EDBT 2026 Demo / reviewers in the wild / expert
Rui Zhao 0005
dblp:26/2578-5
· DBLP profile ↗
19ranked-venue papers
15as first author
10since 2021 · last 2025
0000-0001-8292-8483ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 9 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 4 first-author · 5 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 3 · 3 first-author · 2 since 2021Computer networks · 2 · 2 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Beast in the Cage: A Fine-grained and Object-oriented Permission System to Confine JavaScript Operations on the WebabstractJavaScript plays a crucial role on web. However, the inclusion of unknown, vulnerable, and malicious scripts on websites and in browser extensions and the use of browsers' developer tools often lead to undesired web content manipulations and data acquisitions. To restrict JavaScript operations on web content and data, we introduce a fine-grained, mandatory access control-based, and object-oriented permission system to browsers. With our system, web developers can define policies for sensitive web elements on their web pages to allow or deny scripts' operations on web content and data within browsers. The system substantially thwarts many web threats and attacks, and offers benefits to personal data governance. We developed a tool for automatic policy generation and demonstrated the usability and compatibility of the system in a three-month study. Our system is a reasonable and practical solution, bolstering the security and trustworthiness on the internet. Rui Zhao 0005 |
WWW | 1 |
| 2024 | Toward the flow-centric detection of browser fingerprintingabstractBrowser fingerprinting has become a prevalent technique employed by websites for advertising and analytics. It utilizes JavaScript objects and APIs to gather traditional and non-traditional browser attributes and creates unique identifiers for online user tracking. While previous research has examined the invocation of the browser's built-in JavaScript objects and APIs to retrieve browser attribute values, it overlooks the use and flow of those values within scripts. In this paper, we define browser fingerprinting behavior as the aggregation of different types of browser attributes, and reduce the detection of browser fingerprinting to a joint analysis of the data flows of browser attribute values in JavaScript code. FProbe, our proposed framework for the flow-centric detection of browser fingerprinting, performs context-sensitive static data flow analysis on JavaScript code. Given the complexity and dynamic features of the JavaScript language, achieving soundness in static analysis of JavaScript code is extremely challenging or even impossible. Consequently, FProbe aims to be a practical and accurate tool for detecting browser fingerprinting. We implemented FProbe in Java and evaluated its performance using 4,296 fingerprinting scripts from recent work and 2,335,317 pieces of JavaScript code on 988,220 websites. FProbe achieved F-measures of 97.81% and 96.31% on these datasets, respectively. It identified browser fingerprinting behavior on 0.78% of the 988,220 websites, with the use of the toDataURL method observed in 4.26% of the fingerprinting scripts. Notably, only 72 fingerprinting scripts and 10 fingerprinting providers identified by FProbe were reported in previous work. These results highlight the effectiveness of FProbe in detecting browser fingerprinting and its complementarity to existing detection tools. Additionally, our comprehensive study demonstrates that fingerprinting with traditional browser attributes can achieve a 96.6% F-measure. Rui Zhao 0005 |
Comput. Secur. | 1 |
| 2023 | FProbe: The Flow-Centric Detection and a Large-Scale Measurement of Browser FingerprintingabstractBrowser fingerprinting has been used by websites for advertising and analytics. It uses JavaScript objects and APIs to collect browser attributes and generate unique identifiers for tracking online users. A few research works have been proposed to detect browser fingerprinting. They focused on the browser's built-in JavaScript objects and APIs that are invoked to retrieve browser attribute values but ignored the use of browser attributes in scripts. In this paper, we define the behavior of browser fingerprinting as aggregating different types of browser attributes, and reduce browser fingerprinting detection to a joint analysis of data flows of browser attribute values in JavaScript code. We propose a flow-centric browser fingerprinting detection framework, FProbe, which performs context-sensitive static data flow analysis of JavaScript code. We implemented FProbe in Java and evaluated it using 4,296 fingerprinting scripts from the recent work and 2,335,317 pieces of JavaScript code from 988,220 websites. FProbe achieved 97.81% and 96.31% F-measure on them, respectively. It identified browser fingerprinting behavior on 0.78% of the 988,220 websites. Only 72 fingerprinting scripts and 10 fingerprinting providers identified by FProbe were reported in previous work. The results show that FProbe is effective in detecting browser fingerprinting and complementary to existing detection tools. Rui Zhao 0005 |
ICCCN | 1 |
| 2023 | Securing Zero Trust Networks: the Decentralized Host-to-Host Authentication Policy EnforcementabstractZero trust networks have emerged as a promising solution to assure comprehensive security in network environments. Different from the traditional perimeter-based security approach, zero trust networks provide a robust and adaptable security framework which addresses the evolving threat landscape and enables organizations to protect their critical assets with a higher assurance of confidence. However, the centralized policy engine employed in current zero trust architectures (ZTA) would introduce bottlenecks and single points of failure (SPoF) for ZTA-based networks, thus hindering the scalability and efficiency as network size increases. This paper introduces a novel decentralized host-to-host authentication schema that enables consistent policy engine decisions in a pair-wise manner. By decentralizing the authentication process, the proposed schema effectively eliminates bottlenecks and single points of failure associated with centralized policy engines. The system incorporates a decentralized authentication ledger and a policy validation protocol to ensure the correct and consistent authentication across all network hosts. Through comprehensive tests and simulations, we compared our proposed novel model with the traditional zero trust network, in terms of the correctness, time complexity, and efficiency. Our findings demonstrate the advantages of our decentralized approach and its potential for enhancing security in zero trust networks. Adam Spanier, Rui Zhao 0005, Pei-Chi Huang |
TrustCom | 2 |
| 2023 | CamPass: a Secure Camera-based Password Manager for Kiosk BrowsingabstractText-based passwords have dominated online user authentication for decades and have been constantly targeted by harvesting and phishing attacks. Password managers have become one of the most popular methods for helping users securely manage their online passwords. However, existing pass-word managers are often assumed to be used on trusted devices. To help with automatic sign-in on untrusted computers for kiosk browsing, we propose CamPass, a secure camera-based password manager. It has three components: an application on a user’s trusted mobile device, a browser extension for online sign-in on an untrusted computer, and a trusted key distribution center for the secure exchange of encryption keys. CamPass transmits credentials via QR codes from the mobile device to the browser extension for filling out login forms, and exchanges encryption keys among its three components on the network. CamPass is resistant to man-in-the-middle, eavesdropping, message forgery, and replay attacks. It also protects users from keyloggers and phishing attacks. CamPass is a rational design to make web users’ online experiences more convenient and secure. Rui Zhao 0005 |
TrustCom | 1 |
| 2023 | The Chameleon on the Web: an Empirical Study of the Insidious Proactive Web DefacementsabstractWeb defacement is one of the major promotional channels for online underground economies. It regularly compromises benign websites and injects fraudulent content to promote illicit goods and services. It inflicts significant harm to websites’ reputations and revenues and may lead to legal ramifications. In this paper, we uncover proactive web defacements, where the involved web pages (i.e., landing pages) proactively deface themselves within browsers using JavaScript (i.e., control scripts). Proactive web defacements have not yet received attention from research communities, anti-hacking organizations, or law-enforcement officials. To detect proactive web defacements, we designed a practical tool, PACTOR. It runs in the browser and intercepts JavaScript API calls that manipulate web page content. It takes snapshots of the rendered HTML source code immediately before and after the intercepted API calls and detects proactive web defacements by visually comparing every two consecutive snapshots. Our two-month empirical study, using PACTOR, on 2,454 incidents of proactive web defacements shows that they can evade existing URL safety-checking tools and effectively promote the ranking of their landing pages using legitimate content/keywords. We also investigated the vendor network of proactive web defacements and reported all the involved domains to law-enforcement officials and URL-safety checking tools. Rui Zhao 0005 |
WWW | 1 |
| 2023 | SSDTutor: A feedback-driven intelligent tutoring system for secure software development
Dip Kiran Pradhan Newar, Rui Zhao 0005, Harvey P. Siy, Leen-Kiat Soh, Myoungkyu Song |
Sci. Comput. Program. | 2 |
| 2022 | A Feasibility Study of Using Code Clone Detection for Secure Programming EducationabstractSecure library reuse is critical for modern ap-plications to protect private information in software security engineering. Teaching secure programming is also more critical to tackle the challenges of new and evolving threats. However, novice students often make mistakes by API misuses due to a lack of understanding of secure libraries or a false sense of security. In this paper, we study the feasibility of applying code clone detection (CCD) for finding relevant examples to effectively teach secure programming to computer science students. CCD is an emerging new technology that extracts syntactically or semantically similar code fragments to support many software engineering tasks, such as program understanding, code quality analysis, software evolution analysis, and bug detection. We have developed a prototype implementation ExTUTOR that allows students to search for relevant examples as feedback when they want to fix their programming issues or vulnerabilities. In our evaluation, we applied ExTUTOR to open source subject applications in the security domain. Our approach should help novice students gain benefits from feedback and identify how to effectively make use of APIs, encouraging students to fix their own security violations in their own applications. Michael Menard, Tommy Nelson, Milan Shahi, Hugh Morton, Adam DeTavernier, Harvey P. Siy, Rui Zhao 0005, Myoungkyu Song |
COMPSAC | 7 |
| 2022 | An Intelligent Tutoring System for API Misuse Correction by Instant Quality FeedbackabstractComputer science students have difficulty understanding correct usages of an Application Programming Interface (API) and programming violations that cause compilation or runtime errors. Despite high-quality documentation for programming, the students typically need an instructor's feedback when their programs cause bugs, crashes, and vulnerabilities. This paper presents a pedagogical approach that is based on an Intelligent Tutoring System called INTTuToR. Briefly, INTTUTORprovides novice students with instant feedback to fix their programming issues or vulnerabilities. We have implemented our approach as a plug-in application in the Integrated Development Environment (IDE) for an interactive educational environment. In our proposed evaluation, we plan to perform empirical studies with CS students to assess how effectively INTTUTORimproves their ability to identify and fix potential bugs or vulnerabilities in the cryptography-related programming assignments. Rui Zhao 0005, Harvey P. Siy, Chulwoo Pack, Leen-Kiat Soh, Myoungkyu Song |
COMPSAC | 1 |
| 2021 | FireBugs: Finding and Repairing Cryptography API Misuses in Mobile ApplicationsabstractIn this paper, we present FireBugs for Finding and Repairing Bugs based on security patterns. For the common misuse patterns of cryptography APIs (crypto APIs), we encode common cryptography rules into the pattern representations for bug detection and program repair regarding cryptography rule violations. In the evaluation, we conducted a case study to assess the bug detection capability by applying FireBugs to datasets mined from both open source and commercial projects. Also, we conducted a user study with professional software engineers at Mutual of Omaha Insurance Company to estimate the program repair capability. This evaluation showed that FireBugs can help professional engineers develop various cryptographic requirements in a resilient application. Larry Singleton, Rui Zhao 0005, Harvey P. Siy, Myoungkyu Song |
COMPSAC | 2 |
| 2019 | Traffic-Based Automatic Detection of Browser Fingerprinting
Rui Zhao 0005, Edward Chow, Chunchun Li |
SecureComm (1) | 1 |
| 2019 | Sensor-Based Mobile Web Cross-Site Input Inference Attacks and DefensesabstractIn this paper, we investigate the accelerometer and gyroscope motion sensor-based cross-site input inference attacks that may compromise the security of many mobile Web users, and quantify the extent to which they can be effective. We formulate our attacks as a typical multi-class classification problem and build an inference framework that trains a classifier in the training phase and predicts the user's new inputs in the attacking phase. To make our attacks effective and realistic, we design unique techniques and address major data quality and data segmentation challenges. We intensively evaluate the effectiveness of our attacks using 98 691 keystrokes collected from 20 participants. Overall, our attacks are effective, for example, they are about 10.8 times more effective than the random guessing attacks regarding inferring letters. We also perform experiments to evaluate the effect of using the data perturbation defense techniques on decreasing the accuracy of our input inference attacks. Our results demonstrate that researchers, smartphone vendors, and app developers should pay serious attention to the motion sensor-based cross-site input inference attacks that can be pervasively performed, and start to design and deploy effective defense techniques. Rui Zhao 0005, Chuan Yue, Qi Han 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2017 | Cross-site Input Inference Attacks on Mobile Web Users
Rui Zhao 0005, Chuan Yue, Qi Han 0001 |
SecureComm | 1 |
| 2017 | Design and evaluation of the highly insidious extreme phishing attacks
Rui Zhao 0005, Samantha John, Stacy Karas, Cara Bussell, Jennifer Roberts, Daniel Six, Brandon Gavett, Chuan Yue |
Comput. Secur. | 1 |
| 2016 | The Highly Insidious Extreme Phishing AttacksabstractOne of the most severe and challenging threats to Internet security is phishing, which uses spoofed websites to steal users' passwords and online identities. Phishers mainly use spoofed emails or instant messages to lure users to the phishing websites. A spoofed email or instant message provides the first-layer context to entice users to click on a phishing URL, and the phishing website further provides the second-layer context with the look and feel similar to a targeted legitimate website to lure users to submit their login credentials. In this paper, we focus on the second-layer context to explore the extreme of phishing attacks; we explore the feasibility of creating extreme phishing attacks that have the almost identical look and feel as those of the targeted legitimate websites, and evaluate the effectiveness of such phishing attacks. We design and implement a phishing toolkit that can support both the traditional phishing and the newly emergent Web Single Sign-On (SSO) phishing; our toolkit can automatically construct unlimited levels of phishing webpages in real time based on user interactions. We design and perform a user study to evaluate the effectiveness of the phishing attacks constructed from this toolkit. The user study results demonstrate that extreme phishing attacks are indeed highly effective and insidious. It is reasonable to assume that extreme phishing attacks will be widely adopted and deployed in the future, and we call for a collective effort to effectively defend against them. Rui Zhao 0005, Samantha John, Stacy Karas, Cara Bussell, Jennifer Roberts, Daniel Six, Brandon Gavett, Chuan Yue |
ICCCN | 1 |
| 2015 | SafeSky: A Secure Cloud Storage Middleware for End-User ApplicationsabstractAs the popularity of cloud storage services grows rapidly, it is desirable and even essential for both legacy and new end-user applications to have the cloud storage capability to improve their functionality, usability, and accessibility. However, incorporating the cloud storage capability into applications must be done in a secure manner to ensure the confidentiality, integrity, and availability of users' data in the cloud. Unfortunately, it is non-trivial for ordinary application developers to either enhance legacy applications or build new applications to properly have the secure cloud storage capability, due to the development efforts involved as well as the security knowledge and skills required. In this paper, we propose SafeSky, a middleware that can immediately enable an application to use the cloud storage services securely and efficiently, without any code modification or recompilation. A SafeSky-enabled application does not need to save a user's data to the local disk, but instead securely saves them to different cloud storage services to significantly enhance the data security. We have implemented SafeSky as a shared library on Linux. SafeSky supports applications written in different languages, supports various popular cloud storage services, and supports common user authentication methods used by those services. Our evaluation and analysis of SafeSky with real-world applications demonstrate that SafeSky is a feasible and practical approach for equipping end-user applications with the secure cloud storage capability. Rui Zhao 0005, Chuan Yue, Byung-Chul Tak, Chunqiang Tang |
SRDS | 1 |
| 2015 | Automatic Detection of Information Leakage Vulnerabilities in Browser ExtensionsabstractA large number of extensions exist in browser vendors' online stores for millions of users to download and use. Many of those extensions process sensitive information from user inputs and webpages; however, it remains a big question whether those extensions may accidentally leak such sensitive information out of the browsers without protection. In this paper, we present a framework, LvDetector, that combines static and dynamic program analysis techniques for automatic detection of information leakage vulnerabilities in legitimate browser extensions. Extension developers can use LvDetector to locate and fix the vulnerabilities in their code; browser vendors can use LvDetector to decide whether the corresponding extensions can be hosted in their online stores; advanced users can also use LvDetector to determine if certain extensions are safe to use. The design of LvDetector is not bound to specific browsers or JavaScript engines, and can adopt other program analysis techniques. We implemented LvDetector and evaluated it on 28 popular Firefox and Google Chrome extensions. LvDetector identified 18 previously unknown information leakage vulnerabilities in 13 extensions with a 87% accuracy rate. The evaluation results and the feedback to our responsible disclosure demonstrate that LvDetector is useful and effective. Rui Zhao 0005, Chuan Yue, Qing Yi |
WWW | 1 |
| 2014 | Toward a secure and usable cloud-based password manager for web browsers
Rui Zhao 0005, Chuan Yue |
Comput. Secur. | 1 |
| 2013 | All your browser-saved passwords could belong to us: a security analysis and a cloud-based new designabstractWeb users are confronted with the daunting challenges of creating, remembering, and using more and more strong passwords than ever before in order to protect their valuable assets on different websites. Password manager is one of the most popular approaches designed to address these challenges by saving users' passwords and later automatically filling the login forms on behalf of users. Fortunately, all the five most popular Web browsers have provided password managers as a useful built-in feature. Unfortunately, the designs of all those Browser-based Password Managers (BPMs) have severe security vulnerabilities. In this paper, we uncover the vulnerabilities of existing BPMs and analyze how they can be exploited by attackers to crack users' saved passwords. Moreover, we propose a novel Cloud-based Storage-Free BPM (CSF-BPM) design to achieve a high level of security with the desired confidentiality, integrity, and availability properties. We have implemented a CSF-BPM system into Firefox and evaluated its correctness and performance. We believe CSF-BPM is a rational design that can also be integrated into other popular Web browsers. Rui Zhao 0005, Chuan Yue |
CODASPY | 1 |