we propose Moye, a novel method to identify functions in monolithic firmware. We leverage the important insight that the use of registers must conform to some constraints. In particular, our approach segments the firmware, locate code sections and output the instructions. We use a masked language model to learn hiding relationships among the instructions to identify the function boundaries. We evaluate Moye using 1,318 monolithic firmware images, including 48 samples collected from widely used devices. The evaluation demonstrates that our approach significantly outperforms current works, achieving a precision greater than 98 % and a recall rate greater than 97 % across most datasets, showing robustness to complicated compilation options.
Kai Yang 0037, Gaosheng Wang, Zhiqiang Shi, Zhiwen Pan, Shichao Lv, Limin Sun 0001
ICSE6
2025 Breaking the Traffic Barrier: Unveiling Multi-Format of Protocols via Autonomous Program Exploration
abstract
Protocol reverse engineering (PRE) aims to infer the protocol formats of unknown protocols. Existing techniques, whether Network-Trace based or Execution-Trace based methods, face two main limitations: a reliance on the quality and scale of traffic datasets, which often leads to low accuracy and poor generalization; and a failure to adequately consider the multi-format characteristic prevalent in real-world protocols (i.e., the same protocol may support multiple different formats).To address these challenges, we propose ProbePRE—a PRE tool that performs multi-format extraction on protocol handlers by autonomously generating packets. ProbePRE employs three key techniques: (1) an execution tracing strategy enhanced with implicit data flow analysis to obtain more detailed execution information; (2) constraint extraction methods tailored for different program structures to pass protocol validation; and (3) an innovative constraint combination algorithm to construct effective packets that guide the protocol handler to execute diverse protocol parsing paths. In our experimental evaluation, we compared ProbePRE with 4 state-of-the-art PRE tools in terms of field segmentation accuracy. The results demonstrated that ProbePRE achieved an F1 score of 0.88, significantly outperforming existing methods. Furthermore, evaluations on 6 protocol handlers indicated that ProbePRE attained 83% completeness in multi-format extraction tasks. Notably, in basic block coverage tests, ProbePRE achieved a 67% improvement over traditional traffic dataset methods, which fully validates the effectiveness of its path exploration capabilities.
Dingzhao Xue, Yibo Qu, Xin Chen 0123, Shuaizong Si, Shichao Lv, Zhiqiang Shi, Limin Sun 0001
ASE6
2025 Unveiling Evolving Threats: A Data Analysis for Next-Generation Honeypot Development
abstract
Honeypots act as a powerful security mechanism that diverts malicious actors from production systems while providing valuable insights into adversarial behaviors. Yet, the absence of a high-quality honeypot dataset has long impeded robust benchmarking and restricted the employment of advanced AI-driven honeypot defenses. In this work, we address these limitations by constructing a comprehensive shell request-response dataset from Cowrie honeypots. Such a dataset not only facilitates thorough, in-depth honeypot evaluations but also furnishes an essential research foundation for AI-based honeypot development. We analyzed tens of thousands of shell sessions collected during two distinct time frames. (2021-2022 and 2024). By systematically examining command-level usage, session behaviors, and tactics under the MITRE ATT&CK framework, we identified major shifts in adversary techniques, including mounting command complexity, shorter but more targeted infiltration sessions, a more balanced and diverse range of attack methods, and an intensified focus on circumventing defensive measures. These observations emphasize the evolving nature of shell-based intrusions and underscore the necessity for ongoing experimentation and iterative improvements in honeypot design. Through the collection and analysis of this dataset, our work highlights emerging threats in shell defense while also establishing a robust data foundation for the future development of AI-driven honeypots.
Shichao Lv, Haining Wang 0001, Jianzhou You, Shuoyang Liu, Tianwei Yuan, Limin Sun 0001
SRDS2
2025 Discovering PLC Web Application Vulnerabilities Impacting Physical Control Using LLM-Based Fuzzing
Jiaxing Cheng, Dongliang Fang, Zhongwei Gu, Shichao Lv, Shuaizong Si, Limin Sun 0001
WASA (1)4
2025 ICSPFuzzer: An Efficient Fuzzing Technique for ICS Protocols
Zhanwei Song, Dongliang Fang, Shunchao Xu, Yaowen Zheng, Hong Li 0004, Shichao Lv, Zhiqiang Shi, Limin Sun 0001
WASA (2)6
2025 Asynchronous federated learning based zero trust architecture for the next generation industrial control systems
Feifei Lv, Hangyu Wang, Zhiwen Pan, Rongkang Sun, Shuaizong Si, Shichao Lv, Limin Sun 0001
Comput. Networks7
2025 Detection of cyberattack in Industrial Control Networks using multiple adaptive local kernel learning
Fei Lv 0010, Hangyu Wang, Rongkang Sun, Zhiwen Pan, Shuaizong Si, Shichao Lv, Limin Sun 0001
Comput. Secur.8
2025 H∞Filter and Extended State Observer-Based Disturbance Rejection Control for Systems With Uncertainty and Noise
abstract
The extended state observer (ESO) is widely used in disturbance rejection methods for its ability to achieve rapid convergence through high-gain design. However, this high-gain ESO often leads to significant noise amplification and increased sensitivity to disturbances, which adversely affects performance. To address this issue, we propose a novel method that integrates anH∞filter into the ESO framework. Unlike conventional methods, this approach does not assume Gaussian noise or require prior knowledge of noise statistics. Instead, it only assumes bounded noise, making it applicable to a broader range of scenarios. The method employs theH∞filter to attenuate noise within a predefined bound, after which the filtered signal is passed to the ESO for state and disturbance estimation. This significantly reduces the sensitivity of the high-gain ESO to noise. Finally, the proposed method is applied to the speed control of a permanent magnet synchronous motor servo system to verify its effectiveness. The results demonstrate that the method successfully suppresses noise, enhances control performance, and provides a parameter adjustment steps and recommendations its application.
Shichao Lv, Kai Peng 0004, Huanshui Zhang
IEEE Trans. Circuits Syst. I Regul. Pap.1
2025 EMFuzz: Use Electromagnetic Fuzzing for Automated Attack Surface Assessment of Actuators
abstract
Actuators are essential components in cyber-physical systems, enabling system modules to perform diverse and complex tasks. Unfortunately, the pursuit of higher functional complexity often correlates with a broader attack surface in actuators. Thus, an efficient automated attack surface assessment is crucial to avoid cyber incidents in critical infrastructures. Limited by enormous parameter spaces, current methods rely on heuristic tests to evaluate interference potential but cannot thoroughly investigate the full spectrum of potential hidden interference. The observation that similar interference trigger configurations lead to the same impact has motivated us to use machine learning algorithms for understanding different impact samples around decision boundaries. By leveraging generalized knowledge of responses against specific attack scenarios, we aim to improve the efficiency of automated attack surface assessment of electromagnetic interference on new targets. To this end, we introduce EMFuzz, an automated mechanism to fuzz hardware to quantify varying adverse effects. We evaluate EMFuzz on 16 new servos within real-world scenarios, where it achieves an 86% accuracy in classifying different attack vectors. With the same test time, EMFuzz uncovers over twice the effective attack configurations of the baseline, greatly improving assessment efficiency. To further validate its efficacy, we apply EMFuzz to assess the attack surface of a new actuator from a robot transfer unit, and it can successfully reveal three distinct adverse effects.
Shiquan Dong, Zhi Li 0018, Jianshuo Liu, Hong Li 0004, Dongliang Fang, Shichao Lv, Haining Wang 0001, Limin Sun 0001
IEEE Trans. Inf. Forensics Secur.6
2024 Concrete Constraint Guided Symbolic Execution
abstract
Symbolic execution is a popular program analysis technique. It systematically explores all feasible paths of a program but its scalability is largely limited by the path explosion problem, which causes the number of paths proliferates at runtime. A key idea in existing methods to mitigate this problem is to guide the selection of states for path exploration, which primarily relies on the features to represent program states. In this paper, we propose concrete constraint guided symbolic execution, which aims to cover more concrete branches and ultimately improve the overall code coverage during symbolic execution. Our key insight is based on the fact that symbolic execution strives to cover all symbolic branches while concrete branches are neglected, and directing symbolic execution toward uncovered concrete branches has a great potential to improve the overall code coverage. The experimental results demonstrate that our approach can improve the ability of KLEE to both increase code coverage and find more security violations on 10 open-source C programs.
Guowei Yang 0001, Shichao Lv, Zhi Li 0018, Limin Sun 0001
ICSE3
2024 Adversarial Attack against Intrusion Detectors in Cyber-Physical Systems With Minimal Perturbations
abstract
Cyber-Physical Systems (CPS) are crucial for critical infrastructure sectors such as electricity, water, and transportation. Machine Learning (ML) and Deep Learning (DL)-based Intrusion Detection Systems (IDS) are widely used in CPS for security monitoring. Attack and defense confrontation is an eternal topic, leading to increased research on adversarial attacks against IDS. However, most existing research on CPS adversarial attacks focuses on improving evasion capabilities without ensuring the preservation of malicious attack functionality. To address this problem, we propose a Conditional Wasserstein GAN (CWGAN) based framework to generate adversarial examples that can not only evade IDS detection but also impose constraints on the specified target sensors to preserve the original attack functionality. Evaluation results demonstrate that our approach can effectively preserve the intended malicious functionality by significantly reducing the perturbations to specific target sensors. Specifically, we achieve an average reduction of 96.93% and 90.59%, and a maximum reduction of 93.26% and 95.94% compared to the state-of-the-art JSMA and GAN based methods, respectively, while maintaining largely unchanged evasion capabilities against IDS.
Mingqiang Bai, Puzhuo Liu, Fei Lv 0010, Dongliang Fang, Shichao Lv, Limin Sun 0001
ISPA5
2024 DeLink: Source File Information Recovery in Binaries
abstract
Program comprehension can help analysts understand the primary behavior of a binary and enhance the efficiency of reverse engineering analysis. The existing works focus on instruction translation and function name prediction. However, they are limited in understanding the entire program. The recovered source file information can offer insights into the primary behavior of a binary, serving as high-level program summaries. Nevertheless, the files recovered by the function clustering-based approach contain binary functions with discontinuous distributions, resulting in low accuracy. Additionally, there is no existing research related to predicting the names of these recovered files. To this end, we propose a framework for source file information recovery in binaries, DeLink. This framework first leverages a file structure recovery approach based on boundary location to recognize files within a binary. Then, it utilizes an encoder-decoder model to predict the names of these files. The experimental results show that our file structure recovery approach achieves an average improvement of 14% across six evaluation metrics and requires only an average time of 16.74 seconds, outperforming the state-of-the-art work in both recovery quality and efficiency. Additionally, our file name prediction model achieves 70.09% precision and 63.91% recall. Moreover, we demonstrate the effective application of DeLink in malware homology analysis.
Zhe Lang, Zhengzi Xu, Shichao Lv, Zhanwei Song, Zhiqiang Shi, Limin Sun 0001
ISSTA4
2024 TaiE: Function Identification for Monolithic Firmware
abstract
The principal tasks of program analysis, including bug searching and code similarity detection, are executed at the function level. However, the accurate identification of functions within stripped binary files poses a significant challenge. This difficulty is exacerbated by unformatted monolithic firmware images typically found in industrial controlling device, rendering existing methods ineffective due to their dependence on specific metadata, which may be absent.
Kai Yang 0037, Gaosheng Wang, Zhiqiang Shi, Shichao Lv, Limin Sun 0001
ICPC5
2024 SSAD: State Space-Based Anomaly Detection in Industrial Control Systems
abstract
Industrial Control Systems (ICS) are increasingly facing the threat of False Data Injection (FDI) attacks. Process-based anomaly detection is an emerging intrusion detection approach for I CS that effectively identifies anomalies induced by FDI attacks. Anomaly detection models are constructed to describe the normal patterns of industrial processes and subsequently perform real-time evaluation of process data. However, this approach suffers from low detection accuracy due to the complex nonlinear spatiotemporal correlations in industrial pro-cess data, which are difficult to explicitly describe using anomaly detection models. Additionally, noise and interference within the process data prevent these models from recognizing genuine anomalous events. This paper proposes a State Space-based Anomaly Detection (SSAD) approach. Specifically, to explicitly describe the spatiotemporal correlations in process data, we introduce a deep learning-based state estimation model that employs Convolutional Neural Networks (CNNs) for temporal modeling and utilizes a Selective State Space (SSS) for spatial modeling. To detect anomalies in the presence of noise and interference, we design a robust anomaly identification model that combines maximum deviation and threshold strategies to analyze the outputs of the state estimation model. Extensive experiments on two benchmark I CS security datasets demonstrate the effectiveness of SSAD.
Ziqi Wei 0001, Fei Lv 0010, Xin Chen 0123, Shichao Lv, Limin Sun 0001
MSN5
2024 Fast Firmware Fuzz with Input/Output Reposition
Mingfeng Xin, Liting Deng, Hui Wen 0001, Dongliang Fang, Shichao Lv, Limin Sun 0001
SecureComm (3)5
2024 Active Defense Simulation Evaluation of Industrial Control Systems Based on Attack-Defense Graph
Qun Xiao, Shouguo Yang, Jiaqian Peng, Jingfei Bian, Shichao Lv, Limin Sun 0001, Zhiqiang Shi
WASA (2)5
2024 Detecting Cyber-Attacks Against Cyber-Physical Manufacturing System: A Machining Process Invariant Approach
abstract
The era of the Industrial Internet of Things has led to an escalating menace of Cyber-Physical Manufacturing Systems (CPMS) to cyber-attacks. Presently, the field of intrusion detection for CPMS has significant advancements. However, current methodologies require significant costs for collecting historical data to train detection models, which are tailored to specific machining scenarios. Evolving machining scenarios in the real world challenge the adaptability of these methods. In this paper, We found that the machining code of the CPMS contains a complete machining process, which is an excellent detection basis. Therefore we propose MPI-CNC, an intrusion detection approach based on Machining Process Invariant in the machining code. Specifically, MPI-CNC automates the analysis of the machining codes to extract machining process rules and key parameter rules, which serve as essential detection rules. Then, MPI-CNC actively acquires runtime status from the CPMS and matches the detection rules to identify cyber-attacks behavior. MPI-CNC was evaluated using two FANUC CNC machine tools across ten real machining scenarios. The experiment demonstrated the exceptional adaptability capability of MPI-CNC. Furthermore, MPI-CNC showed superior accuracy in detecting cyber-attacks against CPMS compared to existing state-of-the-art detection methods while ensuring normal machining operations.
Zedong Li, Xin Chen 0123, Yuqi Chen 0001, Hangyu Wang, Shichao Lv, Limin Sun 0001
IEEE Internet Things J.6
2024 PowerGuard: Using Power Side-Channel Signals to Secure Motion Controllers in ICS
abstract
Motion control systems, extensively utilized in domains like 3D printing, CNC machining, and robotic arm operations, are pivotal in modern manufacturing and automation processes. Consequently, a specific category of attacks, designed to target these systems, can manipulate the movements of controlled objects while replaying false sensor readings to evade existing tools, thereby severely disrupting these essential operations without being detected. To make things worse, the limited computing resources of embedded devices in these systems constrain the implementation of robust security protections and monitoring mechanisms locally. To solve this, we propose a novel side-channel method that leverages current signals emitted by motors to reconstruct trajectories for attack detection. In this paper, we design and implement a two-stage detection framework, dubbed PowerGuard. In the offline learning stage, PowerGuard first captures the current signals emitted by the servo motors and models the correlation between these signals and corresponding movement trajectories. In the real-time monitoring stage, PowerGuard finds outliers that deviate from the desired trajectory described in the benign G-code file. We have evaluated PowerGuard using a typical motion control system that contains CNC machine tools from different vendors (e.g., Siemens 828D, 840D-sl, Fanuc 0i-md, 0i-tf). We conducted extensive experiments to evaluate the reconstruction accuracy and attack detection performance. Experimental results show that PowerGuard can reconstruct movement trajectories with an error of 0.047mm, and detect 93.35% of various trajectory anomalies.
Yuqi Chen 0001, Xin Chen 0123, Zedong Li, Dongliang Fang, Kaixiang Liu, Shichao Lv, Limin Sun 0001
IEEE Trans. Inf. Forensics Secur.7
2024 When Industrial Radio Security Meets AI: Opportunities and Challenges
abstract
The rapid development of artificial intelligence (AI) has brought about revolutionary changes to industrial wireless networks. Meanwhile, these AI models have also incurred a more complex security environment. This article will investigate the new situations that may arise in the industrial radio security under the support of AI technologies. First, typical radio threats and the uniqueness of industrial wireless networks are introduced. We then review existing industrial wireless physical-layer security schemes based on various AI models from the perspective of countering these radio threats. From the attackers' perspective, three typical case studies are introduced, in which AI technologies will aid in jamming, spoofing, and eavesdropping attacks. Finally, we discussed the openness issues and potential solutions in industrial radio security. This article is of significant in understanding the current status of AI-based industrial radio security, as well as the main problems and challenges. This investigation can promote the healthy development of smart factories and future industries.
Weiwei Li 0002, Xian-Ming Zhang, Ning Wang 0003, Shichao Lv
IEEE Trans. Ind. Informatics5
2023 SeHBPL: Behavioral Semantics-Based Patch Presence Test for Binaries
Gaosheng Wang, Zhiqiang Shi, Fei Lv 0010, Shichao Lv
SETTA6
2023 Spenny: Extensive ICS Protocol Reverse Analysis via Field Guided Symbolic Execution
abstract
Industrial Control System (ICS) protocols have built a tight coupling between ICS components, including industrial software and field controllers such as Programmable Logic Controllers (PLCs). With more ICS components are exposed on the Internet, huge threats are emerging through the exploitation on the inherent defects of ICS protocols. However, the proprietary of ICS protocols makes it extremely hard to build intrusion detection system or perform penetration tests for ICS security reinforcement. In this work, we introduce a symbolic-execution based protocol reverse analysis framework to extract the message format and field type of ICS protocols from real-world PLC firmware. We design new coverage metric and path prioritization strategy to enhance symbolic execution for extensive protocol reverse analysis. Moreover, we propose a field-expression based method on protocol message format inference, along with the analysis on the value ranges of fields which are ignored by previous work. Our evaluation shows that our methods can extract more protocol information during symbolic execution, and achieve high accuracy on protocol reverse analysis compared to Wireshark. Furthermore, we equip the results on private ICS protocols with a black-box fuzzer to test two real-world PLCs. In total, we have found 10 vulnerabilities, including 4 new vulnerabilities.
Zhi Li 0018, Shichao Lv, Limin Sun 0001
IEEE Trans. Dependable Secur. Comput.3
2022 IPSpex: Enabling Efficient Fuzzing via Specification Extraction on ICS Protocol
Shichao Lv, Jianzhou You, Yuyan Sun, Xin Chen 0123, Yaowen Zheng, Limin Sun 0001
ACNS2
2022 Finding Vulnerabilities in Internal-binary of Firmware with Clues
abstract
Embedded devices, represented by Internet of Things devices, bring great convenience to our daily life. Firmware is the core of the embedded device operation. However, vulnerabilities in the firmware can be exploited remotely by hackers through the network. Unfortunately, existing methods are only suitable for finding vulnerabilities in binaries (border-binary) that interact directly with users. When applied to other binaries (internal-binary) that indirectly interact with users, the lack of analysis sources and constraint conditions leads to many false negatives and false positives. In this paper, we propose a new keyword-sensitive data flow analysis approach to address the challenge. Specifically, we leverage crawlers to collect clues related to vulnerability reports from the Internet. Then we use the clues and communication paradigm finders to establish the relationship between different binaries in the firmware sample to form binary dependency graphs. At the same time, based on the functional features, we further dig out the binary relationships that have no Internet clues. Finally, we perform static taint analysis based on binary dependency graphs to determine vulnerabilities. We implemented and evaluated our prototype system FBI. Compared with Karonte, a state-of-the-art tool, FBI found significantly more true positives in Karonte’s data set.
Puzhuo Liu, Dongliang Fang, Shichao Lv, Hongsong Zhu, Limin Sun 0001
ICC5
2022 Gradient-Based Adversarial Attacks Against Malware Detection by Instruction Replacement
Jiapeng Zhao, Zhongjin Liu, Xiaoling Zhang 0009, Zhiqiang Shi, Shichao Lv, Hong Li 0004, Limin Sun 0001
WASA (1)6
2022 Fuzzing proprietary protocols of programmable controllers to find vulnerabilities that affect physical control
Puzhuo Liu, Yaowen Zheng, Zhanwei Song, Dongliang Fang, Shichao Lv, Limin Sun 0001
J. Syst. Archit.5
2021 HoneyVP: A Cost-Effective Hybrid Honeypot Architecture for Industrial Control Systems
abstract
As a decoy for hackers, honeypots have been proved to be a very valuable tool for collecting real data. However, due to closed source and vendor-specific firmware, there are significant limitations in cost for researchers to design an easy-to-use and high-interaction honeypot for industrial control systems (ICSs). To solve this problem, it’s necessary to find a cost-effective solution. In this paper, we propose a novel honeypot architecture termed HoneyVP to support a semi-virtual and semi-physical honeypot design and implementation to enable high cost performance. Specially, we first analyze cyber-attacks on ICS devices in view of different interaction levels. Then, in order to deal with these attacks, our HoneyVP architecture clearly defines three basic independent and cooperative components, namely, the virtual component, the physical component, and the coordinator. Finally, a local-remote cooperative ICS honeypot system is implemented to validate its feasibility and effectiveness. Our experimental results show the advantages of using the proposed architecture compared with the previous honeypot solutions. HoneyVP provides a cost-effective solution for ICS security researchers, making ICS honeypots more attractive and making it possible to capture physical interactions.
Jianzhou You, Shichao Lv, Hui Wen 0001, Limin Sun 0001
ICC2
2020 A Scalable High-interaction Physical Honeypot Framework for Programmable Logic Controller
abstract
Programmable logic controller (PLC) is an industrial digital computer that has been ruggedized and adapted for the control of manufacturing processes, such as automobile manufacture, or gas pipelines, or power generation. Due to closed source and vendor-specific proprietary firmware, it is difficult to develop a scalable high-interaction honeypot for PLCs. In this paper, we present and discuss a new scalable high-interaction PLC honeypot framework based on physical devices. This framework aims to solve the problems of existing physical honeypots while providing the advantages of virtual honeypots. Specially, we first introduce the main gap existing in virtual PLC honeypots. Then, we present a cheap, flexible, and large-scale-deployment solution for physical PLC honeypots according to the concrete problems. Finally, we evaluated our framework based on Siemens S7-300 PLCs. Our experiment shows that physical PLC honeypots have the absolute advantage in interaction capability and it is entirely feasible to extend the deployment scope with low response delay.
Jianzhou You, Shichao Lv, Lian Zhao, Mengyao Niu, Zhiqiang Shi, Limin Sun 0001
VTC Fall2
2019 Remote Fingerprinting on Internet-Wide Printers Based on Neural Network
abstract
Nowadays, a large number of printers are connecting to the Internet. It is undoubtedly true that these online printers are facing severe cyber threats. However, the research/researchers so far cannot answer the current security status of Internet-wide printers. The principal difficulty is to identify the exact brand and model of online printers with high coverage, which is the primary element in vulnerability description. In this work, we design and implement a system called PrinterRadar. Based on Neural Network, PrinterRadar can automatically generate fingerprints from the application layer protocol banners of online printers, and the precision and recall rate of fingerprints can achieve 98% and 97%. By fingerprint matching with the banners which were collected from Censys and Shodan, PrinterRadar found that 508,719 printers were connected to the Internet, covering 92 printer brands and 4,188 printer models. As to the discovered printers, it is about twice the number of those detected by Censys and Shodan.
Zhaoteng Yan, Shichao Lv, Hongsong Zhu, Limin Sun 0001
GLOBECOM2
2019 SCTM: A Multi-View Detecting Approach Against Industrial Control Systems Attacks
abstract
Off-the-shelf machine learning based intrusion detection systems (IDS) have proved not suitable for protecting industrial control systems (ICS), as they do not consider cooperative regularities between controllers of control loops, and the serious shortage of attacking training sets. We study the consensus and complementary (2C) features which are widely observed in control loops. Subsequently, a multi-view learning framework is proposed to boost the effectiveness of detecting attacks on ICS by using a large number of unlabeled examples with 2C features. Comprehensive attacks of ICS are designed and implemented on a physical testbed, and the experimental data are collected from the historical sequences and IDS alerts. The experimental results demonstrate that the framework is highly adaptive, and it can rapidly match the dynamics of ICS operating environment. Meanwhile, the effectiveness of the method is discussed when parameters take different values, and it exhibits low false-positive rates but high precision. In addition, the case of error propagation of the framework is analyzed.
Ming Zhou 0010, Shichao Lv, Libo Yin, Xin Chen 0123, Hong Li 0004, Limin Sun 0001
ICC2
2019 Characterizing Internet-Scale ICS Automated Attacks Through Long-Term Honeypot Data
Jianzhou You, Shichao Lv, Yichen Hao, Xuan Feng 0005, Ming Zhou 0010, Limin Sun 0001
ICICS2
2018 A Novel Intrusion Detection Algorithm for Industrial Control Systems Based on CNN and Process State Transition
abstract
As closed Industrial Control Systems (ICS) gradually evolve toward networking, ICS data and operational processes can be easily tampered with by attackers, causing industrial control equipment to fail or become damaged. Depending on the characteristics of ICS business logic stability, this paper proposes a novel two-level anomaly detection framework to ensure that system data and business logic are safe and reliable. Specifically, basic information is obtained from network traffic. In our framework, the first-level detection uses convolutional neural network (CNN) to feature extraction and anomaly identification. In the second-level detection, we propose a process state transfer algorithm. The feature extracted by the CNN model is invoked as the input of the algorithm to construct the normal state process transfer model of ICS. The model detects whether the current data meets the normal state transition process of the system, and may find unknown attacks or 0-day attacks. Finally, through laboratory gas pipeline network system verification, we found that the anomaly detection framework combined with the two methods has more outstanding performance than several current latest technologies.
Junjiao Liu, Libo Yin, Shichao Lv, Limin Sun 0001
IPCCC4
2017 Anti-Jamming Power Control Game in Unmanned Aerial Vehicle Networks
abstract
In this paper, the anti-jamming issue in unmanned aerial vehicle (UAV) networks is analyzed in a static game and a dynamic game. We investigate the effect of wireless channel fading characteristics from a UAV to a ground station and flying cost on the performance of a closed-form Nash equilibrium (NE) in the static game. Besides, in a Stackelberg dynamic game, wherein the system model is hard to determine, we propose a Q- learning based anti-jamming scheme and evaluate its performance via exhaustive simulations, which can achieve relatively higher average utility and Signal to Interference plus Noise Ratio (SINR) than a benchmark method.
Shichao Lv, Liang Xiao 0003, Xiaoshan Wang, Changzhen Hu, Limin Sun 0001
GLOBECOM1
2017 CovertMIMO: A covert uplink transmission scheme for MIMO systems
abstract
The covert communication in the physical layer and WiFi network is an important tendency for the current research on covert channel. On the other hand, the MIMO beamforming technique used in the physical layer of WiFi networks provides great potential for developing covert transmission scheme. To fill this gap, this paper presents a novel covert channel based on the coordinated operations in the control channel and data channel of MIMO system, called CovertMIMO. Under this scheme, the covert transmitter can make some slight modification on the normal uplink process, such that the recovered physical layer signal at the receiver side deviates from the pre-agreed overt signal. Through the deviation, some covert information can be encoded and delivered. To implementing CovertMIMO, this paper considers two kinds of wardens that follow the minimum principle and distribution principle respectively. Against them, the parameter identification is transformed into solving an optimization problem or nonlinear equation set. The transmission capacity and undetectability of CovertMIMO are also analyzed in detail. At last, the effectiveness of CovertMIMO is validated through extensive experiments.
Xiaoshan Wang, Yao Liu 0007, Xiang Lu 0004, Shichao Lv, Zhiqiang Shi, Limin Sun 0001
ICC4
2017 Wireless Physical Layer Characteristics Based Random Number Generator: Hijack Attackers
abstract
Random numbers are widely used in 5G communication security. In this paper, we propose a wireless physical layer (PHY-layer) characteristics based random number generator in vehicular networks. Firstly, the closed form expression of random transmission success probability is derived under the presence of multiple jamming attackers in a Nakagami-m fading channel. Secondly, a novel Random Transmission Success Probability based Physical Random Number Generator (RTSP-PhRNG) is presented. Finally, numerical results are conducted and a Universal Software Radio Peripheral (USRP) based prototype is implemented to validate our proposed method. Furthermore, the standard randomness test suite from NIST shows that our proposed PhRNG reveals good randomness.
Ning Gao 0001, Xiaojun Jing, Shichao Lv, Junsheng Mu, Limin Sun 0001
VTC Fall3
2017 Defense Against Advanced Persistent Threats with Expert System for Internet of Things
Shichao Lv, Zhiqiang Shi, Limin Sun 0001, Liang Xiao 0003
WASA2
2017 Physical-layer security in Internet of Things based on compressed sensing and frequency selection
abstract
Information security is a vital concern in Internet of Things (IoT). Traditional security method based on public or private key encryption scheme is limited by the trade‐off between low cost and high level of security. Among different security solutions, utilising compressed sensing (CS) in combination with the physical‐layer security to achieve the security is a remarkable method. However, in the current literatures, little attention has been given to the area of static environment, which will lead the risk of information leakage in the CS security model. In this study, the authors propose a new CS security model, in which circulant matrix is exploited to improve the generation efficiency of the measurement matrix, and binary resilient functions are utilised to enhance the security. Furthermore, considering the practical application, they present a feasible framework, named CS security scheme based on frequency‐selective, where the frequency‐selective feature of the wireless channel is applied to support the static environment. To verify the effectiveness of the proposed scheme, they conducted experiments and numerical simulations to evaluate the performance, and the results are satisfactory.
Ning Wang 0003, Ting Jiang 0008, Weiwei Li 0002, Shichao Lv
IET Commun.4
2017 Physical layer spoofing detection based on sparse signal processing and fuzzy recognition
abstract
Spoofing attacks is one of the most critical attacks in wireless communication security. Traditional solutions are based on cryptology which is performed in the upper layers, and face many challenges especially in resource‐limited application. To overcome this hurdle, physical‐layer security has been received a lot of attention recently. In this study, the authors propose a physical‐layer spoofing detecting scheme, where signal processing and feature recognition are utilised to improve the detection performance. In this study, they present a pretreatment process based on sparse representation (SR) to reinforce the characteristic of the signal. Furthermore, they formulate the problem of spoofing detection as one of the feature extraction and recognition, and employ a developed fuzzy C‐mean algorithm to further increase the recognition accuracy. In addition, in order to verify the proposed method, they conduct experiments and use numerical simulation and analysis to evaluate the detection performance. Results showed that the proposed approach can improve the recognition accuracy significantly (increased by one order of magnitude) and the complexity is acceptable (polynomial complexity). Their findings showed that combining SR and feature extraction and recognition, the proposed method provided a good access to achieve a higher accuracy scheme of spoofing detection.
Ning Wang 0003, Weiwei Li 0002, Ting Jiang 0008, Shichao Lv
IET Signal Process.4
2016 Zero reconciliation secret key extraction in MIMO backscatter wireless systems
abstract
In this paper, we propose a new security design, called as Zero Reconciliation Secret Key Extraction, for backscatter wireless systems, in which a reader needs to establish secret keys for multiple tags. Our design is able to eliminate the reconciliation process in conventional physical layer based key establishment, therefore improving the efficiency while still maintaining security in such a process. The essence in our design is to use a channel state information (CSI) characteristic, named CSI Ratio, at the reader to differentiate multiple tags, then employ multiple-input multiple-output (MIMO) precoding for legitimate tags to effectively and securely establish secret keys, at the same time leveraging artificial jamming to forestall eavesdropping attacks in the network. We evaluate our design with real-world experimental data and show that the proposed approach can achieve relatively high secret key extraction rates and maintain low bit error rates.
Shichao Lv, Xiang Lu 0004, Xiaoshan Wang, Ning Wang 0003, Limin Sun 0001
ICC1