EDBT 2026 Demo / reviewers in the wild / expert
Juanru Li
dblp:41/3261
· DBLP profile ↗
64ranked-venue papers
1as first author
19since 2021 · last 2026
0000-0002-7978-595XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 41 · 1 first-author · 12 since 2021Software engineering, systems software and programming languages · 16 · 6 since 2021Systems, architecture and hardware · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 1 since 2021Databases, data management, data science and information retrieval · 2Computer networks · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | QCP: A Practical Separation Logic-Based C Program Verification Tool
Xiwei Wu, Yueyang Feng, Xiaoyang Lu, Tianchuan Lin, Shushu Wu, Lihan Xie, Chengxi Yang, Hongyi Zhong, Juanru Li, Naijun Zhan, Zhenjiang Hu 0002, Qinxiang Cao |
TASE | 12 |
| 2025 | Enhancing Security in Third-Party Library Reuse - Comprehensive Detection of 1-day Vulnerability through Code Patch Analysis
Shangzhi Xu, Jialiang Dong, Weiting Cai, Juanru Li, Arash Shaghaghi |
NDSS | 4 |
| 2025 | Hotpatching on the Fly - Mitigating Drone Incidents Arising From Incorrect ConfigurationabstractManufacturers offer adjustable control parameters for flight control systems to accommodate diverse environments and missions. To ensure flight safety, they also develop established boundaries, i.e., range specifications for parameter values. However, even when the configuration parameters fall within the prescribed manufacturer range, they could still lead to instability or even severe incidents like crashes, which are referred to asRange Specification Bugs. Prior research has suggested shrinking the range of parameter values to protect drones from the adverse effects of such bugs. However, narrowing the range of parameters may only reduce the probability of errors and could potentially limit the drone’s adaptability. To overcome this limitation, we present an online approach that analyzes a sequence of flight states to detect any potential triggering of bugs and rectify the drone by dynamically adjusting its parameters. We implemented the rectification approach,ConFix, and applied it in current prevalent flight control systems, Ardupilot and PX4. The results demonstrated thatConFixachieved an average rectification success rate of 80%. Ruidong Han, Juanru Li, Zhuo Ma 0001, David Lo 0001, Arash Shaghaghi, Jianfeng Ma 0001, Siqi Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Real-time Rectifying Flight Control Misconfiguration Using Intelligent AgentabstractConfigurations are supported by most flight control systems, allowing users to control a flying drone adapted to complexities such as environmental changes or mission alterations. Such an advanced functionality also introduces a significant problem—misconfiguration settings. It may cause drone instability, threaten drone safety, and potentially lead to substantial financial loss. However, detecting and rectifying misconfigurations across different flight control systems is challenging because (1) (mis)configuration-related code snippets might be syntactically correct and thus hard to identify through traditional code analysis; (2) the response to each configuration varies under different flying scenarios. In this article, we propose and implement a novel rectification approach, Nyctea , to detect instability caused by misconfigurations and conduct an on-the-fly rectification. Nyctea first continuously inspects state changes over consecutive time intervals and calculates the overall deviations to determine whether a drone is in a transition of instability to control loss. When a potential instability is reported, Nyctea instantly invokes a pre-trained intelligent agent to automatically generate proper configurations and then re-configure the drone against entering a state of loss of control. This process of reconfiguration is conducted iteratively until the instability is eliminated. We integrated Nyctea with the widely used flight control system, Ardupilot and PX4 . The simulated and practical experiment results showed that Nyctea successfully eliminates instabilities caused by 85% of misconfigurations. For each misconfiguration, Nyctea averagely generated 4 to 5 configurations to achieve a successful rectification. Ruidong Han, Shangzhi Xu, Juanru Li, Elisa Bertino, David Lo 0001, Jianfeng Ma 0001, Siqi Ma 0001 |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2024 | EvilScreen Attack: Smart TV Hijacking via Multi-Channel Remote Control MimicryabstractModern smart TVs often communicate with their remote controls (including the smartphone simulated ones) using multiple wireless channels (e.g., Infrared, Bluetooth, and Wi-Fi). However, this multi-channel remote control communication introduces a new attack surface. An inherent security flaw is that remote controls of most smart TVs are designed to work in a benign environment rather than an adversarial one, and thus wireless communications between a smart TV and its remote controls are not strongly protected. Attackers can leverage such a flaw to abuse the remote control communication and compromise smart TV systems. In this paper, we propose EVILSCREEN, a novel attack that exploits ill-protected remote control communications to access protected resources of a smart TV or even control the screen. EVILSCREEN exploits a multi-channel remote control mimicry vulnerability present in today smart TVs. Unlike other attacks, which compromise the TV system by exploiting code vulnerabilities or malicious third-party apps, EVILSCREEN directly reuses commands of different remote controls, combines them together to circumvent deployed authentication and isolation policies, and finally accesses or controls TV resources remotely. We evaluated eight mainstream smart TVs and found that they are all vulnerable to EVILSCREEN attacks, including a Samsung product adopting the ISO/IEC security specification. Yiwei Zhang 0008, Siqi Ma 0001, Tiancheng Chen, Juanru Li, Robert H. Deng, Elisa Bertino |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | A Credential Usage Study: Flow-Aware Leakage Detection in Open-Source ProjectsabstractAuthentication and cryptography are critical security functions and, thus, are very often included as part of code. These functions require using credentials, such as passwords, security tokens, and cryptographic keys. However, developers often incorrectly implement/use credentials in their code because of a lack of secure coding skills. This paper analyzes open-source projects concerning the correct use of security credentials. We developed a semantic-rich, language-independent analysis approach for analyzing many projects automatically. We implemented a detection tool, SEAGULL, to automatically check open-source projects based on string literal and code structure information. Instead of analyzing the entire project code, which might result in path explosion when constructing data and control dependencies, SEAGULL pinpoints all literal constants to identify credential candidates and then analyzes the code snippets correlated to these candidates. SEAGULL accurately identifies the leaked credentials by obtaining semantic and syntax information about the code. We applied SEAGULL to 377 open-source projects. SEAGULL successfully reported 19 real-world credential leakages out of those projects. Our analysis shows that some developers protected or erased the credentials in the current project versions, but previously used credentials can still be extracted from the project’s historical versions. Although the implementations of credential leakages seem to be fixed in the current projects, attackers could successfully log into accounts if developers keep using the same credentials as before. Additionally, we found that such credential leakages still affect some projects. By exploiting leaked credentials, attackers can log into particular accounts. Ruidong Han, Huihui Gong, Siqi Ma 0001, Juanru Li, Chang Xu 0002, Elisa Bertino, Surya Nepal, Zhuo Ma 0001, Jianfeng Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Range Specification Bug Detection in Flight Control System Through FuzzingabstractDevelopers and manufacturers provide configurable control parameters for flight control programs to support various environments and missions, along with suggested ranges for these parameters to ensure flight safety. However, this flexible mechanism can also introduce a vulnerability known as range specification bugs. The vulnerability originates from the evidence that certain combinations of parameter values may affect the drone's physical stability even though its parameters are within the suggested range. The paper introduces a novel system calledicsearcher, designed to identify incorrect configurations or unreasonable combinations of parameters and suggest more reasonable ranges for these parameters.icsearcherapplies a metaheuristic search algorithm to find configurations with a high probability of driving the drone into unstable states. In particular,icsearcheradopts a machine learning-based predictor to assist the searcher in evaluating the fitness of configuration. Finally, leveraging searched incorrect configurations,icsearchercan summarize the feasible ranges through multi-objective optimization.icsearcherapplies a predictor to guide the search, which eliminates the need for realistic/simulation executions when evaluating configurations and further promotes search efficiency. We have carried out experimental evaluations oficsearcherin different control programs. The evaluation results show that the system successfully reports potentially incorrect configurations, of which over$94\%$leads to unstable states. Ruidong Han, Siqi Ma 0001, Juanru Li, Surya Nepal, David Lo 0001, Zhuo Ma 0001, Jianfeng Ma 0001 |
IEEE Trans. Software Eng. | 3 |
| 2023 | Medusa Attack: Exploring Security Hazards of In-App QR Code Scanning
Xing Han, Zeyuan Chen 0002, Yiwei Zhang 0008, Siqi Ma 0001, Yu Yu 0001, Elisa Bertino, Juanru Li |
USENIX Security Symposium | 10 |
| 2022 | KingFisher: Unveiling Insecurely Used Credentials in IoT-to-Mobile CommunicationsabstractToday users can access and/or control their IoT devices using mobile apps. Such interactions often rely on IoT-to-Mobile communication that supports direct data exchanges between IoT devices and smartphones. To guarantee mutual authentication and encrypted data transmission in IoT-to-Mobile communications while keeping lightweight implementation, IoT devices and smartphones often share credentials in advance with the help of a cloud server. Since these credentials impact communication security, in this paper we seek to understand how such sensitive materials are implemented. We design a set of analysis techniques and implement them in KingFisher, an analysis framework. KingFisher identifies shared credentials, tracks their uses, and examines violations against nine security properties that the implementation of credentials should satisfy. With an evaluation of eight real-world IoT solutions with more than 35 million deployed devices, KingFisher revealed that all these solutions involve insecurely used credentials, and are subject to privacy leakage or device hijacking. Yiwei Zhang 0008, Siqi Ma 0001, Juanru Li, Dawu Gu, Elisa Bertino |
DSN | 3 |
| 2022 | SIMulation: Demystifying (Insecure) Cellular Network based One-Tap Authentication ServicesabstractA recently emerged cellular network based One-Tap Authentication (OTAuth) scheme allows app users to quickly sign up or log in to their accounts conveniently: Mobile Network Operator (MNO) provided tokens instead of user passwords are used as identity credentials. After conducting a first in-depth security analysis, however, we have revealed several fundamental design flaws among popular OTAuth services, which allow an adversary to easily (1) perform unauthorized login and register new accounts as the victim, (2) illegally obtain identities of victims, and (3) interfere OTAuth services of legitimate apps. To further evaluate the impact of our identified issues, we propose a pipeline that integrates both static and dynamic analysis. We examined 1,025/894 Android/iOS apps, each app holding more than 100 million installations. We confirmed 396/398 Android/iOS apps are affected. Our research systematically reveals the threats against OTAuth services. Finally, we provide suggestions on how to mitigate these threats accordingly. Xing Han, Zeyuan Chen 0002, Yuhong Nan, Juanru Li, Dawu Gu |
DSN | 5 |
| 2022 | PEDroid: Automatically Extracting Patches from Android App Updates
Hehao Li, Yizhuo Wang 0003, Juanru Li, Dawu Gu |
ECOOP | 4 |
| 2022 | Control Parameters Considered Harmful: Detecting Range Specification Bugs in Drone Configuration Modules via Learning-Guided SearchabstractIn order to support a variety of missions and deal with different flight environments, drone control programs typically provide configurable control parameters. However, such a flexibility introduces vulnerabilities. One such vulnerability, referred to as range specification bugs, has been recently identified. The vulnerability originates from the fact that even though each individual parameter receives a value in the recommended value range, certain combinations of parameter values may affect the drone physical stability. In this paper, we develop a novel learning-guided search system to find such combinations, that we refer to as incorrect configurations. Our system applies metaheuristic search algorithms mutating configurations to detect the configuration parameters that have values driving the drone to unstable physical states. To guide the mutations, our system leverages a machine learning based predictor as the fitness evaluator. Finally, by utilizing multi-objective optimization, our system returns the feasible ranges based on the mutation search results. Because in our system the mutations are guided by a predictor, evaluating the parameter configurations does not require realistic/simulation executions. Therefore, our system supports a comprehensive and yet efficient detection of incorrect configurations. We have carried out an experimental evaluation of our system. The evaluation results show that the system successfully reports potentially incorrect configurations, of which over 85% lead to actual unstable physical states. Ruidong Han, Chao Yang 0016, Siqi Ma 0001, Jianfeng Ma 0001, Cong Sun 0001, Juanru Li, Elisa Bertino |
ICSE | 6 |
| 2022 | Annotating, Tracking, and Protecting Cryptographic Secrets with CryptoMPKabstractProtecting confidential data against memory disclosure attacks is crucial to many critical applications, especially those involve cryptographic operations. However, it is neither easy to identify involved cryptographic confidential data in a program nor to implement a fine-grained and yet efficient protection. Existing defensive techniques face many shortcomings such as coarse-grained protection or exorbitant overhead. As a result, real world crypto applications seldom applied this kind of protection in practice.To make the protection of cryptographic confidential data practical, we design and implement CRYPTOMPK, a source code analysis and transformation system to implement a domain-based memory isolation. CRYPTOMPK first automatically tracks and labels all sensitive memory buffers and operations in source code with a context-sensitive, crypto-aware information flow analysis. Then it partitions the source code into crypto and non-crypto domains with a context-dependent privilege switch instrumentation. By further utilizing Intel Memory Protection Keys (MPK), CRYPTOMPK generates executables with efficient domain switching, protecting them against typical memory disclosure vulnerabilities such as arbitrary memory read. In particular, by using CRYPTOMPK, a large number of intermediate memory buffers that have been previously ignored before are well protected, and thus the security risks are reduced significantly. We leveraged CRYPTOMPK to protect prevalent applications such as Apache and Nginx with widely used crypto libraries (e.g., OpenSSL, LibSodium). CRYPTOMPK only needs several minutes to analyze each of these complex cryptographic programs and incurs at most 9.53% performance overhead for the protected programs. Xuancheng Jin, Xuangan Xiao, Songlin Jia, Dawu Gu, Hang Zhang 0012, Siqi Ma 0001, Zhiyun Qian, Juanru Li |
SP | 9 |
| 2022 | Goshawk: Hunting Memory Corruptions via Structure-Aware and Object-Centric Memory Operation SynopsisabstractExisting tools for the automated detection of memory corruption bugs are not very effective in practice. They typically recognize only standard memory management (MM) APIs (e.g., malloc and free) and assume a naive paired-use model—an allocator is followed by a specific deallocator. However, we observe that programmers very often design their own MM functions and that these functions often manifest two major characteristics: (1) Custom allocator functions perform multi-object or nested allocation which then requires structure-aware deallocation functions. (2) Custom allocators and deallocators follow an unpaired-use model. A more effective detection thus needs to adapt those characteristics and capture memory bugs related to non-standard MM behaviors. In this paper, we present a MM function aware memory bug detection technique by introducing the concept of structure-aware and object-centric Memory Operation Synopsis (MOS). A MOS abstractly describes the memory objects of a given MM function, how they are managed by the function, and their structural relations. By utilizing MOS, a bug detection could explore much less code but is still capable of handling multi-object or nested allocations and does not rely on the paired-use model. In addition, to extensively find MM functions and automatically generate MOS for them, we propose a new identification approach that combines natural language processing (NLP) and data flow analysis, which enables the efficient and comprehensive identification of MM functions, even in very large code bases. We implement a MOS-enhanced memory bug detection system, Goshawk, to discover memory bugs caused by complex and custom MM behaviors. We applied Goshawk to well-tested and widely-used open source projects including OS kernels, server applications, and IoT SDKs. Goshawk outperforms the state-of-the-art data flow analysis driven bug detection tools by an order of magnitude in analysis speed and the number of accurately identified MM functions, reports the discovered bugs with a developer-friendly, MOS based description, and successfully detects 92 new double-free and use-after-free bugs. Yunlong Lyu, Yiwei Zhang 0008, Qibin Sun, Siqi Ma 0001, Elisa Bertino, Kangjie Lu, Juanru Li |
SP | 8 |
| 2022 | Orchestration or Automation: Authentication Flaw Detection in Android AppsabstractPasswords are pervasively used to authenticate users’ identities in mobile apps. To secure passwords against attacks, protection is applied to the password authentication protocol (PAP). The implementation of the protection scheme becomes an important factor in protecting PAP against attacks. We focus on two basic protection in Android, i.e., SSL/TLS-based PAP and timestamp-based PAP. Previously, we proposed an automated tool,GLACIATE, to detect authentication flaws. We were curious whether orchestration (i.e., involving manual-effort) works better than automation. To answer this question, we propose an orchestrated approach,AuthExploitand compare its effectivenessGLACIATE. We study requirements for correct implementation of PAP and then applyGLACIATEto identify protection enhancements automatically. Through dependency analysis,GLACIATEmatches the implementations against the abstracted flaws to recognise defective apps. To evaluateAuthExploit, we collected 1,200 Android apps from Google Play. We comparedAuthExploitwith the automation tool,GLACIATE, and two other orchestration tools,${\sf MalloDroid}$and${\sf SMV-Hunter}$. The results demonstrated that orchestration tools detect flaws more precisely although the F1 score ofGLACIATEis higher thanAuthExploit. Further analysis of the results reveals that highly popular apps and e-commerce apps are not more secure than other apps. Siqi Ma 0001, Juanru Li, Surya Nepal, Diethelm Ostry, David Lo 0001, Sanjay K. Jha, Robert H. Deng, Elisa Bertino |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | SparrowHawk: Memory Safety Flaw Detection via Data-Driven Source Code Annotation
Yunlong Lyu, Siqi Ma 0001, Qibin Sun, Juanru Li |
Inscrypt | 5 |
| 2021 | Yet Another Traffic Black Hole: Amplifying CDN Fetching Traffic with RangeFragAmp Attacks
Juanru Li |
CollaborateCom (1) | 2 |
| 2021 | Fine with "1234"? An Analysis of SMS One-Time Password Randomness in Android AppsabstractA fundamental premise of SMS One-Time Password (OTP) is that the used pseudo-random numbers (PRNs) are uniquely unpredictable for each login session. Hence, the process of generating PRNs is the most critical step in the OTP authentication. An improper implementation of the pseudo-random number generator (PRNG) will result in predictable or even static OTP values, making them vulnerable to potential attacks. In this paper, we present a vulnerability study against PRNGs implemented for Android apps. A key challenge is that PRNGs are typically implemented on the server-side, and thus the source code is not accessible. To resolve this issue, we build an analysis tool, OTP-Lint, to assess implementations of the PRNGs in an automated manner without the source code requirement. Through reverse engineering, OTP-Lint identifies the apps using SMS OTP and triggers each app's login functionality to retrieve OTP values. It further assesses the randomness of the OTP values to identify vulnerable PRNGs. By analyzing 6,431 commercially used Android apps downloaded from Google Play and Tencent Myapp, OTP-Lint identified 399 vulnerable apps that generate predictable OTP values. Even worse, 194 vulnerable apps use the OTP authentication alone without any additional security mechanisms, leading to insecure authentication against guessing attacks and replay attacks. Siqi Ma 0001, Juanru Li, Hyoungshick Kim, Elisa Bertino, Surya Nepal, Diethelm Ostry, Cong Sun 0001 |
ICSE | 2 |
| 2021 | Re-Check Your Certificates! Experiences and Lessons Learnt from Real-World HTTPS Certificate Deployments
Wenya Wang 0003, Yakang Li, Yuan Yan, Juanru Li, Dawu Gu |
NSS | 5 |
| 2020 | Certified Copy? Understanding Security Risks of Wi-Fi Hotspot based Android Data Clone ServicesabstractWi-Fi hotspot-based data clone services are increasingly used by Android users to transfer their user data and preferred configurations while upgrading obsolete phones to new models. Unfortunately, since the data clone services need to manipulate sensitive information protected by the Android system, vulnerabilities in the design or implementation of these services may result in data privacy breaches. In this paper we present an empirical security analysis of eight widely used Wi-Fi hotspot-based data clone services deployed to millions of Android phones. Our study evaluates those services with respect to data export/import, data transmission, and Wi-Fi configuration with respect to security requirements that the data clone procedure should satisfy. Since data clone services are closed source, we design Poirot, an analysis system to recover workflows of the data clone services and detect potential flaws. Our study reveals a series of critical security issues in the data clone services. We demonstrate two types of attacks that exploit the data clone service as a new attack surface. A vulnerable data clone service allows attackers to retrieve sensitive user data without permissions, and even inject malicious contents to compromise the system. Siqi Ma 0001, Hehao Li, Juanru Li, Surya Nepal, Elisa Bertino |
ACSAC | 4 |
| 2020 | SMARTSHIELD: Automatic Smart Contract Protection Made EasyabstractThe immutable feature of blockchain determines that traditional security response mechanisms (e.g., code patching) must change to remedy insecure smart contracts. The only proper way to protect a smart contract is to fix potential risks in its code before it is deployed to the blockchain. However, existing tools for smart contract security analysis focus on the detection of bugs but seldom consider the code fix issues. Meanwhile, it is often time-consuming and error-prone for a developer to understand and fix flawed code manually. In this paper we propose SMARTSHIELD, a bytecode rectification system, to fix three typical security-related bugs (i.e., state changes after external calls, missing checks for out-of-bound arithmetic operations, and missing checks for failing external calls) in smart contracts automatically and help developers release secure contracts. Moreover, SMARTSHIELD guarantees that the rectified contract is not only immune to certain attacks but also gas-friendly (i.e., a slightly increase of gas cost). To evaluate the effectiveness and efficiency of SMARTSHIELD, we applied it to 28,621 real-world buggy contracts on Ethereum blockchain (as of January 2nd2019). Experiment results demonstrated that among 95,502 insecure cases in those contracts, 87,346 (91.5%) of them were automatically fixed by SMARTSHIELD. A following test with both program analysis and real-world exploits further testified that the rectified contracts were secure against common attacks. Moreover, the rectification only introduced a 0.2 % gas increment for each contract on average. Siqi Ma 0001, Juanru Li, Kailai Li 0002, Surya Nepal, Dawu Gu |
SANER | 3 |
| 2020 | EthPloit: From Fuzzing to Efficient Exploit Generation against Smart ContractsabstractSmart contracts, programs running on blockchain systems, leverage diverse decentralized applications (DApps). Unfortunately, well-known smart contract platforms, Ethereum for example, face serious security problems. Exploits to contracts may cause enormous financial losses, which emphasize the importance of smart contract testing. However, current exploit generation tools have difficulty to solve hard constraints in execution paths and cannot simulate the blockchain behaviors very well. These problems cause a loss of coverage and accuracy of exploit generation. To overcome the problems, we design and implement EthPloit, a smart contract exploit generator based on fuzzing. EthPloit adopts static taint analysis to generate exploit-targeted transaction sequences, a dynamic seed strategy to pass hard constraints and an instrumented Ethereum Virtual Machine to simulate blockchain behaviors. We evaluate EthPloit on 45,308 smart contracts and discovered 554 exploitable contracts. EthPloit automatically generated 644 exploits without any false positive and 306 of them cannot be generated by previous exploit generation tools. Qingzhao Zhang 0001, Yizhuo Wang 0003, Juanru Li, Siqi Ma 0001 |
SANER | 3 |
| 2020 | Understanding the security of app-in-the-middle IoT
Juanru Li, Dawu Gu |
Comput. Secur. | 2 |
| 2019 | An empirical study of SMS one-time password authentication in Android appsabstractA great quantity of user passwords nowadays has been leaked through security breaches of user accounts. To enhance the security of the Password Authentication Protocol (PAP) in such circumstance, Android app developers often implement a complementary One-Time Password (OTP) authentication by utilizing the short message service (SMS). Unfortunately, SMS is not specially designed as a secure service and thus an SMS One-Time Password is vulnerable to many attacks. To check whether a wide variety of currently used SMS OTP authentication protocols in Android apps are properly implemented, this paper presents an empirical study against them. We first derive a set of rules from RFC documents as the guide to implement secure SMS OTP authentication protocol. Then we implement an automated analysis system, AUTH-EYE, to check whether a real-world OTP authentication scheme violates any of these rules. Without accessing server source code, AUTH-EYE executes Android apps to trigger the OTP-relevant functionalities and then analyzes the OTP implementations including those proprietary ones. By only analyzing SMS responses, AUTH-EYE is able to assess the conformance of those implementations to our recommended rules and identify the potentially insecure apps. In our empirical study, AUTH-EYE analyzed 3,303 popular Android apps and found that 544 of them adopt SMS OTP authentication. The further analysis of AUTH-EYE demonstrated a far-from-optimistic status: the implementations of 536 (98.5%) out of the 544 apps violate at least one of our defined rules. The results indicate that Android app developers should seriously consider our discussed security rules and violations so as to implement SMS OTP properly. Siqi Ma 0001, Runhan Feng, Juanru Li, Yang Liu 0118, Surya Nepal, Diethelm Ostry, Elisa Bertino, Robert H. Deng, Zhuo Ma 0001, Sanjay K. Jha |
ACSAC | 3 |
| 2019 | Finding Flaws from Password Authentication Code in Android Apps
Siqi Ma 0001, Elisa Bertino, Surya Nepal, Juanru Li, Diethelm Ostry, Robert H. Deng, Sanjay K. Jha |
ESORICS (1) | 4 |
| 2019 | Accelerating SM2 Digital Signature Algorithm Using Modern Processor Features
Long Mai, Yuan Yan, Songlin Jia, Shuran Wang, Juanru Li, Siqi Ma 0001, Dawu Gu |
ICICS | 6 |
| 2019 | NLP-EYE: Detecting Memory Corruptions via Semantic-Aware Memory Operation Function Identification
Siqi Ma 0001, Yuanyuan Zhang 0002, Juanru Li, Zheyu Ma, Long Mai, Tiancheng Chen, Dawu Gu |
RAID | 4 |
| 2019 | APPCOMMUNE: Automated Third-Party Libraries De-duplicating and Updating for Android AppsabstractThe increasing usage of third-party libraries in Android apps is double-edged, boosting the development but introducing extra code base and potential vulnerabilities. Unlike desktop operating systems, Android does not support the sharing of third-party libraries between different apps. Thus both the de-duplicating and the updating of those libraries are difficult to be managed in a unified way. In this paper, we propose a third-party library sharing method to address the issues of code bloating and obsolete code updating. Our approach separates all integrated third-party libraries from app code and makes them still accessible through a dynamic loading mechanism. The separated libraries are managed centrally and can be shared by different apps. This not only saves the storage but also guarantees a prompt update of outdated libraries for every app. We implement APPCOMMUNE, a novel app installation and execution infrastructure to support the proposed third-party library sharing without modifying the commodity Android system. Our experiments with 212 popular third-party libraries and 502 real-world Android apps demonstrate the feasibility and efficiency: all apps work stably with our library sharing model, and 11.1% storage and bandwidth are saved for app downloading and installation. In addition, APPCOMMUNE updates 86.4% of the managed third-party libraries (with 44.6% to the latest versions). Bodong Li, Yuanyuan Zhang 0002, Juanru Li, Runhan Feng, Dawu Gu |
SANER | 3 |
| 2019 | Security analysis of third-party in-app payment in mobile applications
Juanru Li, Yuanyuan Zhang 0002, Dawu Gu |
J. Inf. Secur. Appl. | 2 |
| 2018 | An Empirical Study of SDK Credential Misuse in iOS AppsabstractDuring the development of web-based mobile apps, third-party SDKs (Software Development Kit) are frequently used to facilitate the integration of certain functionality such as push notification and mobile payment. Unfortunately, security issues are often considered as a second-tier problem and app developers are prone to implement apps with SDK misuses. Among those typical SDK misuses, the misuse of credentials is the one that introduces serious security threats. A credential is a set of unique information (e.g., APP ID, App Token, etc) allocated to a specific developer to help app authenticate the identity. However, if not properly used, the credential can be easily obtained by attackers and leads to not only the leak of confidential information of mobile developers but also direct threats to the privacy of end users. To investigate the SDK credential misuse issue on iOS platform, in this paper we conduct an empirical study against 100 popular iOS apps using two popular mobile SDKs (each SDK are widely used by at least 40 million users). We implemented iCredFinder, an automated analysis tool to search credential misuses in those apps and our experiment demonstrates 68 apps contain at least one misuse case. Our study demonstrates the severity of credential misuse on iOS platform: even for those well-developed SDKs and apps, credentials are not well protected and can be easily discovered. We expect that our study could help developers fix those flaws and promote better implementations. Haohuang Wen, Juanru Li, Yuanyuan Zhang 0002, Dawu Gu |
APSEC | 2 |
| 2018 | K-Hunt: Pinpointing Insecure Cryptographic Keys from Execution TracesabstractThe only secrets in modern cryptography (crypto for short) are the crypto keys. Understanding how crypto keys are used in a program and discovering insecure keys is paramount for crypto security. This paper presents K-Hunt, a system for identifying insecure keys in binary executables. K-Hunt leverages the properties of crypto operations for identifying the memory buffers where crypto keys are stored. And, it tracks their origin and propagation to identify insecure keys such as deterministically generated keys, insecurely negotiated keys, and recoverable keys. K-Hunt does not use signatures to identify crypto operations, and thus can be used to identify insecure keys in unknown crypto algorithms and proprietary crypto implementations. We have implemented K-Hunt and evaluated it with 10 cryptographic libraries and 15 applications that contain crypto operations. Our evaluation results demonstrate that K-Hunt locates the keys in symmetric ciphers, asymmetric ciphers, stream ciphers, and digital signatures, regardless if those algorithms are standard or proprietary. More importantly, K-Hunt discovers insecure keys in 22 out of 25 evaluated programs including well-developed crypto libraries such as Libsodium, Nettle, TomCrypt, and WolfSSL. Juanru Li, Zhiqiang Lin 0001, Juan Caballero, Yuanyuan Zhang 0002, Dawu Gu |
CCS | 1 |
| 2018 | BinMatch: A Semantics-Based Hybrid Approach on Binary Code Clone AnalysisabstractBinary code clone analysis is an important technique which has a wide range of applications in software engineering (e.g., plagiarism detection, bug detection). The main challenge of the topic lies in the semantics-equivalent code transformation (e.g., optimization, obfuscation) which would alter representations of binary code tremendously. Another challenge is the trade-off between detection accuracy and coverage. Unfortunately, existing techniques still rely on semantics-less code features which are susceptible to the code transformation. Besides, they adopt merely either a static or a dynamic approach to detect binary code clones, which cannot achieve high accuracy and coverage simultaneously. In this paper, we propose a semantics-based hybrid approach to detect binary clone functions. We execute a template binary function with its test cases, and emulate the execution of every target function for clone comparison with the runtime information migrated from that template function. The semantic signatures are extracted during the execution of the template function and emulation of the target function. Lastly, a similarity score is calculated from their signatures to measure their likeness. We implement the approach in a prototype system designated as BinMatch which analyzes IA-32 binary code on the Linux platform. We evaluate BinMatch with eight real-world projects compiled with different compilation configurations and commonly-used obfuscation methods, totally performing over 100 million pairs of function comparison. The experimental results show that BinMatch is robust to the semantics-equivalent code transformation. Besides, it not only covers all target functions for clone analysis, but also improves the detection accuracy comparing to the state-of-the-art solutions. Yikun Hu 0003, Yuanyuan Zhang 0002, Juanru Li, Hui Wang 0037, Bodong Li, Dawu Gu |
ICSME | 3 |
| 2018 | Burn After Reading: Expunging Execution Footprints of Android Apps
Junliang Shu, Juanru Li, Yuanyuan Zhang 0002, Dawu Gu |
NSS | 2 |
| 2018 | Passwords in the Air: Harvesting Wi-Fi Credentials from SmartCfg ProvisioningabstractSmart devices without an interactive UI (e.g., a smart bulb) typically rely on specific provisioning schemes to connect to wireless networks. Among all the provisioning schemes, SmartCfg is a popular technology to configure the connection between smart devices and wireless routers. Although the SmartCfg technology facilitates the Wi-Fi configuration, existing solutions seldom take into serious consideration the protection of credentials and therefore introduce security threats against Wi-Fi credentials. Changyu Li, Quanpu Cai, Juanru Li, Yuanyuan Zhang 0002, Dawu Gu, Yu Yu 0001 |
WISEC | 3 |
| 2018 | AppSpear: Automating the hidden-code extraction and reassembling of packed android malware
Bodong Li, Yuanyuan Zhang 0002, Juanru Li, Dawu Gu |
J. Syst. Softw. | 3 |
| 2017 | Oh-Pwn-VPN! Security Analysis of OpenVPN-Based Android Apps
Juanru Li, Yuanyuan Zhang 0002, Hui Wang 0037, Dawu Gu |
CANS | 2 |
| 2017 | NativeSpeaker: Identifying Crypto Misuses in Android Native Code Libraries
Juanru Li, Yuanyuan Zhang 0002, Hui Wang 0037, Yikun Hu 0003, Bodong Li, Dawu Gu |
Inscrypt | 2 |
| 2017 | Embroidery: Patching Vulnerable Binary Code of Fragmentized Android DevicesabstractThe rapid-iteration, web-style update cycle of Android helps fix revealed security vulnerabilities for its latest version. However, such security enhancements are usually only available for few Android devices released by certain manufacturers (e.g., Google's official Nexus devices). More manufactures choose to stop providing system update service for their obsolete models, remaining millions of vulnerable Android devices in use. In this situation, a feasible solution is to leverage existing source code patches to fix outdated vulnerable devices. To implement this, we introduce Embroidery, a binary rewriting based vulnerability patching system for obsolete Android devices without requiring the manufacturer's source code against Android fragmentation. Embroidery patches the known critical framework and kernel vulnerabilities in Android using both static and dynamic binary rewriting techniques. It transplants official patches (CVE source code patches) of known vulnerabilities to different devices by adopting heuristic matching strategies to deal with the code diversity introduced by Android fragmentation, and fulfills a complex dynamic memory modification to implement kernel vulnerabilities patching. We employ Embroidery to patch sophisticated Android kernel and framework vulnerabilities for various manufactures' obsolete devices ranging from Android 4.2 to 5.1. The result shows the patched devices are able to defend against known exploits and the normal functions are not affected. Xuewen Zhang, Yuanyuan Zhang 0002, Juanru Li, Yikun Hu 0003, Huayi Li, Dawu Gu |
ICSME | 3 |
| 2017 | Nightingale: Translating Embedded VM Code in x86 Binary Executables
Haijiang Xie, Yuanyuan Zhang 0002, Juanru Li, Dawu Gu |
ISC | 3 |
| 2017 | Binary code clone detection across architectures and compiling configurationsabstractBinary code clone (or similarity) detection is a fundamental technique for many important applications, such as plagiarism detection, malware analysis, software vulnerability assessment and program comprehension. With the prevailing of smart and IoT (Internet of Things) devices, more and more programs are ported from traditional desktop platform (e.g., IA-32) to ARM and MIPS architectures. It is imperative to detect cloned binary code across architectures. However, because of incomparable instruction sets of different architectures as well as alternative compiling configurations of binaries, it is difficult to conduct a binary code clone detection with traditional syntax-or structure-based methods. To address, we propose a semantics-based approach to fulfill the target. We recognize arguments and indirect jump targets of each binary function, and emulate executions of those functions to extract semantic signatures helping measure the similarity of functions. The approach has been implemented in a prototype system names CACompare to detect cloned binary functions across architectures and compiling configurations. It supports comparisons between mainstream architectures (IA-32, ARM and MIPS) and is able to analysis binaries on Linux platform. The experimental results show that CACompare not only is effective in dealing with binaries of different architectures and variant compiling configurations, but also improves the accuracy of binary code clone detection comparing to state-of-the-art solutions. Yikun Hu 0003, Yuanyuan Zhang 0002, Juanru Li, Dawu Gu |
ICPC | 3 |
| 2017 | Show Me the Money! Finding Flawed Implementations of Third-party In-app Payment in Android Apps
Yuanyuan Zhang 0002, Juanru Li, Yueheng Zhang, Dawu Gu |
NDSS | 3 |
| 2017 | Why Data Deletion Fails? A Study on Deletion Flaws and Data Remanence in Android SystemsabstractSmart mobile devices are becoming the main vessel of personal privacy information. While they carry valuable information, data erasure is somehow much more vulnerable than was predicted. The security mechanisms provided by the Android system are not flexible enough to thoroughly delete sensitive data. In addition to the weakness among several provided data-erasing and file-deleting mechanisms, we also target the Android OS design flaws in data erasure, and unveil that the design of the Android OS contradicts some secure data-erasure demands. We present the data-erasure flaws in three typical scenarios on mainstream Android devices, such as the data clearing flaw , application uninstallation flaw , and factory reset flaw . Some of these flaws are inherited data-deleting security issues from the Linux kernel, and some are new vulnerabilities in the Android system. Those scenarios reveal the data leak points in Android systems. Moreover, we reveal that the data remanence on the disk is rarely affected by the user’s daily operation, such as file deletion and app installation and uninstallation, by a real-world data deletion latency experiment. After one volunteer used the Android phone for 2 months, the data remanence amount was still considerable. Then, we proposed DataRaider for file recovering from disk fragments. It adopts a file-carving technique and is implemented as an automated sensitive information recovering framework. DataRaider is able to extract private data in a raw disk image without any file system information, and the recovery rate is considerably high in the four test Android phones. We propose some mitigation for data remanence issues, and give the users some suggestions on data protection in Android systems. Junliang Shu, Yuanyuan Zhang 0002, Juanru Li, Bodong Li, Dawu Gu |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2016 | The Achilles heel of OAuth: a multi-platform study of OAuth-based authentication
Hui Wang 0037, Yuanyuan Zhang 0002, Juanru Li, Dawu Gu |
ACSAC | 3 |
| 2016 | Open Sesame! Web Authentication Cracking via Mobile App Analysis
Yuanyuan Zhang 0002, Juanru Li, Hui Wang 0037, Dawu Gu |
APWeb (2) | 3 |
| 2016 | Security Testing of Software on Embedded Devices Using x86 Platform
Yesheng Zhi, Yuanyuan Zhang 0002, Juanru Li, Dawu Gu |
CollaborateCom | 3 |
| 2016 | Security Analysis of Vendor Customized Code in Firmware of Embedded Device
Yuanyuan Zhang 0002, Juanru Li, Junliang Shu, Dawu Gu |
SecureComm | 3 |
| 2016 | Cross-Architecture Binary Semantics Understanding via Similar Code ComparisonabstractWith the prevailing of smart devices (e.g., smart phone, routers, cameras), more and more programs are ported from traditional desktop platform to embedded hardware with ARM or MIPS architecture. While the compiled binary code differs significantly due to the variety of CPU architectures, these ported programs share the same code base of the desktop version. Thus it is feasible to utilize the program of commodity computer to help understand those cross-compiled binaries and locate functions with similar semantics. However, as instruction sets of different architectures are generally incomparable, it is difficult to conduct a static cross-architecture binary code similarity comparison. To address, we propose a semantic-based approach to fulfill this target. We dynamically extract the signature, which is composed of conditional operations behaviors as well as system call information, from binaries on different platforms with the same manner. Then the similarity of signatures is measured to help identify functions in ported programs. We have implemented the approach in MOCKINGBIRD, an automated analysis tool to compare code similarity between binaries across architectures. MOCKINGBIRD supports mainstream architectures and is able to analyze ELF executables on Linux platform. We have evaluated MOCKINGBIRD with a set of popular programs with cross-compiled versions. The results show our approach is not only effective for dealing with this new issue of cross-architecture binary code comparison, but also improves the accuracy of similarity based function identification due to the utilization of semantic information. Yikun Hu 0003, Yuanyuan Zhang 0002, Juanru Li, Dawu Gu |
SANER | 3 |
| 2015 | Vulnerability Assessment of OAuth Implementations in Android ApplicationsabstractEnforcing security on various implementations of OAuth in Android apps should consider a wide range of issues comprehensively. OAuth implementations in Android apps differ from the recommended specification due to the provider and platform factors, and the varied implementations often become vulnerable. Current vulnerability assessments on these OAuth implementations are ad hoc and lack a systematic manner. As a result, insecure OAuth implementations are still widely used and the situation is far from optimistic in many mobile app ecosystems. Hui Wang 0037, Yuanyuan Zhang 0002, Juanru Li, Bodong Li, Dawu Gu |
ACSAC | 3 |
| 2015 | From Collision To Exploitation: Unleashing Use-After-Free Vulnerabilities in Linux KernelabstractSince vulnerabilities in Linux kernel are on the increase, attackers have turned their interests into related exploitation techniques. However, compared with numerous researches on exploiting use-after-free vulnerabilities in the user applications, few efforts studied how to exploit use-after-free vulnerabilities in Linux kernel due to the difficulties that mainly come from the uncertainty of the kernel memory layout. Without specific information leakage, attackers could only conduct a blind memory overwriting strategy trying to corrupt the critical part of the kernel, for which the success rate is negligible. Juanru Li, Junliang Shu, Tianyi Xie, Yuanyuan Zhang 0002, Dawu Gu |
CCS | 2 |
| 2015 | SSG: Sensor Security Guard for Android Smartphones
Bodong Li, Yuanyuan Zhang 0002, Chen Lyu 0002, Juanru Li, Dawu Gu |
CollaborateCom | 4 |
| 2015 | AppSpear: Bytecode Decrypting and DEX Reassembling for Packed Android Malware
Yuanyuan Zhang 0002, Juanru Li, Junliang Shu, Bodong Li, Dawu Gu |
RAID | 3 |
| 2014 | APKLancet: tumor payload diagnosis and purification for android applicationsabstractA huge number of Android applications are bundled with relatively independent modules either during the development or by intentionally repackaging. Undesirable behaviors such as stealthily acquiring and distributing user's private information are frequently discovered in some bundled third-party modules, i.e., advertising libraries or malicious code (we call the module tumor payload in this work), which sabotage the integrity of the original app and lie as a threat to both the security of mobile system and the user's privacy. Juanru Li, Yuanyuan Zhang 0002, Junliang Shu, Dawu Gu |
AsiaCCS | 2 |
| 2014 | Android App Protection via Interpretation ObfuscationabstractTo protect Android app from malicious reproduction or tampering, code obfuscation techniques are introduced to increase the difficulty of reverse engineering and program understanding. Current obfuscation schemes focus more on the protection of the meta information over the executable code which contains valuable or patented algorithms. Therefore, a more sophisticated obfuscator is needed to improve the protection on the executable code. In this paper we propose SMOG, a comprehensive executable code obfuscation system to protect Android app. SMOG is composed of two parts, an obfuscation engine and an execution environment. The obfuscation engine is at software vendor's side to conduct the obfuscation on the app's executable code, and then release the obfuscated app to the end-user along with an execution token. The execution environment is setup by integrating the received execution token, which endows the Android Dalvik VM the capability to execute the obfuscated app. SMOG is an easily deployed system which proves fine-grained level protection. The obfuscated app generated by SMOG could resist static and dynamic reverse engineering. Moreover, the benchmark result shows SMOG only costs about 5% more performance in dispatching the incoming bytecode to the proper interpreter. Junliang Shu, Juanru Li, Yuanyuan Zhang 0002, Dawu Gu |
DASC | 2 |
| 2014 | TagDroid: Hybrid SSL Certificate Verification in Android
Yuanyuan Zhang 0002, Hui Wang 0037, Juanru Li, Dawu Gu |
ICICS | 5 |
| 2014 | iCryptoTracer: Dynamic Analysis on Misuse of Cryptography Functions in iOS Applications
Yuanyuan Zhang 0002, Juanru Li, Dawu Gu |
NSS | 3 |
| 2013 | Automatic Detection and Analysis of Encrypted Messages in Malware
Ruoxu Zhao, Dawu Gu, Juanru Li, Yuanyuan Zhang 0002 |
Inscrypt | 3 |
| 2012 | Differential Fault Analysis on Lightweight Blockciphers with Statistical Cryptanalysis TechniquesabstractDifferential fault analysis is one of the most efficient side channel attack techniques that threat the security of block cipher. However, it often requires a penultimate or an antepenultimate round faulty encryption and is not suitable for middle round fault. This paper presents attacks combining differential fault analysis with statistical cryptanalysis techniques against lightweight ciphers. The analysis makes use of statistical cryptanalysis techniques in practice rather than theoretically, and exploits the weakness of bit-permutation adopted by many lightweight block ciphers under fault attack. Specific attacks against PRESENT and PRINT\scriptsize{CIPHER} \normalsize are given to prove the validity. The result shows that about one fifth of the iterative rounds are needed to be protected for these lightweight ciphers with bit-permutation. Dawu Gu, Juanru Li, Zhouqian Ma, Zheng Guo 0001 |
FDTC | 2 |
| 2012 | Detecting Encryption Functions via Process Emulation and IL-Based Program Analysis
Ruoxu Zhao, Dawu Gu, Juanru Li |
ICICS | 3 |
| 2011 | Linear Cryptanalysis of ARIA Block Cipher
Zhiqiang Liu 0001, Dawu Gu, Ya Liu 0001, Juanru Li, Wei Li 0013 |
ICICS | 4 |
| 2011 | Detection and Analysis of Cryptographic Data Inside Software
Ruoxu Zhao, Dawu Gu, Juanru Li |
ISC | 3 |
| 2010 | Differential fault analysis on Camellia
Wei Li 0013, Dawu Gu, Juanru Li, Zhiqiang Liu 0001, Ya Liu 0001 |
J. Syst. Softw. | 3 |
| 2009 | An Extension of Differential Fault Analysis on AESabstractIn CHES 2006, M. Amir et al. introduced a generalized method of differential fault attack (DFA) against AES-128. Their fault models cover all locations before the 9th round in AES-128. However, their method cannot be applied to AES with other key sizes, such as AES-192 and AES-256. On the differential analysis, we propose a new method to extend DFA on AES with all key sizes. Our results in this study will also be beneficial to the analysis of the same type of other iterated block ciphers. Wei Li 0013, Dawu Gu, Juanru Li, Zhiqiang Liu 0001 |
NSS | 4 |
| 2008 | Exploiting unidirectional links for key establishment protocols in heterogeneous sensor networks
Yuanyuan Zhang 0002, Dawu Gu, Juanru Li |
Comput. Commun. | 3 |
| 2008 | Differential fault analysis on the ARIA algorithm
Wei Li 0013, Dawu Gu, Juanru Li |
Inf. Sci. | 3 |