EDBT 2026 Demo / reviewers in the wild / expert
Bin Zeng 0004
dblp:41/5085-4
· DBLP profile ↗
3ranked-venue papers
2as first author
0since 2021 · last 2013
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Systems and software security · 100% | |
| Software engineering, system software, and programming languages
1 paper |
Program analysis · 100% |
Topics — the 5 heaviest of 5, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security › language-based security
inlined reference monitors |
0.3 | 2 | 2013 | Strato: A Retargetable Framework for Low-Level Inlined-Reference Monitors · USENIX Security Symposium 2013 Combining control-flow integrity and static analysis for efficient and validated data sandboxing · CCS 2011 |
Systems and software security › memory safety
control-flow integrity |
0.1 | 1 | 2011 | Combining control-flow integrity and static analysis for efficient and validated data sandboxing · CCS 2011 |
Systems and software security › operating system security
sandboxing |
0.1 | 1 | 2011 | Combining control-flow integrity and static analysis for efficient and validated data sandboxing · CCS 2011 |
Program analysis › static analysis › abstract interpretation
range analysis |
0.1 | 1 | 2011 | Combining control-flow integrity and static analysis for efficient and validated data sandboxing · CCS 2011 |
Program analysis
static analysis |
0.1 | 1 | 2011 | Combining control-flow integrity and static analysis for efficient and validated data sandboxing · CCS 2011 |
Methods — techniques the papers use, named apart from their topics
range analysis · 0.2control-flow integrity · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2013 | Strato: A Retargetable Framework for Low-Level Inlined-Reference Monitors
Bin Zeng 0004, Gang Tan, Úlfar Erlingsson |
USENIX Security Symposium | 1 |
| 2013 | Bringing java's wild native world under controlabstractFor performance and for incorporating legacy libraries, many Java applications contain native-code components written in unsafe languages such as C and C++. Native-code components interoperate with Java components through the Java Native Interface (JNI). As native code is not regulated by Java's security model, it poses serious security threats to the managed Java world. We introduce a security framework that extends Java's security model and brings native code under control. Leveraging software-based fault isolation, the framework puts native code in a separate sandbox and allows the interaction between the native world and the Java world only through a carefully designed pathway. Two different implementations were built. In one implementation, the security framework is integrated into a Java Virtual Machine (JVM). In the second implementation, the framework is built outside of the JVM and takes advantage of JVM-independent interfaces. The second implementation provides JVM portability, at the expense of some performance degradation. Evaluation of our framework demonstrates that it incurs modest runtime overhead while significantly enhancing the security of Java applications. Mengtao Sun, Gang Tan, Joseph Siefers, Bin Zeng 0004, J. Gregory Morrisett |
ACM Trans. Inf. Syst. Secur. | 4 |
| 2011 | Combining control-flow integrity and static analysis for efficient and validated data sandboxingabstractIn many software attacks, inducing an illegal control-flow transfer in the target system is one common step. Control-Flow Integrity (CFI) protects a software system by enforcing a pre-determined control-flow graph. In addition to providing strong security, CFI enables static analysis on low-level code. This paper evaluates whether CFI-enabled static analysis can help build efficient and validated data sandboxing. Previous systems generally sandbox memory writes for integrity, but avoid protecting confidentiality due to the high overhead of sandboxing memory reads. To reduce overhead, we have implemented a series of optimizations that remove sandboxing instructions if they are proven unnecessary by static analysis. On top of CFI, our system adds only 2.7% runtime overhead on SPECint2000 for sandboxing memory writes and adds modest 19% for sandboxing both reads and writes. We have also built a principled data-sandboxing verifier based on range analysis. The verifier checks the safety of the results of the optimizer, which removes the need to trust the rewriter and optimizer. Our results show that the combination of CFI and static analysis has the potential of bringing down the cost of general inlined reference monitors, while maintaining strong security. Bin Zeng 0004, Gang Tan, J. Gregory Morrisett |
CCS | 1 |