Fenghao Xu

dblp:213/7633 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
7since 2021 · last 2026
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 2 first-author · 3 since 2021Computer networks · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Unidentifiable Identifier: Attacking Bluetooth Applications with Duplicated UUIDs
Siyu Shen, Yi Chen 0024, Fenghao Xu, Shuaike Dong, Wenrui Diao, Di Tang 0001, Kehuan Zhang
EuroS&P3
2026 Dialing Danger: Large-Scale Risk Assessment of Android Secret Codes in OEM Firmware
Ruoyan Lin, Shishuai Yang, Fenghao Xu, Wenrui Diao
SANER3
2025 From guidelines to practice: assessing Android app developer compliance with google's security recommendations
Shishuai Yang, Qinsheng Hou, Fenghao Xu, Wenrui Diao
Empir. Softw. Eng.4
2023 Living in the Past: Analyzing BLE IoT Devices Based on Mobile Companion Apps in Old Versions
abstract
Bluetooth Low Energy has been a widely adopted communication technique in the consumer IoT market. Meanwhile, the security concerns of these BLE-enabled IoT devices have garnered considerable attention. Instead of investigating the device firmware directly, analyzing its companion mobile app has been proven to be an effective approach for vulnerability discovery. However, developers regularly release new versions of these apps, making it more challenging to analyze and identify vulnerabilities. As a result, this action raises the bar on launching attacks on IoT devices. In our study, we found that the earlier versions of the companion apps can still be exploited to attack IoT devices. The key insight is that these devices usually lack firmware update capabilities.In our work, we performed attacks on three BLE-enabled IoT devices by investigating the early versions of their companion apps. We observed that manufacturers merely updated the companion apps to increase the difficulty of reverse engineering through code protection techniques without addressing the vulnerabilities presented in the device firmware. We then conducted a large-scale measurement and confirmed that most BLE devices can be analyzed from their old app versions. Furthermore, we design an automated tool to help developers identify the risks and improve the security of their apps. In our study, we also discuss some mitigation solutions.
Jianqi Du, Zidong Zhang, Fenghao Xu, Wenrui Diao
MSN3
2022 Identifying the BLE Misconfigurations of IoT Devices through Companion Mobile Apps
abstract
Bluetooth Low Energy (BLE) is widely deployed and has become the de-facto communication standard in the IoT ecosystem. Naturally, the security of BLE received much attention from both researchers and attackers. In another aspect, the BLE specifications provide the security guidelines for BLE deployments. Due to various reasons, the developers do not follow the guidelines in the implementation process, which introduces the misconfiguration issue. However, identifying these BLE mis-configurations in IoT device firmware is quite challenging. In this work, we do not handle the BLE-enabled devices directly. Instead, we focus on the security misconfiguration issues in their companion mobile apps, which can reflect the deployment conditions of the corresponding devices. Further, we designed an analysis tool - BSC-Checker to detect the misconfigurations based on pre-defined checking strategies. With BSC-Checker, we conducted large-scale experiments on 4,589 apps from multiple app markets. The result shows that the BLE configurations of most BLE apps disobey at least one security rule, and the current BLE deployment status is not optimistic.
Jianqi Du, Fenghao Xu, Chennan Zhang, Zidong Zhang, Xiaoyin Liu, Wenrui Diao, Shanqing Guo, Kehuan Zhang
SECON2
2022 Authorisation inconsistency in IoT third-party integration
abstract
Abstract Today's IoT platforms provide rich functionalities by integrating with popular third‐party services. Due to the complexity, it is critical to understand whether the IoT platforms have properly managed the authorisation in the cross‐cloud IoT environments. In this study, the authors report the first systematic study on authorisation management of IoT third‐party integration by: (1) presenting two attacks that leak control permissions of the IoT device in the integration of third‐party services; (2) conducting a measurement study over 19 real‐world IoT platforms and three major third‐party services. Results show that eight of the platforms are vulnerable to the threat. To educate IoT developers, the authors provide in‐depth discussion about existing design principles and propose secure design principles for IoT cross‐cloud control frameworks.
Jiongyi Chen, Fenghao Xu, Shuaike Dong, Kehuan Zhang
IET Inf. Secur.2
2021 Android on PC: On the Security of End-user Android Emulators
abstract
Android emulators today are not only acting as a debugging tool for developers but also serving the massive end-users. These end-user Android emulators have attracted millions of users due to their advantages of running mobile apps on desktops and are especially appealing for mobile game players who demand larger screens and better performance. Besides, they commonly provide some customized assistant functionalities to improve the user experience, such as keyboard mapping and app installation from the host. To implement these services, emulators inevitably introduce communication channels between host OS and Android OS (in the Virtual Machine), thus forming a unique architecture which mobile phone does not have. However, it is unknown whether this architecture brings any new security risks to emulators.
Fenghao Xu, Siyu Shen, Wenrui Diao, Zhou Li 0001, Yi Chen 0024, Rui Li 0102, Kehuan Zhang
CCS1
2019 BadBluetooth: Breaking Android Security Mechanisms via Malicious Bluetooth Peripherals
Fenghao Xu, Wenrui Diao, Zhou Li 0001, Jiongyi Chen, Kehuan Zhang
NDSS1
2019 Kindness is a Risky Business: On the Usage of the Accessibility APIs in Android
Wenrui Diao, Yue Zhang 0025, Li Zhang 0039, Zhou Li 0001, Fenghao Xu, Xiaorui Pan, Jian Weng 0001, Kehuan Zhang, XiaoFeng Wang 0001
RAID5
2018 Understanding Android Obfuscation Techniques: A Large-Scale Investigation in the Wild
Shuaike Dong, Wenrui Diao, Jian Liu 0008, Zhou Li 0001, Fenghao Xu, Kai Chen 0012, XiaoFeng Wang 0001, Kehuan Zhang
SecureComm (1)7