Qidan He

dblp:381/7152 · DBLP profile ↗
← Back
2ranked-venue papers
0as first author
2since 2021 · last 2024
0009-0009-0481-6537ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 2 · 2 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Malware analysis · 67% Systems and software security · 33%
Databases, data mining, and information retrieval
1 paper
Data integration and cleaning · 100%

Topics — the 4 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Malware analysis › mobile malware detection
android malware detection
0.812024
Uncovering and Mitigating the Impact of Code Obfuscation on Dataset Annotation with Antivirus Engines · ISSTA 2024
Systems and software security › software protection
code obfuscation
0.812024
Uncovering and Mitigating the Impact of Code Obfuscation on Dataset Annotation with Antivirus Engines · ISSTA 2024
Malware analysis › mobile malware detection › android malware detection
obfuscation-resilient detection
0.812024
Uncovering and Mitigating the Impact of Code Obfuscation on Dataset Annotation with Antivirus Engines · ISSTA 2024
Data integration and cleaning › data quality
annotation quality
0.212024
Uncovering and Mitigating the Impact of Code Obfuscation on Dataset Annotation with Antivirus Engines · ISSTA 2024

Methods — techniques the papers use, named apart from their topics

engine categorization · 1.5data-driven evaluation · 1.5
YearPublicationVenuePosition
2024 Uncovering and Mitigating the Impact of Code Obfuscation on Dataset Annotation with Antivirus Engines
abstract
With the widespread application of machine learning-based Android malware detection methods, building a high-quality dataset has become increasingly important. Existing large-scale datasets are mostly annotated with VirusTotal by aggregating the decisions of antivirus engines, and most of them indiscriminately accept the decisions of all engines. In reality, however, these engines have different capabilities in detecting malware, especially those that have been obfuscated. Previous research has revealed that code obfuscation degrades the detection performance of these engines to varying degrees. This makes us believe that using all engines indiscriminately is unreasonable for dataset annotation. Therefore, in this paper, we first conduct a data-driven evaluation to confirm the negative effects of code obfuscation on engine-based dataset annotation. To gain a deeper understanding of the reasons behind this phenomenon, we evaluate the availability, effectiveness and robustness of every engine under various code obfuscation techniques. Then we categorize the engines and select a set of obfuscation-robust engines. Finally, we conduct comprehensive experiments to verify the effectiveness of the selected engines for dataset annotation. Our experiments show that when 50% obfuscated samples are mixed into the training set, on the classic malware detectors Drebin and Malscan, using our selected engines can effectively improve detection performance by 15.21% and 19.23%, respectively, compared to using all the engines.
Cuiying Gao, Yueming Wu 0001, Heng Li 0008, Wei Yuan 0001, Qidan He, Yang Liu 0003
ISSTA6
2024 PMDET: Automated Detection Tool of Android Parcel Mismatch
abstract
Android has designed Parcel as its high-performance serialization mechanism to pass objects across processes. For classes to be serialized by Parcel, developers must implement the methods for writing and reading the object's properties to and from a Parcel container. The inconsistency between those methods implemented by careless developers introduces Parcel Mismatch bugs, often occurring in vendor-customed classes due to lack of public scrutiny. Parcel Mismatch bugs can be abused by malicious applications to gain system privilege. However, no mature solutions exist to detect Parcel Mismatch bugs. This paper proposes PMDET, a fuzzing-based detection tool for Parcel Mismatch bugs. PMDET is capable of handling different vendors' firmware without actual devices. It loads Parcelable classes from Android firmware, emulates the Android runtime environment for Parcel to work, and monitors the serialization and deserialization procedures for mismatches. We evaluate PMDET with various Android firmware from different vendors. PMDET has identified 12 previously undisclosed mismatches, 6 of which are exploitable. Source code: https://github.com/tkmikan/pmdet.
Yunfan Zhan, Qidan He, Xiuzhen Chen
SANER2