Kehuan Zhang

dblp:66/6560 · DBLP profile ↗
← Back
63ranked-venue papers
3as first author
25since 2021 · last 2026
0000-0003-1519-0057ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 50 · 3 first-author · 14 since 2021Software engineering, systems software and programming languages · 6 · 4 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Systems, architecture and hardware · 4 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Breaking the Stealth-Potency Trade-off in Clean-Image Backdoors with Generative Trigger Optimization
abstract
Clean-image backdoor attacks, which use only label manipulation in training datasets to compromise deep neural networks, pose a significant threat to security-critical applications. A critical flaw in existing methods is that the poison rate required for a successful attack induces a proportional, and thus noticeable, drop in Clean Accuracy (CA), undermining their stealthiness. This paper presents a new paradigm for clean-image attacks that minimizes this accuracy degradation by optimizing the trigger itself. We introduce Generative Clean-Image Backdoors (GCB), a framework that uses a conditional InfoGAN to identify naturally occurring image features that can serve as potent and stealthy triggers. By ensuring these triggers are easily separable from benign task-related features, GCB enables a victim model to learn the backdoor from an extremely small set of poisoned examples, resulting in a CA drop of less than 1%. Our experiments demonstrate GCB's remarkable versatility, successfully adapting to six datasets, five architectures, and four tasks, including the first demonstration of clean-image backdoors in regression and segmentation. GCB also exhibits resilience against most of the existing backdoor defenses.
Binyan Xu, Di Tang 0001, Xilin Dai, Kehuan Zhang
AAAI5
2026 MTFuzz: A Novel Efficacy Fuzzing Framework for Aerospace Monolithic Firmware
Shuai Wang 0012, Xi Xiao 0001, Guangwu Hu, Kehuan Zhang, Le Yu 0002, Chengpei Tang, Qing Li 0006, Qizhen Xu
DSN4
2026 Unidentifiable Identifier: Attacking Bluetooth Applications with Duplicated UUIDs
Siyu Shen, Yi Chen 0024, Fenghao Xu, Shuaike Dong, Wenrui Diao, Di Tang 0001, Kehuan Zhang
EuroS&P7
2026 Beyond Nodes vs. Edges: A Multi-View Fusion Framework for Provenance-Based Intrusion Detection
Binyan Xu, Di Tang 0001, Kehuan Zhang
SP4
2026 Reliable image super-resolution using dual-teacher knowledge distillation
Zhan Li 0004, Weijun Yuan, Boyang Yao, Yihang Chen 0005, Bir Bhanu, Kehuan Zhang
Knowl. Based Syst.6
2026 RuleDroid: LLM-Augmented Synthesis of Static Security Detection Rules for Android Apps
abstract
Android’s vast ecosystem and expansive API surfaces pose a serious challenge to static application security testing (SAST) tools. Mainstream tools such as MobSF, APKHunt, and AUSERA mainly rely on manually crafted rules. Crafting these rules demands considerable effort, yet they still cannot cover every security issue. When Android introduces new APIs, changes its permission model, or revises other security policies, the rules soon fall behind. Without constant maintenance, false positives grow, and true vulnerabilities slip through. Recently released LLM-based detectors are easy to use and potentially support a wide range of vulnerability types, but their findings often lack clear explanations and suffer from high false-positive rates.In this paper, we present RULEDROID, a new framework that leverages LLMs to automatically generate Semgrep-compatible static detection rules from up-to-date official Android security documentation. RULEDROIDtackles the limits of pure LLM detection by combining (i) Retrieval-Augmented Generation (RAG), which grounds model outputs in trusted documents, and (ii) a modular workflow that decomposes rule synthesis into welldefined stages. The resulting rules are then applied with proven static-analysis techniques, ensuring consistent and explainable results. We evaluated RULEDROID on three public benchmark datasets. Based on its large and precise rule set, RULEDROIDachieved higher coverage and accuracy than traditional SAST tools, and sharply reduced false positives compared with direct LLM scanning. When applied to real-world apps, RULEDROIDdiscovered multiple new vulnerabilities, resulting in 57 CVE IDs being assigned. These results show that RULEDROIDcombines the broad vulnerability coverage of LLMs with the precision of static analysis, delivering a fully automated docs-to-rules solution for Android security testing.
Zhentao Xie, Yaqi Gao, Shishuai Yang, Wenrui Diao, Kehuan Zhang
IEEE Trans. Software Eng.7
2025 One Surrogate to Fool Them All: Universal, Transferable, and Targeted Adversarial Attacks with CLIP
Binyan Xu, Xilin Dai, Di Tang 0001, Kehuan Zhang
CCS4
2025 CLIP-Guided Backdoor Defense through Entropy-Based Poisoned Dataset Separation
Binyan Xu, Xilin Dai, Di Tang 0001, Kehuan Zhang
ACM Multimedia5
2025 Patronus: Plug-and-Play and Near-Lossless Facial Privacy Enhancement Against Reconstruction Attacks
abstract
Reconstruction attackers can exploit facial features to recover the original user’s face, resulting in user privacy leakage. One new strategy to enhance the “Edge-Cloud” face recognition system’s privacy is to add adversarial perturbations to facial features, preventing the attackers from high-quality user image recovery. However, the existing works following this strategy suffer from unacceptable damage to face recognition accuracy. Achieving robust privacy enhancement and face recognition accuracy simultaneously is still challenging. To tackle this challenge, we propose an adversarial perturbation-based plug-and-play privacy-enhancing method (Patronus) with robustness against face image reconstruction attacks and near-lossless face recognition performance. The key insight is derived from our observation that the feature distance between two face images of the same person is significantly lower than the threshold set in the face recognition system. This leaves room for adding adversarial perturbations to the facial features without compromising face recognition accuracy. Our strategy limits the amount of adversarial perturbations in a fine-grained manner to ensure that they are within the range of not damaging face recognition accuracy. Our evaluation shows the superior performance ofPatronusin robustness against reconstruction attacks and near-lossless face recognition accuracy compared to state-of-the-art (SOTA) methods.Patronuscan be easily integrated into deployed face recognition systems as a plug-in privacy-enhancing module with low overhead.
Hui Liu 0018, Hongqin Du, Jiageng Chen, Ke Zhang 0039, Kehuan Zhang, Peng Liu 0005
IEEE Trans. Inf. Forensics Secur.6
2024 LiftFuzz: Validating Binary Lifters through Context-aware Fuzzing with GPT
abstract
Analyzing binary code is vital for software engineering and security research, particularly when the source code is unavailable. However, understanding, modifying, and retargeting binary code can be complex tasks. To counter these difficulties, binary lifters have been introduced. These tools translate binary code into Intermediate Representations (IRs), providing several advantages, such as enabling modifications to executables without source code and facilitating code retargetability. So far, accurately developing binary lifters for modern ISAs is universally acknowledged as challenging and error-prone. Existing validation methods mainly concentrate on isolated instructions, overlooking interactions among instructions. In this paper, we introduce LiftFuzz, a novel framework that leverages instruction context-aware fuzzing to validate binary lifters. LiftFuzz harnesses an assembly language model to learn interactions among instructions and generates test cases with the knowledge. LiftFuzz greatly outperforms the baseline, requiring only 1/1000 of the test cases used by the baseline to identify 26 inconsistencies, including a previously uncovered category. LiftFuzz significantly contributes to enhancing the performance of binary lifters, which are frequently employed in binary security applications.
Zirui Song, Ke Zhang 0039, Jiongyi Chen, Kehuan Zhang
CCS6
2024 TypeFSL: Type Prediction from Binaries via Inter-procedural Data-flow Analysis and Few-shot Learning
abstract
Type recovery in stripped binaries is a critical and challenging task in reverse engineering, as it is the basis for many security applications (e.g., vulnerability detection). Traditional analysis methods are limited by software complexity and emerging types in real-world projects. To address these limitations, machine learning methods have been explored. However, the existing supervised learning approaches struggle with analyzing complicated and uncommon types due to the limited availability of samples. Additionally, none of the existing works can capture fine-grained and inter-procedural features in the binaries. In this paper, we present TypeFSL, a framework that addresses the challenge of imbalanced type distributions by incorporating few-shot learning and captures inter-procedural semantics through program slicing. Moreover, based on a dataset with 3,003,117 functions, TypeFSL achieves an average of 77.9% and 84.6% accuracy across all architecture and optimizations in 20-way 5-shot and 10-shot classification tasks. Our prototype outperforms existing techniques in prediction accuracy and obfuscation resistance. Finally, the case studies demonstrate how TypeFSL predicts uncommon and complicated types in practical analysis.
Zirui Song, Shuaike Dong, Ke Zhang 0039, Kehuan Zhang
ASE5
2024 A lightweight unsupervised adversarial detector based on autoencoder and isolation forest
Hui Liu 0018, Bo Zhao 0023, Jiabao Guo, Kehuan Zhang, Peng Liu 0005
Pattern Recognit.4
2023 HOMESPY: The Invisible Sniffer of Infrared Remote Control of Smart TVs
Kong Huang, Ke Zhang 0039, Jiacen Xu 0001, Jiongyi Chen, Di Tang 0001, Kehuan Zhang
USENIX Security Symposium7
2023 Lost in Conversion: Exploit Data Structure Conversion with Attribute Loss to Break Android Systems
Rui Li 0102, Wenrui Diao, Shishuai Yang, Shanqing Guo, Kehuan Zhang
USENIX Security Symposium6
2023 PROGRAPHER: An Anomaly Detection System based on Provenance Graph Embedding
Jiacen Xu 0001, Chun-lin Xiong, Zhou Li 0001, Kehuan Zhang
USENIX Security Symposium5
2022 Default: Mutual Information-based Crash Triage for Massive Crashes
abstract
With the considerable success achieved by modern fuzzing infrastructures, more crashes are produced than ever before. To dig out the root cause, rapid and faithful crash triage for large numbers of crashes has always been attractive. However, hindered by the practical difficulty of reducing analysis imprecision without compromising efficiency, this goal has not been accomplished.
Jiongyi Chen, Chao Feng 0002, Ruilin Li 0002, Wenrui Diao, Kehuan Zhang, Jing Lei 0001, Chaojing Tang
ICSE6
2022 LiCA: A Fine-grained and Path-sensitive Linux Capability Analysis Framework
abstract
The capability mechanism in Linux-based systems is designed for dispersing the root privileges into a set of more refined capabilities, making programs gain no-more-necessary privileges. However, it is challenging to check the necessity and sufficiency of capabilities assigned to programs due to the highly complicated call chains invoked in practice. Inappropriate capability assignment brings threats to the systems. For example, over-privileged programs could allow an attacker to misuse root privileges, while under-privileged programs may incur runtime errors.
Menghan Sun, Zirui Song, Xiaoxi Ren, Daoyuan Wu, Kehuan Zhang
RAID5
2022 Identifying the BLE Misconfigurations of IoT Devices through Companion Mobile Apps
abstract
Bluetooth Low Energy (BLE) is widely deployed and has become the de-facto communication standard in the IoT ecosystem. Naturally, the security of BLE received much attention from both researchers and attackers. In another aspect, the BLE specifications provide the security guidelines for BLE deployments. Due to various reasons, the developers do not follow the guidelines in the implementation process, which introduces the misconfiguration issue. However, identifying these BLE mis-configurations in IoT device firmware is quite challenging. In this work, we do not handle the BLE-enabled devices directly. Instead, we focus on the security misconfiguration issues in their companion mobile apps, which can reflect the deployment conditions of the corresponding devices. Further, we designed an analysis tool - BSC-Checker to detect the misconfigurations based on pre-defined checking strategies. With BSC-Checker, we conducted large-scale experiments on 4,589 apps from multiple app markets. The result shows that the BLE configurations of most BLE apps disobey at least one security rule, and the current BLE deployment status is not optimistic.
Jianqi Du, Fenghao Xu, Chennan Zhang, Zidong Zhang, Xiaoyin Liu, Wenrui Diao, Shanqing Guo, Kehuan Zhang
SECON9
2022 An empirical study of blockchain system vulnerabilities: modules, types, and patterns
abstract
Blockchain, as a distributed ledger technology, becomes increasingly popular, especially for enabling valuable cryptocurrencies and smart contracts. However, the blockchain software systems inevitably have many bugs. Although bugs in smart contracts have been extensively investigated, security bugs of the underlying blockchain systems are much less explored. In this paper, we conduct an empirical study on blockchain’s system vulnerabilities from four representative blockchains, Bitcoin, Ethereum, Monero, and Stellar. Specifically, we first design a systematic filtering process to effectively identify 1,037 vulnerabilities and their 2,317 patches from 34,245 issues/PRs (pull requests) and 85,164 commits on GitHub. We thus build the first blockchain vulnerability dataset, which is available at https://github.com/VPRLab/BlkVulnDataset. We then perform unique analyses of this dataset at three levels, including (i) file-level vulnerable module categorization by identifying and correlating module paths across projects, (ii) text-level vulnerability type clustering by natural language processing and similarity-based sentence clustering, and (iii) code-level vulnerability pattern analysis by generating and clustering code change signatures that capture both syntactic and semantic information of patch code fragments.
Xiao Yi, Daoyuan Wu, Lingxiao Jiang, Yuzhou Fang, Kehuan Zhang, Wei Zhang 0122
ESEC/SIGSOFT FSE5
2022 Authorisation inconsistency in IoT third-party integration
abstract
Abstract Today's IoT platforms provide rich functionalities by integrating with popular third‐party services. Due to the complexity, it is critical to understand whether the IoT platforms have properly managed the authorisation in the cross‐cloud IoT environments. In this study, the authors report the first systematic study on authorisation management of IoT third‐party integration by: (1) presenting two attacks that leak control permissions of the IoT device in the integration of third‐party services; (2) conducting a measurement study over 19 real‐world IoT platforms and three major third‐party services. Results show that eight of the platforms are vulnerable to the threat. To educate IoT developers, the authors provide in‐depth discussion about existing design principles and propose secure design principles for IoT cross‐cloud control frameworks.
Jiongyi Chen, Fenghao Xu, Shuaike Dong, Kehuan Zhang
IET Inf. Secur.5
2022 FLAM-PUF: A Response-Feedback-Based Lightweight Anti-Machine-Learning-Attack PUF
abstract
Physical unclonable functions (PUFs) have been adopted in many resource-constrained Internet of Things (IoT) applications to provide effective and lightweight solutions for device authentication. However, an attacker can collect challenge–response pairs (CRPs) of a strong PUF, to build a machine learning (ML) model and mimic its behavior, i.e., predicting the responses of unseen challenges with high accuracy. Although several PUFs have been proposed to resist such modeling attacks, they incur high hardware overhead. Developing a PUF primitive with low hardware cost and high resistance to ML attacks is thus a crucial task. In this article, we propose the first response–feedback-based lightweight anti-ML-attack PUF (FLAM-PUF). It is only composed of one arbiter PUF (APUF) and one Galois linear-feedback shift register (LFSR), with some basic logic gates, reducing more than 62% hardware cost compared with the state-of-the-art robust strong PUFs. Specifically, FLAM-PUF leverages a cost-effective feedback loop structure to dynamically control and update the LFSR configuration. FLAM-PUF has two main characteristics: 1) it feeds back a 1-bit response in every cycle to intentionally poison the data of the CRP set for training. To resist ML-based modeling attacks, the 1-bit response can randomly update one coefficient of the feedback polynomial to implant more complex correlations into the model built by attackers and 2) it takes advantage of an$n-$bit response feedback-controlled reconfigurable Galois LFSR to enlarge the original challenge space of the APUF. Extensive experimental results show that the proposed FLAM-PUF achieves near-optimal uniformity, uniqueness, and reliability. Our scheme works well under standard attack models with public crucial initial information. In particular, the prediction accuracy of modeling attacks against FLAM-PUF is nearly 50% under the four widely used ML algorithms, i.e., support vector machines (SVMs), logistic regression (LR), covariance matrix adaptation evolution strategy (CMA-ES), and deep neural networks (DNNs), indicating excellent resistance against these ML attacks.
Linjun Wu, Yupeng Hu 0004, Kehuan Zhang, Wenjia Li, Xiaolin Xu 0001, Wanli Chang 0001
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3
2021 Android on PC: On the Security of End-user Android Emulators
abstract
Android emulators today are not only acting as a debugging tool for developers but also serving the massive end-users. These end-user Android emulators have attracted millions of users due to their advantages of running mobile apps on desktops and are especially appealing for mobile game players who demand larger screens and better performance. Besides, they commonly provide some customized assistant functionalities to improve the user experience, such as keyboard mapping and app installation from the host. To implement these services, emulators inevitably introduce communication channels between host OS and Android OS (in the Virtual Machine), thus forming a unique architecture which mobile phone does not have. However, it is unknown whether this architecture brings any new security risks to emulators.
Fenghao Xu, Siyu Shen, Wenrui Diao, Zhou Li 0001, Yi Chen 0024, Rui Li 0102, Kehuan Zhang
CCS7
2021 Towards Evaluating and Training Verifiably Robust Neural Networks
abstract
Recent works have shown that interval bound propagation (IBP) can be used to train verifiably robust neural networks. Reseachers observe an intriguing phenomenon on these IBP trained networks: CROWN, a bounding method based on tight linear relaxation, often gives very loose bounds on these networks. We also observe that most neurons become dead during the IBP training process, which could hurt the representation capability of the network. In this paper, we study the relationship between IBP and CROWN, and prove that CROWN is always tighter than IBP when choosing appropriate bounding lines. We further propose a relaxed version of CROWN, linear bound propagation (LBP), that can be used to verify large networks to obtain lower verified errors than IBP. We also design a new activation function, parameterized ramp function (ParamRamp), which has more diversity of neuron status than ReLU. We conduct extensive experiments on MNIST, CIFAR-10 and Tiny-ImageNet with ParamRamp activation and achieve state-of-the-art verified robustness. Code is available at https://github.com/ZhaoyangLyu/VerifiablyRobustNN.
Zhaoyang Lyu, Kehuan Zhang, Dahua Lin
CVPR5
2021 Understanding the Brains and Brawn of Illicit Streaming App
Kong Huang, Ke Zhang 0039, Jiongyi Chen, Menghan Sun, Di Tang 0001, Kehuan Zhang
ICDF2C7
2021 Demon in the Variant: Statistical Analysis of DNNs for Robust Backdoor Contamination Detection
Di Tang 0001, XiaoFeng Wang 0001, Haixu Tang, Kehuan Zhang
USENIX Security Symposium4
2020 Your Smart Home Can't Keep a Secret: Towards Automated Fingerprinting of IoT Traffic
abstract
The IoT (Internet of Things) technology has been widely adopted in recent years and has profoundly changed the people's daily lives. However, in the meantime, such a fast-growing technology has also introduced new privacy issues, which need to be better understood and measured. In this work, we look into how private information can be leaked from network traffic generated in the smart home network. Although researchers have proposed techniques to infer IoT device types or user behaviors under clean experiment setup, the effectiveness of such approaches become questionable in the complex but realistic network environment, where common techniques like Network Address and Port Translation (NAPT) and Virtual Private Network (VPN) are enabled. To this aim, we propose a traffic analysis framework based on sequence-learning techniques like LSTM and leveraged the temporal relations between packets for the attack of device identification. We evaluated it under different environment settings (e.g., pure-IoT and noisy environment with multiple non-IoT devices). The results showed our framework was able to differentiate device types with a high accuracy. This result suggests IoT network communications pose prominent challenges to users' privacy, even when they are protected by encryption and morphed by the network gateway. As such, new privacy protection methods on IoT traffic need to be developed towards mitigating this new issue.
Shuaike Dong, Zhou Li 0001, Di Tang 0001, Jiongyi Chen, Menghan Sun, Kehuan Zhang
AsiaCCS6
2020 Hidden Electricity Theft by Exploiting Multiple-Pricing Scheme in Smart Grids
abstract
With the development of demand response technologies, the pricing scheme in smart grids is moving from flat pricing to multiple pricing (MP), which facilitates the energy saving at the consumer side. However, the flexible pricing policy may be exploited for the stealthy reduction of utility bills. In this paper, we present a hidden electricity theft (HET) attack by exploiting the emerging MP scheme. The basic idea is that attackers can tamper with smart meters to cheat the utility that some electricity is consumed under a lower price. To construct the HET attack, we propose an optimization problem aiming at maximizing the attack profits while evading current detection methods, and design two algorithms to conduct the attack on smart meters. Moreover, we disclose and exploit several new vulnerabilities of smart meters to demonstrate the feasibility of HET attacks. To protect smart grids against HET attacks, we propose several defense and detection countermeasures, including selective protection on smart meters, limiting the attack cycle, and updating the billing mechanism. Extensive experiments on a real data set demonstrate that the attack could cause high economic losses, and the proposed countermeasures could effectively mitigate the attack's impact at a low cost.
Yang Liu 0090, Ting Liu 0002, Kehuan Zhang
IEEE Trans. Inf. Forensics Secur.4
2019 Your IoTs Are (Not) Mine: On the Remote Binding Between IoT Devices and Users
abstract
Nowadays, IoT clouds are increasingly deployed to facilitate users to manage and control their IoT devices. Unlike the traditional cloud services with communication between a client and a server, IoT cloud architectures involve three parties: the IoT device, the user, and the cloud. Before a user can remotely access her IoT device, remote communication between them is bootstrapped through the cloud. However, the security implications of such a unique process in IoT are less understood today. In this paper, we report the first step towards systematic analyses of IoT remote binding. To better understand the problem, we describe the life cycle of remote binding with a state-machine model which helps us demystify the complexity in various designs and systematically explore the attack surfaces. With the evaluation of 10 real-world remote binding solutions, our study brings to light questionable practices in the designs of authentication and authorization, including inappropriate use of device IDs, weak device authentication, and weak cloud-side access control, as well as the impact of the discovered problems, which could cause sensitive user data leak, persistent denial-of-service, connection disruption, and even stealthy device control.
Jiongyi Chen, Chaoshun Zuo, Wenrui Diao, Shuaike Dong, Qingchuan Zhao, Menghan Sun, Zhiqiang Lin 0001, Yinqian Zhang, Kehuan Zhang
DSN9
2019 BadBluetooth: Breaking Android Security Mechanisms via Malicious Bluetooth Peripherals
Fenghao Xu, Wenrui Diao, Zhou Li 0001, Jiongyi Chen, Kehuan Zhang
NDSS5
2019 Kindness is a Risky Business: On the Usage of the Accessibility APIs in Android
Wenrui Diao, Yue Zhang 0025, Li Zhang 0039, Zhou Li 0001, Fenghao Xu, Xiaorui Pan, Jian Weng 0001, Kehuan Zhang, XiaoFeng Wang 0001
RAID9
2019 CryptoREX: Large-scale Analysis of Cryptographic Misuse in IoT Devices
Li Zhang 0039, Jiongyi Chen, Wenrui Diao, Shanqing Guo, Jian Weng 0001, Kehuan Zhang
RAID6
2019 Stealthy Porn: Understanding Real-World Adversarial Images for Illicit Online Promotion
abstract
Recent years have witnessed the rapid progress in deep learning (DP), which also brings their potential weaknesses to the spotlights of security and machine learning studies. With important discoveries made by adversarial learning research, surprisingly little attention, however, has been paid to the real-world adversarial techniques deployed by the cybercriminal to evade image-based detection. Unlike the adversarial examples that induce misclassification using nearly imperceivable perturbation, real-world adversarial images tend to be less optimal yet equally effective. As a first step to understand the threat, we report in the paper a study on adversarial promotional porn images (APPIs) that are extensively used in underground advertising. We show that the adversary today's strategically constructs the APPIs to evade explicit content detection while still preserving their sexual appeal, even though the distortions and noise introduced are clearly observable to humans. To understand such real-world adversarial images and the underground business behind them, we develop a novel DP-based methodology called Male`na, which focuses on the regions of an image where sexual content is least obfuscated and therefore visible to the target audience of a promotion. Using this technique, we have discovered over 4,000 APPIs from 4,042,690 images crawled from popular social media, and further brought to light the unique techniques they use to evade popular explicit content detectors (e.g., Google Cloud Vision API, Yahoo Open NSFW model), and the reason that these techniques work. Also studied are the ecosystem of such illicit promotions, including the obfuscated contacts advertised through those images, compromised accounts used to disseminate them, and large APPI campaigns involving thousands of images. Another interesting finding is the apparent attempt made by cybercriminals to steal others' images for their advertising. The study highlights the importance of the research on real-world adversarial learning and makes the first step towards mitigating the threats it poses.
Kan Yuan, Di Tang 0001, Xiaojing Liao, XiaoFeng Wang 0001, Xuan Feng 0005, Yi Chen 0024, Menghan Sun, Kehuan Zhang
IEEE Symposium on Security and Privacy9
2019 A feature-hybrid malware variants detection using CNN based opcode embedding and BPNN based API embedding
Jixin Zhang, Zheng Qin 0001, Hui Yin 0001, Lu Ou, Kehuan Zhang
Comput. Secur.5
2019 Understanding Mobile Users' Privacy Expectations: A Recommendation-Based Method Through Crowdsourcing
abstract
Privacy is a pivotal issue of mobile apps because there is a plethora of personal and sensitive information in smartphones. Many mechanisms and tools are proposed to detect and mitigate privacy leaks. However, they rarely consider users' preferences and expectations. Users hold various expectation towards different mobile apps. For example, users may allow a social app to access their photos rather than a game app because it goes beyond users' expectation to access personal photos. Therefore, we believe it is practical and beneficial to understand users' privacy expectations on various mobile apps and help them mitigate privacy risks introduced by smartphones. To achieve this objective, we propose and implement PriWe, a system based on crowdsourcing driven by users who contribute privacy permission settings of the apps installed on their smartphones. PriWe leverages the crowdsourced permission settings to understand users' privacy expectations and provides app specific recommendations to mitigate information leakage. We deployed PriWe in the real world for evaluation. According to the feedback of 78 users who evaluated our system and 422 participants who completed our survey, PriWe is able to make proper recommendations which can match participants' privacy expectations and are mostly accepted by users, thereby help them to mitigate privacy disclosure in smartphones.
Rui Liu 0002, Junbin Liang, Jiannong Cao 0001, Kehuan Zhang, Wenyu Gao, Lei Yang 0024, Ruiyun Yu
IEEE Trans. Serv. Comput.4
2018 Beware of Your Screen: Anonymous Fingerprinting of Device Screens for Off-line Payment Protection
abstract
QR-code mobile payment becomes increasingly popular, being offered by major banks (e.g., ICBC) and payment service providers (e.g., PayPal). Unlike mobile payment solutions provided by hardware vendors (e.g., Apple Pay and Samsung Pay), QR code payment schemes do not rely on any hardware support and can therefore be easily deployed. However, the security guarantee of the new scheme is less clear: in the absence of hardware protection, users' digital wallet can be vulnerable to an OS-level adversary, who could steal her secret for generating payment tokens.
Zhe Zhou 0001, Di Tang 0001, Wenhao Wang 0001, XiaoFeng Wang 0001, Zhou Li 0001, Kehuan Zhang
ACSAC6
2018 IoTFuzzer: Discovering Memory Corruptions in IoT Through App-based Fuzzing
Jiongyi Chen, Wenrui Diao, Qingchuan Zhao, Chaoshun Zuo, Zhiqiang Lin 0001, XiaoFeng Wang 0001, Wing Cheong Lau, Menghan Sun, Ronghai Yang, Kehuan Zhang
NDSS10
2018 Face Flashing: a Secure Liveness Detection Protocol based on Light Reflections
Di Tang 0001, Zhe Zhou 0001, Yinqian Zhang, Kehuan Zhang
NDSS4
2018 Understanding Android Obfuscation Techniques: A Large-Scale Investigation in the Wild
Shuaike Dong, Wenrui Diao, Jian Liu 0008, Zhou Li 0001, Fenghao Xu, Kai Chen 0012, XiaoFeng Wang 0001, Kehuan Zhang
SecureComm (1)10
2018 Vetting Single Sign-On SDK Implementations via Symbolic Reasoning
Ronghai Yang, Wing Cheong Lau, Jiongyi Chen, Kehuan Zhang
USENIX Security Symposium4
2018 Sensitive system calls based packed malware variants detection using principal component initialized MultiLayers neural networks
abstract
Malware detection has become mission sensitive as its threats spread from computer systems to Internet of things systems. Modern malware variants are generally equipped with sophisticated packers, which allow them bypass modern machine learning based detection systems. To detect packed malware variants, unpacking techniques and dynamic malware analysis are the two choices. However, unpacking techniques cannot always be useful since there exist some packers such as private packers which are hard to unpack. Although dynamic malware analysis can obtain the running behaviours of executables, the unpacking behaviours of packers add noisy information to the real behaviours of executables, which has a bad affect on accuracy. To overcome these challenges, in this paper, we propose a new method which first extracts a series of system calls which is sensitive to malicious behaviours, then use principal component analysis to extract features of these sensitive system calls, and finally adopt multi-layers neural networks to classify the features of malware variants and legitimate ones. Theoretical analysis and real-life experimental results show that our packed malware variants detection technique is comparable with the the state-of-art methods in terms of accuracy. Our approach can achieve more than 95.6\% of detection accuracy and 0.048 s of classification time cost.
Jixin Zhang, Kehuan Zhang, Zheng Qin 0001, Hui Yin 0001, Qixin Wu
Cybersecur.2
2018 Accessing mobile user's privacy based on IME personalization: Understanding and practical attacks
abstract
Input Method Editor (IME) is an indispensable component on current smartphones. With its assistance, the number of key presses is reduced, and non-Latin characters could be inputted. Furthermore, modern IMEs integrate several personalized features like reordering suggestion lists and predicting the next words based on user’s input history. Such optimization improves the user experience but turns the IME dictionary into a pool of user privacy. Previous works have discussed the privacy risks coming from malicious IMEs. Indeed, they could cause security and privacy issues if installed by common users, but their impact is limited as the majority of IMEs are well-behaved. However, whether legitimate IMEs are bullet-proof is not answered before. In this paper, we make the first attempt to study the security implications of IME personalization and the back-end infrastructure on Android devices. In the end, we identify a critical vulnerability lying under the Android KeyEvent processing framework, which can be exploited to launch cross-app KeyEvent injection (CAKI) attack and bypass the app-isolation mechanism. By abusing such design flaw, an adversary can harvest entries from the personalized user dictionary of IME through an ostensibly innocuous app only asking for common permissions. Our evaluation over a broad spectrum of Android OSes, devices, and IMEs suggests such issue should be fixed immediately. All Android versions we examined (from very old 2.3.4 to the latest 6.0.1) and most IME apps we surveyed (11 out of 18) are vulnerable. User’s private information, like contact names, location, etc., can be easily exfiltrated. Up to hundreds of millions of mobile users are under this threat. To mitigate this security issue, we propose a practical defense mechanism which augments the existing KeyEvent processing framework without forcing any change to IME apps.
Wenrui Diao, Rui Liu 0002, Zhe Zhou 0001, Zhou Li 0001, Kehuan Zhang
J. Comput. Secur.6
2018 When Privacy Meets Usability: Unobtrusive Privacy Permission Recommendation System for Mobile Apps Based on Crowdsourcing
abstract
People nowadays almost want everything at their fingertips, from business to entertainment, and meanwhile they do not want to leak their sensitive data. Strong information protection can be a competitive advantage, but preserving privacy is a real challenge when people use the mobile apps in the smartphone. If they are too lax with privacy preserving, important or sensitive information could be lost. If they are too tight with privacy, making users jump through endless hoops to access the data they need to get their work done, productivity can nosedive. Thus, striking a balance between privacy and usability in mobile applications can be difficult. Leveraging the privacy permission settings in mobile operating systems, our basic idea to address this issue is to provide proper recommendations about the settings so that the users can preserve their sensitive information and maintain the usability of apps. In this paper, we propose an unobtrusive recommendation system to implement this idea, which can crowdsource users' privacy permission settings and generate the recommendations for them accordingly. Besides, our system allows users to provide feedback to revise the recommendations for getting better performance and adapting different scenarios. For the evaluation, we collected users' preferences from 382 participants on Amazon Technical Turks and released our system to users in the real world for 10 days. According to the study, our system can make appropriate recommendations which can meet participants' privacy expectation and mobile apps' usability.
Rui Liu 0002, Jiannong Cao 0001, Kehuan Zhang, Wenyu Gao, Junbin Liang, Lei Yang 0024
IEEE Trans. Serv. Comput.3
2017 All Your VMs are Disconnected: Attacking Hardware Virtualized Network
abstract
Single Root I/O Virtualization (SRIOV) allows one physical device to be used by multiple virtual machines simultaneously without the mediation from the hypervisor. Such technique significantly decreases the overhead of I/O virtualization. But according to our latest findings, in the meantime, it introduces a high-risk security issue that enables an adversary-controlled VM to cut off the connectivity of the host machine, given the limited filtering capabilities provided by the SRIOV devices.
Zhe Zhou 0001, Zhou Li 0001, Kehuan Zhang
CODASPY3
2017 Picking Up My Tab: Understanding and Mitigating Synchronized Token Lifting and Spending in Mobile Payment
Xiaolong Bai, Zhe Zhou 0001, XiaoFeng Wang 0001, Zhou Li 0001, Xianghang Mi, Nan Zhang 0018, Tongxin Li 0002, Shi-Min Hu 0001, Kehuan Zhang
USENIX Security Symposium9
2017 Vulnerable GPU Memory Management: Towards Recovering Raw Data from GPU
abstract
Abstract According to previous reports, information could be leaked from GPU memory; however, the security implications of such a threat were mostly over-looked, because only limited information could be indirectly extracted through side-channel attacks. In this paper, we propose a novel algorithm for recovering raw data directly from the GPU memory residues of many popular applications such as Google Chrome and Adobe PDF reader. Our algorithm enables harvesting highly sensitive information including credit card numbers and email contents from GPU memory residues. Evaluation results also indicate that nearly all GPU-accelerated applications are vulnerable to such attacks, and adversaries can launch attacks without requiring any special privileges both on traditional multi-user operating systems, and emerging cloud computing scenarios.
Zhe Zhou 0001, Wenrui Diao, Zhou Li 0001, Kehuan Zhang, Rui Liu 0002
Proc. Priv. Enhancing Technol.5
2016 On Code Execution Tracking via Power Side-Channel
abstract
With the proliferation of Internet of Things, there is a growing interest in embedded system attacks, e.g., key extraction attacks and firmware modification attacks. Code execution tracking, as the first step to locate vulnerable instruction pieces for key extraction attacks and to conduct control-flow integrity checking against firmware modification attacks, is therefore of great value. Because embedded systems, especially legacy embedded systems, have limited resources and may not support software or hardware update, it is important to design low-cost code execution tracking methods that require as little system modification as possible. In this work, we propose a non-intrusive code execution tracking solution via power-side channel, wherein we represent the code execution and its power consumption with a revised hidden Markov model and recover the most likely executed instruction sequence with a revised Viterbi algorithm. By observing the power consumption of the microcontroller unit during execution, we are able to recover the program execution flow with a high accuracy and detect abnormal code execution behavior even when only a single instruction is modified.
Yannan Liu, Lingxiao Wei, Zhe Zhou 0001, Kehuan Zhang, Wenyuan Xu 0001, Qiang Xu 0001
CCS4
2016 Model-based Security Testing: An Empirical Study on OAuth 2.0 Implementations
abstract
Motivated by the prevalence of OAuth-related vulnerabilities in the wild, large-scale security testing of real-world OAuth 2.0 implementations have received increasing attention lately [31,37,42]. However, these existing works either rely on manual discovery of new vulnerabilities in OAuth 2.0 implementations or perform automated testing for specific, previously-known vulnerabilities across a large number of OAuth implementations. In this work, we propose an adaptive model-based testing framework to perform automated, large-scale security assessments for OAuth 2.0 implementations in practice. Key advantages of our approach include (1) its ability to identify existing vulnerabilities and discover new ones in an automated manner; (2) improved testing coverage as all possible execution paths within the scope of the model will be checked and (3) its ability to cater for the implementation differences of practical OAuth systems/ applications, which enables the analyst to offload the manual efforts for large-scale testing of OAuth implementations. We have designed and implemented OAuthTester to realize our proposed framework. Using OAuthTester, we examine the implementations of 4 major Identity Providers as well as 500 top-ranked US and Chinese websites which use the OAuth-based Single-Sign-On service provided by the formers. Our empirical findings demonstrate the efficacy of adaptive model-based testing on OAuth 2.0 deployments at scale. More importantly, OAuthTester not only manages to rediscover various existing vulnerabilities but also identify several previously unknown security flaws and new exploits for a large number of eal-world applications implementing OAuth 2.0.
Ronghai Yang, Wing Cheong Lau, Kehuan Zhang, Pili Hu
AsiaCCS4
2016 Efficient Authenticated Multi-Pattern Matching
abstract
Multi-pattern matching compares a large set of patterns against a given query string, which has wide application in various domains such as bio-informatics and intrusion detection. This paper shows how to authenticate the classic Aho-Corasick multi-pattern matching automation, without requiring the verifier to store the whole pattern set, nor downloading a proof for every single matching step. The storage complexity for the authentication metadata at the server side is the same as that of the unauthenticated version. The communication overhead is minimal since the proof size is linear in the query length and does not grow with the sizes of query result nor the pattern set. Our evaluation has shown that the query and verification times are practical.
Zhe Zhou 0001, Tao Zhang 0014, Sherman S. M. Chow, Yupeng Zhang 0001, Kehuan Zhang
AsiaCCS5
2016 No Pardon for the Interruption: New Inference Attacks on Android Through Interrupt Timing Analysis
abstract
Many new specialized hardware components have been integrated into Android smartphones to improve mobility and usability, such as touchscreen, Bluetooth module, and NFC controller. At the system level, the kernel of Android is built on Linux and inherits its device management mechanisms. However, the security implications surfaced from the integration of new hardware components and the tailored Linux kernel are not fully understood. In this paper, we make the first attempt to evaluate such implications. As a result, we identify a critical information leakage channel from the interrupt handling mechanism, which can be exploited to launch inference attacks without any permission. On Android, all reported interrupts are counted by Linux kernel and the statistical information is logged in a system file /proc/interrupts, which is public to any process. Such statistical information reveals the running status of all integrated devices, and could be exploited by attackers to infer sensitive information passing through them. To assess this new threat, we propose a general attack approach -- interrupt timing analysis and apply it to interrupt logs. As showcases, we present two concrete inference attacks against user's unlock pattern and foreground app status respectively. Through analyzing the interrupt time series produced from touchscreen controller, attacker's chance of cracking user's unlock pattern is increased substantially. The interrupt time series produced from Display Sub-System reveals unique UI refreshing patterns and could be leveraged as fingerprints to identify the app running in the foreground. Such information can serve as the stepping stone for the subsequent phishing attacks. The experiment results suggest our inference attacks are highly effective, and the risks should be mitigated immediately.
Wenrui Diao, Zhou Li 0001, Kehuan Zhang
IEEE Symposium on Security and Privacy4
2016 The Ever-Changing Labyrinth: A Large-Scale Analysis of Wildcard DNS Powered Blackhat SEO
Kun Du, Zhou Li 0001, Hai-Xin Duan, Kehuan Zhang
USENIX Security Symposium5
2016 Evading Android Runtime Analysis Through Detecting Programmed Interactions
abstract
Dynamic analysis technique has been widely used in Android malware detection. Previous works on evading dynamic analysis focus on discovering the fingerprints of emulators. However, such method has been challenged since the introduction of real devices in recent works. In this paper, we propose a new approach to evade automated runtime analysis through detecting programmed interactions. This approach, in essence, tries to tell the identity of the current app controller (human user or automated exploration tool), by finding intrinsic differences between human user and machine tester in interaction patterns. The effectiveness of our approach has been demonstrated through evaluation against 11 real-world online dynamic analysis services.
Wenrui Diao, Zhou Li 0001, Kehuan Zhang
WISEC4
2015 When Good Becomes Evil: Keystroke Inference with Smartwatch
abstract
One rising trend in today's consumer electronics is the wearable devices, e.g., smartwatches. With tens of millions of smartwatches shipped, however, the security implications of such devices are not fully understood. Although previous studies have pointed out some privacy concerns about the data that can be collected, like personalized health information, the threat is considered low as the leaked data is not highly sensitive and there is no real attack implemented. In this paper we investigate a security problem coming from sensors in smartwatches, especially the accelerometer. The results show that the actual threat is much beyond people's awareness. Being worn on the wrist, the accelerometer built within a smartwatch can track user's hand movements, which makes inferring user inputs on keyboards possible in theory. But several challenges need to be addressed ahead in the real-world settings: e.g., small and irregular hand movements occur persistently during typing, which degrades the tracking accuracy and sometimes even overwhelms useful signals.
Zhe Zhou 0001, Wenrui Diao, Zhou Li 0001, Kehuan Zhang
CCS5
2015 Mind-Reading: Privacy Attacks Exploiting Cross-App KeyEvent Injections
Wenrui Diao, Zhe Zhou 0001, Kehuan Zhang, Zhou Li 0001
ESORICS (2)4
2015 An Empirical Study on Android for Saving Non-shared Data on Public Storage
Zhe Zhou 0001, Wenrui Diao, Zhou Li 0001, Kehuan Zhang
SEC5
2014 Acoustic Fingerprinting Revisited: Generate Stable Device ID Stealthily with Inaudible Sound
abstract
The popularity of mobile devices has made people's lives more convenient, but threatened people's privacy at the same time. As end users are becoming more and more concerned on the protection of their private information, it is even harder for hackers to track a specific user by using conventional technologies. For example, cookies might be cleared by users regularly. Besides, OS designers have developed a series of measures to cope with tracker. Apple has stopped apps accessing UDIDs, and Android phones use some special permissions to protect IMEI code. However, some recent studies showed that attackers are able to find new ways to get around those limitations, even though these new methods should be improved in order to be practically deployed in large scale. For example, attackers can trace smart phones by using the hardware features resulting from the imperfect manufacturing process of accelerometers. In this paper, we will present another new and more practical method for the adversaries to generate stable and unique device ID stealthily for the smartphone by exploiting the frequency response of the speaker. With carefully selected audio frequencies and special sound wave patterns, we can reduce the impact of non-linear effects and noises, and keep our feature extraction process un-noticeable to phone owners. The extracted feature is not only very stable for a given smart phone, but also unique to that phone. The feature contains rich information, which is even enough to differentiate millions of smart phones of the same model. We have built a prototype to evaluate our method, and the results show that the generated device ID can be used to track users practically.
Zhe Zhou 0001, Wenrui Diao, Kehuan Zhang
CCS4
2012 Knowing your enemy: understanding and detecting malicious web advertising
abstract
With the Internet becoming the dominant channel for marketing and promotion, online advertisements are also increasingly used for illegal purposes such as propagating malware, scamming, click frauds, etc. To understand the gravity of these malicious advertising activities, which we call malvertising, we perform a large-scale study through analyzing ad-related Web traces crawled over a three-month period. Our study reveals the rampancy of malvertising: hundreds of top ranking Web sites fell victims and leading ad networks such as DoubleClick were infiltrated.
Zhou Li 0001, Kehuan Zhang, Yinglian Xie, Fang Yu 0002, XiaoFeng Wang 0001
CCS2
2011 Sedic: privacy-aware data intensive computing on hybrid clouds
abstract
The emergence of cost-effective cloud services offers organizations great opportunity to reduce their cost and increase productivity. This development, however, is hampered by privacy concerns: a significant amount of organizational computing workload at least partially involves sensitive data and therefore cannot be directly outsourced to the public cloud. The scale of these computing tasks also renders existing secure outsourcing techniques less applicable. A natural solution is to split a task, keeping the computation on the private data within an organization's private cloud while moving the rest to the public commercial cloud. However, this hybrid cloud computing is not supported by today's data-intensive computing frameworks, MapReduce in particular, which forces the users to manually split their computing tasks. In this paper, we present a suite of new techniques that make such privacy-aware data-intensive computing possible. Our system, called Sedic, leverages the special features of MapReduce to automatically partition a computing job according to the security levels of the data it works on, and arrange the computation across a hybrid cloud. Specifically, we modified MapReduce's distributed file system to strategically replicate data, moving sanitized data blocks to the public cloud. Over this data placement, map tasks are carefully scheduled to outsource as much workload to the public cloud as possible, given sensitive data always stay on the private cloud. To minimize inter-cloud communication, our approach also automatically analyzes and transforms the reduction structure of a submitted job to aggregate the map outcomes within the public cloud before sending the result back to the private cloud for the final reduction. This also allows the users to interact with our system in the same way they work with MapReduce, and directly run their legacy code in our framework. We implemented Sedic on Hadoop and evaluated it using both real and synthesized computing jobs on a large-scale cloud test-bed. The study shows that our techniques effectively protect sensitive user data, offload a large amount of computation to the public cloud and also fully preserve the scalability of MapReduce.
Kehuan Zhang, Xiao-yong Zhou, Yangyi Chen, XiaoFeng Wang 0001, Yaoping Ruan
CCS1
2011 Soundcomber: A Stealthy and Context-Aware Sound Trojan for Smartphones
Roman Schlegel, Kehuan Zhang, Xiao-yong Zhou, Mehool Intwala, Apu Kapadia, XiaoFeng Wang 0001
NDSS2
2010 Sidebuster: automated detection and quantification of side-channel leaks in web application development
abstract
A web application is a "two-part" program, with its components deployed both in the browser and in the web server. The communication between these two components inevitably leaks out the program's internal states to those eavesdropping on its web traffic, simply through the side channel features of the communication such as packet length and timing, even if the traffic is entirely encrypted. Our recent study shows that such side-channel leaks are both fundamental and realistic: a set of popular web applications are found to disclose highly sensitive user data such as one's family incomes, health profiles, investment secrets and more through their side channels. Our study also shows that an significant improvement of the current web-application development practice is necessary to mitigate this threat. To answer this urgent call, we present in this paper a suite of new techniques for automatic detection and quantification of side-channel leaks in web applications. Our approach, called Sidebuster, can automatically analyze an application's source code to detect its side channels and then perform a rerun test to assess the amount of information disclosed through such channels (quantified as the entropy loss). Sidebuster has been designed to work on event-driven applications and can effectively handle the AJAX GUI widgets used in most web applications. In our research, we implemented a prototype of our technique for analyzing GWT applications and evaluated it using complicated web applications. Our study shows that Sidebuster can effectively identify the side-channel leaks in these applications and assess their severity, with a small overhead.
Kehuan Zhang, Zhou Li 0001, Rui Wang 0010, XiaoFeng Wang 0001, Shuo Chen 0001
CCS1
2010 Mash-IF: Practical information-flow control within client-side mashups
abstract
Mashup is a representative of Web 2.0 technology that needs both convenience of cross-domain access and protection against the security risks it brings in. Solutions proposed by prior research focused on mediating access to the data in different domains, but little has been done to control the use of the data after the access. In this paper, we present Mash-IF, a new technique for information-flow control within mashups. Our approach allows cross-domain communications within a browser, but disallows disclosure of sensitive information to remote parties without the user's permission. It mediates the cross-domain channels in existing mashups and works on the client without collaborations from other parties. Also of particular interest is a novel technique that automatically generates declassification rules for a script by statically analyzing its code. Such rules can be efficiently enforced through monitoring the script's call sequences and DOM operations.
Zhou Li 0001, Kehuan Zhang, XiaoFeng Wang 0001
DSN2
2010 Side-Channel Leaks in Web Applications: A Reality Today, a Challenge Tomorrow
abstract
With software-as-a-service becoming mainstream, more and more applications are delivered to the client through the Web. Unlike a desktop application, a web application is split into browser-side and server-side components. A subset of the application's internal information flows are inevitably exposed on the network. We show that despite encryption, such a side-channel information leak is a realistic and serious threat to user privacy. Specifically, we found that surprisingly detailed sensitive information is being leaked out from a number of high-profile, top-of-the-line web applications in healthcare, taxation, investment and web search: an eavesdropper can infer the illnesses/medications/surgeries of the user, her family income and investment secrets, despite HTTPS protection; a stranger on the street can glean enterprise employees' web search queries, despite WPA/WPA2 Wi-Fi encryption. More importantly, the root causes of the problem are some fundamental characteristics of web applications: stateful communication, low entropy input for better interaction, and significant traffic distinctions. As a result, the scope of the problem seems industry-wide. We further present a concrete analysis to demonstrate the challenges of mitigating such a threat, which points to the necessity of a disciplined engineering practice for side-channel mitigations in future web application developments.
Shuo Chen 0001, Rui Wang 0010, XiaoFeng Wang 0001, Kehuan Zhang
IEEE Symposium on Security and Privacy4
2009 Peeping Tom in the Neighborhood: Keystroke Eavesdropping on Multi-User Systems
Kehuan Zhang, XiaoFeng Wang 0001
USENIX Security Symposium1
2008 Towards automatic reverse engineering of software security configurations
abstract
The specifications of an application's security configuration are crucial for understanding its security policies, which can be very helpful in security-related contexts such as misconfiguration detection. Such specifications, however, are often ill-documented, or even close because of the increasing use of graphic user interfaces to set program options. In this paper, we propose ConfigRE, a new technique for automatic reverse engineering of an application's access-control configurations. Our approach first partitions a configuration input into fields, and then identifies the semantic relations among these fields and the roles they play in enforcing an access control policy. Based upon such knowledge, ConfigRE automatically generates a specification language to describe the syntactic relations of these fields. The language can be converted into a scanner using standard parser generators for scanning configuration files and discovering the security policies specified in an application. We implemented ConfigRE in our research and evaluated it against real applications. The experiment results demonstrate the efficacy of our approach.
Rui Wang 0010, XiaoFeng Wang 0001, Kehuan Zhang, Zhuowei Li 0001
CCS3