EDBT 2026 Demo / reviewers in the wild / expert
Ping Chen 0003
dblp:33/3675-3
· DBLP profile ↗
30ranked-venue papers
10as first author
12since 2021 · last 2026
0000-0002-8517-0580ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 28 · 10 first-author · 11 since 2021Systems, architecture and hardware · 3 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Dataset Reduction and Watermark Removal via Self-supervised Learning for Model Extraction Attack
Xue Tan, Jun Dai 0001, Xiaoyan Sun 0003, Ping Chen 0003 |
NDSS | 6 |
| 2026 | Was My Data Used for Training? Membership Inference in Open-Source LLMs via Neural Activations
Xue Tan, Mingyu Luo, Zhuyang Yu, Jun Dai 0001, Xiaoyan Sun 0003, Ping Chen 0003 |
NDSS | 7 |
| 2026 | FirmUpdate: Automated multi-phase static analysis for detecting firmware update vulnerabilities in IoT Linux-based firmware
Ping Chen 0003 |
Comput. Secur. | 2 |
| 2026 | SQLaser: Detecting database management system (DBMS) logic bugs with clause-guided fuzzingabstractDatabase management systems (DBMSs) are vital components in modern data-driven systems. Their complexity often leads to logic bugs, which are implementation errors within the DBMSs that can lead to incorrect query results, data exposure, unauthorized access, etc., without necessarily causing visible system failures. Existing detection employs two strategies: rule-based bug detection and coverage-guided fuzzing. In general, rule specification itself is challenging; as a result, rule-based detection is limited to specific and simple rules. Coverage-guided fuzzing blindly explores code paths or blocks, many of which are unlikely to contain logic bugs; therefore, this strategy is cost-ineffective. In this paper, we design SQLaser, a SQL-clause-guided fuzzer for detecting logic bugs in DBMSs. Through a comprehensive examination of existing logic bugs across four distinct DBMSs, excluding those causing system crashes, we have identified 35 logic-bug patterns. These patterns manifest as certain SQL clause combinations that commonly result in logic bugs, and behind these clause combinations are a sequence of functions. We therefore model logic-bug patterns as error-prone function chains (i.e., sequences of functions). We further develop a directed fuzzer with a new path-to-path distance-calculation mechanism for effectively testing these chains and discovering additional logic bugs. This mechanism enables SQLaser to swiftly navigate to target sites and uncover potential bugs emerging from these paths. Our evaluation, conducted on SQLite, MySQL, PostgreSQL, and TiDB, demonstrates that SQLaser significantly accelerates bug discovery compared to other fuzzing approaches, reducing detection time by approximately 60%. As a standalone fuzzer, SQLaser identified 22 bugs spanning 18 of the 35 logic-bug patterns, outperforming contemporary fuzzers such as SQLRight, which only uncovered two logic bugs across two patterns within the same testing period (i.e., 60 days) when testing SQLite. Notably, four of the bugs discovered by SQLaser are zero-day, all of which have been reported to and confirmed by vendors. Ping Chen 0003, Kangjie Lu, Jun Dai 0001, Xiaoyan Sun 0003 |
J. Comput. Secur. | 2 |
| 2025 | Concept Replacer: Replacing Sensitive Concepts in Diffusion Models via Precision LocalizationabstractAs large-scale diffusion models continue to advance, they excel at producing high-quality images but often generate unwanted content, such as sexually explicit or violent imagery. Existing methods for removing such content typically guide the image generation process but can inadvertently modify unrelated regions, leading to inconsistencies with the original model. We propose a novel approach for targeted concept replacement in diffusion models, enabling specific unwanted concepts to be removed without significantly affecting non-target areas. Our method introduces a dedicated concept localizer for precisely identifying the target concept during the denoising process, using few-shot learning to minimize the need for labeled data.Within the identified region, we further introduce a Dual Prompts Cross-Attention module that operates without additional training to substitute the target concept, ensuring minimal disruption to surrounding content. We evaluate our method in terms of concept localization precision and replacement efficiency. Experimental results demonstrate that our method achieves superior precision in localizing target concepts and performs coherent concept replacement with minimal impact on non-target areas, outperforming existing approaches. The code is available at https://github.com/zhang-lingyun/ConceptReplacer Yanwei Fu 0001, Ping Chen 0003 |
CVPR | 4 |
| 2025 | Deep Learning Assisted Reverse Engineering: Recognizing Encryption Loops in RansomwareabstractReverse Engineering (RE) is a critical task performed by security professionals for various purposes. However, the complexity and exertion of malware reverse engineering, particularly for ransomware, have posed significant challenges to experts in the field. In response, this study explores the feasibility of incorporating deep learning techniques to assist the ransomware reverse engineering (RE). To tackle specific challenges of encryption loop recognition, our approach employs two learning strategies. Firstly, we develop code-obfuscation-resilient and encryption-algorithm-agnostic features, including K-complexity and operations that yield equiprobable outputs. Secondly, we carefully select a neural network architecture capable of extracting informative features. The evaluation of our toolchain shows that our toolchain achieves an accuracy of 99% on the test set. Our method exhibits strong generalization capabilities, as it successfully handled common code obfuscation schemes, proprietary and unknown ciphers. When applied to real-world ransomware samples such as WannaCry, Conti, Lockbit, and TeslaCryt, our toolchain effectively identified 205 encryption loops with a low false positive rate of 6.8%. These findings validate the effectiveness of our approach in automatically recognizing encryption code during ransomware reverse engineering. Nanqing Luo, Lan Zhang 0008, Ping Chen 0003, Peng Liu 0005 |
TrustCom | 5 |
| 2025 | FedRAB: Robust federated learning against backdoor attacks based on collaborative defense with smoothingabstractFederated learning (FL) enables collaborative model training without exposing local data, offering privacy benefits. However, its distributed nature makes it vulnerable to backdoor attacks, where adversaries manipulate training data or model updates to trigger attacker-chosen outputs. Existing defenses often fail under high proportions of malicious clients and struggle to balance robustness and model utility. This article proposes FedRAB, a collaborative FL defense framework using dynamic smoothing to mitigate backdoor threats. FedRAB remains effective even when over 50% of clients are malicious. In this framework, clients are categorized into three types: fully trusted clients, malicious but trusted clients and malicious and untrusted clients. The first two inject controlled perturbation noise into their local datasets, suppressing poisoning attacks while preserving accuracy. To address diverse and severe backdoor behaviors, the server applies dimensionality reduction followed by clustering to identify and filter out the most harmful malicious updates. This enhances both the accuracy and efficiency of malicious update detection. The server then clips and perturbs the remaining model updates, further strengthening defense against backdoors while preserving data diversity and generalization. We evaluate the effectiveness of FedRAB on various datasets. For example, on the MNIST dataset, when 65% of clients are malicious, FedRAB reduces the backdoor accuracy from 94.6% to 1.5%, while only decreasing the model's accuracy on benign samples by 1.2%. Xue Tan, Ping Chen 0003 |
J. Comput. Secur. | 2 |
| 2025 | HuntFUZZ: Enhancing error handling testing through clustering based fuzzingabstractTesting a program’s capability to effectively handle errors is a significant challenge, given that program errors are relatively uncommon. To address this, software fault injection (SFI)-based fuzzing combines SFI with traditional fuzzing to inject faults and trigger errors, enabling the testing of (error handling) code. However, current SFI-based fuzzing approaches have overlooked the correlation between paths housing error points. In fact, the execution paths of error points often share common paths. As a result, fuzzers usually generate test cases repeatedly to explore these common paths. This practice can compromise the efficiency of the fuzzer(s). To address this issue, this paper introduces HuntFUZZ, a novel SFI-based fuzzing framework designed to minimize redundant exploration of error points with correlated paths. HuntFUZZ achieves this by clustering these correlated error points and using concolic execution to resolve the path constraints necessary for approaching or reaching these clusters. This approach provides the fuzzer with optimized test cases, allowing it to efficiently explore error points within the cluster while minimizing redundancy. We evaluate HuntFUZZ on a diverse set of 42 applications, and HuntFUZZ successfully reveals 162 known bugs, with 62 of them being related to error handling. Additionally, due to its efficient error point detection method, HuntFUZZ discovers seven unique zero-day bugs, which are all missed by existing fuzzers. Furthermore, we compare HuntFUZZ with four existing fuzzing approaches, including AFL, AFL++, AFLGo, and EH-FUZZ. Our evaluation confirms that HuntFUZZ can cover a broader range of error points, and it exhibits better performance in terms of bug-finding speed. Ping Chen 0003, Jun Dai 0001, Xiaoyan Sun 0003 |
J. Comput. Secur. | 2 |
| 2024 | DSLR-: A low-overhead data structure layout randomization for defending data-oriented programmingabstractBy developing a Turing-complete non-control data attack to bypass existing defenses against control flow attacks, Data-Oriented Programming (DOP) has gained significant attention from researchers in recent years. While several defense techniques have been proposed to mitigate DOP attacks, they often introduce substantial overhead due to the blind protection of a large range of data objects. To address this issue, we focus on selecting and protecting the specific target data that are of interest to DOP attackers, rather than securing the entire non-control data in the program. In this regard, we perform static analysis on 20 real-world applications and identify the target data, verifying that they constitute only a small percentage of the overall program, averaging around 3%. Additionally, we propose a semi-automated tool to analyze how to chain operations on the target data in these 20 applications to achieve Turing-complete attacks. Furthermore, we introduce DSLR-: a low-overhead Data Structure Layout Randomization (DSLR) method, which modifies the existing DSLR technique to only randomize the selected target data for DOP. Experimental results demonstrate that DSLR- effectively mitigates DOP attacks, reducing performance overhead by 71.2% and memory overhead by 82.5% compared to the original DSLR technique. Ping Chen 0003 |
J. Comput. Secur. | 2 |
| 2023 | Semantics-Preserving Reinforcement Learning Attack Against Graph Neural Networks for Malware DetectionabstractAs an increasing number of deep-learning-based malware scanners have been proposed, the existing evasion techniques, including code obfuscation and polymorphic malware, are found to be less effective. In this work, we propose a reinforcement learning based semantics-preserving (i.e. functionality-preserving) attack against black-box GNNs (Graph Neural Networks) for malware detection. The key factor of adversarial malware generation via semanticNopsinsertion is to select the appropriate semanticNopsand their corresponding basic blocks. The proposed attack uses reinforcement learning to automatically make these “how to select” decisions. To evaluate the attack, we have trained two kinds of GNNs with three types (e.g., Backdoor, Trojan, and Virus) of Windows malware samples and various benign Windows programs. The evaluation results have shown that the proposed attack can achieve a significantly higher evasion rate than four baseline attacks, namely the binary diversification attack, the semantics-preserving random instruction insertion attack, the semantics-preserving accumulative instruction insertion attack, and the semantics-preserving gradient-based instruction insertion attack. Lan Zhang 0008, Peng Liu 0005, Yoon-Ho Choi, Ping Chen 0003 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | HARM: Hardware-Assisted Continuous Re-randomization for MicrocontrollersabstractMicrocontroller-based embedded systems have become ubiquitous with the emergence of IoT technology. Given its critical roles in many applications, its security is becoming increasingly important. Unfortunately, MCU devices are especially vulnerable. Code reuse attacks are particularly noteworthy since the memory address of firmware code is static. This work seeks to combat code reuse attacks, including ROP and more advanced JIT-ROP via continuous randomization. Previous proposals are geared towards full-fledged OSs with rich runtime environments, and therefore cannot be applied to MCUs. We propose the first solution for ARM-based MCUs. Our system, named HARM, comprises a secure runtime and a binary analysis tool with rewriting module. The secure runtime, protected inside the secure world, proactively triggers and performs non-bypassable randomization to the firmware running in a sandbox in the normal world. Our system does not rely on any firmware feature, and therefore is generally applicable to both bare-metal and RTOS-powered firmware. We have implemented a prototype on a development board. Our evaluation results indicate that HARM can effectively thaw code reuse attacks while keeping the performance and energy overhead low. Jiameng Shi, Le Guan, Dayou Zhang, Ping Chen 0003, Ning Zhang 0017 |
EuroS&P | 5 |
| 2021 | A Co-Design Adaptive Defense Scheme With Bounded Security Damages Against Heartbleed-Like AttacksabstractThis paper proposes a co-design adaptive defense scheme against a class of zero-day buffer over-read attacks that follow unknown stationary probability distributions. In particular, the co-design scheme integrates an improved UCB algorithm and a customized server. The improved UCB algorithm adaptively allocates guard pages on a heap based on induced damage of the guard pages so as to minimize the accumulated damage over time. The security damages of the improved UCB algorithm are proven to be always below a temporal bound without knowing which attack is launched when the buffer allocation follows a certain stationary probability distribution. Then an efficient server modification is introduced to randomly allocate buffers. Moreover, the damages of our scheme asymptotically converge to those of the optimal defense policy where the launched attacks and their distributions are known in advance. Further, the co-design scheme is evaluated with several real-world Heartbleed attacks. The experiment results demonstrate the validity of the upper bound and show that the adaptive defense is effective against all the attacks of interest with runtime overheads as low as 5%. Zhisheng Hu, Ping Chen 0003, Peng Liu 0005 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2020 | DeepReturn: A deep neural network can learn how to detect previously-unseen ROP payloads without using any heuristicsabstractReturn-oriented programming (ROP) is a code reuse attack that chains short snippets of existing code to perform arbitrary operations on target machines. Existing detection methods against ROP exhibit unsatisfactory detection accuracy and/or have high runtime overhead. In this paper, we present DeepReturn, which innovatively combines address space layout guided disassembly and deep neural networks to detect ROP payloads. The disassembler treats application input data as code pointers and aims to find any potential gadget chains, which are then classified by a deep neural network as benign or malicious. Our experiments show that DeepReturn has high detection rate (99.3%) and a very low false positive rate (0.01%). DeepReturn successfully detects all of the 100 real-world ROP exploits that are collected in-the-wild, created manually or created by ROP exploit generation tools. DeepReturn is non-intrusive and does not incur any runtime overhead to the protected program. Zhisheng Hu, Yiwei Fu, Ping Chen 0003, Peng Liu 0005 |
J. Comput. Secur. | 5 |
| 2018 | Feedback control can make data structure layout randomization more cost-effective under zero-day attacksabstractIn the wake of the research community gaining deep understanding about control-hijacking attacks, data-oriented attacks have emerged. Among data-oriented attacks, data structure manipulation attack (DSMA) is a major category. Pioneering research was conducted and shows that DSMA is able to circumvent the most effective defenses against control-hijacking attacks — DEP, ASLR and CFI. Up to this day, only two defense techniques have demonstrated their effectiveness: Data Flow Integrity (DFI) and Data Structure Layout Randomization (DSLR). However, DFI has high performance overhead, and dynamic DSLR has two main limitations. L-1: Randomizing a large set of data structures will significantly affect the performance. L-2: To be practical, only a fixed sub-set of data structures are randomized. In the case that the data structures targeted by an attack are not covered, dynamic DSLR is essentially noneffective. To address these two limitations, we propose a novel technique, feedback-control-based adaptive DSLR and build a system named SALADSPlus. SALADSPlus seeks to optimize the trade-off between security and cost through feedback control. Using a novel feedback-control-based adaptive algorithm extended from the Upper Confidence Bound (UCB) algorithm, the defender (controller) uses the feedbacks (cost-effectiveness) from previous randomization cycles to adaptively choose the set of data structures to randomize (the next action). Different from dynamic DSLR, the set of randomized data structures are adaptively changed based on the feedbacks. To obtain the feedbacks, SALADSPlus inserts canary in each data structure at the time of compilation. We have implemented SALADSPlus based on gcc-4.5.0. Experimental results show that the runtime overheads are 1.8%, 3.7%, and 5.3% when the randomization cycles are selected as 10s, 5s, and 1s respectively. Ping Chen 0003, Zhisheng Hu, Jun Xu 0024, Peng Liu 0005 |
Cybersecur. | 1 |
| 2017 | What You See is Not What You Get! Thwarting Just-in-Time ROP with ChameleonabstractAddress space randomization has long been used for counteracting code reuse attacks, ranging from conventional ROP to sophisticated Just-in-Time ROP. At the high level, it shuffles program code in memory and thus prevents malicious ROP payload from performing arbitrary operations. While effective in mitigating attacks, existing randomization mechanisms are impractical for real-world applications and systems, especially considering the significant performance overhead and potential program corruption incurred by their implementation. In this paper, we introduce CHAMELEON, a practical defense mechanism that hinders code reuse attacks, particularly Just-in-Time ROP attacks. Technically speaking, CHAMELEON instruments program code, randomly shuffles code page addresses and minimizes the attack surface exposed to adversaries. While this defense mechanism follows in the footprints of address space randomization, our design principle focuses on using randomization to obstruct code page disclosure, making the ensuing attacks infeasible. We implemented a prototype of CHAMELEON on Linux operating system and extensively experimented it in different settings. Our theoretical and empirical evaluation indicates the effectiveness and efficiency of CHAMELEON in thwarting Just-in-Time ROP attacks. Ping Chen 0003, Jun Xu 0024, Zhisheng Hu, Xinyu Xing 0001, Bing Mao 0001, Peng Liu 0005 |
DSN | 1 |
| 2017 | Postmortem Program Analysis with Hardware-Enhanced Post-Crash Artifacts
Jun Xu 0024, Dongliang Mu, Xinyu Xing 0001, Peng Liu 0005, Ping Chen 0003, Bing Mao 0001 |
USENIX Security Symposium | 5 |
| 2017 | Dancing with Wolves: Towards Practical Event-driven VMM MonitoringabstractThis paper presents a novel framework that enables practical event-driven monitoring for untrusted virtual machine monitors (VMMs) in cloud computing. Unlike previous approaches for VMM monitoring, our framework neither relies on a higher privilege level nor requires any special hardware support. Instead, we place the trusted monitor at the same privilege level and in the same address space with the untrusted VMM to achieve superior efficiency, while proposing a unique mutual-protection mechanism to ensure the integrity of the monitor. Our security analysis demonstrates that our framework can provide high-assurance for event-driven VMM monitoring, even if the highest-privilege VMM is fully compromised. The experimental results show that our framework only incurs trivial performance overhead for enforcing event-driven monitoring policies, exhibiting tremendous performance improvement on previous approaches. Liang Deng, Peng Liu 0005, Jun Xu 0024, Ping Chen 0003, Qingkai Zeng 0002 |
VEE | 4 |
| 2016 | CREDAL: Towards Locating a Memory Corruption Vulnerability with Your Core DumpabstractAfter a program has crashed and terminated abnormally, it typically leaves behind a snapshot of its crashing state in the form of a core dump. While a core dump carries a large amount of information, which has long been used for software debugging, it barely serves as informative debugging aids in locating software faults, particularly memory corruption vulnerabilities. A memory corruption vulnerability is a special type of software faults that an attacker can exploit to manipulate the content at a certain memory. As such, a core dump may contain a certain amount of corrupted data, which increases the difficulty in identifying useful debugging information (e.g. , a crash point and stack traces). Without a proper mechanism to deal with this problem, a core dump can be practically useless for software failure diagnosis. In this work, we develop CREDAL, an automatic tool that employs the source code of a crashing program to enhance core dump analysis and turns a core dump to an informative aid in tracking down memory corruption vulnerabilities. Specifically, CREDAL systematically analyzes a core dump potentially corrupted and identifies the crash point and stack frames. For a core dump carrying corrupted data, it goes beyond the crash point and stack trace. In particular, CREDAL further pinpoints the variables holding corrupted data using the source code of the crashing program along with the stack frames. To assist software developers (or security analysts) in tracking down a memory corruption vulnerability, CREDAL also performs analysis and highlights the code fragments corresponding to data corruption. Jun Xu 0024, Dongliang Mu, Ping Chen 0003, Xinyu Xing 0001, Pei Wang 0007, Peng Liu 0005 |
CCS | 3 |
| 2015 | A Practical Approach for Adaptive Data Structure Layout RandomizationabstractAttackers often corrupt data structures to compromise software systems. As a countermeasure, data structure layout randomization has been proposed. Unfortunately, existing techniques require manual designation of randomize-able data structures without guaranteeing the correctness and keep the layout unchanged at runtime. We present a system, called SALADS, that automatically translates a program to a DSSR (Data Structure Self-Randomizing) program. At runtime, a DSSR program dynamically randomizes the layout of each security-sensitive data structure by itself autonomously. DSSR programs regularly re-randomize a data structure when it has been accessed several times after last randomization. More importantly, DSSR programs automatically determine the randomizability of instances and randomize each instance independently. We have implemented SALADS based on gcc-4.5.0 and generated DSSR user-level applications, OS kernels, and hypervisors. Our experiments show that the DSSR programs can defeat a wide range of attacks with reasonable performance overhead. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Ping Chen 0003, Jun Xu 0024, Zhiqiang Lin 0001, Dongyan Xu, Bing Mao 0001, Peng Liu 0005 |
ESORICS (1) | 1 |
| 2014 | System Call Redirection: A Practical Approach to Meeting Real-World Virtual Machine Introspection NeedsabstractExisting VMI techniques have high overhead, and require customized introspection programs/tools for different guest OS versions - lack of generality. In this paper, we present Shadow Context, a system for close-to-real time manual-effort-free VMI. Shadow Context can meet several important real-world VMI needs which existing VMI techniques cannot. Compared to other automatic introspection tool generation techniques, Shadow Contexthas two merits: (1) Its overhead is significantly less. It achieves close-to-real time VMI. (2) It significantly improves the practical usefulness of introspection tools by allowing one introspection program to inspect a variety of guest OS versions. These merits are achieved via a new concept called "Shadow Context" which allows the guest OSessystem call code to be reused inside a "shadowed" portion of the context of the out-of-guest inspection program. Besides, Shadow Context is secure enough to defend against a variety of real world attacks. Shadow Context is designed, implemented and systematically evaluated. Experimental results show that the performance overhead is about 75%with a median initialization time of 0.117 milliseconds. Ping Chen 0003, Peng Liu 0005, Bing Mao 0001 |
DSN | 2 |
| 2013 | JITSafe: a framework against Just-in-time spraying attacksabstractA new code‐reuse attack, named Just‐in‐time (JIT) spraying attack, leverages the predictable generated JIT compiled code to launch an attack. It can circumvent the defenses such as data execution prevention and address space layout randomisation built‐in in the modern operation system, which were thought the insurmountable barrier so that the attackers cannot construct the traditional code injection attacks. In this study, the authors describe JITSafe, a framework that can be applied to existing JIT‐based virtual machines (VMs), in the purpose of preventing the attacker from reusing the JIT compiled code to construct the attack. The authors framework narrows the time window of the JIT compiled code in the executable pages, eliminates the immediate value and obfuscates the JIT compiled code. They demonstrate the effectiveness of JITSafe that it can successfully prevent existing JIT spraying attacks with low performance overhead. Ping Chen 0003, Bing Mao 0001 |
IET Inf. Secur. | 1 |
| 2012 | RIM: A Method to Defend from JIT Spraying AttackabstractAs a code reuse technique, JIT spraying attack becomes popular on the JITed VM (Virtual Machine) (e.g., Javascript Engine, Flash Engine). Using a bug in web applications, an attacker can reuse the code generated by the JIT (Just-In-Time) compiler, which is used to optimize the performance of web applications. JIT spraying attacks can circumvent DEP and ASLR -- protection mechanisms of modern operating systems. Based on the observation that JIT spraying attack mostly uses the immediate operand of the arithmetic instruction to build a shellcode, we propose RIM, a technique that obfuscates the arithmetic operations in the JITed code and prevents attackers from reusing the native code to construct a malicious code. We implement a prototype on Tamarin flash engine and demonstrate the effectiveness of RIM. Experimental results show that RIM's overhead is very low (less than 1%). And RIM greatly improves the security functionality of JIT compilers. Ping Chen 0003, Bing Mao 0001, Li Xie 0001 |
ARES | 2 |
| 2012 | CloudER: a framework for automatic software vulnerability location and patching in the cloudabstractIn a virtualization-based cloud infrastructure, customers of the cloud deploy virtual machines (VMs) with their own applications and customized runtime environments. The cloud provider supports the execution of these VMs without detailed knowledge of the guest applications and operating systems in the VMs. In addition to elastic resource provisioning for the VMs, a desirable "value-added" service the cloud provider can provide is the emergency response to runtime incidences of software bugs and vulnerabilities. The challenge is to facilitate the automatic runtime detection, location, and patching of the software vulnerability -- outside the VMs and without the source code. In this paper, we present CloudER, a cloud "emergency room" architecture that automatically detect, locate, and patch software vulnerabilities in cloud application binaries at runtime. CloudER leverages an existing taint-based system (Demand Emulation) for runtime anomaly detection, employs new algorithms for software vulnerability location and patch generation, and adapts a virtual machine introspection system (XenAccess) for dynamic patching. Our preliminary evaluation experiments with a number of real-world server applications show that CloudER achieves timely response to runtime software faults or attacks from outside the VMs. The main contributions of this paper are highlighted as follows: (1) CloudER is an integrated architecture that improves the runtime reliability of cloud applications. It covers the full life cycle of exploit detection, culprit instruction location, patch generation and application, and execution state recording and reset -- all performed from outside the protected VM and without the source code of the applications. (2) While leveraging existing techniques for taint-based exploit detection, CloudER involves new methods for culprit instruction location and binary patch generation. The methods cover some of the most common types of software vulnerabilities and the patches generated are of small size (tens of bytes). (3) CloudER incurs reasonable performance overhead to the application in comparison with running the application in an unprotected VM. The interruption to the production VM's execution (for culprit instruction location and patch generation) is less than half a minute in our experiments with real-world applications. Ping Chen 0003, Dongyan Xu, Bing Mao 0001 |
AsiaCCS | 1 |
| 2012 | RandHyp: Preventing Attacks via Xen Hypercall Interface
Ping Chen 0003, Bing Mao 0001, Li Xie 0001 |
SEC | 2 |
| 2011 | Automatic construction of jump-oriented programming shellcode (on the x86)abstractReturn-Oriented Programming (ROP) is a technique which leverages the instruction gadgets in existing libraries/executables to construct Turing complete programs. However, ROP attack is usually composed with gadgets which are ending in ret instruction without the corresponding call instruction. Based on this fact, several defense mechanisms have been proposed to detect the ROP malicious code. To circumvent these defenses, Return-Oriented Programming without returns has been proposed recently, which uses the gadgets ending in jmp instruction but with much diversity. In this paper, we propose an improved ROP techniques to construct the ROP shellcode without returns. Meanwhile we implement a tool to automatically construct the real-world Return-Oriented Programming without returns shellcode, which as demonstrated in our experiment can bypass most of the existing ROP defenses. Ping Chen 0003, Xiao Xing, Bing Mao 0001, Li Xie 0001, Xiaobin Shen 0001, Xinchun Yin |
AsiaCCS | 1 |
| 2011 | JITDefender: A Defense against JIT Spraying Attacks
Ping Chen 0003, Bing Mao 0001, Li Xie 0001 |
SEC | 1 |
| 2010 | Return-Oriented Rootkit without Returns (on the x86)
Ping Chen 0003, Xiao Xing, Bing Mao 0001, Li Xie 0001 |
ICICS | 1 |
| 2009 | BRICK: A Binary Tool for Run-Time Detecting and Locating Integer-Based VulnerabilityabstractInteger-based vulnerability is an extremely serious bug for programs written in languages such as C/C++. However,in practice, very few software security tools can efficiently detect and accurately locate such vulnerability. In addition, previous methods mainly depend on source code analysis and recompilation which are impractical when protecting the program without source code. In this paper,we present the design, implementation, and evaluation of BRICK (binary run-time integer-based vulnerability checker), a tool for run-time detecting and locating integer-based vulnerability. Given an integer-based vulnerability exploit, BRICK is able to catch the value which falls out of the range of its corresponding type, then find the root cause for this vulnerability, and finally locate the vulnerability code and give a warning, based on its checking scheme. BRICK is implemented on the dynamic binary instrumentation framework Valgrind and its type inference plug-in: Catchconv. Preliminary experimental results are quit promising: BRICK can detect and locate most of integer-based vulnerability in real software, and has very low false positives and negatives. Ping Chen 0003, Zhi Xin, Bing Mao 0001, Li Xie 0001 |
ARES | 1 |
| 2009 | Traffic Controller: A Practical Approach to Block Network Covert Timing ChannelabstractThis paper discusses the network covert timing channel. This channel modulates network packet's time properties to transfer information secretly. Much work has been done in inventing and utilizing network covert timing channels, however, there is not so much work in other areas such as detecting and handling covert channels. Covert channel detection is difficult, what's more, it often needs human analysis to confirm whether a suspect is a real covert channel. However, we figured out that we can try to control covert channels without knowing whether there are covert channels in using, which means our approach does not rely on the detection of covert channels at all. A network traffic controller is proposed to undermine the network covert timing channel communication mechanism. We will show how our method works and why our traffic control strategy is especially efficient to handle network covert timing channels. Ping Chen 0003, Yi Ge, Bing Mao 0001, Li Xie 0001 |
ARES | 2 |
| 2009 | IntFinder: Automatically Detecting Integer Bugs in x86 Binary Program
Ping Chen 0003, Xiaobin Shen 0001, Xinchun Yin, Bing Mao 0001, Li Xie 0001 |
ICICS | 1 |