Chunjing Kou

dblp:289/8856 · DBLP profile ↗
← Back
6ranked-venue papers
0as first author
5since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 since 2021Computer networks · 1Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Mitigating the Unprivileged User Namespaces Based Privilege Escalation Attacks with Linux Capabilities
Jingzi Meng, Yuewu Wang, Lingguang Lei, Chunjing Kou, Peng Wang 0009, Huawei Lu
ACISP (3)4
2025 Tracing Your Roots: Exploring the Security Issues of Root Certificates in Android TLS Connections
Yuewu Wang, Lingguang Lei, Peng Wang 0009, Chunjing Kou
Inscrypt (2)5
2025 CapAssess: An Endeavor to Assess and Enhance Linux Capabilities Utilization
abstract
The Linux capabilities mechanism divides the root privileges to provide more fine-grained access control, but its effectiveness depends on proper implementation and configuration. The scattered enforcement of capabilities in the kernel and its sporadic usage in programs pose challenges in gathering assessment information. To address this, we propose three tools for diagnosing potential problems in its design, implementation, and utilization. First, we employ LLVM/Clang to examine the capabilities enforcement in the kernel to map capabilities checks to files. This is the first attempt to explore the interaction between capabilities and other mechanisms, such as UGO. Second, We propose a pattern-based method to identify the sensitive kernel functions protected by capabilities, quanti-fying the overlap problem of capabilities. Third, we employ a customized fuzzing approach to determine the minimal set of capabilities required by programs, offering insight for secure usage. Additionally, Our study is further guided by international access management standards, providing structured criteria for the assessment. Leveraging data collected by our tools, we identify imperfections of capabilities and reported to stakeholders. To the best of our knowledge, this is the first systematic assessment of Linux capabilities.
Jingzi Meng, Yuewu Wang, Lingguang Lei, Jiwu Jing, Pingjian Wang, Chunjing Kou, Peng Wang 0009
SANER6
2024 HiddenStor: A Steganographic Storage System Built on Secret Sharing
Yuewu Wang, Chunjing Kou, Peng Wang 0009, Jiwu Jing
Inscrypt (1)3
2024 A Lightweight Defense Scheme Against Usermode Helper Privilege Escalation Using Linux Capability
Jingzi Meng, Yuewu Wang, Lingguang Lei, Chunjing Kou, Peng Wang 0009
ISC (1)4
2020 SASAK: Shrinking the Attack Surface for Android Kernel with Stricter "seccomp" Restrictions
abstract
The following topics are dealt with: learning (artificial intelligence); mobile computing; security of data; Internet of Things; optimisation; resource allocation; data privacy; protocols; and cloud computing.
Yingjiao Niu, Lingguang Lei, Yuewu Wang, Shijie Jia 0001, Chunjing Kou
MSN6