EDBT 2026 Demo / reviewers in the wild / expert
Linli Lu
dblp:301/9741
· DBLP profile ↗
3ranked-venue papers
0as first author
3since 2021 · last 2022
0000-0003-2615-8300ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | MoLE: Mitigation of Side-channel Attacks against SGX via Dynamic Data Location EscapeabstractNumerous works have experimentally shown that Intel Software Guard eXtensions (SGX) is vulnerable to side-channel attacks (SCAs) and related threats, including transient execution attacks. These threats compromise the security of SGX-protected apps. Obfuscating data access patterns is a realistic way to guard against these threats. However, existing defenses impose either too much performance overhead or additional usage restrictions (such as multi-threading). Furthermore, these obfuscation schemes may no longer work if the attacker has the capacity to single-step the target application. Fan Lang, Wei Wang 0314, Lingjia Meng, Jingqiang Lin 0001, Qiongxiao Wang, Linli Lu |
ACSAC | 6 |
| 2022 | You Cannot Fully Trust Your Device: An Empirical Study of Client-Side Certificate Validation in WPA2-Enterprise NetworksabstractWPA2-Enterprise networks offer access to the Internet widely for multifarious client devices. Certificate-based authentication is adopted on the client-side to authenticate the server during network connection. Due to a lack of professional knowledge, client users commonly fully trust the devices, which may result in insecure network connection and user credential leakage. Previous works commonly focus on the security vulnerabilities due to the design weaknesses of the user interfaces from mainstream operating systems, while the built-in certificate validation implementations, which act as a block box for users to validate the received certificates, are not taken into consideration.In this paper, we design a series of comprehensive testings to evaluate the built-in certificate validation implementations of mainstream client devices for the first time. Moreover, we investigate the configuration options provided by the devices from different vendors, which may downgrade the security of the certificate validation. We select both Windows and Android (from vendors with the largest five market share) devices as our empirical study target. The results show that more than one security vulnerability exists in the built-in certificate validation implementations of the selected devices, and all the selected devices provide a certain option which may downgrade the security of certificate validation. We also conduct a real Evil Twin attack, which reveals that the user credentials can be cracked due to the discovered security vulnerabilities. Our findings have been responsibly disclosed to the relevant device vendors, and we received an assortment of responses, meanwhile many vendors (e.g., Huawei) have already positively acknowledged our findings. Qiongxiao Wang, Shijie Jia 0001, Jingqiang Lin 0001, Linli Lu, Yanduo Fu |
TrustCom | 5 |
| 2021 | Exploring the Security Issues of Trusted CA Certificate Management
Yanduo Fu, Qiongxiao Wang, Jingqiang Lin 0001, Aozhuo Sun, Linli Lu |
ICICS (1) | 5 |