EDBT 2026 Demo / reviewers in the wild / expert
Xiaoqi Jia
dblp:41/761
· DBLP profile ↗
69ranked-venue papers
4as first author
42since 2021 · last 2026
0000-0002-8376-3235ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 34 · 3 first-author · 19 since 2021Systems, architecture and hardware · 13 · 9 since 2021Computer networks · 9 · 6 since 2021Software engineering, systems software and programming languages · 6 · 3 since 2021Artificial intelligence and machine learning · 5 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Focusing on Language: Revealing and Exploiting Language Attention Heads in Multilingual Large Language ModelsabstractLarge language models (LLMs) increasingly support multilingual understanding and generation. Meanwhile, efforts to interpret their internal mechanisms have emerged, offering insights to enhance multilingual performance. While multi-head self-attention (MHA) has proven critical in many areas, its role in multilingual capabilities remains underexplored. In this work, we study the contribution of MHA in supporting multilingual processing in LLMs. We propose Language Attention Head Importance Scores (LAHIS), an effective and efficient method that identifies attention head importance for multilingual capabilities via a single forward and backward pass through the LLM. Applying LAHIS to Aya-23-8B, Llama-3.2-3B, and Mistral-7B-v0.1, we reveal the existence of both language-specific and language-general heads. Language-specific heads enable cross-lingual attention transfer to guide the model toward target language contexts and mitigate off-target language generation issue, contributing to addressing challenges in multilingual LLMs. We also introduce a lightweight adaptation that learns a soft head mask to modulate attention outputs over language heads, requiring only 20 tunable parameters to improve XQuAD accuracy. Overall, our work enhances both the interpretability and multilingual capabilities of LLMs from the perspective of MHA. Qiyang Song, Qihang Zhou, Haichao Du, Shaowen Xu, Weijuan Zhang, Xiaoqi Jia |
AAAI | 8 |
| 2026 | WorksetEnclave: Towards Optimizing Cold Starts in Confidential Serverless with Workset-Based Enclave Restore
Xiaolong Yan, Qihang Zhou, Zisen Wan, Feifan Qian, Weijuan Zhang, Xiaoqi Jia |
ASPLOS (2) | 7 |
| 2026 | VCAligner: Aligning Source Distribution Versions with Upstream Git Commits to Secure Supply Chain
Qihang Zhou, Shaowen Xu, Yamin Xie, Xiaoqi Jia |
DSN | 6 |
| 2026 | IoTBec: An Accurate and Efficient Recurring Vulnerability Detection Framework for Black Box IoT devices
Jiaming Guo, Shuangning Yang, Guoli Zhao, Qing-Qi Liu, Zhenlu Tan, Lixiao Shan, Qihang Zhou, Mengting Zhou, Jianwei Tai, Xiaoqi Jia |
NDSS | 12 |
| 2026 | DRShield: Coordinating Line-Rate Enforcement and Global Adaptation for Dynamic DDoS Defense
Qihang Zhou, Zibo Gao, Xiaoqi Jia, Zhiqiang Lv |
SECON | 6 |
| 2026 | FalconScope: Effective and Efficient Detection of Hidden Web Interfaces in IoT DevicesabstractHidden web interfaces in Internet of Things (IoT) devices pose significant security threats by unintentionally exposing inadequately protected functionalities, enabling attackers to bypass authentication, alter configurations, leak sensitive data, or execute arbitrary commands. Despite recent advancements, current detection approaches suffer from two critical challenges: 1) inadequately model the complex internal routing mechanisms of IoT firmware, leading to incomplete interface enumeration and substantial false negatives; and 2) inefficiently generate probing requests and verify unauthorized access due to limited semantic understanding of interface communication protocols. To overcome these challenges, we introduce FalconScope, a novel system combining precise firmware routing modeling and Large Language Model (LLM)-driven semantic analysis to detect hidden web interfaces effectively and efficiently. FalconScope achieves this through two key innovations: 1) a static analysis technique precisely reconstructs the device's internal routing mechanisms, enabling comprehensive enumeration of Routing Unique Identifiers and their corresponding backend handlers; and 2) an LLM-powered semantic engine automatically generates syntactically and semantically valid HTTP requests to efficiently trigger backend logic, coupled with semantic validation of device responses to accurately confirm unauthorized access. Evaluations on 11 real-world IoT devices from four major vendors demonstrate that FalconScope significantly surpasses existing state-of-the-art tools, detecting 620 hidden web interfaces—103 times more than IoTScope—while consuming only 3.6% of its analysis time. Following responsible disclosure, 50 issues have been assigned CVE IDs. Jiaming Guo, Kuihao Yan, Jiekang Hu, Xiaoqi Jia, Haichao Du, Qihang Zhou |
WWW | 5 |
| 2026 | FlexClave: An Extensible and Secure Trusted Execution Environment FrameworkabstractAs computer system software stacks become increasingly complex, the associated security risks also escalate. Trusted Execution Environments (TEEs) have emerged as a mainstream security solution to enhance system security. TEEs can be categorized into user-level TEEs, OS-level TEEs, and hybrid TEEs. However, these TEEs typically possess fixed security boundaries and isolation domains, limiting their adaptability to varying security requirements and dynamic scenarios. Moreover, the design of Trusted Computing Base (TCB) components in TEE frameworks often operates at the highest privilege levels of the architecture. This concentration of critical code at the highest privilege level increases the whole platform’s security risk due to the growing amount of code as more security functions are added. In this paper, we propose FlexClave, an extensible and secure TEE framework designed to address these issues. FlexClave leverages hardware primitives to create secure isolation boundaries tailored to different use cases. Additionally, our framework distributes TCB components across various privilege levels, reducing the concentration of security functions at the highest privilege levels and mitigating the risks associated with running extensive code in a single, highly privileged context. We implement two prototypes on ARMv9-A Fixed Virtual Platform and ARMv8 RK3399 SoC, each with two use cases (container and virtual machine), to evaluate the system’s security and performance. Qihang Zhou, Wenzhuo Cao, Xiaoqi Jia, Shaowen Xu, Jiayun Chen, Haichao Du, Yamin Xie, Peijie Yin, Shengzhi Zhang, Peng Liu 0005 |
IEEE Trans. Computers | 3 |
| 2025 | EMHunter: An Evasive Malware Detection Approach to Improve Dynamic Analysis EfficiencyabstractCurrently, a growing number of malware employ evasion techniques to hinder security analysts from analyzing their dynamic behavior, making them more likely to evade detection and pose a threat to users. The above malware is classified as Evasive Malware. To address this issue, we collect a dataset of labeled samples and propose a novel analysis method for evasive malware detection called EMHunter (Evasive Malware Hunter). After injecting samples into a specially designed software environment, EMHunter modifies the section table to launch from a designated location, and alters the export table to disable evasion-related behavior via identifying 48 commonly used APIs. When the malicious code attempts evasive actions, such as detecting if it's running in an analysis environment, the software cooperates with the dynamic analysis environment to determine the malware's key characteristics. It then selects appropriate countermeasures to lure the malicious code into continued execution, thereby exposing more malicious behavior and improving the accuracy of dynamic analysis. Our dataset consists of 12,543 samples, experiments show that this method successfully induced 4084 samples to exhibit their behavior. Furthermore, we integrated EMHunter into the open-source sandbox CAPE, enabling it to gather more behavioral information from the samples. Finally, we evaluated our approach using a LightGBM model, achieving the accuracy of 96.61%. Yamin Xie, Zhengcai Chen, Haichao Du, Xiaoqi Jia, Jianwu Ni |
CSCWD | 4 |
| 2025 | Latent Knowledge Scalpel: Precise and Massive Knowledge Editing for Large Language ModelsabstractLarge Language Models (LLMs) often retain inaccurate or outdated information from pre-training, leading to incorrect predictions or biased outputs during inference. While existing model editing methods can address this challenge, they struggle with editing large amounts of factual information simultaneously and may compromise the general capabilities of the models. In this paper, our empirical study demonstrates that it is feasible to edit the internal representations of LLMs and replace the entities in a manner similar to editing natural language inputs. Based on this insight, we introduce the Latent Knowledge Scalpel (LKS), an LLM editor that manipulates the latent knowledge of specific entities via a lightweight hypernetwork to enable precise and large-scale editing. Experiments conducted on Llama-2 and Mistral show even with the number of simultaneous edits reaching 10,000, LKS effectively performs knowledge editing while preserving the general abilities of the edited LLMs. Code is available at: https://github.com/Linuxin-xxx/LKS. Qiyang Song, Shaowen Xu, Kerou Zhou, Xiaoqi Jia, Weijuan Zhang, Heqing Huang 0001, Yakai Li |
ECAI | 6 |
| 2025 | An RPKI Certificate Validator for Formal Correctness
Yajun Teng, Wei Wang 0314, Jingqiang Lin 0001, Shijie Jia 0001, Xiaoqi Jia |
ISPEC | 5 |
| 2025 | Chameleon: Towards Building Least-privileged TEE via Functionality-based Resource Re-groupingabstractTrustZone-assisted Trusted Execution Environment (TEE) has been widely employed in mobile devices to protect sensitive applications. With increased customization demands, Trusted Applications (TAs) have become more flexible and complex, exposing numerous vulnerabilities within the TEE. Furthermore, due to the unrestricted Trusted Operating System (TOS) services provided to TA, an attacker can exploit vulnerabilities to compromise the whole TEE system. In this paper, we propose a novel customized TOS partition approach, called Chameleon, to enhance the security of the TrustZone-assisted TEE system. Inspired by the principle of least privilege and our TEE vulnerability analysis, we first categorize the TOS into TOS service modules and basic kernel modules. Then, we selectively encapsulate these modules into distinct Capsules based on the TA's functional requirements, providing each TA with a separate execution environment (TA-entity). To enforce access control and confine vulnerable modules within a TA-entity, we introduce T-Visor, which serves as our Trusted Computing Base. Our prototype implementation, built upon Linaro's OP-TEE, requires only 2.9K Lines of Code (LoC) modifications. Evaluation on a Hikey960 board demonstrates that Chameleon reduces the attack surface of TOS services to 51% and mitigates 122 out of 138 CVEs (88.41%) with negligible performance overhead. Qihang Zhou, Feifan Qian, Jiayun Chen, Heqing Huang 0001, Xiaoqi Jia, Haichao Du |
MobiSys | 6 |
| 2025 | Silence False Alarms: Identifying Anti-Reentrancy Patterns on Ethereum to Refine Smart Contract Reentrancy Detection
Qiyang Song, Heqing Huang 0001, Xiaoqi Jia, Yuanbo Xie, Jiahao Cao 0001 |
NDSS | 3 |
| 2025 | RContainer: A Secure Container Architecture through Extending ARM CCA Hardware Primitives
Qihang Zhou, Wenzhuo Cao, Xiaoqi Jia, Peng Liu 0005, Shengzhi Zhang, Jiayun Chen, Shaowen Xu |
NDSS | 3 |
| 2025 | CEDS: A Container Escape Detection System Based on Filesystem Isolation BoundariesabstractContainer technology is becoming increasingly important in cloud computing due to its efficiency and agility, but it also introduces new security risks. In particular, container escape attacks exploiting inherent vulnerabilities in container components have emerged as a primary threat to container security due to their pervasive nature and severe impact. However, existing container escape detection methods mainly rely on known attack patterns and pay insufficient attention to exploits targeting container components. In this work, we propose CEDS, a system based on container filesystem isolation boundaries to detect escape attacks caused by container component vulnerabilities in real time. We first establish an attack model by analyzing 16 container component exploits. Then, we propose a method to identify isolation boundaries by analyzing mount namespaces and container filesystem hierarchies, and subsequently detect abnormal cross-boundary file operations at the kernel level via system call monitoring. Finally, we implement a prototype of CEDS with eBPF. Experimental results demonstrate that, compared with the existing baseline methods, CEDS can effectively detect container escape attacks with minimal performance overhead. Weijuan Zhang, Junhao Fang, Yuxia Fu, Xiaoqi Jia, Qingjia Huang |
SMC | 7 |
| 2024 | CubeVisor: A Multi-realm Architecture Design for Running VM with ARM CCAabstractCloud computing nowadays provides flexible and scalable computing services, using different hardware platforms, including ARM. Virtualization allows multiple virtual machines (VMs) to share the physical resources of a host machine. However, these technologies have security risks. The hypervisor is the software that controls VMs, and it can be exploited or manipulated by hackers or untrusted providers. ARM CCA, a novel feature of ARMv9-A, allows confidential VMs to run in a new security state called realm. However, the current CCA prototype still has some problems, including risks brought by external libraries, single point of failure, highly privileged TF-RMM and costly world switch. In this paper, we introduce CubeVisor, a new secure virtualization architecture based on ARM CCA. It uses the idea of the Cube, which is a combination of a hypervisor and a VM, protecting each Cube from other Cubes or components. The CubeVisor also improves performance by optimizing memory allocation and world-switching processes. We implement prototypes on both software-based ARM FVP platform and hardware-based ARM Cortex-A platform for evaluations. The results show that the CubeVisor can protect VMs well and has very low overhead compared to the CCA based virtualization methods. Jiayun Chen, Qihang Zhou, Xiaolong Yan, Xiaoqi Jia, Weijuan Zhang |
ACSAC | 5 |
| 2024 | vASP: Full VM Life-cycle Protection Based on Active Security Processor ArchitectureabstractCloud computing has been applied on a large scale due to its competitive advantages. However, the introduction of virtualization brings new risks, which can come from within the VM and the host. Due to the abstraction of hardware resources by the hypervisor, traditional trusted computing methods, such as TPM and ASP, are no longer available in cloud environments. Existing work focusing on enabling trusted computing in cloud computing is primarily based on TPM and vTPM, but there are still issues such as the trusted chain not covering all stages of the VM life cycle and the integrity measurement operation potentially causing high overhead. In this paper, we present the vASP architecture, which solves the limitation of the ASP architecture in a cloud environment. Using customization features provided by the ASP, we customize interfaces for the vASP architecture and pass the trusted relationship to the upper layer to form a complete chain of trust. The vASP front-end plugs into the hypervisor actively and regularly operates the dynamic measurement process of the guest to ensure that data from the guest machine are not tampered with. With the introduction of vASP in the cloud computing platform, the security of vASP components during VM operation is also a concern. As a result, we propose a full VM life-cycle protection method through verification and measurement mechanisms that cannot be bypassed to ensure that vASP maintains a match with specific VMs. We have implemented the vASP architecture on a commercial platform deployed with ASP architecture and evaluated it. The result shows that the vASP architecture can protect VM integrity well during full life-cycle and has very low overhead compared to the native virtualization architecture. Jiayun Chen, Qihang Zhou, Weijuan Zhang, Yamin Xie, Xiaoqi Jia |
CCGrid | 6 |
| 2024 | ConMonitor: Lightweight Container Protection with Virtualization and VM FunctionsabstractContainers are widely used in multi-tenant cloud computing for their ease of deployment, minimal overhead, and fast start-up. However, the intrinsic shared kernel model of containers poses significant security threats, risking confidentiality and integrity from co-located containers or compromised OS. Researchers have proposed various methods to protect containers from untrusted OS, but few consider both the universality and efficiency. In this paper, we present ConMonitor---a lightweight and efficient container protection architecture. ConMonitor protects the security of container application data by introducing a compact virtualization software, called ConVisor, as a trusted computing base. ConVisor enforces isolation of the physical memory between containers and the kernel, and monitors the sensitive operations performed by the OS. To ensure the security of ConMonitor, we implement a Container Guardian to serve as an intermediary for the kernel, managing sensitive operations. Moreover, we also leverage the VMFUNC feature to achieve fast context switching, thereby mitigating the performance penalty associated with frequent context switching. We have implemented ConMonitor on Intel CPU with Virtualization Technology, and the evaluation results show that ConMonitor can protect the security of container applications with a negligible performance overhead. Shaowen Xu, Qihang Zhou, Xiaoqi Jia, Heqing Huang 0001, Haichao Du |
SoCC | 4 |
| 2024 | SEDSpec: Securing Emulated Devices by Enforcing Execution SpecificationabstractDevice emulation is a vital aspect of virtualization, yet remains vulnerable to security threats. Prior research has focused on monitoring I/O data flow or identifying internal device anomalies but often falls short in precision and automation. In this paper, we propose a novel method that leverages the normal operations of an emulated device to formulate an execution specification. The specification acts as a criterion to evaluate the device's behavior and state transitions. We implement SEDSpec, a prototype system that automatically generates the execution specification for an emulated device and devises three check strategies for identifying any deviations from this specification, thereby ensuring normal operations and enhancing the security of the emulated device. We evaluate SEDSpec with five different execution specifications. The results show that SEDSpec can detect anomalies caused by vulnerability exploitation while maintaining the devices' regular functioning with minimal performance overhead. Shengzhi Zhang, Xiaoqi Jia, Qihang Zhou, Heqing Huang 0001, Shaowen Xu, Haochao Du |
DSN | 3 |
| 2024 | SummSlim: A Universal and Automated Approach for Debloating Container ImagesabstractContainer technology has become a cornerstone of cloud computing, offering notable benefits such as enhanced resource utilization and streamlined deployment processes. The adoption of container technology by leading cloud service providers has steadily increased over the years. However, during the image construction phase, the reuse of base images and the execution of certain commands often results in the retention of redundant files, leading to resource wastage and potential security vulnerabilities. In this research, we systematically review and analyze existing methodologies, identify shortcomings in current approaches, and propose an automated image debloating tool named SummSlim according to the characteristics of the container image construction process. We selected 195 official images from Docker Hub for testing and evaluated the effectiveness of SummSlim with a success rate of $98.46 \%$. Then we compare and analyze the images before and after debloating, and make some novel suggestions for developers. To the best of our knowledge, SummSlim is the first practically available universal image debloating tool. Heqing Huang 0001, Shaowen Xu, Qihang Zhou, Xiaoqi Jia, Weijuan Zhang |
ICPADS | 6 |
| 2024 | Structure-Sensitive Pointer Analysis for Multi-structure ObjectsabstractStatic analysis is a method within software analysis, and pointer analysis is an important component of static analysis. An important dimension of pointer analysis is field-sensitivity, which has been proven to effectively enhance the accuracy of pointer analysis results. A crucial area of research within field-sensitivity is structure-sensitivity. Structure-sensitivity has been shown to further enhance the precision of pointer analysis. However, existing structure-sensitive methods cannot handle cases where an object possesses multiple structures. Xun An, Xiaoqi Jia, Haichao Du, Yamin Xie |
Internetware | 2 |
| 2024 | LightArmor: A Lightweight Trusted Operating System Isolation Approach for Mobile Systems
Qihang Zhou, Xiaoqi Jia, Jiayun Chen, Qingjia Huang, Haichao Du |
SEC | 3 |
| 2024 | Malware Classification Method Based on Dynamic Features with Sensitive BehaviorsabstractTraditional malware classification methods often just scratch the surface by analyzing the sequence of system commands (API calls) used by malware during its operation. These approaches miss out on deeper, complex behaviors that could significantly enhance accuracy in identifying different malware types. To address this, we introduce SenBeMC, a method that delves deeper into the behaviors exhibited by malware. SenBeMC combine API call information vectors with behavioral information to enhance the deep semantic information of input features, enriching the hierarchical structure of feature representation. SenBeMC stands out by employing soft thresholding and attention mechanisms to sift through the noise — extraneous information that can mask the malware's true nature, and a BiLSTM model that excels in understanding the sequence and timing of actions, crucial for spotting sophisticated threats. Experimental evaluations on real-world datasets affirm that SenBeMC effectively improves feature representation and accuracy of malware classification when compared to other contemporary state-of-the-art models. Yamin Xie, Siyuan Li 0014, Zhengcai Chen, Haichao Du, Xiaoqi Jia, Yuejin Du |
SMC | 5 |
| 2024 | LLM4MDG: Leveraging Large Language Model to Construct Microservices Dependency GraphabstractMicroservices architecture has gained popularity in modern software development due to its scalability and flexibility. However, understanding the complexity of interactions and dependencies between services presents significant challenges, which complicates the identification and analysis of errors within microservice applications. To gain insights into the architecture and interdependencies of microservices applications, prior studies have developed dependency graphs to illustrate the relationships among services. However, the methods used to construct these dependency graphs are not suitable for common microservices applications and suffer from insufficient data granularity. To address these shortcomings, we introduce LLM4MDG, an in-novative framework for constructing microservices dependency graphs using an LLM-driven multi-agent system. By leveraging optimized prompt engineering and principles of knowledge graphs, LLM4MDG can effectively identify and interpret service interactions across diverse microservice ecosystems, achieving high accuracy and adaptability across various scenarios. We also present a new open-source dataset comprising 47 microservices applications, annotated by domain experts, to validate our frame-work. Evaluation results demonstrate that LLM4MDG achieves an 88.3% accuracy in identifying data dependencies in the Train Ticket project, a benchmark application with over 80 service instances. This study provides a robust solution for constructing dependency graphs and facilitating better system understanding and management. Jiekang Hu, Yakai Li, Zhaoxi Xiang, Luping Ma, Xiaoqi Jia, Qingjia Huang |
TrustCom | 5 |
| 2024 | SeChannel: A Secure and Lightweight Channel Protection Approach for TEE SystemsabstractTrusted Execution Environments (TEEs) are essential for securing sensitive data by isolating it from potentially vulnerable execution environments. In ARM-based devices, TEEs utilize TrustZone technology to create a secure world for Trusted Applications (TAs) and a normal world for Client Applications (CAs), ensuring strict isolation through hardware mechanisms. Despite this protection, current TEE systems lack robust mechanisms for securing TA access, leaving them vulnerable to attacks that exploit cross-world communication channels.This paper introduces SeChannel, a lightweight solution for securing communication channels in TrustZone-assisted TEEs. Unlike existing methods, SeChannel requires no additional hardware and avoids the performance penalties of encryption and memory copying. By leveraging existing ARM Trusted Firmware (ATF), SeChannel implements fine-grained access control to ensure that communication between CAs and TAs is authenticated and protected. It verifies shared memory addresses and TA sessions, preventing unauthorized access by the Rich OS. We implement a prototype of SeChannel on the Hikey960 development board with minimal code modifications to the existing system. Our evaluation demonstrates that SeChannel significantly enhances the security of TrustZone-assisted TEEs with negligible performance overhead. Yuanbo Zhao, Qihang Zhou, Xiaoqi Jia |
TrustCom | 4 |
| 2024 | HClave: An isolated execution environment design for hypervisor runtime security
Qihang Zhou, Wenzhuo Cao, Xiaoqi Jia, Shengzhi Zhang, Jiayun Chen, Weijuan Zhang, Haichao Du, Qingjia Huang |
Comput. Secur. | 3 |
| 2024 | MDGraph: A novel malware detection method based on memory dump and graph neural network
Donghai Tian, Xiaoqi Jia, Changzhen Hu |
Expert Syst. Appl. | 4 |
| 2024 | The Potential Harm of Email Delivery: Investigating the HTTPS Configurations of Webmail ServicesabstractWebmail, protected by the HTTPS protocol, only works correctly if both the server and client implement HTTPS-related features without vulnerability. Nevertheless, the deployment situation of these features in the webmail world is still unclear. To this end, we perform the first end-to-end and large-scale measurement of webmail service. For the server side, we first build an email address set with a size of 2.2 billion. Then we construct two webmail domain datasets: one contains 21 k domains filtered from the email address set; the other only includes 34 domains but supports more than 75% of the 2.2 billion email addresses. After performing a comprehensive measurement on these two webmail domain datasets, we find that some features are poorly deployed. Furthermore, we also rank servers by analyzing the properties of HTTPS-related features. For the client side, we investigate implement of HTTPS-related features in 50 different combinations of web browsers and operating systems (OSes). We find that even the latest browsers have poor support for some features. For example, Firefox in all OSes does not support CT. Our findings highlight that the full deployment of the security features for the HTTPS ecosystem is still a challenge, even in the webmail service. Ruixuan Li 0008, Zhenyong Zhang, Jun Shao 0001, Rongxing Lu, Xiaoqi Jia, Guiyi Wei |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | Log2Policy: An Approach to Generate Fine-Grained Access Control Rules for Microservices from ScratchabstractMicroservice application architecture is one of the most widely used service architectures in the industry. To prevent a compromised microservice from abusing other microservices, authorization policy is applied to regulate the access among them. However, configuring access control policy manually is challenging due to the complexity and dynamic nature of microservice applications. In this paper, we present Log2Policy, a novel approach to generate microservice authorization policy based on access logs. Our approach consists of three fundamental techniques: (1) a log-based topological graph generation mechanism that automatically infers the invocation logic among microservices, (2) a machine learning based attributes mining method that extracts the relevant attributes of requests, and (3) a policy upgrade mechanism based on traffic management that can significantly reduce the upgrade time. We have implemented a prototype of Log2Policy on mainstream microservice infrastructures and have evaluated it with several microservice applications. The results show that Log2Policy can generate fine-grained and effective access control rules and upgrade them with negligible overhead. Shaowen Xu, Qihang Zhou, Heqing Huang 0001, Xiaoqi Jia, Haichao Du, Yamin Xie |
ACSAC | 4 |
| 2023 | Refining Use-After-Free Defense: Eliminating Dangling Pointers in Registers and MemoryabstractThe prevalence of use-after-free (UAF) vulnerabilities poses a significant threat to software security, with dangling pointers identified as the primary cause. However, existing de-fense methods suffer from bypass attacks, high runtime overhead, or only address memory dangling pointers while neglecting register-based ones that also contribute to UAF vulnerabilities. To overcome these shortcomings, we introduce a novel approach, ISDE, that eliminates both register and memory dangling point-ers with minimal additional runtime overhead. ISDE leverages an inter-procedural static pointer analysis method to statically collect object pointers during compilation, and uses the call graph and data flow graph to identify and eliminate potential dangling pointers. Our implementation of ISDE demonstrated its effectiveness in defending against real-world UAF vulnerabilities while maintaining efficiency in the SPEC CPU2006 evaluation. Xun An, Qihang Zhou, Haichao Du, Xiaoqi Jia |
APSEC | 5 |
| 2023 | Protecting Encrypted Virtual Machines from Nested Page Fault Controlled ChannelabstractAMD Secure Encrypted Virtualization (SEV) assumes the hypervisor (HV) is untrusted and introduces hardware memory encryption support for virtual machines (VMs). Previous studies have proposed various attacks against encrypted VMs by exploiting SEV security flaws such as unencrypted VMCB and lack of memory integrity. Most of these flaws have been solved by the subsequent releases of SEV with Encrypted State (SEV-ES) and SEV with Secure Nested Paging (SEV-SNP). However, the latest SEV-SNP cannot stop the malicious HV tampering with critical flags in the nested page table (NPT). So SEV-SNP is still vulnerable to the nested page fault (NPF) controlled channel attack, which is a commonly shared step of most attacks against SEV. Existing works on SEV also cannot defend against NPF controlled channel. In this paper, we first analyze the root cause of NPF controlled channel. Then we propose a software-based approach to protect encrypted VMs from NPF controlled channel. We introduce a virtualization security module (VSM) as a software TCB to deprivilege the HV by modifing the HV to access critical resources indirectly through interfaces managed by VSM. To prevent the untrusted HV from compromising the VSM-based protection, we extend the nested kernel architecture to the virtualization layer to provide isolation for VSM at the same privilege level. A prototype of this approach is implemented based on KVM. The experiments show that the approach can protect encrypted VMs from NPF controlled channel with 1.21% average runtime overhead and 1.47% average I/O overhead. Haoxiang Qin, Weijuan Zhang, Sicong Huang 0004, Xiaoqi Jia, Haichao Du |
CODASPY | 7 |
| 2023 | ELAMD: An ensemble learning framework for adversarial malware defense
Chong Yuan, Jiashuo Li, Donghai Tian, Rui Ma 0004, Xiaoqi Jia |
J. Inf. Secur. Appl. | 6 |
| 2023 | Non-transferable blockchain-based identity authentication
Yuxia Fu, Jun Shao 0001, Qingjia Huang, Qihang Zhou, Huamin Feng, Xiaoqi Jia, Ruiyi Wang, Wenzhi Feng |
Peer Peer Netw. Appl. | 6 |
| 2023 | A Longitudinal and Comprehensive Measurement of DNS Strict PrivacyabstractThe DNS privacy protection mechanisms, DNS over TLS (DoT) and DNS over HTTPS (DoH), only work correctly if both the server and client support the Strict Privacy profile and no vulnerability exists in the implemented TLS/HTTPS. A natural question then arises: what is the landscape of DNS Strict Privacy? To this end, we provide the first longitudinal and comprehensive measurement of DoT/DoH deployments in recursive resolvers, authoritative servers, and browsers. With the collected data, we find the number of DoT/DoH servers increased substantially during our ten-month-long scan. However, around 60% of DoT and 44% of DoH recursive resolver certificates are invalid. Worryingly, our measurements confirm the centralization problem of DoT/DoH. Furthermore, we classify DNS Strict Privacy servers into four levels according to daily scanning results on TLS/HTTPS-related security features. Unfortunately, around 25% of DoH Strict Privacy recursive resolvers fail to meet the minimum level requirements. To help the Internet community better perceive the landscape of DNS Strict Privacy, we implement a DoT/DoH server search engine and recommender system. Additionally, we investigate five popular browsers across four operating systems and find some inconsistent behavior with their DNS privacy implementations. For example, Firefox in Windows, Linux, and Android allows DoH communication with the server without the SAN certificate. At last, we advocate that all participants head together for a bright DNS Strict Privacy landscape by discussing current hindrances and controversies in DNS privacy. Ruixuan Li 0008, Zhenyong Zhang, Jun Shao 0001, Rongxing Lu, Jingqiang Lin 0001, Xiaoqi Jia, Guiyi Wei |
IEEE/ACM Trans. Netw. | 7 |
| 2022 | Protecting Virtual Machines against Untrusted Hypervisor on ARM64 Cloud PlatformabstractIn cloud computing, the confidentiality and integrity of virtual machines (VMs) are facing severe threats because of the huge trusted computing base (TCB) software stack in virtualization layer. With the increasing momentum of ARM64 in cloud computing server markets, it is important to protect VMs from privileged software (including host operating system and hypervisor) on ARM64. In this paper, we have created SecureHyp, a new virtualization platform design for refactoring the existing hypervisor using the ARM64 hardware security mechanisms to reduce the TCB while protecting VMs against untrusted privileged software. Based on the principle of the least privilege, SecureHyp separates the sensitive-resource management from the rights of the hypervisor and prohibits the hypervisor from accessing specific sensitive resources. By deploying the memory isolation using ARM Trusted Firmware (ATF) and virtual Memory Management Unit (vMMU), SecureHyp ensures both the security and efficiency of the guest VMs. We have implemented SecureHyp on Linux firefly-4.4.194 with modest modification. The results show that SecureHyp can protect the confidentiality and integrity of virtual machines with only around 2000 lines of code software TCB and negligible performance overhead. Qihang Zhou, Xiaoqi Jia |
ICC | 2 |
| 2022 | SecFortress: Securing Hypervisor using Cross-layer IsolationabstractVirtualization is the corner stone of cloud computing, but the hypervisor, the crucial software component that enables virtualization, is known to suffer from various attacks. It is challenging to secure the hypervisor due to at least two reasons. On one hand, commercial hypervisors are usually integrated into a privileged Operating System (OS), which brings in a larger attack surface. On the other hand, multiple Virtual Machines (VM) share a single hypervisor, thus a malicious VM could leverage the hypervisor as a bridge to launch “cross-VM” attacks. In this work, we propose SecFortress, a dependable hypervisor design that decouples the virtualization layer into a mediator, an outerOS, and multiple HypBoxes through a cross-layer isolation approach. SecFortress extends the nested kernel approach to de-privilege the outerOS from accessing the mediator's memory and creates an isolated hypervisor instance, HypBox, to confine the impacts from the untrusted VMs. We implemented SecFortress based on KVM and evaluated its effectiveness and efficiency through case studies and performance evaluation. Experimental results show that SecFortress can significantly improve the security of the hypervisor with negligible runtime overhead. Qihang Zhou, Xiaoqi Jia, Shengzhi Zhang, Jiayun Chen, Weijuan Zhang |
IPDPS | 2 |
| 2022 | Practical Backdoor Attack Against Speaker Recognition System
Jianwei Tai, Xiaoqi Jia, Shengzhi Zhang |
ISPEC | 3 |
| 2022 | An Efficient Use-after-Free Mitigation Approach via Static Dangling Pointer Nullification
Xiaoqi Jia, Xun An, Shengzhi Zhang |
SEC | 2 |
| 2022 | EnShare: Sharing Files Securely and Efficiently in the Cloud using EnclaveabstractAs the cloud-based file sharing becomes increasingly popular, it is crucial to protect the outsourced data against unauthorized access. In this paper, we propose EnShare, a secure and practical file sharing system that leverages cooperation of server-side and client-side enclaves to enforce access control, with the former responsible for registration, authentication and access control enforcement and the latter performing file decryption. Such design significantly reduces the computation workload of server-side enclaves, thus capable of handling concurrent requests. Meanwhile, it also supports immediate permission revocation, since the file decryption keys inside the client-side enclaves are destroyed immediately after use. We implement a prototype of EnShare and the evaluation demonstrates it enforces access control securely with high throughput and low latency. Xiaoqi Jia, Shengzhi Zhang, Lubomir T. Chitkushev |
TrustCom | 2 |
| 2022 | CJSpector: A Novel Cryptojacking Detection Method Using Hardware Trace and Deep Learning
Qianjin Ying, Yulei Yu, Donghai Tian, Xiaoqi Jia, Rui Ma 0004, Changzhen Hu |
J. Grid Comput. | 4 |
| 2022 | Towards time evolved malware identification using two-head neural network
Chong Yuan, Jingxuan Cai, Donghai Tian, Rui Ma 0004, Xiaoqi Jia, Wenmao Liu |
J. Inf. Secur. Appl. | 5 |
| 2021 | MDCHD: A novel malware detection method in cloud using hardware trace and deep learning
Donghai Tian, Qianjin Ying, Xiaoqi Jia, Rui Ma 0004, Changzhen Hu, Wenmao Liu |
Comput. Networks | 3 |
| 2021 | BinDeep: A deep learning approach to binary code similarity detection
Donghai Tian, Xiaoqi Jia, Rui Ma 0004, Shuke Liu, Changzhen Hu |
Expert Syst. Appl. | 2 |
| 2020 | SEEF-ALDR: A Speaker Embedding Enhancement Framework via Adversarial Learning based Disentangled RepresentationabstractSpeaker verification, as a biometric authentication mechanism, has been widely used due to the pervasiveness of voice control on smart devices. However, the task of “in-the-wild” speaker verification is still challenging, considering the speech samples may contain lots of identity-unrelated information, e.g., background noise, reverberation, emotion, etc. Previous works focus on optimizing the model to improve verification accuracy, without taking into account the elimination of the impact from the identity-unrelated information. To solve the above problem, we propose SEEF-ALDR, a novel Speaker Embedding Enhancement Framework via Adversarial Learning based Disentangled Representation, to reinforce the performance of existing models on speaker verification. The key idea is to retrieve as much speaker identity information as possible from the original speech, thus minimizing the impact of identity-unrelated information on the speaker verification task by using adversarial learning. Experimental results demonstrate that the proposed framework can significantly improve the performance of speaker verification by 20.3% and 23.8% on average over 13 tested baselines on dataset Voxceleb1 and 8 tested baselines on dataset Voxceleb2 respectively, without adjusting the structure or hyper-parameters of them. Furthermore, the ablation study was conducted to evaluate the contribution of each module in SEEF-ALDR. Finally, porting an existing model into the proposed framework is straightforward and cost-efficient, with very little effort from the model owners due to the modular design of the framework. Jianwei Tai, Xiaoqi Jia, Qingjia Huang, Weijuan Zhang, Haichao Du, Shengzhi Zhang |
ACSAC | 2 |
| 2020 | ET-GAN: Cross-Language Emotion Transfer Based on Cycle-Consistent Generative Adversarial NetworksabstractDespite the remarkable progress made in synthesizing emotional speech from text, it is still challenging to provide emotion information to existing speech segments. Previous methods mainly rely on parallel data, and few works have studied the generalization ability for one model to transfer emotion information across different languages. To cope with such problems, we propose an emotion transfer system named ET-GAN, for learning language-independent emotion transfer from one emotion to another without parallel training samples. Based on cycle-consistent generative adversarial network, our method ensures the transfer of only emotion information across speeches with simple loss designs. Besides, we introduce an approach for migrating emotion information across different languages by using transfer learning. The experiment results show that our method can efficiently generate high-quality emotional speech for any given emotion category, without aligned speech pairs. Xiaoqi Jia, Jianwei Tai, Yakai Li, Weijuan Zhang, Haichao Du, Qingjia Huang |
ECAI | 1 |
| 2020 | PiDicators: An Efficient Artifact to Detect Various VMs
Qingjia Huang, Haiming Li, Jianwei Tai, Xiaoqi Jia |
ICICS | 5 |
| 2020 | EnclavePDP: A General Framework to Verify Data Integrity in Cloud Using Intel SGX
Yihua Xu, Xiaoqi Jia, Shengzhi Zhang, Peng Liu 0005, Shuai Chang |
RAID | 3 |
| 2020 | MSYM: A multichannel communication system for android devices
Donghai Tian, Weizhi Meng 0001, Xiaoqi Jia, Rui Ma 0004 |
Comput. Networks | 4 |
| 2020 | Built-in Security Computer: Deploying Security-First Architecture Using Active Security ProcessorabstractContinually disclosed vulnerabilities reveal that traditional computer architecture lacks the consideration of security. This article proposes a security-first architecture, with an Active Security Processor (ASP) integrated to conventional computer architectures. To reduce the attack surface of ASP and improve the security of the whole system, the ASP is physically isolated from Computation Processor Units (CPU) with an asymmetric address space, which enables both ASP and CPU to run their operating system and applications independently in their own memory space. Furthermore, the ASP, which has the highest privilege (Super Root) of the whole system, possesses two advantageous features. First, the ASP can efficiently access all CPU resources and collect multi-dimensional information to monitor malicious behaviors, meanwhile, the CPU cannot access the ASP's private resources in any way. Second, instead of being scheduled by CPUs, the ASP can actively manage the security mechanisms employed in either CPUs or the ASP. Based on the security-first architecture, we introduce several typical security tasks running on ASP. With different considerations in terms of system overhead, complexity and performance, we also explore four typical system-level implementations for integrating the ASP to the security-first architecture. The first-generation ASP was designed and implemented based on the 40nm technology, and a security computer system was implemented based on it. Evaluations on this real hardware platform demonstrate that the security-first architecture can protect the system effectively with minor performance impacts on computing workloads. Dan Meng 0002, Rui Hou 0001, Bibo Tu, Xiaoqi Jia, Yu Wen 0001 |
IEEE Trans. Computers | 7 |
| 2019 | An online approach to defeating ROP attacks∗abstractSummary Return‐Oriented Programming (ROP) attacks become very popular in recent years as these attacks can bypass traditional defense mechanisms such as data execution prevention (DEP) effectively. Previous solutions suffer from limitations in that: 1) some methods need to modify the target programs; 2) some methods introduce considerable performance cost; 3) some methods rely on the special hardware; and 4) ,most of existing methods could not provide an online protection for the target processes. In this paper, we present OnRop, an on‐the‐fly ROP attack protection system by using the commodity hardware features and OS internal facilities. Our system is compatible with the existing programs, and its protection layer can be added on demand. The experiments show that OnRop can detect ROP attacks effectively with moderate performance cost. Donghai Tian, Xiaoqi Jia, Zhaolong Zhang, Li Zhan, Changzhen Hu, Jingfeng Xue |
Concurr. Comput. Pract. Exp. | 2 |
| 2019 | KEcruiser: A novel control flow protection for kernel extensions
Donghai Tian, Rui Ma 0004, Xiaoqi Jia, Changzhen Hu |
Future Gener. Comput. Syst. | 3 |
| 2018 | Running OS Kernel in Separate Domains: A New Architecture for Applications and OS Services QuarantineabstractContainer-based PaaS cloud is ease of use and cost-efficient, but vulnerable to attacks due to the weak isolation provided by the built-in containers. In this paper, we present a lightweight virtualization based kernel decomposition approach to securely isolate cloud tenants as well as the operating system (OS) services against various threats. Our design decouples existing OS kernels based on their functionality and isolates different kernel partitions in separate domains. The kernel partition that enables application execution is quarantined in an application domain, while other partitions that offer various services are isolated in separate service domains. The application owned by one tenant can run transparently in a dedicated application domain, with strong isolation to those owned by other tenants. Furthermore, the kernel partition approach effectively defeats the malware that requires support from different kernel services. We have implemented a prototype based on Linux kernel and Xen hypervisor. Our evaluation demonstrates that the proposed kernel decomposition approach can defeat various OS kernel-targeted attacks with minimal performance overhead. Weijuan Zhang, Xiaoqi Jia, Shengzhi Zhang, Rui Wang 0032, Peng Liu 0005 |
APSEC | 2 |
| 2018 | Security-first architecture: deploying physically isolated active security processors for safeguarding the future of computingabstractIt is fundamentally challenging to build a secure system atop the current computer architecture. The complexity in software, hardware and ASIC manufacture has reached beyond the capability of existing verification methodologies. Without whole-system verification, current systems have no proven security. It is observed that current systems are exposed to a variety of attacks due to the existence of a large number of exploitable security vulnerabilities. Some vulnerabilities are difficult to remove without significant performance impact because performance and security can be conflicting with each other. Even worse, attacks are constantly evolving, and sophisticated attacks are now capable of systematically exploiting multiple vulnerabilities while remain hidden from detection. Eagering to achieve security hardening of current computer architecture, existing defenses are mostly ad hoc and passive in nature. They are normally developed in responding to specific attacks spontaneously after specific vulnerabilities were discovered. As a result, they are not yet systematic in protecting systems from existing attacks and likely defenseless in front of zero-day attacks. To confront the aforementioned challenges, this paper proposes Security-first Architecture , a concept which enforces systematic and active defenses using Active Security Processors . In systems built based on this concept, traditional processors (i.e., Computation Processors ) are monitored and protected by Active Security Processors. The two types of processors execute on their own physically-isolated resources, including memory, disks, network and I/O devices. The Active Security Processors are provided with dedicated channels to access all the resources of the Computation Processors but not vice versa. This allows the Active Security Processors to actively detect and tackle malicious activities in the Computation Processors with minimum performance degradation while protecting themselves from the attacks launched from the Computation Processors thanks to the resource isolation. Dan Meng 0002, Rui Hou 0001, Bibo Tu, Xiaoqi Jia, Peng Liu 0005 |
Cybersecur. | 7 |
| 2017 | Towards comprehensive protection for OpenFlow controllersabstractOpenFlow has recently emerged as a powerful paradigm to help build dynamic, adaptive and agile networks. By decoupling control plane from data plane, OpenFlow allows network operators to program a centralized intelligence, OpenFlow controller, to manage network-wide traffic flows to meet the changing needs. However, from the security's point of view, a buggy or even malicious controller could compromise the control logic, and then the entire network. Even worse, the recent attack Stuxnet on industrial control systems also indicates the similar, severe threat to OpenFlow controllers from the commercial operating systems they are running on. In this paper, we comprehensively studied the attack vectors against the OpenFlow critical component, controller, and proposed a cross layer diversity approach that enables OpenFlow controllers to detect attacks, corruptions, failures, and then automatically continue correct execution. Case studies demonstrate that our approach can protect OpenFlow controllers from threats coming from compromised operating systems and themselves. Shengzhi Zhang, Xiaoqi Jia, Weijuan Zhang |
APNOMS | 2 |
| 2017 | FindEvasion: An Effective Environment-Sensitive Malware Detection System for the Cloud
Xiaoqi Jia, Guangzhe Zhou, Qingjia Huang, Weijuan Zhang, Donghai Tian |
ICDF2C | 1 |
| 2017 | CacheRascal: Defending the Flush-Reload Side-Channel Attack in PaaS Clouds
Weijuan Zhang, Xiaoqi Jia, Jianwei Tai, Mingsheng Wang |
WASA | 2 |
| 2016 | A Comprehensive Study of Co-residence Threat in Multi-tenant Public PaaS Clouds
Weijuan Zhang, Xiaoqi Jia, Shengzhi Zhang, Qingjia Huang, Mingsheng Wang, Peng Liu 0005 |
ICICS | 2 |
| 2016 | Towards service continuity for transactional applications via diverse device driversabstractExisting techniques, such as state roll-back or replay can preserve as much accumulated 'state' as possible when one application is compromised. However, when operating system kernel is compromised, e.g., driver vulnerability exploitation, the default behaviour of most commodity operating systems today is to reboot from a clean initial state. All the running applications also need to be terminated and restarted, thus losing their accumulated 'work in progress' states. In this paper, we propose to leverage virtualisation technique to produce operating system replicas with driver diversity. By replicating transactional application on each replica and loosely synchronising them, we validate the output, critical memory regions and persistent data of transactional applications, thus detecting intrusion stemming from driver code vulnerability. We implement such diversity approach on Xen hypervisor, and rely on a proxy to conduct request replication and response validation. Our evaluation demonstrates that the proposed approach can accurately and immediately detect driver-bug-orientated exploitation and achieve on-the-fly intrusion response to ensure the correctness/continuity of the applications' execution. We only incur 4.44% and 4.7% overhead to response time and CPU respectively in the best case. Shengzhi Zhang, Xiaoqi Jia, Peng Liu 0005 |
Int. J. Inf. Comput. Secur. | 2 |
| 2015 | An Effective Method for Gender Classification with Convolutional Neural Networks
Qing Zhu 0004, Xiaoqi Jia |
ICA3PP (2) | 3 |
| 2015 | Program Characterization Using Runtime Values and Its Application to Software Plagiarism DetectionabstractIllegal code reuse has become a serious threat to the software community. Identifying similar or identical code fragments becomes much more challenging in code theft cases where plagiarizers can use various automated code transformation or obfuscation techniques to hide stolen code from being detected. Previous works in this field are largely limited in that (i) most of them cannot handle advanced obfuscation techniques, and (ii) the methods based on source code analysis are not practical since the source code of suspicious programs typically cannot be obtained until strong evidences have been collected. Based on the observation that some critical runtime values of a program are hard to be replaced or eliminated by semantics-preserving transformation techniques, we introduce a novel approach to dynamic characterization of executable programs. Leveraging such invariant values, our technique is resilient to various control and data obfuscation techniques. We show how the values can be extracted and refined to expose the critical values and how we can apply this runtime property to help solve problems in software plagiarism detection. We have implemented a prototype with a dynamic taint analyzer atop a generic processor emulator. Our value-based plagiarism detection method (VaPD) uses the longest common subsequence based similarity measuring algorithms to check whether two code fragments belong to the same lineage. We evaluate our proposed method through a set of real-world automated obfuscators. Our experimental results show that the value-based method successfully discriminates 34 plagiarisms obfuscated by SandMark, plagiarisms heavily obfuscated by KlassMaster, programs obfuscated by Thicket, and executables obfuscated by Loco/Diablo. Yoon-chan Jhi, Xiaoqi Jia, Sencun Zhu, Peng Liu 0005, Dinghao Wu |
IEEE Trans. Software Eng. | 2 |
| 2013 | Defending return-oriented programming based on virtualization techniquesabstractABSTRACT Over the past few years, return‐oriented programming (ROP) has drawn great attention of both academia and industry. Because of its Turing completeness, ROP reuses short instruction sequences already present in the victim program's address space to perform arbitrary computation. Hence, it can successfully bypass state‐of‐the‐art code integrity check mechanisms. In this paper, we look into using virtualization technologies to defeat return‐oriented programming. We design and implement HyperCropII, a virtualization‐based automatic runtime approach to defend such attacks. ROP attackers extract short instruction sequences ending in ret called “gadgets” and craft stack content to “chain” these gadgets together. We observe that a key characteristic of ROP is to fill the stack with plenty of addresses that are within the range of the program's libraries. Accordingly, we inspect the content of the stack to see if a potential ROP attack exists and quarantine the damages for further security purposes. We have implemented a proof‐of‐concept system based on the open source Xen hypervisor. The evaluation results exhibit that our solution is effective and efficient. Copyright © 2013 John Wiley & Sons, Ltd. Xiaoqi Jia, Rui Wang 0032, Shengzhi Zhang, Peng Liu 0005 |
Secur. Commun. Networks | 1 |
| 2011 | HyperCrop: A Hypervisor-Based Countermeasure for Return Oriented Programming
Xiaoqi Jia, Dengguo Feng, Shengzhi Zhang, Peng Liu 0005 |
ICICS | 2 |
| 2011 | Value-based program characterization and its application to software plagiarism detectionabstractIdentifying similar or identical code fragments becomes much more challenging in code theft cases where plagiarizers can use various automated code transformation techniques to hide stolen code from being detected. Previous works in this field are largely limited in that (1) most of them cannot handle advanced obfuscation techniques; (2) the methods based on source code analysis are less practical since the source code of suspicious programs is typically not available until strong evidences are collected; and (3) those depending on the features of specific operating systems or programming languages have limited applicability. Yoon-chan Jhi, Xiaoqi Jia, Sencun Zhu, Peng Liu 0005, Dinghao Wu |
ICSE | 3 |
| 2011 | An Efficient Group-Based Secret Sharing Scheme
Chunli Lv, Xiaoqi Jia, Jingqiang Lin 0001, Jiwu Jing, Lijun Tian |
ISPEC | 2 |
| 2011 | PEDA: Comprehensive Damage Assessment for Production Environment Server SystemsabstractAnalyzing the intrusion to production servers is an onerous and error-prone work for system security technicians. Existing tools or techniques are quite limited. For instance, system events tracking lacks completeness of intrusion propagation, while dynamic taint tracking is not feasible to be deployed due to significant runtime overhead. Thus, we propose production environment damage assessment (PEDA), a systematic approach to do postmortem intrusion analysis for production workload servers. PEDA replays the “has-been-infected” execution with high fidelity on a separate analyzing instrumentation platform to conduct the heavy workload analysis. Though the replayed execution runs atop the instrumentation platform (i.e., binary-translation-based virtual machine), PEDA allows the first-run execution to run atop the hardware-assisted virtual machine to ensure minimum runtime overhead. Our evaluation demonstrates the efficiency of the PEDA system with a runtime overhead as low as 5%. The real-life intrusion studies show the advantage of PEDA intrusion analysis over existing techniques. Shengzhi Zhang, Xiaoqi Jia, Peng Liu 0005, Jiwu Jing |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2010 | Cross-layer comprehensive intrusion harm analysis for production workload server systemsabstractAnalyzing the (harm of) intrusion to enterprise servers is an onerous and error-prone work. Though dynamic taint tracking enables automatic fine-grained intrusion harm analysis for enterprise servers, the significant runtime overhead introduced is generally intolerable in the production workload environment. Thus, we propose PEDA (Production Environment Damage Analysis) system, which decouples the onerous analysis work from the online execution of the production servers. Once compromised, the "has-been-infected" execution is analyzed during high fidelity replay on a separate instrumentation platform. The replay is implemented based on the heterogeneous virtual machine migration. The servers' online execution runs atop fast hardware-assisted virtual machines (such as Xen for near native speed), while the infected execution is replayed atop binary instrumentation virtual machines (such as Qemu for the implementation of taint analysis). From identified intrusion symptoms, PEDA is capable of locating the fine-grained taint seed by integrating the backward system call dependency tracking and one-step-forward taint information flow auditing. Started with the fine-grained taint seed, PEDA applies dynamic taint analysis during the replayed execution. Evaluation demonstrates the efficiency of PEDA system with runtime overhead as low as 5%. The real-life intrusion studies successfully show the comprehensiveness and the precision of PEDA's intrusion harm analysis. Shengzhi Zhang, Xiaoqi Jia, Peng Liu 0005, Jiwu Jing |
ACSAC | 2 |
| 2010 | Proactive Identification and Prevention of Unexpected Future Rule Conflicts in Attribute Based Access Control
Daren Zha, Jiwu Jing, Peng Liu 0005, Jingqiang Lin 0001, Xiaoqi Jia |
ICCSA (4) | 5 |
| 2010 | Using Purpose Capturing Signatures to Defeat Computer Virus Mutating
Xiaoqi Jia, Jiwu Jing, Peng Liu 0005 |
ISPEC | 1 |
| 2010 | Efficient Ideal Threshold Secret Sharing Schemes Based on EXCLUSIVE-OR OperationsabstractMost of secret sharing schemes have to be computed in a Galois field, such as Shamir's scheme, which have relatively heavy computational cost. Kurihara et al. recently proposed a fast secret sharing scheme using only Exclusive-OR(XOR) operations to make shares and recover the secret. Their proposed scheme was shown to be hundreds of times faster than Shamir's (in GF(q=264)) in terms of both distribution and recovery with a 4.5 MB secret when k=3 and n=11. However, some steps in their scheme still need to be improved. Their security proofs were too complex and difficult to be understood and verified intuitively. In this paper, we present a conciser, cleaner, faster scheme which is also based on XOR. Moreover, we give two geometric explanations of making shares in both our and Kurihara's schemes respectively, which would help to easier and further understand how the shares are made in the two schemes. Chunli Lv, Xiaoqi Jia, Lijun Tian, Jiwu Jing, Mingli Sun |
NSS | 2 |
| 2009 | SHELF: Preserving Business Continuity and Availability in an Intrusion Recovery SystemabstractRecovering from intrusions for a compromised computer system is a challenging job, especially for systems that run continuous services. Current intrusion recovery techniques often do not preserve the accumulated useful state of running applications and have very limited system availability when performing recovery routines. In this paper, we propose SHELF, an on-the-fly intrusion recovery prototype system that provides a comprehensive solution to preserve business continuity, availability and recovery accuracy. SHELF preserves accumulated clean states for infected applications and files so that they can continue with the most recent pre-infection states after recovery. Moreover, SHELF leverages OS-aware taint tracking techniques to swiftly determine the sources of intrusion and assess system-wide damages caused by the intrusion. SHELF uses quarantine methods to prevent infection propagation so that uninfected and recovered objects can provide availability during the recovery phase. We integrate SHELF prototype in a virtualization environment to achieve user transparency and protection. Our evaluation shows that SHELF can perform accurate recovery on-the-fly effectively with an acceptable performance overhead. Xiaoqi Jia, Peng Liu 0005 |
ACSAC | 2 |