EDBT 2026 Demo / reviewers in the wild / expert
Mu Zhang 0001
dblp:28/3341-1
· DBLP profile ↗
29ranked-venue papers
6as first author
14since 2021 · last 2025
0000-0001-5905-9515ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 24 · 6 first-author · 12 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021Systems, architecture and hardware · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Needle in a Haystack: Automated and Scalable Vulnerability Hunting in the Windows ALPC SeaabstractWindows services utilizing Remote Procedure Call (RPC) and Component Object Model (COM) technology over the underlying Advanced Local Procedure Call (ALPC) transport present a significant attack surface. However, previous research often focused on known vulnerability patterns or required time-consuming reverse engineering, which hinders scalable vulnerability discovery. We developed a tool designed to automate and scale the fuzzing of ALPC communications. It employs a record-and-replay based strategy, capturing live system-wide ALPC traffic and replaying mutated payloads directly at the ALPC layer, thereby overcoming the scalability barrier posed by the manual preparation required with conventional methods. Furthermore, it integrates dedicated detection techniques to identify information leakage vulnerabilities that crash-centric fuzzers often miss. After evaluating various versions of Windows operating systems, we discovered 12 vulnerabilities confirmed by Microsoft, 10 of which have already been assigned CVE numbers. Haoyi Liu, Feng Dong 0008, Yunpeng Tian, Mu Zhang 0001, Fangming Gu, Zhiniang Peng, Haoyu Wang 0001 |
CCS | 4 |
| 2025 | RICSS'25: 3rd International Workshop on Re-design Industrial Control Systems with SecurityabstractIndustrial Control System (ICS) and its software touches every aspect of the critical infrastructure used by our industry, academia, and government. Back in the days, these systems and software were not designed with security in mind. With the ever expanding inter- connectivity of ICS environments and new threats, practitioners are stuck on a patchwork of security. While certain proprietary ICS software manufacturers have started to provide security solutions, free and open source ICS software is often less known. The goal of the workshop is twofold: we want to collect ideas on redesigning (parts of) the ICS ecosystem so that security is built-in by design; we also invite contributions on designing, incorporating, and maintaining secure open-source ICS software. Ruimin Sun, Mu Zhang 0001 |
CCS | 2 |
| 2025 | Error Messages to Fuzzing: Detecting XPS Parsing Vulnerabilities in Windows Printing ComponentsabstractWindows printing services remain a notable vector for attacks. Previous studies have predominantly targeted vulnerabilities within various control aspects of printing services, such as spooler services and firmware updates. Yet, we contend that an essential aspect of data processing—the document parser within printer drivers—has been overlooked in past research. We present a coverage-based fuzzing system, PrintXPSurge, specifically crafted to detect weaknesses in the XPS printer driver's parsing function. To craft semantically correct XPS files, we leverage a large language model-assisted repair approach to automate the creation of semantically correct XPS files that comply with necessary constraints. To ensure our fuzzing process effectively interacts with the XPS printer driver, we develop a progressive state reconstruction method that addresses individual dependency requirements across the entire printing service workflow. Furthermore, when a crash is detected, we employ backtracing to confirm its origin in the XPS parser, isolating it from other components in the pipeline. Our evaluation reveals that PrintXPSurge surpasses existing top Windows fuzzers in performance, successfully identifying 102 bugs in 10 drivers from major brands, including 17 zero-day vulnerabilities confirmed by Microsoft and third-party vendors. Yunpeng Tian, Feng Dong 0008, Junhai Wang, Mu Zhang 0001, Zhiniang Peng, Zesen Ye, Xiapu Luo, Haoyu Wang 0001 |
CCS | 4 |
| 2025 | ICSTracker: Backtracking Intrusions in Modern Industrial Control SystemsabstractApplying "provenance analysis" to industrial control systems (ICS) is challenging. Existing research struggles with recovering the physical semantics of controller logic, managing inconsistent state transitions, tracking cross-domain causality, and practical implementation. In this paper, we introduce ICS Tracker, a comprehensive approach that addresses these gaps by using digital twins to collect logs, automatically recovering physical semantics, reconstructing data dependencies, and linking controller operations to OS-level events. Tested on ten attack scenarios across two testbeds, ICSTracker outperforms previous methods, capturing all attack activities where earlier techniques missed 56%. Md. Raihan Ahmed, Jainta Paul, Levi Taiji Li, Luis Garcia 0001, Mu Zhang 0001 |
DSN | 5 |
| 2025 | CollisionRepair: First-Aid and Automated Patching for Storage Collision Vulnerabilities in Smart Contracts
Wanjing Han, Yue Duan, Mu Zhang 0001 |
USENIX Security Symposium | 4 |
| 2025 | DeepVMUnProtect: Neural Network-Based Recovery of VM-Protected Android Apps for Semantics-Aware Malware DetectionabstractThe emerging virtual machine-based Android packers render existing unpacking techniques ineffective. The state-of-the-art unpacker falls short because it relies on unreliable heuristics and manually crafted semantic models. Hence, it cannot precisely recover app semantics necessary for malware detection. In this paper, we proposeDeepVMUnProtect, a deep learning-based approach to automatically and accurately capture the semantics of VM-packed code, so as to facilitate semantic-based Android malware classification. Experiments have shown thatDeepVMUnProtectoutperforms the state-of-the-art tool on recovering opcode semantics in Qihoo(58.3%), Baidu(47.5%) and NMMP (58.8%) respectively, and can enable semantics-aware malware detection which prior work fails to do. Mu Zhang 0001, Xiaopeng Ke, Yue Duan, Sheng Zhong 0002, Fengyuan Xu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | RICSS'24: 2nd International Workshop on Re-design Industrial Control Systems with SecurityabstractIndustrial Control System (ICS) and its software touches every aspect of the critical infrastructure used by our industry, academia, and government.Back in the days, these systems and software were not designed with security in mind.With the ever expanding interconnectivity of ICS environments and new threats, practitioners are stuck on a patchwork of security.While certain proprietary ICS software manufacturers have started to provide security solutions, free and open source ICS software is often less known.The goal of the workshop is twofold: we want to collect ideas on redesigning (parts of) the ICS ecosystem so that security is built-in by design; we also invite contributions on designing, incorporating, and maintaining secure open-source ICS software. Ruimin Sun, Mu Zhang 0001 |
CCS | 2 |
| 2024 | WASMaker: Differential Testing of WebAssembly Runtimes via Semantic-Aware Binary GenerationabstractA fundamental component of the Wasm ecosystem is the Wasm runtime, as it directly impacts whether Wasm applications can be executed as expected. Bugs in Wasm runtimes are frequently reported, so the research community has made a few attempts to design automated testing frameworks to detect bugs in Wasm runtimes. However, existing testing frameworks are limited by the quality of test cases, i.e., they face challenges in generating Wasm binaries that are both semantically rich and syntactically correct. As a result, complicated bugs cannot be triggered effectively. In this work, we present WASMaker, a novel differential testing framework that can generate complicated Wasm test cases by disassembling and assembling real-world Wasm binaries, which can trigger hidden inconsistencies among Wasm runtimes. To further pinpoint the root causes of unexpected behaviors, we design a runtime-agnostic root cause location method to locate bugs accurately. Extensive evaluation suggests that WASMaker outperforms state-of-the-art techniques in terms of both efficiency and effectiveness. We have uncovered 33 unique bugs in popular Wasm runtimes, among which 25 have been confirmed. Shangtong Cao, Ningyu He, Xinyu She, Mu Zhang 0001, Haoyu Wang 0001 |
ISSTA | 5 |
| 2024 | VETEOS: Statically Vetting EOSIO Contracts for the "Groundhog Day" Vulnerabilities
Levi Taiji Li, Ningyu He, Haoyu Wang 0001, Mu Zhang 0001 |
NDSS | 4 |
| 2023 | Arvin: Greybox Fuzzing Using Approximate Dynamic CFG AnalysisabstractFuzzing has emerged as the most broadly used testing technique to discover bugs. Effective fuzzers rely on coverage to prioritize inputs that exercise new program areas. Edge-based code coverage of the Program Under Test (PUT) is the most commonly used coverage today. It is cheap to collect—a simple counter per basic block edge suffices. Unfortunately, edge coverage lacks context information: it exclusively records how many times each edge was executed but lacks the information necessary to trace actual paths of execution. Sirus Shahini, Mu Zhang 0001, Mathias Payer, Robert Ricci |
AsiaCCS | 2 |
| 2023 | Automated Generation of Security-Centric Descriptions for Smart Contract BytecodeabstractSmart contract and DApp users are taking great risks, as they do not obtain necessary knowledge that can help them avoid using vulnera- ble and malicious contract code. In this paper, we develop a novel system Tx2TXT that can automatically create security-centric textual descriptions directly from smart contract bytecode. To capture the security aspect of financial applications, we formally define a funds transfer graph to model critical funds flows in smart contracts. To ensure the expressiveness and conciseness of the descriptions de- rived from these graphs, we employ a GCN-based model to identify security-related condition statements and selectively add them to our graph models. To convert low-level bytecode instructions to human- readable textual scripts, we leverage robust API signatures to recover bytecode semantics. We have evaluated Tx2TXT on 890 well-labeled vulnerable, malicious and safe contracts where developer-crafted descriptions are available. Our results have shown that Tx2TXT out- performs state-of-the-art solutions and can effectively help end users avoid risky contracts Zhichao Xu 0001, Levi Taiji Li, Yunhe Yang, Mu Zhang 0001 |
ISSTA | 5 |
| 2022 | Towards Automated Safety Vetting of Smart Contracts in Decentralized ApplicationsabstractWe propose VetSC, a novel UI-driven, program analysis guided model checking technique that can automatically extract contract semantics in DApps so as to enable targeted safety vetting. To facilitate model checking, we extract business model graphs from contract code that capture its intrinsic business and safety logic. To automatically determine what safety specifications to check, we retrieve textual semantics from DApp user interfaces. To exclude untrusted UI text, we also validate the UI-logic consistency and detect any discrepancies. We have implemented VetSC and applied it to 34 real-world DApps. Experiments have demonstrated that VetSC can accurately interpret smart contract code, enable autonomous safety vetting, and discover safety risks in real-world Dapps. Using our tool, we have successfully discovered 19 new safety risks in the wild, such as expired lottery tickets and double voting. Yue Duan, Shucheng Li, Minghao Li 0003, Fengyuan Xu, Mu Zhang 0001 |
CCS | 7 |
| 2022 | Poster: EOSDFA: Data Flow Analysis of EOSIO Smart ContractsabstractAs an efficient blockchain platform, EOSIO is becoming increasingly popular. However, it has exposed many security problems and caused a large amount of financial losses. In the past, the difficulty of collecting open-source EOSIO smart contracts and analyzing WebAssembly (Wasm) bytecode compiled by EOSIO smart contracts, making few researchers proposed static analysis tools for EOSIO smart contracts, and tools capable of dataflow analysis have not yet appeared. In this work, we first propose a dataflow analysis method for EOSIO smart contracts. Based on Octopus, we designed an efficient dataflow analysis method, which can generate Static Single Assignment (SSA) form intermediate representation (IR) for the objective function and its variables to obtain the results of dataflow. We further proved the effectiveness of the proposed method through experiments on our collected data sets. Levi Taiji Li, Mu Zhang 0001 |
CCS | 2 |
| 2022 | Automated Runtime Mitigation for Misconfiguration Vulnerabilities in Industrial Control SystemsabstractCyber-physical industrial control systems (ICS) commonly implement configuration parameters that can be remotely tuned by human-machine interfaces (HMI) at runtime. These parameters directly control the behaviors of ICSs thus they can be exploited by attackers to compromise the safety of ICSs, proved by real-world attacks worldwide. However, existing anomaly detection methods, which mostly focus on the programmable logic controller (PLC) programs or sensor signals, lack a comprehensive analysis of configuration’s impact on the entire system and thus cannot effectively detect improper parameters. A tool that automatically analyzes complicated control logic to determine the safety of configuration is absent. To fill this gap, we design SmtConf, a verification-based framework for detecting and mitigating improper parameters in ICSs at runtime. To understand the impact of configuration parameters on complicated control logic, we design a symbolic formal model representing behaviors of the ICS under any possible configuration parameters. Based on the model, SmtConf works as a monitoring system that detects safety violations in real-time when the improper configuration is injected. To further assist developers to determine the safe configuration, SmtConf recommends safe configuration parameters by solving an optimization problem. In 18 test cases collected from two production-level ICS testbeds, SmtConf detects all true violations caused by improper parameters in 0.41 seconds and correctly repairs the ICS with recommended safe parameters in 0.45 seconds. Qingzhao Zhang 0001, Xiao Zhu 0001, Mu Zhang 0001, Z. Morley Mao |
RAID | 3 |
| 2020 | APTrace: A Responsive System for Agile Enterprise Level Causality AnalysisabstractWhile backtracking analysis has been successful in assisting the investigation of complex security attacks, it faces a critical dependency explosion problem. To address this problem, security analysts currently need to tune backtracking analysis manually with different case-specific heuristics. However, existing systems fail to fulfill two important system requirements to achieve effective backtracking analysis. First, there need flexible abstractions to express various types of heuristics. Second, the system needs to be responsive in providing updates so that the progress of backtracking analysis can be frequently inspected, which typically involves multiple rounds of manual tuning. In this paper, we propose a novel system, APTrace, to meet both of the above requirements. As we demonstrate in the evaluation, security analysts can effectively express heuristics to reduce more than 99.5% of irrelevant events in the backtracking analysis of real-world attack cases. To improve the responsiveness of backtracking analysis, we present a novel execution-window partitioning algorithm that significantly reduces the waiting time between two consecutive updates (especially, 57 times reduction for the top 1% waiting time). Jiaping Gui, Ding Li 0001, Zhengzhang Chen, Junghwan Rhee, Xusheng Xiao, Mu Zhang 0001, Kangkook Jee, Zhichun Li |
ICDE | 6 |
| 2019 | Towards Automated Safety Vetting of PLC Code in Real-World PlantsabstractSafety violations in programmable logic controllers (PLCs), caused either by faults or attacks, have recently garnered significant attention. However, prior efforts at PLC code vetting suffer from many drawbacks. Static analyses and verification cause significant false positives and cannot reveal specific runtime contexts. Dynamic analyses and symbolic execution, on the other hand, fail due to their inability to handle real-world PLC programs that are event-driven and timing sensitive. In this paper, we propose VetPLC, a temporal context-aware, program analysis-based approach to produce timed event sequences that can be used for automatic safety vetting. To this end, we (a) perform static program analysis to create timed event causality graphs in order to understand causal relations among events in PLC code and (b) mine temporal invariants from data traces collected in Industrial Control System (ICS) testbeds to quantitatively gauge temporal dependencies that are constrained by machine operations. Our VetPLC prototype has been implemented in 15K lines of code. We evaluate it on 10 real-world scenarios from two different ICS settings. Our experiments show that VetPLC outperforms state-of-the-art techniques and can generate event sequences that can be used to automatically detect hidden safety violations. Mu Zhang 0001, Chien-Ying Chen, Bin-Chou Kao, Yassine Qamsane, Yuru Shao, Yikai Lin, Elaine Shi, Sibin Mohan, Kira Barton, James R. Moyne, Z. Morley Mao |
IEEE Symposium on Security and Privacy | 1 |
| 2019 | Duet: an expressive higher-order language and linear type system for statically enforcing differential privacyabstractDuring the past decade, differential privacy has become the gold standard for protecting the privacy of individuals. However, verifying that a particular program provides differential privacy often remains a manual task to be completed by an expert in the field. Language-based techniques have been proposed for fully automating proofs of differential privacy via type system design, however these results have lagged behind advances in differentially-private algorithms, leaving a noticeable gap in programs which can be automatically verified while also providing state-of-the-art bounds on privacy. We propose Duet, an expressive higher-order language, linear type system and tool for automatically verifying differential privacy of general-purpose higher-order programs. In addition to general purpose programming, Duet supports encoding machine learning algorithms such as stochastic gradient descent, as well as common auxiliary data analysis tasks such as clipping, normalization and hyperparameter tuning - each of which are particularly challenging to encode in a statically verified differential privacy framework. We present a core design of the Duet language and linear type system, and complete key proofs about privacy for well-typed programs. We then show how to extend Duet to support realistic machine learning applications and recent variants of differential privacy which result in improved accuracy for many practical differentially private algorithms. Finally, we implement several differentially private machine learning algorithms in Duet which have never before been automatically verified by a language-based tool, and we present experimental results which demonstrate the benefits of Duet's language design in terms of accuracy of trained machine learning models. Joseph P. Near, David Darais, Chike Abuah, Tim Stevens, Pranav Gaddamadugu, Lun Wang 0001, Neel Somani, Mu Zhang 0001, Alex Shan, Dawn Song |
Proc. ACM Program. Lang. | 8 |
| 2018 | NodeMerge: Template Based Efficient Data Reduction For Big-Data Causality AnalysisabstractToday's enterprises are exposed to sophisticated attacks, such as Advanced Persistent Threats~(APT) attacks, which usually consist of stealthy multiple steps. To counter these attacks, enterprises often rely on causality analysis on the system activity data collected from a ubiquitous system monitoring to discover the initial penetration point, and from there identify previously unknown attack steps. However, one major challenge for causality analysis is that the ubiquitous system monitoring generates a colossal amount of data and hosting such a huge amount of data is prohibitively expensive. Thus, there is a strong demand for techniques that reduce the storage of data for causality analysis and yet preserve the quality of the causality analysis. To address this problem, in this paper, we propose NodeMerge, a template based data reduction system for online system event storage. Specifically, our approach can directly work on the stream of system dependency data and achieve data reduction on the read-only file events based on their access patterns. It can either reduce the storage cost or improve the performance of causality analysis under the same budget. Only with a reasonable amount of resource for online data reduction, it nearly completely preserves the accuracy for causality analysis. The reduced form of data can be used directly with little overhead. To evaluate our approach, we conducted a set of comprehensive evaluations, which show that for different categories of workloads, our system can reduce the storage capacity of raw system dependency data by as high as 75.7 times, and the storage capacity of the state-of-the-art approach by as high as 32.6 times. Furthermore, the results also demonstrate that our approach keeps all the causality analysis information and has a reasonably small overhead in memory and hard disk. Yutao Tang, Ding Li 0001, Zhichun Li, Mu Zhang 0001, Kangkook Jee, Xusheng Xiao, Zhenyu Wu 0003, Junghwan Rhee, Fengyuan Xu, Qun Li 0001 |
CCS | 4 |
| 2018 | Things You May Not Know About Android (Un)Packers: A Systematic Study based on Whole-System Emulation
Yue Duan, Mu Zhang 0001, Abhishek Vasisht Bhaskar, Heng Yin 0001, Xiaorui Pan, Tongxin Li 0002, Xueqiang Wang, XiaoFeng Wang 0001 |
NDSS | 2 |
| 2018 | Towards a Timely Causality Analysis for Enterprise Security
Yushan Liu 0004, Mu Zhang 0001, Ding Li 0001, Kangkook Jee, Zhichun Li, Zhenyu Wu 0003, Junghwan Rhee, Prateek Mittal |
NDSS | 2 |
| 2017 | Extracting Conditional Formulas for Cross-Platform Bug SearchabstractWith the recent increase in security breaches in embedded systems and IoT devices, it becomes increasingly important to search for vulnerabilities directly in binary executables in a cross-platform setting. However, very little has been explored in this domain. The existing efforts are prone to producing considerable false positives, and their results cannot provide explainable evidence for human analysts to eliminate these false positives. In this paper, we propose to extract conditional formulas as higher-level semantic features from the raw binary code to conduct the code search. A conditional formula explicitly captures two cardinal factors of a bug: 1) erroneous data dependencies and 2) missing or invalid condition checks. As a result, binary code search on conditional formulas produces significantly higher accuracy and provide meaningful evidence for human analysts to further examine the search results. We have implemented a prototype, XMATCH, and evaluated it using well-known software, including OpenSSL and BusyBox. Experimental results have shown that XMATCH outperforms the existing bug search techniques in terms of accuracy. Moreover, by evaluating 5 recent vulnerabilities, XMATCH provides clear evidence for human analysts to determine if a matched candidate is indeed vulnerable or has been patched. Mu Zhang 0001, Rundong Zhou, Andrew Henderson, Heng Yin 0001 |
AsiaCCS | 3 |
| 2016 | Extract Me If You Can: Abusing PDF Parsers in Malware Detectors
Curtis Carmony, Xunchao Hu, Heng Yin 0001, Abhishek Vasisht Bhaskar, Mu Zhang 0001 |
NDSS | 5 |
| 2015 | Towards Automatic Generation of Security-Centric Descriptions for Android AppsabstractTo improve the security awareness of end users, Android markets directly present two classes of literal app information: 1) permission requests and 2) textual descriptions. Unfortunately, neither can serve the needs. A permission list is not only hard to understand but also inadequate; textual descriptions provided by developers are not security-centric and are significantly deviated from the permissions. To fill in this gap, we propose a novel technique to automatically generate security-centric app descriptions, based on program analysis. We implement a prototype system, DescribeME, and evaluate our system using both DroidBench and real-world Android apps. Experimental results demonstrate that DescribeME enables a promising technique which bridges the gap between descriptions and permissions. A further user study shows that automatically produced descriptions are not only readable but also effectively help users avoid malware and privacy-breaching apps. Mu Zhang 0001, Yue Duan, Heng Yin 0001 |
CCS | 1 |
| 2014 | Semantics-Aware Android Malware Classification Using Weighted Contextual API Dependency GraphsabstractThe drastic increase of Android malware has led to a strong interest in developing methods to automate the malware analysis process. Existing automated Android malware detection and classification methods fall into two general categories: 1) signature-based and 2) machine learning-based. Signature-based approaches can be easily evaded by bytecode-level transformation attacks. Prior learning-based works extract features from application syntax, rather than program semantics, and are also subject to evasion. In this paper, we propose a novel semantic-based approach that classifies Android malware via dependency graphs. To battle transformation attacks, we extract a weighted contextual API dependency graph as program semantics to construct feature sets. To fight against malware variants and zero-day malware, we introduce graph similarity metrics to uncover homogeneous application behaviors while tolerating minor implementation differences. We implement a prototype system, DroidSIFT, in 23 thousand lines of Java code. We evaluate our system using 2200 malware samples and 13500 benign samples. Experiments show that our signature detection can correctly label 93\% of malware instances; our anomaly detector is capable of detecting zero-day malware with a low false negative rate (2\%) and an acceptable false positive rate (5.15\%) for a vetting purpose. Mu Zhang 0001, Yue Duan, Heng Yin 0001, Zhiruo Zhao |
CCS | 1 |
| 2014 | Efficient, context-aware privacy leakage confinement for android applications without firmware moddingabstractAs Android has become the most prevalent operating system in mobile devices, privacy concerns in the Android platform are increasing. A mechanism for efficient runtime enforcement of information-flow security policies in Android apps is desirable to confine privacy leakage. The prior works towards this problem require firmware modification (i.e., modding) and incur considerable runtime overhead. Besides, no effective mechanism is in place to distinguish malicious privacy leakage from those of legitimate uses. In this paper, we take a bytecode rewriting approach. Given an unknown Android app, we selectively insert instrumentation code into the app to keep track of private information and detect leakage at runtime. To distinguish legitimate and malicious leaks, we model the user's decisions with a context-aware policy enforcement mechanism. We have implemented a prototype called Capper and evaluated its efficacy on confining privacy-breaching apps. Our evaluation on 4723 real-world Android applications demonstrates that Capper can effectively track and mitigate privacy leaks. Moreover, after going through a series of optimizations, the instrumentation code only represents a small portion (4.48% on average) of the entire program. The runtime overhead introduced by Capper is also minimal, merely 1.5% for intensive data propagation. Mu Zhang 0001, Heng Yin 0001 |
AsiaCCS | 1 |
| 2014 | AppSealer: Automatic Generation of Vulnerability-Specific Patches for Preventing Component Hijacking Attacks in Android Applications
Mu Zhang 0001, Heng Yin 0001 |
NDSS | 1 |
| 2013 | TransBlocker: Transforming and Taming Privacy-Breaching Android Applications
Mu Zhang 0001, Heng Yin 0001 |
NDSS | 1 |
| 2012 | Hubble: Transparent and Extensible Malware Analysis by Combining Hardware Virtualization and Software Emulation
Lok-Kwong Yan, Manjukumar Jayachandra, Mu Zhang 0001, Heng Yin 0001 |
NDSS | 3 |
| 2012 | V2E: combining hardware virtualization and softwareemulation for transparent and extensible malware analysisabstractA transparent and extensible malware analysis platform is essential for defeating malware. This platform should be transparent so malware cannot easily detect and bypass it. It should also be extensible to provide strong support for heavyweight instrumentation and analysis efficiency. However, no existing platform can meet both requirements. Leveraging hardware virtualization technology, analysis platforms like Ether can achieve good transparency, but its instrumentation support and analysis efficiency is poor. In contrast, software emulation provides strong support for code instrumentation and good analysis efficiency by using dynamic binary translation. However, analysis platforms based on software emulation can be easily detected by malware and thus is poor in transparency. To achieve both transparency and extensibility, we propose a new analysis platform that combines hardware virtualization and software emulation. The essence is precise heterogeneous replay: the malware execution is recorded via hardware virtualization and then replayed in software. Our design ensures the execution replay is precise. Moreover, with page-level recording granularity, the platform can easily adjust to analyze various forms of malware (a process, a kernel module, or a shared library). We implemented a prototype called V2E and demonstrated its capability and efficiency by conducting an extensive evaluation with both synthetic samples and 14 realworld emulation-resistant malware samples. Lok-Kwong Yan, Manjukumar Jayachandra, Mu Zhang 0001, Heng Yin 0001 |
VEE | 3 |