EDBT 2026 Demo / reviewers in the wild / expert
Debin Gao
dblp:60/206
· DBLP profile ↗
79ranked-venue papers
6as first author
24since 2021 · last 2026
0000-0001-9412-9961ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 65 · 6 first-author · 15 since 2021Software engineering, systems software and programming languages · 7 · 6 since 2021Systems, architecture and hardware · 4 · 1 since 2021Computer networks · 2Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AGChain: A Blockchain-based Gateway for Trustworthy App Delegation from Mobile App MarketsabstractThe popularity of smartphones has led to the growth of mobile app markets, creating a need for enhanced transparency, global access, and secure downloading. This article introduces AGChain, a blockchain-based gateway that enables trustworthy app delegation within existing markets. AGChain ensures that markets can continue providing services while users benefit from permanent, distributed, and secure app delegation. During its development, we address two key challenges: significantly reducing smart contract gas costs and enabling fully distributed IPFS-based file storage. Additionally, we tackle three system issues related to security and sustainability. We have implemented a prototype of AGChain on Ethereum and Polygon blockchains, achieving effective security and decentralization with a minimal gas cost of around 0.0028 USD per app upload (no cost for app download). AGChain also exhibits reasonable performance with an average overhead of 12%. Mengjie Chen, Xiao Yi, Daoyuan Wu, Jianliang Xu, Yingjiu Li, Debin Gao |
Distributed Ledger Technol. Res. Pract. | 6 |
| 2026 | Automated TEE Adaptation With LLMs: Identifying, Transforming, and Porting Sensitive Functions in Programs
Ruidong Han, Zhou Yang 0003, Chengyan Ma 0001, Ye Liu 0012, Yuqing Niu, Siqi Ma 0001, Debin Gao, David Lo 0001 |
IEEE Trans. Software Eng. | 7 |
| 2026 | Towards Secure Program Partitioning for Smart Contracts With LLM's In-Context LearningabstractSmart contracts are highly susceptible to manipulation attacks due to the leakage of sensitive information. Addressing manipulation vulnerabilities is particularly challenging because they stem from inherent data confidentiality issues rather than straightforward implementation bugs. To tackle this by preventing sensitive information leakage, we present PARTITIONGPT, the first LLM-driven approach that combines static analysis with the in-context learning capabilities of large language models (LLMs) to partition smart contracts into critical (privileged) and normal codebases, guided by a few annotated sensitive data variables. We evaluated PARTITIONGPT on 18 annotated smart contracts containing 99 sensitive functions. The results demonstrate that PARTITIONGPT successfully generatescompilable, andverifiedpartitions, achieving a precision of 80% while reducing more than 26% code compared to functionlevel partitioning approach. Furthermore, we evaluated PARTITIONGPT on nine real-world manipulation attacks that led to a total loss of 25 million dollars, PARTITIONGPT effectively prevents eight cases, highlighting its potential for broad applicability and the necessity for secure program partitioning during smart contract development to diminish manipulation vulnerabilities. Ye Liu 0012, Yuqing Niu, Chengyan Ma 0001, Ruidong Han, Wei Ma 0014, Yi Li 0008, Debin Gao, David Lo 0001 |
IEEE Trans. Software Eng. | 7 |
| 2025 | Density Boosts Everything: A One-stop Strategy for Improving Performance, Robustness, and Sustainability of Malware Detectors
Jianwen Tian, Debin Gao, Taotao Gu, Kefan Qiu, Zhi Wang 0014, Xiaohui Kuang |
NDSS | 3 |
| 2025 | CacheAlarm: Monitoring Sensitive Behaviors of Android Apps Using Cache Side ChannelabstractMalware attack has been a serious threat to the security and privacy of both individual and corporation users of the Android platform. Business entities seek to protect themselves by means of monitoring privacy-related sensitive behaviors conducted on company-issued Android devices. However, due to Android’s own access control and privacy protection policies, this is difficult to be done with third-party apps using only normal privileges. Existing works proposed using side-channel readings from leaky APIs and system virtual files to speculate runtime app behaviors, which could be unreliable due to future system updates (that ban exploited resources), hardware jittering, etc. In this paper, we argue that a more traditional side-channel attack strategy, namely the CPU-cache-based side channel, could be exploited in the benign scenario of app behavior surveillance. Specifically, we propose CacheAlarm, a sensitive app behavior monitor and foreground app identification system, which works by measuring cache side-channel readings of selected methods within the Android framework, and conducted in-lab and in-the-wild user studies to compare the effectiveness of our scheme against SideNet, a previous Android app behavior surveillance scheme using API-based side channels. Results of the studies suggested that CacheAlarm outperforms SideNet on the accuracy of detecting sensitive behaviors in addition to gaining the capability of detecting apps running at foreground of the user device. Jianwen Tian, Debin Gao, Xiaohui Kuang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | MtdScout: Complementing the Identification of Insecure Methods in Android Apps via Source-to-Bytecode Signature Generation and Tree-based Layered SearchabstractModern Android apps consist of both host app code and third-party libraries. Traditional static analysis tools conduct taint analysis for API misuses on the entire app code, while third-party library (TPL) detection tools focus solely on library code. Both approaches, however, are prone to some inherent false negatives: taint analysis tools may neglect third-party libraries or face timeouts/errors in whole app-based analysis, and TPL detection tools are not designed for pinpointing specific vulnerable methods. These challenges underscore the need for enhanced identification of insecure methods in Android apps, particularly for app markets addressing open-source security incidents. In this paper, we aim to complement the identification of missed false negatives in both TPL detection and taint analysis by directly identifying clones of insecure methods, regardless of whether they are in the host app code or a shrunk library. We propose MtdScout, a novel crosslayer, method-level clone detection tool for Android apps. MtdScout generates bytecode signatures for flawed source methods using compiler-style interpretation and abstraction, and efficiently matches them with target app bytecode using signature-mapped search trees. Our experiment using ground-truth apps shows that MtdScout achieves the highest accuracy among three tested clone detection tools, with a precision of 92.5% and recall of 87.2%. A large-scale experiment with 23.9K apps from Google Play demonstrates MtdScout's effectiveness in complementing both LibScout and CryptoGuard by identifying numerous false negatives they missed due to app shrinking, method-only cloning, and inherent timeouts and failures in expensive taint analysis. Additionally, our experiment uncovers four security findings that highlight the disparities between MtdScout's methodlevel clone detection and package-level library detection. Daoyuan Wu, Debin Gao, Xiao Yi, Lingxiao Jiang |
EuroS&P | 4 |
| 2024 | MiniMon: Minimizing Android Applications with Intelligent Monitoring-Based DebloatingabstractThe size of Android applications is getting larger to fulfill the requirements of various users. However, not all the features of the applications are needed and desired by a specific user. The unnecessary and non-desired features can increase the attack surface and consume system resources such as storage and memory. To address this issue, we propose a framework, MiniMon, to debloat unnecessary features from an Android app based on the logs of specific users' interactions with the app. Xing Hu 0008, Ferdian Thung, Shahar Maoz, Debin Gao, Eran Toch, David Lo 0001 |
ICSE | 6 |
| 2024 | Custom Permission Misconfigurations in Android: A Large-Scale Security AnalysisabstractAndroid’s popularity is due to its openness and vast app ecosystem. Global developers can use Android Studio and rich Android APIs to create their apps. Within this ecosystem, Android permissions play a crucial role in managing access to resources, with system permissions controlled by system apps and custom permissions declared by third-party apps. However, the security of custom permissions has not received enough attention from the mobile security community, resulting in a lack of thorough evaluation of security practices for app developers using custom permissions. This study systematically evaluated the misconfiguration of custom permissions by Android app developers. It is based on ten configuration guidelines derived from the Android development documentation, OS source code, and related research papers to ensure proper functioning and adherence to best security practices of custom permissions. The study established the corresponding violation rules and built a dataset containing 174,740 APK files for large-scale measurement and analysis of guideline violations. The measurement results indicate that misconfiguration of custom permissions by Android app developers is quite common, with approximately 29.02% of the 92,461 apps involving custom permissions having configuration guideline violations. The two most common errors in custom permission configuration are 1) putting custom permissions into a defective custom group and 2) protecting components with undeclared custom permissions. Such misconfigurations can lead to various issues, including private app data leaks, app installation failures, or incomplete implementation of app functions. Rui Li 0102, Wenrui Diao, Debin Gao |
TrustCom | 3 |
| 2024 | Peep With A Mirror: Breaking The Integrity of Android App Sandboxing via Unprivileged Cache Side Channel
Yan Lin 0003, Joshua Wong, Debin Gao |
USENIX Security Symposium | 5 |
| 2024 | Analyzing and revivifying function signature inference using deep learning
Yan Lin 0003, Trisha Singhal, Debin Gao, David Lo 0001 |
Empir. Softw. Eng. | 3 |
| 2023 | BinAlign: Alignment Padding Based Compiler Provenance Recovery
Maliha Ismail, Yan Lin 0003, DongGyun Han, Debin Gao |
ACISP | 4 |
| 2023 | TypeSqueezer: When Static Recovery of Function Signatures for Binary Executables Meets Dynamic AnalysisabstractControl-Flow Integrity (CFI) is considered a promising solution in thwarting advanced code-reuse attacks. While the problem of backward-edge protection in CFI is nearly closed, effective forward-edge protection is still a major challenge. The keystone of protecting the forward edge is to resolve indirect call targets, which although can be done quite accurately using type-based solutions given the program source code, it faces difficulties when carried out at the binary level. Since the actual type information is unavailable in COTS binaries, type-based indirect call target matching typically resorts to approximate function signatures inferred using the arity and argument width of indirect callsites and calltargets. Doing so with static analysis, therefore, forces the existing solutions to assume the arity/width boundaries in a too-permissive way to defeat sophisticated attacks. Jinku Li, Debin Gao, Jianfeng Ma 0001 |
CCS | 5 |
| 2023 | AutoDebloater: Automated Android App DebloatingabstractAndroid applications are getting bigger with an increasing number of features. However, not all the features are needed by a specific user. The unnecessary features can increase the attack surface and cost additional resources (e.g., storage and memory). Therefore, it is important to remove unnecessary features from Android applications. However, it is difficult for the end users to fully explore the apps to identify the unnecessary features, and there is no off-the-shelf tool available to assist users to debloat the apps by themselves. In this work, we propose AutoDebloater to debloat Android applications automatically for end users. AutoDebloater is a web application that can be accessed by end-users through a web browser. In particular, AutoDebloater can automatically explore an app and identify the transitions between activities. Then, AutoDebloater will present the Activity Transition Graph to users and ask them to select the activities they do not want to keep. Finally, AutoDebloater will remove the activities that are selected by users from the app. We conducted a user study on five Android apps downloaded from three categories (i.e., Finance, Tools, and Navigation) in Google Play and F-Droid. The results show that users are satisfied with AutoDebloater in terms of the stability of the debloated apps and the ability of AutoDebloater to identify features that are never noticed before. The tool is available at http://autodebloater.club. The code is available at https://github.com/jiakun-liu/autodebloater/ and the demonstration video can be found at https://youtu.be/Gmz0-p2n9D4. Xing Hu 0008, Ferdian Thung, Shahar Maoz, Eran Toch, Debin Gao, David Lo 0001 |
ASE | 6 |
| 2023 | Sparsity Brings Vulnerabilities: Exploring New Metrics in Backdoor Attacks
Jianwen Tian, Kefan Qiu, Debin Gao, Zhi Wang 0014, Xiaohui Kuang |
USENIX Security Symposium | 3 |
| 2022 | ReSIL: Revivifying Function Signature Inference using Deep Learning with Domain-Specific KnowledgeabstractFunction signature recovery is important for binary analysis and security enhancement, such as bug finding and control-flow integrity enforcement. However, binary executables typically have crucial information vital for function signature recovery stripped off during compilation. To make things worse, recent studies show that many compiler optimization strategies further complicate the recovery of function signatures with intended violations to function calling conventions. Yan Lin 0003, Debin Gao, David Lo 0001 |
CODASPY | 2 |
| 2022 | Chosen-Instruction Attack Against Commercial Code Virtualization Obfuscators
Shijia Li, Chunfu Jia, Pengda Qiu, Qiyuan Chen 0006, Jiang Ming 0002, Debin Gao |
NDSS | 6 |
| 2022 | Secure Repackage-Proofing Framework for Android Apps Using Collatz ConjectureabstractApp repackaging has been raising serious concerns about the health of the Android ecosystem, and repackage-proofing is an important mitigation against threat of such attacks. However, existing app repackage-proofing schemes were only evaluated against trivial adversaries simulated using analyzers for other purposes (e.g., disclosing privacy leakage vulnerabilities), hence were shown “effective” mainly because their key programming features were not even supported by those toolkits. Furthermore, existing works have also neglected dynamic adversaries capable of manipulating victim apps at runtime, making them vulnerable against such stronger opponents. In this article, we propose a novel repackage-proofing framework, which deploys distributed detection and response sites into the subject app's native partition to cross-verify all its code files. The detection sites transmit obtained integrity metrics to response sites via secure communication channels built on the subject app's own control flows using a specialized obfuscation technique based on Collatz conjecture, turning the repackage-proofing process into complicated implicit flows that are intrinsically difficult to be resolved due to the conjecture's nonlinear dynamical behaviors. We evaluated our framework using sophisticated Android data-flow analyzers. Results showed that our prototype effectively impeded analyses aiming to trace the information flows of its cross-verification. Shijia Li, Debin Gao, Chunfu Jia |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | Active Warden Attack: On the (In)Effectiveness of Android App Repackage-ProofingabstractApp repackaging has raised serious concerns to the Android ecosystem with the repackage-proofing technology attracting attention in the Android research community. In this article, we first show that existing repackage-proofing schemes rely on a flawed security assumption, and then propose a new class ofactive warden attackthat intercepts and falsifies the metrics used by repackage-proofing for detecting the integrity violations during repackaging. We develop a proof-of-concept toolkit to demonstrate that all the existing repackage-proofing schemes can be bypassed by our attack toolkit. On the positive side, our analysis further identifies a new integrity metric in the Android ART runtime that can robustly and efficiently indicate bytecode tampering caused by either repackaging or active warden attacks. By associating this new metric with two supplemental verification mechanisms, we construct a multi-party verification framework that significantly raises the bar of repackage-proofing and identify conditions under which the proposed framework could detect app repackaging without getting compromised by active warden attacks. Shijia Li, Debin Gao, Daoyuan Wu, Qiaowen Jia, Chunfu Jia |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | On the Effectiveness of Using Graphics Interrupt as a Side Channel for User Behavior SnoopingabstractGraphics Processing Units (GPUs) are now a key component of many devices and systems, including those in the cloud and data centers, thus are also subject to side-channel attacks. Existing side-channel attacks on GPUs typically leak information from graphics libraries like OpenGL and CUDA, which require creating contentions within the GPU resource space and are being mitigated with software patches. This article evaluates potential side channels exposed at a lower-level interface between GPUs and CPUs, namely the graphics interrupts. These signals could indicate unique signatures of GPU workload, allowing a spy process to infer the behavior of other processes. We demonstrate the practicality and generality of such side-channel exploitation with a variety of assumed attack scenarios. Simulations on both Nvidia and Intel graphics adapters showed that our attack could achieve high accuracy, while in-depth studies were also presented to explore the low-level rationale behind such effectiveness. On top of that, we further propose a practical mitigation scheme which protects GPU workloads against the graphics-interrupt-based side-channel attack by piggybacking mask payloads on them to generate interfering graphics interrupt “noises”. Experiments show that our mitigation technique effectively prohibited spy processes from inferring user behaviors via analyzing runtime patterns of graphics interrupt with only trivial overhead. Jianwen Tian, Debin Gao, Chunfu Jia |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | When Program Analysis Meets Bytecode Search: Targeted and Efficient Inter-procedural Analysis of Modern Android Apps in BackDroidabstractWidely-used Android static program analysis tools, e.g., Amandroid and FlowDroid, perform the whole-app inter-procedural analysis that is comprehensive but fundamentally difficult to handle modern (large) apps. The average app size has increased three to four times over five years. In this paper, we explore a new paradigm of targeted inter-procedural analysis that can skip irrelevant code and focus only on the flows of security-sensitive sink APIs. To this end, we propose a technique called on-the-fly bytecode search, which searches the disassembled app bytecode text just in time when a caller needs to be located. In this way, it guides targeted (and backward) inter-procedural analysis step by step until reaching entry points, without relying on a whole-app graph. Such search-based inter-procedural analysis, however, is challenging due to Java polymorphism, callbacks, asynchronous flows, static initializers, and inter-component communication in Android apps. We overcome these unique obstacles in our context by proposing a set of bytecode search mechanisms that utilize flexible searches and forward object taint analysis. Atop this new inter-procedural analysis, we further adjust the traditional backward slicing and forward constant propagation to provide the complete dataflow tracking of sink API calls. We have implemented a prototype called BackDroid and compared it with Amandroid in analyzing 3,178 modern popular apps for crypto and SSL misconfigurations. The evaluation shows that for such sink-based problems, BackDroid is 37 times faster (2.13v.s. 78.15 minutes) and has no timed-out failure (v.s. 35% in Amandroid) while maintaining close or even better detection effectiveness. Daoyuan Wu, Debin Gao, Robert H. Deng, Rocky K. C. Chang |
DSN | 2 |
| 2021 | An Exploratory Study of Social Support Systems to Help Older Adults in Managing Mobile SafetyabstractOlder adults face increased safety challenges, such as targeted online fraud and phishing, contributing to the growing technological divide between them and younger adults. Social support from family and friends is often the primary way older adults receive help, but it may also lead to reliance on others. We have conducted an exploratory study to investigate older adults' attitudes and experiences related to mobile social support technologies for mobile safety. We interviewed 18 older adults about their existing support experiences and used the think-aloud method to gather data about a prototype for providing social support during mobile safety challenges. Our findings point to the potential of mobile technology to increase older adults' ability to mitigate mobile safety challenges through active learning from close social connections. We discuss how to support technology can address helpers' intolerance and overcome the challenges of physical distance. Tamir Mendel, Debin Gao, David Lo 0001, Eran Toch |
MobileHCI | 2 |
| 2021 | When Function Signature Recovery Meets Compiler OptimizationabstractMatching indirect function callees and callers using function signatures recovered from binary executables (number of arguments and argument types) has been proposed to construct a more fine-grained control-flow graph (CFG) to help control-flow integrity (CFI) enforcement. However, various compiler optimizations may violate calling conventions and result in unmatched function signatures. In this paper, we present eight scenarios in which compiler optimizations impact function signature recovery, and report experimental results with 1,344 real-world applications of various optimization levels. Most interestingly, our experiments show that compiler optimizations have both positive and negative impacts on function signature recovery, e.g., its elimination of redundant instructions at callers makes counting of the number of arguments more accurate, while it hurts argument type matching as the compiler chooses the most efficient (but potentially different) types at callees and callers. To better deal with these compiler optimizations, we propose a set of improved policies and report our more accurate CFG models constructed from the 1,344 applications. We additionally compare our results recovered from binary executables with those extracted from program source and reveal scenarios where compiler optimization makes the task of accurate function signature recovery undecidable. Yan Lin 0003, Debin Gao |
SP | 2 |
| 2021 | Scalable online vetting of Android apps for measuring declared SDK versions and their consistency with API calls
Daoyuan Wu, Debin Gao, David Lo 0001 |
Empir. Softw. Eng. | 2 |
| 2021 | Deep-Learning-Based App Sensitive Behavior Surveillance for Android Powered Cyber-Physical SystemsabstractAndroid as an operating system is now increasingly being adopted in industrial information systems, especially with cyber-physical systems (CPS). This also puts Android devices onto the front line of handling security-related data and conducting sensitive behaviors, which could be misused by the increasing number of polymorphic and metamorphic malicious applications targeting the platform. The existence of such malware threats, therefore, call for more accurate identification and surveillance of sensitive Android app behaviors, which is essential to the security of CPS and Internet of Things (IoT) devices powered by Android. Nevertheless, achieving dynamic app behavior monitoring and identification on real CPS powered by Android is challenging because of restrictions from the security and privacy model of the platform. In this article, the authors investigate how the latest advances in deep learning could address this security problem with better accuracy. Specifically, a deep learning engine is proposed that detects sensitive app behaviors by classifying patterns of system-wide statistics, such as available storage space and transmitted packet volume, using a customized deep neural network based on existing models called Encoder and ResNet. Meanwhile, to handle resource limitations on typical CPS and IoT devices, sparse learning is adopted to reduce the amount of valid parameters in the trained neural network. Evaluations show that the proposed model outperforms a well-established group of baselines on time series classification in identifying sensitive app behaviors with background noise and the targeted behaviors potentially overlapping. Jianwen Tian, Kefan Qiu, David Lo 0001, Debin Gao, Daoyuan Wu, Chunfu Jia, Thar Baker |
IEEE Trans. Ind. Informatics | 5 |
| 2020 | Walls Have Ears: Eavesdropping User Behaviors via Graphics-Interrupt-Based Side Channel
Jianwen Tian, Debin Gao, Chunfu Jia |
ISC | 3 |
| 2019 | DynOpVm: VM-Based Software Obfuscation with Dynamic Opcode Mapping
Xiaoyang Cheng, Yan Lin 0003, Debin Gao, Chunfu Jia |
ACNS | 3 |
| 2019 | Control-Flow Carrying CodeabstractControl-Flow Integrity~(CFI) is an effective approach in mitigating control-flow hijacking attacks including code-reuse attacks. Most conventional CFI techniques use memory page protection mechanism, Data Execution Prevention~(DEP), as an underlying basis. For instance, CFI defenses use read-only address tables to avoid metadata corruption. However, this assumption has shown to be invalid with advanced attacking techniques, such as Data-Oriented Programming, data race, and Rowhammer attacks. In addition, there are scenarios in which DEP is unavailable, e.g., bare-metal systems and applications with dynamically generated code. We present the design and implementation of Control-Flow Carrying Code~(C^3), a new CFI enforcement without depending on DEP, which makes the CFI policies embedded safe from being overwritten by attackers. C3 embeds the Control-Flow Graph (CFG) and its enforcement into instructions of the program by encrypting each basic block with a key derived from the CFG. The "proof-carrying" code ensures that only valid control flow transfers can decrypt the corresponding instruction sequences, and that any unintended control flow transfers or overwritten code segment would cause program crash with high probability due to the wrong decryption key and the corresponding random code bytes obtained. We implement C3 on top of an instrumentation platform and apply it to many popular programs. Our security evaluation shows that C3 is capable of enforcing strong CFI policies and is able to defend against most control-flow hijacking attacks while suffering from moderate runtime overhead. Yan Lin 0003, Xiaoyang Cheng, Debin Gao |
AsiaCCS | 3 |
| 2019 | Towards Understanding Android System Vulnerabilities: Techniques and InsightsabstractAs a common platform for pervasive devices, Android has been targeted by numerous attacks that exploit vulnerabilities in its apps and the operating system. Compared to app vulnerabilities, system-level vulnerabilities in Android, however, were much less explored in the literature. In this paper, we perform the first systematic study of Android system vulnerabilities by comprehensively analyzing all 2,179 vulnerabilities on the Android Security Bulletin program over about three years since its initiation in August 2015. To this end, we propose an automatic analysis framework, upon a hierarchical database structure, to crawl, parse, clean, and analyze vulnerability reports and their publicly available patches. This framework includes (i) a lightweight technique to pinpoint the affected modules of given vulnerabilities; (ii) a robust method to study the complexity of patch code; and most importantly, (iii) a similarity-based algorithm to cluster patch code patterns. Our clustering algorithm first extracts patch code's essential changes that not only concisely reflect syntactic changes but also keep important semantics, and then leverages affinity propagation to automatically generate clusters based on their pairwise similarity. It allows us to obtain 16 vulnerability patterns, including six new ones not known in the literature, and we further analyze their characteristics via case studies. Besides identifying these useful patterns, we also find that 92% Android vulnerabilities are located in the low-level modules (mostly in native libraries and the kernel), whereas the framework layer causes only 5% vulnerabilities, and that half of the vulnerabilities can be fixed in fewer than 10 lines of code each, with 110 out of 1,158 cases requiring only one single line of code change. We further discuss the implications of all these results. Overall, we provide a clear overview and new insights about Android system vulnerabilities. Daoyuan Wu, Debin Gao, Eric K. T. Cheng, Yichen Cao, Jintao Jiang, Robert H. Deng |
AsiaCCS | 2 |
| 2019 | An empirical study of mobile network behavior and application performance in the wildabstractMonitoring mobile network performance is critical for optimizing the QoE of mobile apps. Until now, few studies have considered the actual network performance that mobile apps experience in a per-app or per-server granularity. In this paper, we analyze a two-year-long dataset collected by a crowdsourcing per-app measurement tool to gain new insights into mobile network behavior and application performance. We observe that only a small portion of WiFi networks can work in high-speed mode, and more than one-third of the observed ISPs still have not deployed 4G networks. For cellular networks, the DNS settings on smartphones can have a significant impact on mobile app network performance. Moreover, we notice that instant messaging (IM) and voice over IP (VoIP) services nowadays are not as performant as Web services, because the traffic using XMPP experiences longer latencies than HTTPS. We propose an automatic performance degradation detection and localization method for finding possible network problems in our huge, imbalanced and sparse dataset. Our evaluation and case studies show that our method is effective and the running time is acceptable. Weichao Li 0001, Daoyuan Wu, Bo Jin 0002, Rocky K. C. Chang, Debin Gao, Yi Wang 0004, Ricky K. P. Mok |
IWQoS | 6 |
| 2019 | Understanding Open Ports in Android Applications: Discovery, Diagnosis, and Security Assessment
Daoyuan Wu, Debin Gao, Rocky K. C. Chang, En He, Eric K. T. Cheng, Robert H. Deng |
NDSS | 2 |
| 2019 | SplitSecond: Flexible Privilege Separation of Android AppsabstractAndroid applications have been attractive targets to attackers due to the large number of users and the sensitive information they possess. After the success of the first step of an attack exploiting a software vulnerability, the consequential damage is primarily determined by the criticality and the amount of Android permissions that a victim application has. As a countermeasure, process separation techniques that isolate potentially vulnerable components - usually native libraries - from the critical data and permissions, have been proposed. However, existing techniques offer little flexibility in the separation, e.g., with all native code being placed into one process without considering its dependency with other (Java) components and the non-empty set of permissions needed. In this paper, we propose a flexible privilege separation system, named SplitSecond, that enables selective permission separation at the granularity of Java components and native methods. SplitSecond provides safety against the attacks by restricting permissions on a user selectable isolation unit. According to our case study and experimental evaluation on a real handset with SplitSecond adopted Android OS and 100 top-ranked Android applications, 59.59% of activities, 66.8% of native methods, and 47.49% of permissions on average are flexibly splittable by SplitSecond with moderate overhead. Jehyun Lee, Akshaya Venkateswara Raja, Debin Gao |
PST | 3 |
| 2018 | SCLib: A Practical and Lightweight Defense against Component Hijacking in Android ApplicationsabstractCross-app collaboration via inter-component communication is a fundamental mechanism on Android. Although it brings the benefits such as functionality reuse and data sharing, a threat called component hijacking is also introduced. By hijacking a vulnerable component in victim apps, an attack app can escalate its privilege for operations originally prohibited. Many prior studies have been performed to understand and mitigate this issue, but no defense is being deployed in the wild, largely due to the deployment difficulties and performance concerns. In this paper we present SCLib, a secure component library that performs in-app mandatory access control on behalf of app components. It does not require firmware modification or app repackaging as in previous works. The library-based nature also makes SCLib more accessible to app developers, and enables them produce secure components in the first place over fragmented Android devices. As a proof of concept, we design six mandatory policies and overcome unique implementation challenges to mitigate attacks originated from both system weaknesses and common developer mistakes. Our evaluation using ten high-profile open source apps shows that SCLib can protect their 35 risky components with negligible code footprint (less than 0.3% stub code) and nearly no slowdown to normal intra-app communication. The worst-case performance overhead is only about 5%. Daoyuan Wu, Debin Gao, Yingjiu Li, Robert H. Deng |
CODASPY | 3 |
| 2018 | Towards Mining Comprehensive Android SandboxesabstractAndroid is the most widely used mobile operating system with billions of users and devices. The popularity of Android apps have enticed malware writers to target them. Recently, Jamrozik et al. proposed an approach, named Boxmate, to mine sandboxes to protect Android users from malicious behaviors. In a nutshell, Boxmate analyzes the execution of an app, and collects a list of sensitive APIs that are invoked by that app in a monitoring phase. Then, it constructs a sandbox that can restrict accesses to sensitive APIs not called by the app. In such a way, malicious behaviors that are not observed in the monitoring phase - occurring, for example, due to malicious code injection during an attack - can be prevented. Nevertheless, Boxmate only focuses on a specific API type (i.e., sensitive APIs); it also ignores parameter values of many API methods and requested permissions during the execution of a target app. As a result, Boxmate is not able to detect malicious behaviors in many cases. In this work, we address the limitation of Jamrozik et al.'s work by considering input parameters of many different types of API methods for mining a more comprehensive sandbox. Given a benign app, we first extract a list of Android permissions that the app may request during its execution. Next, we leverage an automated test case generation tool, named Droidbot, to generate a rich set of GUI test cases for exploring behaviors of the app. During the execution of these test cases, we analyze the execution of four different types of API methods. Furthermore, we record input parameters to these API methods, and classify those into four different categories. We leverage the collected parameter values, and the list of requested permissions to create a sandbox that can protect users from malicious behaviors. Our experiments on 25 pairs of real benign and malicious apps show that our approach is more effective than the coarse-and fine-grained variants of Boxmate by 267.37% and 81.64% in terms of F-measure respectively. Tien-Duy B. Le, Lingfeng Bao, David Lo 0001, Debin Gao, Li Li 0029 |
ICECCS | 4 |
| 2018 | Towards Dynamically Monitoring Android Applications on Non-rooted Devices in the WildabstractDynamic analysis is an important technique to reveal sensitive behavior of Android apps. Current works require access to the code-level and system-level events (e.g., API calls and system calls) triggered by the running apps and consequently they can only be conducted on in-lab running environments (e.g., emulators and modified OS). The strict requirement of running environment hinders their deployment in scale and makes them vulnerable to anti-analysis techniques. Furthermore, current dynamic analysis of Android apps exploits input generators to invoke app behavior, which, however, cannot provide sufficient code coverage. Xiaoxiao Tang, Yan Lin 0003, Daoyuan Wu, Debin Gao |
WISEC | 4 |
| 2017 | SafeStack ^+ : Enhanced Dual Stack to Combat Data-Flow Hijacking
Yan Lin 0003, Xiaoxiao Tang, Debin Gao |
ACISP (2) | 3 |
| 2017 | On-Demand Time Blurring to Support Side-Channel Defense
Weijie Liu 0004, Debin Gao, Michael K. Reiter |
ESORICS (2) | 2 |
| 2017 | On Return Oriented Programming Threats in Android RuntimeabstractAndroid has taken a large share of operating systems for smart devices including smartphones, and has been an attractive target to the attackers. The arms race between attackers and defenders typically occurs on two front lines - the latest attacking technology and the latest updates to the operating system (including defense mechanisms deployed). In terms of attacking technology, Return-Oriented Programming (ROP) is one of the most sophisticated attack methods on Android devices. In terms of the operating system updates, Android Runtime (ART) was the latest and biggest change to the Android family. In this paper, we investigate the extent to which Android Runtime (ART) makes Return-Oriented Programming (ROP) attacks easier or more difficulty. In particular, we show that by updating system libraries and adopting Ahead-of-Time compiling instead of Justin- Time compiling in the ART architecture, a larger number and more diverse gadgets are disclosed to ROP attackers, which serve as direct ingredients to ROP attacks. We show that between three and six times more gadgets are found on the ART adopted versions of Android due to the new ART runtime. Moreover, in constrained situations where an attacker requires specific instructions and target registers, Android running ART provides up to 30% more conditional coverage than pre-ART Android does. We additionally demonstrate a sample ROP attack on post- ART Android that would not have been possible on pre-ART Android. Akshaya Venkateswara Raja, Jehyun Lee, Debin Gao |
PST | 3 |
| 2017 | MopEye: Opportunistic Monitoring of Per-app Mobile Network Performance
Daoyuan Wu, Rocky K. C. Chang, Weichao Li 0001, Eric K. T. Cheng, Debin Gao |
USENIX ATC | 5 |
| 2017 | Measuring the Declared SDK Versions and Their Consistency with API Calls in Android Apps
Daoyuan Wu, Jiayun Xu, David Lo 0001, Debin Gao |
WASA | 5 |
| 2016 | MobiPot: Understanding Mobile Telephony Threats with HoneycardsabstractOver the past decade, the number of mobile phones has increased dramatically, overtaking the world population in October 2014. In developing countries like India and China, mobile subscribers outnumber traditional landline users and account for over 90% of the active population. At the same time, convergence of telephony with the Internet with technologies like VoIP makes it possible to reach a large number of telephone users at a low or no cost via voice calls or SMS (short message service) messages. As a consequence, cybercriminals are abusing the telephony channel to launch attacks, e.g., scams that offer fraudulent services and voice-based phishing or vishing, that have previously relied on the Internet. In this paper, we introduce and deploy the first mobile phone honeypot called MobiPot that allow us to collect fraudulent calls and SMS messages. We implement multiple ways of advertising mobile numbers (honeycards) on MobiPot to investigate how fraudsters collect phone numbers that are targeted by them. During a period of over seven months, MobiPot collected over two thousand voice calls and SMS messages, and we confirmed that over half of them were unsolicited. We found that seeding honeycards enables us to discover attacks on the mobile phone numbers which were not known before. Marco Balduzzi, Payas Gupta, Lion Gu, Debin Gao, Mustaque Ahamad |
AsiaCCS | 4 |
| 2016 | Control Flow Integrity Enforcement with Dynamic Code Optimization
Yan Lin 0003, Xiaoxiao Tang, Debin Gao, Jianming Fu |
ISC | 3 |
| 2016 | A novel covert channel detection method in cloud based on XSRM and improved event association algorithmabstractCovert channel is a major threat to the information system security and commonly found in operating systems, especially in cloud computing environment. Owing to the characteristics in cloud computing environment such as resources sharing and logic boundaries, covert channels become more varied and difficult to find. Focusing on those problems, this paper presents a universal method for detecting covert channel automatically. To achieve a global detection, we leveraged a virtual machine event record mechanism in hypervisor to gather necessary metadata. Combining the shared resources matrix methodology with events association mechanism, we proposed a distinctive algorithm that can accurately locate and analyze malicious covert channels from the respect of behaviors. Compared with the popular statistical test methods focusing on the single covert channel, our method is capable of recognizing and detecting more covert channels in real time. Experimental results show that this method is not only able to detect multilevel and multiform covert channels in cloud environment effectively but also facilitates the implementation and deployment in practical scenarios without modifying the existing system. Copyright © 2016 John Wiley & Sons, Ltd. Lina Wang 0001, Weijie Liu 0004, Neeraj Kumar 0001, Debiao He, Cheng Tan 0006, Debin Gao |
Secur. Commun. Networks | 6 |
| 2016 | Integrated Software Fingerprinting via Neural-Network-Based Control Flow ObfuscationabstractDynamic software fingerprinting has been an important tool in fighting against software theft and pirating by embedding unique fingerprints into software copies. However, the existing work uses the methods from dynamic software watermarking as direct solutions, in which the secret marks are inside rather independent code modules attached to the software. This results in an intrinsic weakness against targeted collusive attacks, since differences among the software copies correspond directly to the fingerprint-related components. In this paper, we suggest a novel mode of the dynamic fingerprinting called integrated fingerprinting, of which the goal is to ensure all the fingerprinted software copies possess identical behaviors at semantic level. We then provide the first implementation of integrated fingerprinting called Neuroprint on top of a control flow obfuscator that replaces program's conditional structures with neural networks trained to simulate their branching behaviors. Leveraging the rich entropy in the outputs of these neural networks, Neuroprint embeds the software fingerprints, such that a one-time construction of the networks serves both the purposes of obfuscation and fingerprinting. Evaluations show that due to the incomprehensibility of neural networks, it is infeasible to de-obfuscate the software transformed by Neuroprint or attack the fingerprint using even the latest program analysis techniques. Revealing information regarding the hidden fingerprints via collusive attacks on Neuroprint is difficult as well. Finally, Neuroprint also demonstrates negligible runtime overhead. Xiaoxu Yu, Chunfu Jia, Debin Gao |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2015 | Software Watermarking using Return-Oriented ProgrammingabstractWe propose a novel dynamic software watermarking design based on Return-Oriented Programming (ROP). Our design formats watermarking code into well-crafted data arrangements that look like normal data but could be triggered to execute. Once triggered, the pre-constructed ROP execution will recover the hidden watermark message. The proposed ROP-based watermarking technique is more stealthy and resilient over existing techniques since the watermarking code is allocated dynamically into data region and therefore out of reach of attacks based on code analysis. Evaluations show that our design not only achieves satisfying stealth and resilience, but also causes significantly lower overhead to the watermarked program. Kangjie Lu, Xinjie Ma, Haining Zhang, Chunfu Jia, Debin Gao |
AsiaCCS | 6 |
| 2015 | Replica Placement for Availability in the Worst CaseabstractWe explore the problem of placing object replicas on nodes in a distributed system to maximize the number of objects that remain available when node failures occur. In our model, failing (the nodes hosting) a given threshold of replicas is sufficient to disable each object, and the adversary selects which nodes to fail to minimize the number of objects that remain available. We specifically explore placement strategies based on combinatorial structures called t-packings, provide a lower bound for the object availability they offer, show that these placements offer availability that is c-competitive with optimal, propose an efficient algorithm for computing combinations of t-packings that maximize their availability lower bound, and provide parameter selection strategies to concretely instantiate our schemes for different system sizes. We compare the availability offered by our approach to that of random replica placement, owing to the popularity of the latter approach in previous work. After quantifying the availability offered by random replica placement in our model, we show that our combinatorial strategy yields placements with better availability than random replica placement for many realistic parameter values. Peng Li 0059, Debin Gao, Michael K. Reiter |
ICDCS | 2 |
| 2014 | RopSteg: program steganography with return oriented programmingabstractMany software obfuscation techniques have been proposed to hide program instructions or logic and to make reverse engineering hard. In this paper, we introduce a new property in software obfuscation, namely program steganography, where certain instructions are "diffused" in others in such a way that they are non-existent until program execution. Program steganography does not raise suspicion in program analysis, and conforms to the W⊕X and mandatory code signing security mechanisms. We further implement RopSteg, a novel software obfuscation system, to provide (to a certain degree) program steganography using return-oriented programming. We apply RopSteg to eight Windows executables and evaluate the program steganography property in the corresponding obfuscated programs. Results show that RopSteg achieves program steganography with a small overhead in program size and execution time. RopSteg is the first attempt of driving return-oriented programming from the "dark side", i.e., using return-oriented programming in a non-attack application. We further discuss limitations of RopSteg in achieving program steganography. Kangjie Lu, Siyang Xiong, Debin Gao |
CODASPY | 3 |
| 2014 | Keystroke biometrics: the user perspectiveabstractUsability is an important aspect of security, because poor usability motivates users to find shortcuts that bypass the system. Existing studies on keystroke biometrics evaluate the usability issue in terms of the average false rejection rate (FRR). We show in this paper that such an approach underestimates the user impact in two ways. First, the FRR of keystroke biometrics changes for the worse under a range of common conditions such as background music, exercise and even game playing. In a user study involving 111 participants, the average penalties (increases) in FRR are 0.0360 and 0.0498, respectively, for two different classifiers. Second, presenting the FRR as an average obscures the fact that not everyone is suitable for keystroke biometrics deployment. For example, using a Monte Carlo simulation, we found that 30% of users would encounter an account lockout before their 50th authentication session (given a lockout policy of 3 attempts) if they are affected by external influences 50% of the time when authenticating. Chee Meng Tey, Payas Gupta, Kartik Muralidharan, Debin Gao |
CODASPY | 4 |
| 2014 | Control Flow Obfuscation Using Neural Network to Fight Concolic Testing
Xinjie Ma, Weijie Liu 0004, Zhipeng Huang 0006, Debin Gao, Chunfu Jia |
SecureComm (1) | 5 |
| 2014 | StopWatch: A Cloud Architecture for Timing Channel MitigationabstractThis article presents StopWatch, a system that defends against timing-based side-channel attacks that arise from coresidency of victims and attackers in infrastructure-as-a-service clouds. StopWatch triplicates each cloud-resident guest virtual machine (VM) and places replicas so that the three replicas of a guest VM are coresident with nonoverlapping sets of (replicas of) other VMs. StopWatch uses the timing of I/O events at a VM’s replicas collectively to determine the timings observed by each one or by an external observer, so that observable timing behaviors are similarly likely in the absence of any other individual, coresident VMs. We detail the design and implementation of StopWatch in Xen, evaluate the factors that influence its performance, demonstrate its advantages relative to alternative defenses against timing side channels with commodity hardware, and address the problem of placing VM replicas in a cloud under the constraints of StopWatch so as to still enable adequate cloud utilization. Peng Li 0059, Debin Gao, Michael K. Reiter |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2013 | Launching Generic Attacks on iOS with Approved Third-Party Applications
Jin Han 0002, Su Mon Kywe, Qiang Yan 0001, Feng Bao 0001, Robert H. Deng, Debin Gao, Yingjiu Li, Jianying Zhou 0001 |
ACNS | 6 |
| 2013 | Keystroke Timing Analysis of on-the-fly Web Apps
Chee Meng Tey, Payas Gupta, Debin Gao |
ACNS | 3 |
| 2013 | Your love is public now: questioning the use of personal information in authenticationabstractMost social networking platforms protect user's private information by limiting access to it to a small group of members, typically friends of the user, while allowing (virtually) everyone's access to the user's public data. In this paper, we exploit public data available on Facebook to infer users' undisclosed interests on their profile pages. In particular, we infer their undisclosed interests from the public data fetched using Graph APIs provided by Facebook. We demonstrate that simply liking a Facebook page does not corroborate that the user is interested in the page. Instead, we perform sentiment-oriented mining on various attributes of a Facebook page to determine the user's real interests. Our experiments conducted on over 34,000 public pages collected from Facebook and data from volunteers show that our inference technique can infer interests that are often hidden by users on their personal profile with moderate accuracy. We are able to disclose 22 interests of a user and find more than 80,097 users with at least 2 interests. We also show how this inferred information can be used to break a preference based backup authentication system. Payas Gupta, Swapna Gottipati, Jing Jiang 0001, Debin Gao |
AsiaCCS | 4 |
| 2013 | Mitigating access-driven timing channels in clouds using StopWatchabstractThis paper presents StopWatch , a system that defends against timing-based side-channel attacks that arise from coresidency of victims and attackers in infrastructure-as-a-service clouds. StopWatch triplicates each cloud-resident guest virtual machine (VM) and places replicas so that the three replicas of a guest VM are coresident with nonoverlapping sets of (replicas of) other VMs. StopWatch uses the timing of I/O events at a VM's replicas collectively to determine the timings observed by each one or by an external observer, so that observable timing behaviors are similarly likely in the absence of any other individual, coresident VM. We detail the design and implementation of StopWatch in Xen, evaluate the factors that influence its performance, and address the problem of placing VM replicas in a cloud under the constraints of StopWatch so as to still enable adequate cloud utilization. Peng Li 0059, Debin Gao, Michael K. Reiter |
DSN | 2 |
| 2013 | Defending against Heap Overflow by Using Randomization in Nested Virtual Clusters
Chee Meng Tey, Debin Gao |
ICICS | 2 |
| 2013 | Comparing Mobile Privacy Protection through Cross-Platform Applications
Jin Han 0002, Qiang Yan 0001, Debin Gao, Jianying Zhou 0001, Robert H. Deng |
NDSS | 3 |
| 2013 | I can be You: Questioning the use of Keystroke Dynamics as Biometrics
Chee Meng Tey, Payas Gupta, Debin Gao |
NDSS | 3 |
| 2012 | Coercion resistance in authentication responsibility shiftingabstractTo meet the demand of scalability and usability, many real-world authentication systems have adopted the idea of responsibility shifting, explicitly or implicitly, where a user's responsibility of authentication is shifted to another entity, usually in case of failure of the primary authentication method. One example of responsibility shifting is in the fourth-factor authentication [1] whereby a user gets the crucial authentication assistance from a helper who takes over the responsibility. In the fourth-factor authentication system [1], subverting/coercing the helper (trustee) allows the adversary to log in without capturing the password of the user. Payas Gupta, Xuhua Ding, Debin Gao |
AsiaCCS | 3 |
| 2012 | OTO: online trust oracle for user-centric trust establishmentabstractMalware continues to thrive on the Internet. Besides automated mechanisms for detecting malware, we provide users with trust evidence information to enable them to make informed trust decisions. To scope the problem, we study the challenge of assisting users with judging the trustworthiness of software downloaded from the Internet. Tiffany Hyun-Jin Kim, Payas Gupta, Jun Han 0001, Emmanuel Owusu, Jason I. Hong, Adrian Perrig, Debin Gao |
CCS | 7 |
| 2012 | Learning Fine-Grained Structured Input for Memory Corruption Detection
Lei Zhao 0012, Debin Gao, Lina Wang 0001 |
ISC | 2 |
| 2011 | deRop: removing return-oriented programming from malwareabstractOver the last few years, malware analysis has been one of the hottest areas in security research. Many techniques and tools have been developed to assist in automatic analysis of malware. This ranges from basic tools like disassemblers and decompilers, to static and dynamic tools that analyze malware behaviors, to automatic malware clustering and classification techniques, to virtualization technologies to assist malware analysis, to signature- and anomaly-based malware detection, and many others. However, most of these techniques and tools would not work on new attacking techniques, e.g., attacks that use return-oriented programming (ROP). Kangjie Lu, Dabi Zou, Weiping Wen, Debin Gao |
ACSAC | 4 |
| 2011 | Linear Obfuscation to Combat Symbolic Execution
Zhi Wang 0014, Jiang Ming 0002, Chunfu Jia, Debin Gao |
ESORICS | 4 |
| 2011 | Towards ground truthing observations in gray-box anomaly detectionabstractAnomaly detection has been attracting interests from researchers due to its advantage of being able to detect zero-day exploits. A gray-box anomaly detector first observes benign executions of a computer program and then extracts reliable rules that govern the normal execution of the program. However, such observations from benign executions are not necessarily true evidences supporting the rules learned. For example, the observation that a file descriptor being equal to a socket descriptor should not be considered supporting a rule governing the two values to be the same. Ground truthing such observations is a difficult problem since it is not practical to analyze the semantics of every instruction in every program to be protected. In this paper, we propose using taint analysis to automatically help the ground truthing. Intuitively, the same taint source of two values provides ground truth of the data dependence. We implement a host-based anomaly detector with our proposed taint tracking and evaluate the accuracy of rules learned. Results show that we not only manage to filter out incorrect rules that would otherwise be learned (with high support and confidence), but manage recover good rules that are previously believed to be unreliable. We also present overheads of our system and time needed for training. Jiang Ming 0002, Debin Gao |
NSS | 3 |
| 2011 | Packed, Printable, and Polymorphic Return-Oriented Programming
Kangjie Lu, Dabi Zou, Weiping Wen, Debin Gao |
RAID | 4 |
| 2011 | On Detection of Erratic Arguments
Jin Han 0002, Qiang Yan 0001, Robert H. Deng, Debin Gao |
SecureComm | 4 |
| 2011 | Launching Return-Oriented Programming Attacks against Randomized Relocatable ExecutablesabstractSince the day it was proposed, return-oriented programming has shown to be an effective and powerful attack technique against the write or execute only (W ⊕ X) protection. However, a general belief in the previous research is, systems deployed with address space randomization where the executables are also randomized at run-time are able to defend against return-oriented programming, as the addresses of all instructions are randomized. In this paper, we show that due to the weakness of current address space randomization technique, there are still ways of launching return-oriented programming attacks against those well-protected systems efficiently. We demonstrate and evaluate our attacks with existing typical web server applications and discuss possible methods of mitigating such threats. Jin Han 0002, Debin Gao, Jiwu Jing, Daren Zha |
TrustCom | 3 |
| 2010 | A multi-user steganographic file system on untrusted shared storageabstractExisting steganographic file systems enable a user to hide the existence of his secret data by claiming that they are (static) dummy data created during disk initialization. Such a claim is plausible if the adversary only sees the disk content at the point of attack. In a multi-user computing environment that employs untrusted shared storage, however, the adversary could have taken multiple snapshots of the disk content over time. Since the dummy data are static, the differences across snapshots thus disclose the locations of user data, and could even reveal the user passwords. Jin Han 0002, Meng Pan, Debin Gao, HweeHwa Pang |
ACSAC | 3 |
| 2010 | On Challenges in Evaluating Malware Clustering
Peng Li 0059, Debin Gao, Michael K. Reiter |
RAID | 3 |
| 2010 | Fighting Coercion Attacks in Key Generation using Skin Conductance
Payas Gupta, Debin Gao |
USENIX Security Symposium | 2 |
| 2009 | On the Effectiveness of Software Diversity: A Systematic Study on Real-World Vulnerabilities
Jin Han 0002, Debin Gao, Robert H. Deng |
DIMVA | 2 |
| 2009 | Denial-of-Service Attacks on Host-Based Generic Unpackers
Jiang Ming 0002, Zhi Wang 0014, Debin Gao, Chunfu Jia |
ICICS | 4 |
| 2009 | Automatically Adapting a Trained Anomaly Detector to Software Patches
Peng Li 0059, Debin Gao, Michael K. Reiter |
RAID | 2 |
| 2009 | Beyond Output Voting: Detecting Compromised Replicas Using HMM-Based Behavioral DistanceabstractMany host-based anomaly detection techniques have been proposed to detect code-injection attacks on servers. The vast majority, however, are susceptible to "mimicry" attacks in which the injected code masquerades as the original server software, including returning the correct service responses, while conducting its attack. "Behavioral distance," by which two diverse replicas processing the same inputs are continually monitored to detect divergence in their low-level (system-call) behaviors and hence potentially the compromise of one of them, has been proposed for detecting mimicry attacks. In this paper, we present a novel approach to behavioral distance measurement using a new type of hidden Markov model, and present an architecture realizing this new approach. We evaluate the detection capability of this approach using synthetic workloads and recorded workloads of production Web and game servers, and show that it detects intrusions with substantially greater accuracy than a prior proposal on measuring behavioral distance. We also detail the design and implementation of a new architecture, which takes advantage of virtualization to measure behavioral distance. We apply our architecture to implement intrusion-tolerant Web and game servers, and through trace-driven simulations demonstrate that it experiences moderate performance costs even when thresholds are set to detect stealthy mimicry attacks. Debin Gao, Michael K. Reiter, Dawn Song |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2008 | Bridging the Gap between Data-Flow and Control-Flow Analysis for Anomaly DetectionabstractHost-based anomaly detectors monitor the control-flow and data-flow behavior of system calls to detect intrusions. Control-flow-based detectors monitor the sequence of system calls, while data-flow-based detectors monitor the data propagation among arguments of system calls. Besides pointing out that data-flow-based detectors can be layered on top of control-flow-based ones (or vice versa) to improve accuracy, there is a large gap between the two research directions in that research along one direction had been fairly isolated and had not made good use of results from the other direction. In this paper, we show how data-flow analysis can leverage results from control-flow analysis to learn more accurate and useful rules for anomaly detection. Our results show that the proposed control-flow-analysis-aided data-flow analysis reveals some accurate and useful rules that cannot be learned in prior data-flow analysis techniques. These relations among system call arguments and return values are useful in detecting many real attacks. A trace-driven evaluation shows that the proposed technique enjoys low false-alarm rates and overhead when implemented on a production server. Peng Li 0059, Hyundo Park, Debin Gao, Jianming Fu |
ACSAC | 3 |
| 2008 | BinHunt: Automatically Finding Semantic Differences in Binary Programs
Debin Gao, Michael K. Reiter, Dawn Song |
ICICS | 1 |
| 2008 | Distinguishing between FE and DDoS Using Randomness Check
Hyundo Park, Peng Li 0059, Debin Gao, Heejo Lee, Robert H. Deng |
ISC | 3 |
| 2006 | Behavioral Distance Measurement Using Hidden Markov Models
Debin Gao, Michael K. Reiter, Dawn Song |
RAID | 1 |
| 2005 | Behavioral Distance for Intrusion Detection
Debin Gao, Michael K. Reiter, Dawn Song |
RAID | 1 |
| 2004 | Gray-box extraction of execution graphs for anomaly detectionabstractMany host-based anomaly detection systems monitor a process by observing the system calls it makes, and comparing these calls to a model of behavior for the program that the process should be executing. In this paper we introduce a new model of system call behavior, called an execution graph. The execution graph is the first such model that both requires no static analysis of the program source or binary, and conforms to the control flow graph of the program. When used as the model in an anomaly detection system monitoring system calls, it offers two strong properties: (i) it accepts only system call sequences that are consistent with the control flow graph of the program; (ii) it is maximal given a set of training data, meaning that any extensions to the execution graph could permit some intrusions to go undetected. In this paper, we formalize and prove these claims. We additionally evaluate the performance of our anomaly detection technique. Debin Gao, Michael K. Reiter, Dawn Song |
CCS | 1 |
| 2004 | On Gray-Box Program Tracking for Anomaly Detection
Debin Gao, Michael K. Reiter, Dawn Song |
USENIX Security Symposium | 1 |