Yi He 0020

dblp:65/425-20 · DBLP profile ↗
← Back
17ranked-venue papers
7as first author
13since 2021 · last 2025
0000-0002-1807-4185ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 6 first-author · 11 since 2021Computer networks · 4 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2025 BLMProbe: Enhancing Internet-Connected Device Discovery by Automated Device Labeling and Label Migration
abstract
10.1109/TIFS.2025.3587211
Zhenhao Tian, Yi He 0020, Nuo Zhang, Qixiao Lin, Hetian Shi, Jianwei Zhuge, Deliang Chang
IEEE Trans. Inf. Forensics Secur.2
2025 OTA-Key: Over-the-Air Key Management for Flexible and Reliable IoT Device Provision
abstract
As the Internet of Things (IoT) industry advances, the imperative to secure IoT devices has become increasingly critical. Current practices in both industry and academia advocate for the enhancement of device security through key installation. However, it has been observed that, in practice, IoT vendors frequently assign shared keys to batches of devices. This practice can expose devices to risks, such as data theft by attackers or large-scale Distributed Denial of Service (DDoS) attacks. To address this issue, our intuition is to assign a unique key to each device. Unfortunately, this strategy proves to be highly complex within the IoT context, as existing keys are typically hardcoded into the firmware, necessitating the creation of bespoke firmware for each device. Furthermore, correct pairing of device keys with their respective devices is crucial. Errors in this pairing process would incur substantial human and temporal resources to rectify and require extensive communication between IoT vendors, device manufacturers, and cloud platforms, leading to significant communication overhead. To overcome these challenges, we propose the OTA-Key scheme. This approach fundamentally decouples device keys from the firmware features stored in flash memory, utilizing an intermediary server to allocate unique device keys in two distinct stages and update keys. We conducted a formal security verification of our scheme using ProVerif and assessed its performance through a series of evaluations. The results demonstrate that our scheme is secure and effectively manages the large-scale distribution and updating of unique device keys. Additionally, it achieves significantly lower update times and data transfer volumes compared to other schemes.
Yi He 0020, Xiaoli Zhang 0003, Chunhua Song
IEEE Trans. Netw. Serv. Manag.2
2024 BlueSWAT: A Lightweight State-Aware Security Framework for Bluetooth Low Energy
abstract
Bluetooth Low Energy (BLE) is a short-range wireless communication technology for resource-constrained IoT devices. Unfortunately, BLE is vulnerable to session-based attacks, where previous packets construct exploitable conditions for subsequent packets to compromise connections. Defending against session-based attacks is challenging because each step in the attack sequence is legitimate when inspected individually. In this paper, we present BlueSWAT, a lightweight state-aware security framework for protecting BLE devices. To perform inspection on the session level rather than individual packets, BlueSWAT leverages a finite state machine (FSM) to monitor sequential actions of connections at runtime. Patterns of session-based attacks are modeled as malicious transition paths in the FSM. To overcome the heterogeneous IoT environment, we develop a lightweight eBPF framework to facilitate universal patch distribution across different BLE architectures and stacks, without requiring device reboot. We implement BlueSWAT on 5 real-world devices with different chips and stacks to demonstrate its cross-device adaptability. On our dataset with 101 real-world BLE vulnerabilities, BlueSWAT can mitigate 76.1% of session-based attacks, outperforming other defense frameworks. In our end-to-end application evaluation, BlueSWAT introduces an average of 0.073% memory overhead and negligible latency.
Xijia Che, Yi He 0020, Xuewei Feng, Kun Sun 0001, Ke Xu 0002, Qi Li 0002
CCS2
2024 From Hardware Fingerprint to Access Token: Enhancing the Authentication on IoT Devices
Yi He 0020, Xiaoli Zhang 0003, Qian Wang 0002, Renjie Xie, Kun Sun 0001, Ke Xu 0002, Qi Li 0002
NDSS2
2024 Demystifying the Security Implications in IoT Device Rental Services
Yi He 0020, Yunchao Guan, Ruoyu Lun, Shangru Song, Jianwei Zhuge, Jianjun Chen 0005, Zehui Wu, Hetian Shi, Qi Li 0002
USENIX Security Symposium1
2024 Your Firmware Has Arrived: A Study of Firmware Update Vulnerabilities
Yuhao Wu 0006, Shixuan Zhai, Yi He 0020, Kun Sun 0001, Qi Li 0002, Ning Zhang 0017
USENIX Security Symposium6
2024 Cactus: Obfuscating Bidirectional Encrypted TCP Traffic at Client Side
abstract
As the mainstream encrypted protocols adopt TCP protocol to ensure lossless data transmissions, the privacy of encrypted TCP traffic becomes a significant focus for adversaries. They can leverage Deep Learning (DL) models to infer the sensitive information from encrypted TCP traffic by analyzing its packet size, direction, and timing information. To defend against such DL-based traffic analysis attacks, recent advances reshape the encrypted traffic and achieve desired results. However, they typically require deploying cooperative modules on both communication endpoints and only support specific applications, such as browsers. In this paper, we propose Cactus, a client-side plug-in to obfuscate bidirectional encrypted TCP traffic for a wide range of applications transparently using the inherent TCP semantics and the emerging eBPF technique. In particular, Cactus provides four effective operations to enable bidirectional traffic obfuscation while preserving communication semantics of applications. Besides, Cactus empowers users to specify which applications to conduct traffic obfuscation and what obfuscation level for each application. We conduct comprehensive experiments to demonstrate that Cactus can effectively obfuscate encrypted TCP traffic with low overhead to hinder the traffic analysis efforts in website fingerprinting and application identification.
Renjie Xie, Jiahao Cao 0001, Yuxi Zhu, Yi He 0020, Hanyi Peng, Mingwei Xu 0001, Kun Sun 0001, Enhuan Dong, Qi Li 0002, Menghao Zhang 0001
IEEE Trans. Inf. Forensics Secur.5
2023 Cross Container Attacks: The Bewildered eBPF on Clouds
Yi He 0020, Roland Guo, Yunlong Xing, Xijia Che, Kun Sun 0001, Zhuotao Liu, Ke Xu 0002, Qi Li 0002
USENIX Security Symposium1
2023 A Systematic Study of Android Non-SDK (Hidden) Service API Security
abstract
Android allows apps to communicate with its system services via system service helpers so that these apps can use various functions provided by the system services. Meanwhile, the system services rely on their service helpers to enforce security checks for protection. Unfortunately, the security checks in the service helpers may be bypassed via directly exploiting the non-SDK (hidden) APIs, degrading the stability and posing severe security threats such as privilege escalation, automatic function execution without users’ interactions, crashes, and DoS attacks. Google has proposed various approaches to address this problem, e.g., case-by-case fixing the bugs or even proposing a blacklist to block all the non-SDK APIs. However, the developers can still figure out new ways of exploiting these hidden APIs to evade the non-SDKs restrictions. In this article, we systematically study the vulnerabilities due to the hidden API exploitation and analyze the effectiveness of Google’s countermeasures. We aim to answer if there are still vulnerable hidden APIs that can be exploited in newest Android 12. We develop a static analysis tool called${{\sf ServiceAudit}}$to automatically mine the inconsistent security enforcement between service helper classes and the hidden service APIs. We apply${{\sf ServiceAudit}}$to Android 6$\sim$12. Our tool discovers 112 vulnerabilities in Android 6 with a higher precision than existing approaches. Moreover, in Android 11 and 12, we identify more than 25 hidden APIs with inconsistent protections; however, only one of the vulnerable APIs can lead to severe security problem in Android 11, and none of them work on Android 12.
Yi He 0020, Yacong Gu, Purui Su, Kun Sun 0001, Yajin Zhou, Zhi Wang 0004, Qi Li 0002
IEEE Trans. Dependable Secur. Comput.1
2022 RapidPatch: Firmware Hotpatching for Real-Time Embedded Devices
Yi He 0020, Zhenhua Zou, Kun Sun 0001, Zhuotao Liu, Ke Xu 0002, Qian Wang 0002, Chao Shen 0001, Zhi Wang 0004, Qi Li 0002
USENIX Security Symposium1
2022 JNI Global References Are Still Vulnerable: Attacks and Defenses
abstract
System services and resources in Android are accessed through IPC-based mechanisms. Previous research has demonstrated that they are vulnerable to the denial-of-service attack (DoS attack). For instance, the JNI global reference (JGR), which is widely used by system services, can be exhausted to cause the system reboot (hence the name JGRE attack). Even though the Android team tries to fix the problem by enforcing security checks, we find that it is still possible to construct a JGR exhaustion DoS attack in the latest Android system. In this article, we propose a new JGR exhaustion DoS attack, which is effective in different Android versions, including thelatest one (i.e., Android 10). Specifically, we developed JGREAnalyzer, a tool that can systematically detect JGR vulnerable services APIs via a call graph analysis and a forwarding reachability analysis. We applied this tool to different Android versions and found multiple vulnerabilities. In particular, among 148 system services in Android 10, 12 of them have 21 vulnerabilities. Among them, 9 can be successfully exploited without any permissions. We further analyze the root cause of the vulnerabilities and propose a new defense to mitigate the JGRE attack by restricting resource consumption via global reference counting.
Yi He 0020, Yajin Zhou, Qi Li 0002, Kun Sun 0001, Yacong Gu, Yong Jiang 0001
IEEE Trans. Dependable Secur. Comput.1
2021 Ruledger: Ensuring Execution Integrity in Trigger-Action IoT Platforms
abstract
Smart home IoT systems utilize trigger-action platforms, e.g., IFTTT, to manage devices from various vendors. These platforms allow users to define rules for automatically triggering operations on devices. However, they may be abused by triggering malicious rule execution with forged IoT devices or events violating the execution integrity and the intentions of the users. To address this issue, we propose a ledger based IoT platform called Ruledger, which ensures the correct execution of rules by verifying the authenticity of the corresponding information. Ruledger utilizes smart contracts to enforce verifying the information associated with rule executions, e.g., the user and configuration information from users, device events, and triggers in the trigger-action platforms. In particular, we develop three algorithms to enable ledger-wallet based applications for Ruledger and guarantee that the records used for verification are stateful and correct. Thus, the execution integrity of rules is ensured even if devices and platforms in the smart home systems are compromised. We prototype Ruledger in a real IoT platform, i.e., IFTTT, and evaluate the performance with various settings. The experimental results demonstrate Ruledger incurs an average of 12.53% delay, which is acceptable for smart home systems.
Jingwen Fan, Yi He 0020, Qi Li 0002, Ravi S. Sandhu
INFOCOM2
2021 Vulnerable Service Invocation and Countermeasures
abstract
Before Android 5.0, the services in Android applications can be invoked either explicitly or implicitly. However, since the implicit service invocations may suffer service hijacking attacks and thus lead to sensitive data leakage, they have been forbidden since Android 5.0. Thereafter the Android system will simply throw an exception and crash the applications that still invokes services implicitly, so that it was expected that application developers will be forced to convert the implicit service invocations to explicit ones. In this paper, we develop a static analysis framework called ISA to analyze the effectiveness of forbidden policy on removing the vulnerable service invocations. We collect two datasets containing common 1390 apps downloaded 1 to 3 months before the forbidden policy is enforced and 30 months after the forbidden policy is enforced, respectively. Our preliminary analysis indicates a 82.58% reduction in the number of vulnerable service invocations due to the enforcement of forbidden policy. However, upon further investigation, we discover that the forbidden policy fails to resolve service hijacking attacks. We find that 36 popular applications are still vulnerable to service hijacking attacks, which can lead to the leakage of sensitive information such as user login credential. Finally, we analyze the reasons of the residue vulnerable invocations and then propose two countermeasures.
Lingguang Lei, Kun Sun 0001, Yuewu Wang, Jiwu Jing, Yi He 0020, Pingjian Wang
IEEE Trans. Dependable Secur. Comput.6
2017 Vulnerable Implicit Service: A Revisit
abstract
The services in Android applications can be invoked either explicitly or implicitly before Android 5.0. However, since the implicit service invocations suffer service hijacking attacks and thus lead to sensitive information leakage, they have been forbidden since Android 5.0. Thereafter since the Android system will simply throw an exception and crash the application that still invokes services implicitly, it was expected that application developers will be forced to convert the implicit service invocations to explicit ones by specifying the package name of the service to be called.
Lingguang Lei, Yi He 0020, Kun Sun 0001, Jiwu Jing, Yuewu Wang, Qi Li 0002, Jian Weng 0001
CCS2
2017 LinkFlow: Efficient Large-Scale Inter-app Privacy Leakage Detection
Yi He 0020, Qi Li 0002, Kun Sun 0001
SecureComm1
2016 Detecting and defending against inter-app permission leaks in android apps
abstract
Android encourages inter-app interactions and facilitates functionality reusability by providing flexible inter-component communication (ICC) among apps. Components in apps can communicate with other components within single app or cross different apps. However, through this mechanism, components may leak permissions either carelessly or maliciously. Unfortunately, the current app-level permission model in Android cannot prevent such permissions leaks incurred by inter app communication. Simple permission enforcement is not sufficient as it cannot differentiate between normal permission usage and malicious permission usage (i.e., permission leakage). Therefore, users are required to grant permissions to apps during app installation, which may lead to permission mismanaged. In this paper, we propose IntentChecker that aims to detect permission leakage by proposing a light-weight mechanism. IntentChecker defends against the permission leakage attacks by adding authorization extension to the ICC mechanism and automatically generating patches for vulnerable apps. We evaluate IntentChecker with two benchmarks, i.e., Droidbench and ICCbench, and with 4031 real world apps. IntentChecker finds 324 apps that includes at least one permission leakage. We verify the effectiveness of the defense mechanism with 10 apps randomly selected from the vulnerable apps, which demonstrates that it is effective to prevent inter app permission leakage.
Yi He 0020, Qi Li 0002
IPCCC1
2016 CrashFuzzer: Detecting input processing related crash bugs in android applications
abstract
Android has become the largest-selling operating system for smartphones, and thousands of new Android applications are developed and published everyday. However, quality, not quantity, is the real mobile application problem. The robustness of Android applications are worrisome as many of them always have crash bugs. It's unrealistic to rely on developers' experience to eliminate them all. There are so many input sources and we cannot assume developers will check all data from them properly. And some Android system services suffer denial-of-service attacks because of crash bugs due to their poor input validation. Crash bugs not only degrade user experience but also may raise security issues. In this paper, we propose a heuristic approach which combines static analysis and semi-random input generation to detect crash bugs related to input data processing in Android applications. We present techniques for automatic generating input data, injecting them to an application, producing structured trace information. We perform experiments on 100 Android applications and find 28 of them have crash bugs due to their poor input validation. We believe our study and techniques also have the potential to release developers from boring testing tasks to a certain extent and help developers improve quality of their Android applications.
Yi He 0020, Yong Jiang 0001
IPCCC2