EDBT 2026 Demo / reviewers in the wild / expert
Runhao Liu 0001
dblp:264/1811-1
· DBLP profile ↗
5ranked-venue papers
3as first author
5since 2021 · last 2026
0009-0006-7767-7986ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | FirmCross: Detecting Taint-style Vulnerabilities in Modern C-Lua Hybrid Web Services of Linux-based Firmware
Runhao Liu 0001, Jiarun Dai, Haoyu Xiao, Yeqi Mou, Lukai Xu, Bo Yu 0008 |
NDSS | 1 |
| 2023 | Automatic discovery of stateful variables in network protocol software based on replay analysisabstractNetwork protocol software is usually characterized by complicated functions and a vast state space. In this type of program, a massive number of stateful variables that are used to represent the evolution of the states and store some information about the sessions are prone to potential flaws caused by violations of protocol specification requirements and program logic. Discovering such variables is significant in discovering and exploiting vulnerabilities in protocol software, and still needs massive manual verifications. In this paper, we propose a novel method that could automatically discover the use of stateful variables in network protocol software. The core idea is that a stateful variable features information of the communication entities and the software states, so it will exist in the form of a global or static variable during program execution. Based on recording and replaying a protocol program’s execution, varieties of variables in the life cycle can be tracked with the technique of dynamic instrument. We draw up some rules from multiple dimensions by taking full advantage of the existing vulnerability knowledge to determine whether the data stored in critical memory areas have stateful characteristics. We also implement a prototype system that can discover stateful variables automatically and then perform it on nine programs in ProFuzzBench and two complex real-world software programs. With the help of available open-source code, the evaluation results show that the average true positive rate (TPR) can reach 82% and the average precision can be approximately up to 96%. Bo Yu 0008, Runhao Liu 0001, Jinshu Su |
Frontiers Inf. Technol. Electron. Eng. | 3 |
| 2022 | A Component Vulnerability Matching Approach for IoT FirmwareabstractComponent vulnerability matching offers an approach for discovering vulnerabilities existing in IoT firmware. In this work, A component composition analysis and reliability assessment (C2ARA) is developed to improve the component vulnerability matching. The C2ARA method employs a knowledge graph for discovering the components and their relationships from the extracted file system of the firmware. The key to the proposed method is to discover vulnerabilities from the component composition extracted from IoT firmware file systems, rather than only the information provided by CVE databases and firmware vendor. The results of the experiment with a large-scale dataset demonstrate the effectiveness of the C2ARA method. Bo Yu 0008, Yongyi Zhang, Runhao Liu 0001, Zhoushi Sheng |
APNet | 3 |
| 2022 | Anatomist: Enhanced Firmware Vulnerability Discovery Based on Program State Abnormality Determination with Whole-System Replay
Runhao Liu 0001, Bo Yu 0008, Jianbin Ye |
ISC | 1 |
| 2022 | SEEKER: A Root Cause Analysis Method Based on Deterministic Replay for Multi-Type Network Protocol VulnerabilitiesabstractVarious types of network protocol software vulnerabilities often result in considerable damage. However, existing root cause analysis methods, which rely on symbolic path tracing and the hardware processor tracing (PT) function, cannot be applied in protocol software. They are also limited by the restricted resources of embedded platforms and symbolic execution ability. Additionally, manually analysing vulnerabilities is typically labour intensive. To solve this problem, we propose SEEKER, the first root cause analysis method based on deterministic replay for multi-type network protocol vulnerabilities to automatically generate vulnerability analysis reports. By proposing a multilayer semantic model, SEEKER extracts fine-grained semantics, compares the extracted semantics with predefined vulnerability rules and finally generates an analysis report.We implemented and evaluated SEEKER against 7 vulnerability types, across 4 real-world software programs, covering 2 different platforms. The experimental results show that SEEKER can identify the root causes of multi-type vulnerabilities and even find 3 new 0-day vulnerabilities. Meanwhile, SEEKER demonstrates impressive adaptability and scalability. It can analyse one execution path that involves up to 135,437,793 instructions and upwards of 15,893,356 memory access requests. Runhao Liu 0001, Bo Yu 0008, Jianbin Ye |
TrustCom | 1 |