EDBT 2026 Demo / reviewers in the wild / expert
Jianwei Hou
dblp:49/8706
· DBLP profile ↗
9ranked-venue papers
4as first author
4since 2021 · last 2026
0000-0001-5503-8143ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 2 since 2021Computer networks · 2 · 2 first-authorSoftware engineering, systems software and programming languages · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | TEP-BS: Public opinion evolution prediction based on stochastic competitive learning-taking the hot case of platform X in september 2024 as an example
Yijun Gu, Jianwei Hou, Shunshun Fu |
Neural Networks | 3 |
| 2023 | Scaling JavaScript Abstract Interpretation to Detect and Exploit Node.js Taint-style VulnerabilityabstractTaint-style vulnerabilities, such as OS command injection and path traversal, are common and severe software weaknesses. There exists an inherent trade-off between analysis scalability and accuracy in detecting such vulnerabilities. On one hand, existing syntax-directed approaches often make compromises in the analysis accuracy on dynamic features like bracket syntax. On the other hand, existing abstract interpretation often faces the issue of state explosion in the abstract domain, thus leading to a scalability problem.In this paper, we present a novel approach, called FAST, to scale the vulnerability discovery of JavaScript packages via a novel abstract interpretation approach that relies on two new techniques, called bottom-up and top-down abstract interpretation. The former abstractly interprets functions based on scopes instead of call sequences to construct dynamic call edges. Then, the latter follows specific control-flow paths and prunes the program to skip statements unrelated to the sink. If an end-to-end data-flow path is found, FAST queries the satisfiability of constraints along the path and verifies the exploitability to reduce human efforts.We implement a prototype of FAST and evaluate it against real-world Node.js packages. We show that FAST is able to find 242 zero-day vulnerabilities in NPM with 21 CVE identifiers being assigned. Our evaluation also shows that FAST can scale to real-world applications such as NodeBB and popular frameworks such as total.js and strapi in finding legacy vulnerabilities that no prior works can. Mingqing Kang, Yichao Xu, Song Li 0006, Rigel Gjomemo, Jianwei Hou, V. N. Venkatakrishnan, Yinzhi Cao |
SP | 5 |
| 2022 | Mining Node.js Vulnerabilities via Object Dependence Graph and Query
Song Li 0006, Mingqing Kang, Jianwei Hou, Yinzhi Cao |
USENIX Security Symposium | 3 |
| 2021 | Detecting Node.js prototype pollution vulnerabilities via object lookup analysisabstractPrototype pollution is a type of vulnerability specific to prototype-based languages, such as JavaScript, which allows an adversary to pollute a base object’s property, leading to a further consequence such as Denial of Service (DoS), arbitrary code execution, and session fixation. On one hand, the only prior work in detecting prototype pollution adopts dynamic analysis to fuzz package inputs, which inevitably has code coverage issues in triggering some deeply embedded vulnerabilities. On the other hand, it is challenging to apply state-of-the-art static analysis in detecting prototype pollution because of the involvement of prototype chains and fine-grained object relations including built-in ones. Song Li 0006, Mingqing Kang, Jianwei Hou, Yinzhi Cao |
ESEC/SIGSOFT FSE | 3 |
| 2020 | On the fine-grained fingerprinting threat to software-defined networks
Jianwei Hou, Minjian Zhang 0001, Wenchang Shi, Bin Liang 0002 |
Future Gener. Comput. Syst. | 1 |
| 2020 | A Survey on Digital Forensics in Internet of ThingsabstractInternet of Things (IoT) is increasingly permeating peoples' lives, gradually revolutionizing our way of life. Due to the tight connection between people and IoT, now civil and criminal investigations or internal probes must take IoT into account. From the forensic perspective, the IoT environment contains a rich set of artifacts that could benefit investigations, while the forensic investigation in IoT paradigm may have to alter to accommodate characteristics of IoT. Therefore, in this article, we analyze the impact of IoT on digital forensics and systematize the research efforts made by previous researchers from 2010 to 2018. We sketch the landscape of IoT forensics and examine the state of IoT forensics under a 3-D framework. The 3-D framework consists of a temporal dimension, a spatial dimension, and a technical dimension. The temporal dimension walks through the standard digital forensic process while the spatial dimension explores where to identify sources of evidence in IoT environment. These two dimensions attempt to provide principles and guidelines for standardizing digital investigations in the context of IoT. The technical dimension guides a way to the exploration of tools and techniques to ensure the enforcement of digital forensics in the ever-evolving IoT environment. Put together, we present a holistic overview of digital forensics in IoT. We also highlight open issues and outline promising suggestions to inspire future study. Jianwei Hou, Yuewei Li, Jingyang Yu, Wenchang Shi |
IEEE Internet Things J. | 1 |
| 2019 | DTGuard: A Lightweight Defence Mechanism Against a New DoS Attack on SDN
Jianwei Hou, Wenchang Shi, Bin Liang 0002 |
ICICS | 1 |
| 2019 | An Approach to Recommendation of Verbosity Log Levels Based on Logging IntentionabstractVerbosity levels of logs are designed to discriminate highly diverse runtime events, which facilitates system failure identification through simple keyword search (e.g., fatal, error). Verbosity levels should be properly assigned to logging statements, as inappropriate verbosity levels would confuse users and cause a lot of redundant maintenance effort. However, to achieve such a goal is not an easy task due to the lack of practical specifications and guidelines towards verbosity log level usages. The existing research has built a classification model on log related quantitative metrics such as log density to improve logging level practice. Though such quantitative metrics can reveal logging characteristics, their contributions on logging level decision are limited, since valuable logging intention information buried in logging code context can not be captured. In this paper, we propose an automatic approach to help developers determine the appropriate verbosity log levels. More specially, our approach discriminates different verbosity log level usages based on code context features that contain underlying logging intention. To validate our approach, we implement a prototype tool, VerbosityLevelDirector, and perform a case study to measure its effectiveness on four well-known open source software projects. Evaluation results show that VerbosityLevelDirector achieves high performance on verbosity level discrimination and outperforms the baseline approaches on all those projects. Furthermore, through applying noise handling technique, our approach can detect previously unknown inappropriate verbosity level configurations in the code repository. We have reported 21 representative logging level errors with modification advice to issue tracking platforms of the examined software projects and received positive feedback from their developers. The above results confirm that our work can help developers make a better logging level decision in real-world engineering. Han Anu, Wenchang Shi, Jianwei Hou, Bin Liang 0002 |
ICSME | 4 |
| 2019 | A survey on internet of things security from data perspectives
Jianwei Hou, Leilei Qu, Wenchang Shi |
Comput. Networks | 1 |