EDBT 2026 Demo / reviewers in the wild / expert
Jia Yan 0004
dblp:18/3055-4
· DBLP profile ↗
7ranked-venue papers
4as first author
3since 2021 · last 2025
0000-0002-1248-7114ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Towards Efficient C/C++ Vulnerability Impact Assessment in Package Management Systems
Xiangkun Jia, Jia Yan 0004, Yi Yang 0040, Huafeng Huang, Purui Su |
ICICS (3) | 3 |
| 2022 | DitDetector: Bimodal Learning based on Deceptive Image and Text for Macro Malware DetectionabstractMacro malware has always been a severe threat to cyber security although the Microsoft Office suite applies the default macro-disabling policy. Among the defense solutions at different stages of the attack chain, document analysis is more targeted through detecting malicious documents with macro malware. It is effective, especially with machine learning methods, but still faces problems handling malware variants, supporting file formats, and attack countermeasures with advanced attack techniques (e.g., Excel 4.0 macro and remote template injection). Jia Yan 0004, Xiangkun Jia, Lingyun Ying, Purui Su, Zhanyi Wang |
ACSAC | 1 |
| 2022 | Understanding and Mitigating Label Bias in Malware Classification: An Empirical StudyabstractMachine learning techniques are promising for malware classification, but there is a neglected problem of label bias in the annotation process which decreases the performance in practice. To understand the label bias problems and existing solutions, we conduct an empirical study based on two Portable Executable (PE) malware sample datasets (i.e., open-sourced BODMAS with 52,793 samples and a new collected MAIN dataset of 153,811 samples), and 67 anti-virus engines in VirusTotal. We first show the two ways of label bias problems, including chaotic naming rules and annotation inconsistency. Then we present the effects of two solutions (i.e., electing one reputable AV engine and aggregating multiple labels based on majority voting) and find they face the problems of feature preference and engine independence. Finally, we propose some recommendations for improvements and get a 7.79% increase in the F1 score (i.e., from 84.83% to 92.62%). The dataset will be open-source for further study. Jia Yan 0004, Xiangkun Jia, Lingyun Ying, Purui Su |
QRS | 1 |
| 2018 | A Comprehensive Study of Permission Usage on Android
Yemian Lu, Qi Li 0002, Purui Su, Juan Pan, Jia Yan 0004, Pengyi Zhan |
NSS | 5 |
| 2017 | Automatically assessing crashes from heap overflowsabstractHeap overflow is one of the most widely exploited vulnerabilities, with a large number of heap overflow instances reported every year. It is important to decide whether a crash caused by heap overflow can be turned into an exploit. Efficient and effective assessment of exploitability of crashes facilitates to identify severe vulnerabilities and thus prioritize resources. In this paper, we propose the first metrics to assess heap overflow crashes based on both the attack aspect and the feasibility aspect. We further present HCSIFTER, a novel solution to automatically assess the exploitability of heap overflow instances under our metrics. Given a heap-based crash, HCSIFTER accurately detects heap overflows through dynamic execution without any source code or debugging information. Then it uses several novel methods to extract program execution information needed to quantify the severity of the heap overflow using our metrics. We have implemented a prototype HCSIFTER and applied it to assess nine programs with heap overflow vulnerabilities. HCSIFTER successfully reports that five heap overflow vulnerabilities are highly exploitable and two overflow vulnerabilities are unlikely exploitable. It also gave quantitatively assessments for other two programs. On average, it only takes about two minutes to assess one heap overflow crash. The evaluation result demonstrates both effectiveness and efficiency of HC Sifter. Liang He 0011, Yan Cai 0001, Hong Hu 0004, Purui Su, Zhenkai Liang, Yi Yang 0040, Huafeng Huang, Jia Yan 0004, Xiangkun Jia, Dengguo Feng |
ASE | 8 |
| 2014 | Revisiting Node Injection of P2P Botnet
Jia Yan 0004, Lingyun Ying, Yi Yang 0040, Purui Su, Qi Li 0002, Dengguo Feng |
NSS | 1 |
| 2014 | Long Term Tracking and Characterization of P2P BotnetabstractP2P Botnet is quite robust against various attacks once very effective against centralized network. In this paper, we concentrate on the tracking of P2P botnets, investigate botnet victims which are routable on the Internet, also known as super peers. The super peers are the backbone of the botnet to disseminate its commands and payload updates. Through tracking of three typical live P2P botnets over 6 months and analysis of their network dynamics, we outline a number of descriptive and statistical characterization of super peers, such as geo-location, peer session time and intersession time, in-degree and out-degree distribution, pattern of arrival and departure. In addition, based on the assumption that IP dynamic allocation will not cross the AS (Autonomous System) border, we give out a lower bound estimate of total infected super peers in a conservative manner. We also propose several guidelines on disrupting P2P botnets concerning its various features we have characterized which could be helpful to the security community. Jia Yan 0004, Lingyun Ying, Yi Yang 0040, Purui Su, Dengguo Feng |
TrustCom | 1 |