Purui Su

dblp:46/3714 · DBLP profile ↗
← Back
46ranked-venue papers
0as first author
15since 2021 · last 2026
0000-0001-6701-0383ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 31 · 10 since 2021Software engineering, systems software and programming languages · 9 · 5 since 2021Computer networks · 2Graphics, computer vision, multimedia, augmented reality and games · 2Systems, architecture and hardware · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 OSmartPro: a large language model-assisted option fuzzing approach
abstract
Abstract Program options provide flexible software functionality control but complicate fuzz testing, as triggering many behaviors require specific option combinations. Although existing option-aware fuzzing approaches attempt to mutate options as inputs or leverage AI technologies to extract option relationships from documentation, these methods have limitations. Documentation is often incomplete, and some option dependencies are embedded deeply within program logic via data or control flows, making these methods challenging to detect all possible dependencies. This paper introduces OSmartPro , an advanced option-fuzzing approach that directly extracts options and infers option dependencies from source code. Given LLM’s capabilities to interpret program semantics, OSmartPro employs LLM-assisted static analysis to handle diverse option-parsing structures and extract comprehensive options. Through control and data dependency analysis, it constructs option impact graph , which it uses to guide fuzzing strategies. The tool successfully extracted complete options from all 59 programs in our test set, uncovering undocumented options in over 66% of them. Additionally, OSmartPro inferred 14,701 option combinations, identified 45.03% more execution paths compared to AFL++, and uncovered 54 zero-day vulnerabilities, of which 18 awarded CVE IDs. Lastly, in a benchmark comparison against four option-aware fuzzers, OSmartPro achieved higher line coverage in 66.7% (20 out of 30) of the programs.
Kelin Wang, Mengda Chen, Liang He 0011, Purui Su, Jiongyi Chen, Yan Cai 0001, Chao Feng 0002, Chaojing Tang, Guojun Peng
Cybersecur.5
2025 PromeFuzz: A Knowledge-Driven Approach to Fuzzing Harness Generation with Large Language Models
abstract
API-level fuzzing has become increasingly important for discovering subtle bugs in modern software, yet generating effective fuzzing harnesses remains a complex and error-prone task. Existing approaches often rely on limited consumer code or shallow program analysis, which fail to capture deep API semantics and interdependencies, resulting in poor coverage and high false positive rates. Recent methods incorporating Large Language Models (LLMs) have improved harness generation by leveraging pretrained knowledge, but they still struggle with hallucinations and lack domain-specific understanding.
Yuwei Liu 0001, Junquan Deng, Xiangkun Jia, Lin Huang 0005, Tao Wei 0002, Purui Su
CCS8
2025 Towards Efficient C/C++ Vulnerability Impact Assessment in Package Management Systems
Xiangkun Jia, Jia Yan 0004, Yi Yang 0040, Huafeng Huang, Purui Su
ICICS (3)6
2024 OSmart: Whitebox Program Option Fuzzing
abstract
Program options are ubiquitous and serve as a fundamental mechanism for configuring and customizing software behaviors. Given their widespread use, testing program options becomes essential to ensure that the software behaves as expected across various configurations. Existing option-aware fuzzers either mutate options as if they were standard program inputs or employ NLP techniques to deduce relationships among options from the documentation. However, there has not been a whitebox approach that generates option combinations by capturing the inherent execution logic of the program.
Kelin Wang, Mengda Chen, Liang He 0011, Purui Su, Yan Cai 0001, Jiongyi Chen, Chao Feng 0002, Chaojing Tang
CCS4
2024 AFGen: Whole-Function Fuzzing for Applications and Libraries
abstract
Fuzzing technology has been widely used to discover vulnerabilities, but existing fuzzing techniques still cannot cover and explore all functions in an application or a library. The works that automatically generate fuzzing harnesses for API functions of libraries provide a way to test the target function directly. However, applying these approaches to arbitrary internal functions of a project (e.g., library) is challenging. Specifically, the context of an API function is usually simple and clear for users, but the complex dependence of the internal functions leads to a more complicated running context and constraints on their parameters, making it hard to generate fuzzing harnesses efficiently.In this paper, we propose whole-function fuzzing, a "bottom-up" approach that fuzzes applications and libraries by covering all functions. We argue that it is beneficial to vulnerability discovery if one achieves full function coverage with precision sacrifice that can be mitigated through a delicate design. To this end, we design and implement AFGen, a framework of automatic whole-function fuzzing. Given a target function, AFGen will generate a fuzzing harness that reaches the target function with proper initial program context, and it will refine the fuzzing harness based on the constraints of the discovered crashes. Specifically, it slices the calling statements of a target function based on the control flow and data flow dependency, assigns values for the necessary variables used in the sliced code according to their types, and searches the constraint statements of the variables related to crash. In this way, AFGen generates fuzzing harnesses with a low false positive rate. To verify the effectiveness of AFGen, we collected 102 known vulnerabilities from 11 open-source projects. AFGen successfully creates fuzzing harnesses for all vulnerable functions, and it identifies 66 vulnerabilities of the collected 102 known vulnerabilities, which outperforms all comparing tools and achieves 2x vulnerabilities discovered by the second best fuzzer (i.e., AFL++). The crashes triggered by AFGen achieve 77.1% precision, which is 10 times the precision of FUDGE. AFGen also discovers 24 unknown vulnerabilities confirmed with CVE IDs.
Yuwei Liu 0001, Xiangkun Jia, Purui Su
SP5
2024 AirTaint: Making Dynamic Taint Analysis Faster and Easier
abstract
Dynamic Taint Analysis (DTA) is a widely used data flow tracking technique and helps security researchers in various applications, such as fuzzing and vulnerability analysis. One critical problem that affects its practicability is the significant overhead. According to our analysis, in some scenarios, the state-of-the-art works even slow the program execution efficiency by more than 100x. The high overhead is mainly because most of them conduct taint analysis at the instruction level and use just-in-time instrumentation methods to insert the tracking codes into the original program.In this paper, we propose AirTaint, a novel approach that combines the basic block-level abstraction of taint rules and assembly code-level instrumentation to conduct high-level dynamic taint analysis. Specifically, AirTaint leverages instruction-level emulation to identify the in and out operands (i.e., registers and memory variables) of each basic block, and then uses the existing taint engine to infer the taint rule abstraction for each basic block. Finally, it inserts the assembly code of the taint rule abstraction into the original program. While running, the program will execute the inserted taint analysis code quickly. In our evaluation based on 14 CVEs in 9 real-world applications, AirTaint detects all these vulnerabilities successfully. And in the comparison experiments, AirTaint performs much better than the existing tools in efficiency on 29 real-world applications, with maximum improvements of 931.0x, 5.97x, and 328.3x than libdft, SelectiveTaint, and TaintRabbit, respectively.
Qian Sang, Yuwei Liu 0001, Xiangkun Jia, Tiffany Bao, Purui Su
SP6
2023 VD-Guard: DMA Guided Fuzzing for Hypervisor Virtual Device
abstract
Virtualization has been widely used in various scenarios, such as cloud computing. As its core technology, virtualization hypervisor brings up the efficiency of sharing the physical machine's resources via virtual devices. However, virtualization hypervisor also introduces significant security risks due to defective design or implementation schemes on virtual devices. Although several methods have been proposed to detect vulnerabilities in virtual devices, they still cannot effectively discover them because of missing critical information related to the MMIO/PIO and DMA operations to guide their dynamic methods. In this paper, we propose a hybrid method, VD-GUARD, to detect vulnerabilities in virtual devices. Specifically, it first leverages static control flow analysis to track call traces from various data entry points of virtual devices (MMIO/PIO functions) to the critical dispatcher points (DMA functions), and generate seeds that can trigger this call trace via static analysis and limited fuzzing test. And then, it takes these seeds as input and leverages DMA guided fuzzing to discover bugs. To verify the effectiveness of Vd-guard, we build a dataset, including 10 bugs in QEMU, based on previous works, and Vd-guardoutperforms the state-of-the-art hypervisor fuzzer Morphuzz. Vd-guardalso has found 4 new vulnerabilities in QEMU and VirtualBox, all of which have been confirmed and fixed (have been assigned 3 CVE IDs).
Yuwei Liu 0001, Yuchong Xie, Libo Chen 0001, Yingming Zeng, Zhi Xue, Purui Su
ASE9
2023 One Simple API Can Cause Hundreds of Bugs An Analysis of Refcounting Bugs in All Modern Linux Kernels
abstract
Reference counting (refcounting) is widely used in Linux kernel. However, it requires manual operations on the related APIs. In practice, missing or improperly invoking these APIs has introduced too many bugs, known as refcounting bugs. To evaluate the severity of these bugs in history and in future, this paper presents a comprehensive study on them.
Liang He 0011, Purui Su, Chao Zhang 0008, Yan Cai 0001, Jinxin Ma
SOSP2
2023 A Systematic Study of Android Non-SDK (Hidden) Service API Security
abstract
Android allows apps to communicate with its system services via system service helpers so that these apps can use various functions provided by the system services. Meanwhile, the system services rely on their service helpers to enforce security checks for protection. Unfortunately, the security checks in the service helpers may be bypassed via directly exploiting the non-SDK (hidden) APIs, degrading the stability and posing severe security threats such as privilege escalation, automatic function execution without users’ interactions, crashes, and DoS attacks. Google has proposed various approaches to address this problem, e.g., case-by-case fixing the bugs or even proposing a blacklist to block all the non-SDK APIs. However, the developers can still figure out new ways of exploiting these hidden APIs to evade the non-SDKs restrictions. In this article, we systematically study the vulnerabilities due to the hidden API exploitation and analyze the effectiveness of Google’s countermeasures. We aim to answer if there are still vulnerable hidden APIs that can be exploited in newest Android 12. We develop a static analysis tool called${{\sf ServiceAudit}}$to automatically mine the inconsistent security enforcement between service helper classes and the hidden service APIs. We apply${{\sf ServiceAudit}}$to Android 6$\sim$12. Our tool discovers 112 vulnerabilities in Android 6 with a higher precision than existing approaches. Moreover, in Android 11 and 12, we identify more than 25 hidden APIs with inconsistent protections; however, only one of the vulnerable APIs can lead to severe security problem in Android 11, and none of them work on Android 12.
Yi He 0020, Yacong Gu, Purui Su, Kun Sun 0001, Yajin Zhou, Zhi Wang 0004, Qi Li 0002
IEEE Trans. Dependable Secur. Comput.3
2022 DitDetector: Bimodal Learning based on Deceptive Image and Text for Macro Malware Detection
abstract
Macro malware has always been a severe threat to cyber security although the Microsoft Office suite applies the default macro-disabling policy. Among the defense solutions at different stages of the attack chain, document analysis is more targeted through detecting malicious documents with macro malware. It is effective, especially with machine learning methods, but still faces problems handling malware variants, supporting file formats, and attack countermeasures with advanced attack techniques (e.g., Excel 4.0 macro and remote template injection).
Jia Yan 0004, Xiangkun Jia, Lingyun Ying, Purui Su, Zhanyi Wang
ACSAC5
2022 HTFuzz: Heap Operation Sequence Sensitive Fuzzing
abstract
Heap-based temporal vulnerabilities (i.e., use-after-free, double-free and null pointer dereference) are highly sensitive to heap operation (e.g., memory allocation, deallocation and access) sequences. To efficiently find such vulnerabilities, traditional code coverage-guided fuzzing solutions could be promoted by integrating heap operation sequence feedback. But current sequence sensitive solutions have limitations in practice.
Yuanping Yu, Xiangkun Jia, Yuwei Liu 0001, Qian Sang, Chao Zhang 0008, Purui Su
ASE7
2022 COOPER: Testing the Binding Code of Scripting Languages with Cooperative Mutation
Hong Hu 0004, Purui Su
NDSS4
2022 Understanding and Mitigating Label Bias in Malware Classification: An Empirical Study
abstract
Machine learning techniques are promising for malware classification, but there is a neglected problem of label bias in the annotation process which decreases the performance in practice. To understand the label bias problems and existing solutions, we conduct an empirical study based on two Portable Executable (PE) malware sample datasets (i.e., open-sourced BODMAS with 52,793 samples and a new collected MAIN dataset of 153,811 samples), and 67 anti-virus engines in VirusTotal. We first show the two ways of label bias problems, including chaotic naming rules and annotation inconsistency. Then we present the effects of two solutions (i.e., electing one reputable AV engine and aggregating multiple labels based on majority voting) and find they face the problems of feature preference and engine independence. Finally, we propose some recommendations for improvements and get a 7.79% increase in the F1 score (i.e., from 84.83% to 92.62%). The dataset will be open-source for further study.
Jia Yan 0004, Xiangkun Jia, Lingyun Ying, Purui Su
QRS4
2022 FreeWill: Automatically Diagnosing Use-after-free Bugs via Reference Miscounting Detection on Binaries
Liang He 0011, Hong Hu 0004, Purui Su, Yan Cai 0001, Zhenkai Liang
USENIX Security Symposium3
2021 InstruGuard: Find and Fix Instrumentation Errors for Coverage-based Greybox Fuzzing
abstract
As one of the most successful methods at vulnerability discovery, coverage-based greybox fuzzing relies on the lightweight compile-time instrumentation to achieve the fine-grained coverage feedback of the target program. Researchers improve it by optimizing the coverage metrics without questioning the correctness of the instrumentation. However, instrumentation errors, including missed instrumentation locations and redundant instrumentation locations, harm the ability of fuzzers. According to our experiments, it is a common and severe problem in various coverage-based greybox fuzzers and at different compiler optimization levels.In this paper, we design and implement InstruGuard, an open-source and pragmatic platform to find and fix instrumentation errors. It detects instrumentation errors by static analysis on target binaries, and fixes them with a general solution based on binary rewriting. To study the impact of instrumentation errors and test our solutions, we built a dataset of 15 real-world programs and selected 6 representative fuzzers as targets. We used InstruGuard to check and repair the instrumented binaries with different fuzzers and different compiler optimization options. To evaluate the effectiveness of the repair, we ran the fuzzers with original instrumented programs and the repaired ones, and compared the fuzzing results from aspects of execution paths, line coverage, and real bug findings. The results showed that InstruGuard had corrected the instrumentation errors of different fuzzers and helped to find more bugs in the dataset. Moreover, we discovered one new zero-day vulnerability missed by other fuzzers with fixed instrumentation but without any changes to the fuzzers.
Yuwei Liu 0001, Purui Su, Yuanping Yu, Xiangkun Jia
ASE3
2020 Not All Coverage Measurements Are Equal: Fuzzing by Coverage Accounting for Input Prioritization
Xiangkun Jia, Yuwei Liu 0001, Kyle Zeng, Tiffany Bao, Dinghao Wu, Purui Su
NDSS7
2020 Resource Race Attacks on Android
abstract
Smartphones are frequently involved in accessing private user data. Although many studies have been done to prevent malicious apps from leaking private user data, only a few recent works examine how to remove the sensitive information from the data collected by smartphone hardware resources (e.g., camera). Unfortunately, none of them investigates whether a malicious app can obtain such sensitive information when (or right before/after) a legitimate app collects such data (e.g., taking photos). To fill in the gap, in this paper, we model such attacks as the Resource Race Attack (RRAttack) based on races between two apps during their requests to exclusive resources to access sensitive information. RRAttacks have three categories according to when a race on requesting resources occurs: Pre-Use, In-Use, and Post-Use attacks. We further conduct the first systematic study on the feasibility of launching the RRAttacks on two heavily used exclusive Android resources: camera and touchscreen. In details, we perform Proof-of-Concept (PoC) attacks to reveal that, (a) camera is highly vulnerable to both In-Use and Post-Use attacks; and (b) touchscreen is vulnerable to Pre-Use attacks. Particularly, we demonstrate successful RRAttacks on them to steal private information, to cause financial loss, and to steal user passwords from Android 6 to the latest Android Q. Moreover, our analyses on 1,000 apps indicate that most of them are vulnerable to one to three RRAttacks. Finally, we propose a set of defense strategies against RRAttacks for user apps, system apps, and Android system itself.
Yan Cai 0001, Yutian Tang, Haicheng Li, Le Yu 0002, Hao Zhou 0043, Xiapu Luo, Liang He 0011, Purui Su
SANER8
2020 Visual Analysis of Collective Anomalies Using Faceted High-Order Correlation Graphs
abstract
Successfully detecting, analyzing, and reasoning about collective anomalies is important for many real-life application domains (e.g., intrusion detection, fraud analysis, software security). The primary challenges to achieving this goal include the overwhelming number of low-risk events and their multimodal relationships, the diversity of collective anomalies by various data and anomaly types, and the difficulty in incorporating the domain knowledge of experts. In this paper, we propose the novel concept of the faceted High-Order Correlation Graph (HOCG). Compared with previous, low-order correlation graphs, HOCG achieves better user interactivity, computational scalability, and domain generality through synthesizing heterogeneous types of objects, their anomalies, and the multimodal relationships, all in a single graph. We design elaborate visual metaphors, interaction models, and the coordinated multiple view based interface to allow users to fully unleash the visual analytics power of the HOCG. We conduct case studies for three application domains and collect feedback from domain experts who apply our method to these scenarios. The results demonstrate the effectiveness of the HOCG in the overview of point anomalies, the detection of collective anomalies, and the reasoning process of root cause analyses.
Lei Shi 0002, Jun Tao 0002, Zhou Zhuang, Congcong Huang, Rulei Yu, Purui Su, Chaoli Wang 0001, Yang Chen 0001
IEEE Trans. Vis. Comput. Graph.8
2019 One Engine To Serve 'em All: Inferring Taint Rules Without Architectural Semantics
Zheng Leong Chua, Teodora Baluta, Prateek Saxena, Zhenkai Liang, Purui Su
NDSS6
2019 Detecting concurrency memory corruption vulnerabilities
abstract
Memory corruption vulnerabilities can occur in multithreaded executions, known as concurrency vulnerabilities in this paper. Due to non-deterministic multithreaded executions, they are extremely difficult to detect. Recently, researchers tried to apply data race detectors to detect concurrency vulnerabilities. Unfortunately, these detectors are ineffective on detecting concurrency vulnerabilities. For example, most (90%) of data races are benign. However, concurrency vulnerabilities are harmful and can usually be exploited to launch attacks. Techniques based on maximal causal model rely on constraints solvers to predict scheduling; they can miss concurrency vulnerabilities in practice. Our insight is, a concurrency vulnerability is more related to the orders of events that can be reversed in different executions, no matter whether the corresponding accesses can form data races. We then define exchangeable events to identify pairs of events such that their execution orders can be probably reversed in different executions. We further propose algorithms to detect three major kinds of concurrency vulnerabilities. To overcome potential imprecision of exchangeable events, we also adopt a validation to isolate real vulnerabilities. We implemented our algorithms as a tool ConVul and applied it on 10 known concurrency vulnerabilities and the MySQL database server. Compared with three widely-used race detectors and one detector based on maximal causal model, ConVul was significantly more effective by detecting 9 of 10 known vulnerabilities and 6 zero-day vulnerabilities on MySQL (four have been confirmed). However, other detectors only detected at most 3 out of the 16 known and zero-day vulnerabilities.
Yan Cai 0001, Biyun Zhu, Ruijie Meng, Hao Yun, Liang He 0011, Purui Su, Bin Liang 0002
ESEC/SIGSOFT FSE6
2019 Fuzzing Program Logic Deeply Hidden in Binary Program Stages
abstract
Fuzzing is an effective method to identify bugs and security vulnerabilities in software. One particular difficulty faced by fuzzing is how to effectively generate inputs to cover program paths, especially for programs with complex logic. We observe that complex programs are often composed of components, which is a natural result of software engineering principles. The components interface with each other using memory buffers, forming stages of processing in the program logic. Program logic in later stages is difficult to reach by fuzzers. In this paper, we develop a novel solution to fuzz such program logic, called STAGEFUZZER. It identifies the stages and memory interfaces from program binaries, and fuzzes later stages of the program effectively. In our evaluation with a suite of typical binaries, STAGEFUZZER correctly identifies the program structure and effectively increases the coverage of program logic compared to AFL fuzzer.
Zheng Leong Chua, Yuwei Liu 0001, Purui Su, Zhenkai Liang
SANER4
2018 Visual Analysis of Collective Anomalies Through High-Order Correlation Graph
abstract
Detecting, analyzing and reasoning collective anomalies is important for many real-life application domains such as facility monitoring, software analysis and security. The main challenges include the overwhelming number of low-risk events and their multifaceted relationships which form the collective anomaly, the diversity in various data and anomaly types, and the difficulty to incorporate domain knowledge in the anomaly analysis process. In this paper, we propose a novel concept of high-order correlation graph (HOCG). Compared with the previous correlation graph definition, HOCG achieves better user interactivity, computational scalability, and domain generality through synthesizing heterogeneous types of nodes, attributes, and multifaceted relationships in a single graph. We design elaborate visual metaphors, interaction models, and the coordinated multiple view based interface to allow users to fully unleash the visual analytics power over HOCG. We conduct case studies in two real-life application domains, i.e., facility monitoring and software analysis. The results demonstrate the effectiveness of HOCG in the overview of point anomalies, detection of collective anomalies, and reasoning process of root cause analysis.
Jun Tao 0002, Lei Shi 0002, Zhou Zhuang, Congcong Huang, Rulei Yu, Purui Su, Chaoli Wang 0001, Yang Chen 0001
PacificVis6
2018 LEMNA: Explaining Deep Learning based Security Applications
abstract
While deep learning has shown a great potential in various domains, the lack of transparency has limited its application in security or safety-critical areas. Existing research has attempted to develop explanation techniques to provide interpretable explanations for each classification decision. Unfortunately, current methods are optimized for non-security tasks ( e.g., image analysis). Their key assumptions are often violated in security applications, leading to a poor explanation fidelity. In this paper, we propose LEMNA, a high-fidelity explanation method dedicated for security applications. Given an input data sample, LEMNA generates a small set of interpretable features to explain how the input sample is classified. The core idea is to approximate a local area of the complex deep learning decision boundary using a simple interpretable model. The local interpretable model is specially designed to (1) handle feature dependency to better work with security applications ( e.g., binary code analysis); and (2) handle nonlinear local boundaries to boost explanation fidelity. We evaluate our system using two popular deep learning applications in security (a malware classifier, and a function start detector for binary reverse-engineering). Extensive evaluations show that LEMNA's explanation has a much higher fidelity level compared to existing methods. In addition, we demonstrate practical use cases of LEMNA to help machine learning developers to validate model behavior, troubleshoot classification errors, and automatically patch the errors of the target models.
Wenbo Guo 0002, Dongliang Mu, Jun Xu 0024, Purui Su, Gang Wang 0011, Xinyu Xing 0001
CCS4
2018 A Comprehensive Study of Permission Usage on Android
Yemian Lu, Qi Li 0002, Purui Su, Juan Pan, Jia Yan 0004, Pengyi Zhan
NSS3
2017 JGRE: An Analysis of JNI Global Reference Exhaustion Vulnerabilities in Android
abstract
Android system applies a permission-based security model to restrict unauthorized apps from accessing system services, however, this security model cannot constrain authorized apps from sending excessive service requests to exhaust the limited system resource allocated for each system service. As references from native code to a Java object, JNI Global References (JGR) are prone to memory leaks, since they are not automatically garbage collected. Moreover, JGR exhaustion may lead to process abort or even Android system reboot when the victim process could not afford the JGR requests triggered by malicious apps through inter-process communication. In this paper, we perform a systematic study on JGR exhaustion (JGRE) attacks against all system services in Android. Our experimental results show that among the 104 system services in Android 6.0.1, 32 system services have 54 vulnerabilities. Particularly, 22 system services can be successfully attacked without any permission support. After reporting those vulnerabilities to Android security team and getting confirmed, we study the existing ad hoc countermeasures in Android against JGRE attacks. Surprisingly, among the 10 system services that have been protected, 8 system services are still vulnerable to JGRE attacks. Finally, we develop an effective defense mechanism to defeat all identified JGRE attacks by adopting Android's low memory killer (LMK) mechanism.
Yacong Gu, Kun Sun 0001, Purui Su, Qi Li 0002, Yemian Lu, Lingyun Ying, Dengguo Feng
DSN3
2017 RealDroid: Large-Scale Evasive Malware Detection on "Real Devices"
abstract
In order to effectively detect malware in Android, dynamic analysis techniques with Android emulators are widely adopted. Emulators can be deployed for large-scale malware detection and restored to an ensured clean state in a short period after each app analysis process such that dynamic analysis upon emulators can effectively detect malware. Moreover, emulators significantly reduce the detection cost compared to real devices. However, emulator-based analysis has limited capability in detecting evasive malware that can detect the presence of the emulator-based environment and hide its malicious behaviors. In this paper, we propose RealDroid, a dynamic and emulator-based analysis system that can capture Android evasive malware and is capable of large-scale malware detection. RealDroid completely simulates a real device such that it can't be identified by evasive malware. Thereby, evasive malware can exhibit its malicious behaviors in RealDroid. Moreover, we propose an automated exploration mechanism, i.e., Android Test Engine (ATE), to improve the code coverage of dynamic analysis in RealDroid, such that it provides efficient and effective automatic detection of large-scale apps. Our experimental results demonstrate that ATE in RealDroid achieves much better exploration effects compared with state-of-the-art automatic exploration tools in large-scale malware detection. In particular, it can successfully detect evasive malware.
Yacong Gu, Qi Li 0002, Purui Su
ICCCN4
2017 Automatically assessing crashes from heap overflows
abstract
Heap overflow is one of the most widely exploited vulnerabilities, with a large number of heap overflow instances reported every year. It is important to decide whether a crash caused by heap overflow can be turned into an exploit. Efficient and effective assessment of exploitability of crashes facilitates to identify severe vulnerabilities and thus prioritize resources. In this paper, we propose the first metrics to assess heap overflow crashes based on both the attack aspect and the feasibility aspect. We further present HCSIFTER, a novel solution to automatically assess the exploitability of heap overflow instances under our metrics. Given a heap-based crash, HCSIFTER accurately detects heap overflows through dynamic execution without any source code or debugging information. Then it uses several novel methods to extract program execution information needed to quantify the severity of the heap overflow using our metrics. We have implemented a prototype HCSIFTER and applied it to assess nine programs with heap overflow vulnerabilities. HCSIFTER successfully reports that five heap overflow vulnerabilities are highly exploitable and two overflow vulnerabilities are unlikely exploitable. It also gave quantitatively assessments for other two programs. On average, it only takes about two minutes to assess one heap overflow crash. The evaluation result demonstrates both effectiveness and efficiency of HC Sifter.
Liang He 0011, Yan Cai 0001, Hong Hu 0004, Purui Su, Zhenkai Liang, Yi Yang 0040, Huafeng Huang, Jia Yan 0004, Xiangkun Jia, Dengguo Feng
ASE4
2017 Towards Efficient Heap Overflow Discovery
Xiangkun Jia, Chao Zhang 0008, Purui Su, Yi Yang 0040, Huafeng Huang, Dengguo Feng
USENIX Security Symposium3
2017 Capability-Based Security Enforcement in Named Data Networking
abstract
Named data networking (NDN) enhances traditional IP networking by supporting in-network content caching for better bandwidth usage and location-independent data accesses for multi-path forwarding. However, NDN also brings new security challenges. For example, an adversary can arbitrarily inject packets to NDN to poison content cache, or access content packets without any restrictions. We propose capability-based security enforcement architecture (CSEA), a capability-based security enforcement architecture that enables data authenticity in NDN in a distributed manner. CSEA leverages capabilities to specify the access rights of forwarded packets. It allows NDN routers to verify the authenticity of forwarded packets, and throttles flooding-based DoS attacks from unsolicited packets. We further develop a lightweight one-time signature scheme for CSEA to ensure the timeliness of packets and support efficient verification. We prototype CSEA on the open-source CCNx platform, and evaluate CSEA via testbed and Planetlab experiments. Our experimental results show that CSEA only incurs around 4% of additional delays in retrieving data packets.
Qi Li 0002, Patrick P. C. Lee, Peng Zhang 0011, Purui Su, Liang He 0011, Kui Ren 0001
IEEE/ACM Trans. Netw.4
2016 Attacks and Defence on Android Free Floating Windows
abstract
Nowadays, the popular Android is so closely involved in people's daily lives that people rely on Android to perform critical operations and trust Android with sensitive information. It is of great importance to guarantee the usability and security of Android which, however, is such a huge system that a potential threat may arise from any part of it. In this paper, we focus on the Free Floating window (FF window) which is a category of windows that can appear freely above any other applications. It can share the screen space with other FF windows, dialogs, and activities. An FF window is flexible in both its appearance and behaviour features. We analyse the behaviour features of FF windows, including the priority in display layer and the capability of processing user-generated events. Three types of attacks via FF windows with delicate design in their appearance and behaviour features are demonstrated, i.e., DoS attack against Android system, GUI hijacking by targeting overlap, and input inference using FF windows as a side channel. To address the threat caused by FF windows, we design a priority framework for FF windows, which protects a sensitive activity/FF window declared by developers from being attacked by any malicious FF windows. A complementary solution is proposed to mitigate the confusion attack from malicious activities. Finally, we provide Android with suggestions on how to manage FF windows.
Lingyun Ying, Yemian Lu, Yacong Gu, Purui Su, Dengguo Feng
AsiaCCS5
2016 Exploiting Android System Services Through Bypassing Service Helpers
Yacong Gu, Lingyun Ying, Yemian Lu, Qi Li 0002, Purui Su
SecureComm6
2015 Binary Code Continent: Finer-Grained Control Flow Integrity for Stripped Binaries
abstract
Control Flow Integrity (CFI) is an effective technique to mitigate threats such as code-injection and code-reuse attacks in programs by protecting indirect transfers. For stripped binaries, a CFI policy has to be made conservatively due to the lack of source code level semantics. Existing binary-only CFI solutions such as BinCFI and CCFIR demonstrate the ability to protect stripped binaries, but the policies they apply are too permissive, allowing sophisticated code-reuse attacks. In this paper, we propose a new binary-only CFI protection scheme called BinCC, which applies static binary rewriting to provide finer-grained protection for x86 stripped ELF binaries. Through code duplication and static analysis, we divide the binary code into several mutually exclusive code continents. We further classify each indirect transfer within a code continent as either an Intra-Continent transfer or an Inter-Continent transfer, and apply separate, strict CFI polices to constrain these transfers. To evaluate BinCC, we introduce new metrics to estimate the average amount of legitimate targets of each kind of indirect transfer as well as the difficulty to leverage call preceded gadgets to generate ROP exploits. Compared to the state of the art binary-only CFI, BinCFI, the experimental results show that BinCC significantly reduces the legitimate transfer targets by 81.34% and increases the difficulty for adversaries to bypass CFI restriction to launch sophisticated ROP attacks. Also, BinCC achieves a reasonable performance, around 14% of the space overhead decrease and only 4% runtime overhead increase as compared to BinCFI.
Heng Yin 0001, Abhishek Vasisht Bhaskar, Purui Su, Dengguo Feng
ACSAC4
2015 A Rapid and Scalable Method for Android Application Repackaging Detection
Sibei Jiao, Lingyun Ying, Purui Su, Dengguo Feng
ISPEC4
2015 Xede: Practical Exploit Early Detection
Meining Nie, Purui Su, Qi Li 0002, Zhi Wang 0004, Lingyun Ying, Dengguo Feng
RAID2
2015 Invalidating Idealized BGP Security Proposals and Countermeasures
abstract
Border Gateway Protocol (BGP) is vulnerable to routing attacks because of the lack of inherent verification mechanism. Several secure BGP schemes have been proposed to prevent routing attacks by leveraging cryptographic verification of BGP routing updates. In this paper, we present a new type of attacks, called TIGER, which aims to invalidate the “proven” security of these secure BGP schemes and allow ASes to announce forged routes even under full deployment of any existing secure BGP proposal. By launching TIGER attacks, malicious ASes can easily generate and announce forged routes which can be successfully verified by the existing secure BGP schemes. Furthermore, TIGER attacks can evade existing routing anomaly detection schemes by guaranteeing routing data-plane availability and consistency of control- and data-plane. Toward a new securing BGP scheme, we propose Anti-TIGER to detect and defend against TIGER attacks. Anti-TIGER enables robust TIGER detection by collaborations between ASes. In particular, we leverage Spread Spectrum Communication technique to watermark certain special probing packets, which manifest the existence of TIGER attacks. Anti-TIGER does not require any modifications in routing data-plane, therefore it is easy to deploy and incrementally deployable. We evaluate the effectiveness of TIGER and Anti-TIGER by experiments with real AS topologies of the Internet. Our experiment results show that TIGER attacks can successfully hijack a considerable number of prefixes. In the meanwhile, Anti-TIGER can achieve 100 percent detection ratio of TIGER attacks.
Qi Li 0002, Xinwen Zhang, Purui Su
IEEE Trans. Dependable Secur. Comput.4
2014 Revisiting Node Injection of P2P Botnet
Jia Yan 0004, Lingyun Ying, Yi Yang 0040, Purui Su, Qi Li 0002, Dengguo Feng
NSS4
2014 Automated User Profiling in Location-Based Mobile Messaging Applications
abstract
Location-based messaging applications (LMAs), a kind of messaging applications for mobile devices which enable users to connect with people based on their geographical locations, have recently experienced a huge popularity growth. The killer feature in LMAs that embodies the concept of geo-based instant messaging, named people nearby, allows users at any place to search and communicate with other registered users nearby. In this paper, we discuss a common weakness in LMAs that relates to the abuse of the people nearby function. In this case, rich personal data of registered LMA users can be easily obtained, bringing a chance to perform automated user profiling in LMAs. Specifically, we build an automated and scalable system to construct extended profiles (or we call life profile) of LMA users, which contain not only personal information of LMA users but also the daily activities and social ties inferred from their leaked spatio-temporal privacy. The system is highly adaptable to various applications, requiring no modification of applications or trivial work on protocol reverse engineering. We conduct the evaluation on a large scale for the first time. In our experiment, we succeed to construct life profiles for more than 280,000 users from two popular LMAs. The results of empirical analysis not only validate the existence of the privacy issue in LMAs, but also demonstrate its severity.
Chang Xu 0003, Yi Yang 0040, Lingyun Ying, Purui Su, Dengguo Feng
TrustCom5
2014 Long Term Tracking and Characterization of P2P Botnet
abstract
P2P Botnet is quite robust against various attacks once very effective against centralized network. In this paper, we concentrate on the tracking of P2P botnets, investigate botnet victims which are routable on the Internet, also known as super peers. The super peers are the backbone of the botnet to disseminate its commands and payload updates. Through tracking of three typical live P2P botnets over 6 months and analysis of their network dynamics, we outline a number of descriptive and statistical characterization of super peers, such as geo-location, peer session time and intersession time, in-degree and out-degree distribution, pattern of arrival and departure. In addition, based on the assumption that IP dynamic allocation will not cross the AS (Autonomous System) border, we give out a lower bound estimate of total infected super peers in a conservative manner. We also propose several guidelines on disrupting P2P botnets concerning its various features we have characterized which could be helpful to the security community.
Jia Yan 0004, Lingyun Ying, Yi Yang 0040, Purui Su, Dengguo Feng
TrustCom4
2013 Bind your phone number with caution: automated user profiling through address book matching on smartphone
abstract
Due to the cost-efficient communicating manner and attractive user experience, messenger applications have dominated every smartphone in recent years. Nowadays, Address Book Matching, a new feature that helps people keep in touch with real world contacts, has been loaded in many popular messenger applications, which unfortunately as well brings severe privacy issues to users. In this paper, we propose a novel method to abuse such feature to automatically collect user profiles. This method can be applied to any application equipped with Address Book Matching independent of mobile platforms. We also build a prototype on Android to verify the effectiveness of our method. Moreover, we integrate profiles gathered from different messenger applications and provide insights by performing a consistency and authenticity analysis on user profile fields. As our experiments show, the abuse of Address Book Matching can cause severe user privacy leakage. Finally, we provide some countermeasures for developers to avoid this issue when designing messenger applications.
Lingyun Ying, Sibei Jiao, Purui Su, Dengguo Feng
AsiaCCS4
2013 OSNGuard: Detecting Worms with User Interaction Traces in Online Social Networks
Liang He 0011, Dengguo Feng, Purui Su, Lingyun Ying, Yi Yang 0040, Huafeng Huang, Huipeng Fang
ICICS3
2013 VCCBox: Practical Confinement of Untrusted Software in Virtual Cloud Computing
Meining Nie, Purui Su, Dengguo Feng
SecureComm3
2013 Automatic Polymorphic Exploit Generation for Software Vulnerabilities
Purui Su, Qi Li 0002, Lingyun Ying, Yi Yang 0040, Dengguo Feng
SecureComm2
2012 Black-box testing based on colorful taint analysis
Kai Chen 0012, Dengguo Feng, Purui Su
Sci. China Inf. Sci.3
2010 DepSim: A Dependency-Based Malware Similarity Comparison System
Yi Yang 0040, Lingyun Ying, Rui Wang 0032, Purui Su, Dengguo Feng
Inscrypt4
2010 CloudSEC: A Cloud Architecture for Composing Collaborative Security Services
abstract
Massive Internet invasions implemented through the distributed platform fabricated by rapid diffusion of malwares, has become a significant issue in network security. We argue that the notion of “Collaborative Security” is an emerging trend in resisting distributed attacks originated from malware. Therefore, this paper proposes a new architecture: CloudSEC, for composing collaborative security-related services in clouds, such as correlated intrusion analysis, anti-spam, anti-DDOS, automated malware detection and containment. CloudSEC is modeled as a dynamic peer-to-peer overlay hierarchy with three types of top-down architectural components. Based on, this architecture, both data distribution and task scheduling overlays can be simultaneously implemented in a loosely coupled fashion, which can efficiently retrieve data resources from heterogeneous network security facilities, and harness distributed collection of computational resources to process data-intensive tasks. Hence, CloudSEC endues the network security infrastructure with the capability of dynamic adaptation and collaboration on an inter-organizational scale. The results of preliminary evaluation demonstrate that, CloudSEC not only delivers a sample service of distributed intrusion correlation with high scalability and robustness, but also achieves remarkable effectiveness in data sharing and task scheduling.
Purui Su, Dengguo Feng
CloudCom4
2009 Reconstructing a Packed DLL Binary for Static Analysis
Xianggen Wang, Dengguo Feng, Purui Su
ISPEC3