Diyu Wu

dblp:225/0440 · DBLP profile ↗
← Back
5ranked-venue papers
2as first author
1since 2021 · last 2023
0009-0008-8474-0685ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 5 · 2 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
2 papers
Program analysis · 100%
Network and information security
1 paper
Web and mobile security · 100%

Topics — the 6 heaviest of 6, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Program analysis
static analysis
0.822023
Hybrid Inlining: A Framework for Compositional and Context-Sensitive Static Analysis · ISSTA 2023
TDroid: exposing app switching attacks in Android with control flow specialization · ASE 2018
Program analysis › static analysis › interprocedural analysis
compositional analysis
0.712023
Hybrid Inlining: A Framework for Compositional and Context-Sensitive Static Analysis · ISSTA 2023
Program analysis › static analysis › interprocedural analysis
context-sensitive analysis
0.712023
Hybrid Inlining: A Framework for Compositional and Context-Sensitive Static Analysis · ISSTA 2023
Web and mobile security
mobile security
0.312018
TDroid: exposing app switching attacks in Android with control flow specialization · ASE 2018
Program analysis › static analysis
pointer analysis
0.212023
Hybrid Inlining: A Framework for Compositional and Context-Sensitive Static Analysis · ISSTA 2023
Program analysis
control flow analysis
0.112018
TDroid: exposing app switching attacks in Android with control flow specialization · ASE 2018

Methods — techniques the papers use, named apart from their topics

summarization · 0.7hybrid inlining · 0.7dynamic analysis · 0.7control flow specialization · 0.7
YearPublicationVenuePosition
2023 Hybrid Inlining: A Framework for Compositional and Context-Sensitive Static Analysis
abstract
Context-sensitivity is essential for achieving good precision in inter-procedural static analysis. To be context-sensitive, top-down analysis needs to fully inline all the statements in a callee at all its callsites, leading to statement explosion. Compositional analysis, which inlines summaries of all the callees, scales up but often loses precision, as it is not strictly context-sensitive. We propose a compositional and strictly context-sensitive framework for static analysis. This framework is based on a key observation: a compositional analysis often loses precision only on some critical statements that need to be analyzed context-sensitively. Our approach hybridly inlines the critical statements and the summaries of non-critical statements of each callee, thus avoiding re-analyzing non-critical ones. In addition, our analysis lazily summarizes the critical statements, by stopping propagating the critical statements once the calling context accumulated is adequate. We have designed and implemented several analyses (including a pointer analysis) based on this framework. Our evaluation on the pointer analysis shows that it can analyze large Java programs from the DaCapo benchmark suite and industry in minutes. Compared to context-insensitive analysis, Hybrid Inlining introduces only 65% and 1% additional time overheads on DaCapo and industrial applications, respectively.
Jiangchao Liu, Jierui Liu, Peng Di, Diyu Wu, Hengjie Zheng, Alex X. Liu, Jingling Xue
ISSTA4
2020 Correlating UI Contexts with Sensitive API Calls: Dynamic Semantic Extraction and Analysis
abstract
The Android framework provides sensitive APIs for Android apps to access the user's private information, e.g., SMS, call logs and locations. Whether a sensitive API call in an app is legitimate or not depends on whether the app has provided enough natural-language semantics to reflect the need for the permission. The prior efforts on analyzing description-to-permission fidelity in an app are all static. Some check whether the permissions requested (or sensitive APIs used) by the app are consistent with the functionalities described by the app. These app-level techniques are too coarse-grained, as they cannot tell if a sensitive API call under a certain runtime context, such as a UI state, is legitimate or not. Others attempt to establish this connection by performing a data-flow analysis, but such fine-grained API-level static analyses are too imprecise to handle a variety of dynamic language features used in Android apps, including dynamic class loading, reflection and code obfuscation. We introduce APICOG, an automated fine-grained API-level approach, representing the first dynamic description-to-permission fidelity analysis for an Android app that can check if a sensitive API call is legitimate or not under a given runtime context. APICOGrelates each sensitive API call with a UI state, called its UI context, under which the call is made via dynamic analysis and then extracts the text-based semantics for each UI context from its associated text- and image-typed attributes by applying a natural language processing (NLP) technique. Finally, APICOGrelies on machine-learning to deduce if a sensitive API call under a UI context is legitimate or not. We have evaluated APICOGwith thousands of Android apps drawn from a third-party market and a malware dataset, achieving an accuracy of 97.7%, a precision of 94.1% and a recall of 92.8% overall, outperforming the prior art in all the three metrics.
Jie Liu 0020, Dongjie He, Diyu Wu, Jingling Xue
ISSRE3
2020 Exposing Android Event-Based Races by Selective Branch Instrumentation
abstract
Android supports an event dispatching system that reacts to system and user actions by generating events. However, lack of synchronization between events can lead to event-based races in Android apps. Such event-based races are difficult to detect dynamically due to the challenges faced in generating the right events to satisfy the right event-dependent conditional branches, so that their guarded racy statements can be reached. As a result, existing dynamic tools, which try to find and reschedule some race-triggering events heuristically, are often ineffective.We introduce SIEVE, a tool for exposing event-based races in Android apps dynamically by leveraging a new selective branch instrumentation technique. For the conditionals potentially affecting a race (detected, say, by a static tool), SIEVE fixes the true/false outcomes of some of these conditionals based on a systematic branch analysis, which analyzes the satisfiability of all the conditionals guarding the given racy statements and their safeness for instrumentation. By instrumenting certain branches selectively this way, we can not only expose effectively event-based races but also reduce substantially the negative ramifications of instrumentation (e.g., reporting non-existent races and introducing unexpected crashes during dynamic execution). An evaluation of SIEVE with 25 Android apps shows that our tool can expose event-based races more effectively than the state of the art.
Diyu Wu, Dongjie He, Shiping Chen 0001, Jingling Xue
ISSRE1
2019 Precise Static Happens-Before Analysis for Detecting UAF Order Violations in Android
abstract
Unlike Java, Android provides a rich set of APIs to support a hybrid concurrency system, which consists of both Java threads and an event queue mechanism for dispatching asynchronous events. In this model, concurrency errors often manifest themselves in the form of order violations. An order violation occurs when two events access the same shared object in an incorrect order, causing unexpected program behaviors (e.g., null pointer dereferences). This paper presents SARD, a static analysis tool for detecting both intra-and inter-thread use-after-free (UAF) order violations, when a pointer is dereferenced (used) after it no longer points to any valid object, through systematic modeling of Android's concurrency mechanism. We propose a new flow-and context-sensitive static happens-before (HB) analysis to reason about the interleavings between two events to effectively identify precise HB relations and eliminate spurious event interleavings. We have evaluated SARD by comparing with NADROID, a state-of-the-art static order violation detection tool for Android. SARD outperforms NADROID in terms of both precision (by reporting three times fewer false alarms than NADROID given the same set of apps used by NADROID) and efficiency (by running two orders of magnitude faster than NADROID).
Diyu Wu, Jie Liu 0020, Yulei Sui, Shiping Chen 0001, Jingling Xue
ICST1
2018 TDroid: exposing app switching attacks in Android with control flow specialization
abstract
The Android multitasking mechanism can be plagued with app switching attacks, in which a malicious app replaces the legitimate top activity of the focused app with one of its own, thus mounting, e.g., phishing and denial-of-service attacks. Existing market-level defenses are still ineffective, as static analysis is fundamentally unable to reason about the intention of an app and dynamic analysis has low coverage.
Jie Liu 0020, Diyu Wu, Jingling Xue
ASE2