EDBT 2026 Demo / reviewers in the wild / expert
Song Li 0006
dblp:67/2580-6
· DBLP profile ↗
25ranked-venue papers
3as first author
21since 2021 · last 2026
0000-0002-7961-8502ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 1 first-author · 10 since 2021Software engineering, systems software and programming languages · 6 · 1 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RlDecompiler: Enhancing LLM-based Decompilation via Reinforcement Learning with a Multi-Faceted Reward FunctionabstractDecompiling binary code into human-readable, high-level source code is a core challenge in reverse engineering. While traditional methods often rely on brittle, pattern-based heuristics, the advent of Large Language Models (LLMs) offers a more flexible and robust approach. However, current LLM-based decompilation efforts are often limited by their training methodologies, which typically treat the task as a simple sequence-to-sequence translation and struggle to enforce the functional correctness of the output. To address these issues, this paper proposes an innovative framework for training LLMs to perform high-fidelity decompilation. A core contribution of our work is a novel data processing pipeline that enriches the model’s input. This pipeline integrates Ghidra-based static analysis to directly embed crucial context, such as static resources (strings, floating-point numbers) and relabeled basic blocks—from the binary into an LLM-friendly prompt. Building on this enriched input, we employ reinforcement learning fine-tuning guided by a multi-faceted reward function that comprehensively evaluates syntactic correctness, AST similarity, compilability, and functional correctness via test cases. Using this framework, we trained the RlDecompiler family of models (1.3B and 3B). Experimental results demonstrate that RlDecompiler achieves state-of-the-art performance, and its generated code quality is also higher than that of the baseline models. The RlDecompiler 1.3B and 3B models achieve rerunnable rates of 27.96% and 40.70%, respectively, outperforming existing baselines. The code is available at https://github.com/ri-char/rldecompile. Yuchi Su, Weina Niu, Jiacheng Gong, Song Li 0006, Xin Liu 0050, Xiaosong Zhang 0001 |
ICPC | 5 |
| 2026 | Practical Covert Channel Across Isolated Browser Instances via GPU Command Queue Contention
Jinhong Liu, Zifeng Kang, Song Li 0006, Yinzhi Cao |
SP | 3 |
| 2026 | Towards a comprehensive framework for verifying open-source software license compatibility
Ziang Liu 0006, Xin Liu 0050, Yingli Zhang, Song Li 0006, Weina Niu, Qingguo Zhou, Rui Zhou 0005, Xiaokang Zhou |
Empir. Softw. Eng. | 4 |
| 2025 | LLM-SZZ: Novel Vulnerability-Inducing Commit Identification Driven by Large Language Model and CVE DescriptionabstractThe SZZ method and its variants are widely employed to identify vulnerability-affected ranges by analyzing vulnerability-fixing commits to trace back vulnerability-inducing commits. However, these methods generally suffer from low precision due to several key factors: 1) Current static method-based variants often incorrectly consider too many irrelevant lines and files in a commit. While methods that extract file references from vulnerability discussions can help narrow down relevant files, obtaining bug discussions for every CVE is often difficult. 2) Learning-based approaches focus exclusively on code to capture semantic relationships for identifying root cause lines. However, these models utilize limited information and demonstrate insufficient capacity for effective capture. 3) The reliance on line mapping algorithms results in inadequate tracing capabilities for complex vulnerabilities, especially when vulnerability-inducing commits are obscured in earlier software versions. To address these issues, this paper innovatively incorporates semantic information from descriptive text and the nature of CVEs derived from vulnerability-fixing commit diffs. By leveraging large language models (LLMs), this approach aims to capture the true root cause lines of vulnerabilities more accurately and enhance the tracing capabilities of the SZZ method, thereby achieving precise localization of the vulnerability impact range. Experimental results indicate that our proposed LLM-SZZ method outperforms existing state-of-the-art approaches, achieving over a 18 % increase in precision across datasets in various programming languages, demonstrating a significant performance advantage. Siqi Fan 0005, Xin Liu 0050, Yingli Zhang, Yuan Tan 0003, Luxing Yin, Zhaorun Chen, Song Li 0006, Rui Zhou 0005 |
ICSME | 7 |
| 2025 | ISGraphVD: Precise Vulnerability Detection for IoT Supply Chains Based on Identifier Sensitive GraphabstractOpen-source software (OSS) is widely reused in Internet of Things (IoT) devices, leading to widespread N-Day vulnerabilities when outdated components remain unpatched. Existing methods typically encode features of different Common Vulnerabilities and Exposures (CVEs) within a shared representation space. However, the model’s limited capacity, combined with the new vulnerability features, can disrupt previously learned patterns. Minimal code modifications in tiny-patch vulnerabilities are often overshadowed by variations introduced by different compilation settings, making it more difficult to distinguish vulnerable functions from their patched counterparts. This paper introduces ISGraphVD, a novel graph-based and function-level vulnerability detection approach that supports cross-compilation settings and enhances detection accuracy. By modeling each CVE independently through a one-model-per-CVE strategy, ISGraphVD reduces feature interference and improves detection accuracy across diverse CVEs. To better detect tinypatch vulnerability, we propose ISGraph, a fine-grained graph representation that models variable dependencies within and across basic blocks by integrating control flow analysis. Then, ISGraphVD utilizes a Graph Matching Network (GMN) with a cross-graph attention mechanism to identify critical vulnerability patterns. Experiments on IoT OSS projects show that ISGraphVD outperforms state-of-the-art methods, achieving a 6.3 percentage-point (pp) accuracy improvement over the strongest baseline, and real-world tests further validate its effectiveness in IoT supply chains. Yingli Zhang, Xin Liu 0050, Ziang Liu 0006, Song Li 0006, Weina Niu, Rui Zhou 0005, Qingguo Zhou |
ISSRE | 4 |
| 2025 | SiFMimicEvader: Evading Fake Voice Detection with Adversarial Neural Mimicry AttacksabstractThe application of deep learning in voice cloning has significantly enhanced the quality of cloned voices. While advanced voice cloning technologies are widely applied across various domains, they also pose serious security challenges such as producing natural Deepfakes. In response, numerous studies have focused on detecting fake voices, with many reporting outstanding performance. However, is the issue truly resolved? This paper introduces Adversarial Neural Mimicry Attack (ANMA) which leverages a specialized model to predict the behavior of other similar models, transforming black-box attacks into white-box scenarios indirectly. Based on ANMA and Speaker-irrelative Features (SiFs), we propose a novel black-box attack framework called SiFMimicEvader, designed to evade fake voice detectors with high success rates and minimal query requirements. The framework utilizes speech representation models as the breakthrough to predict the behaviors of fake voice detectors and employs a series of SiFs editing operations as perturbations to deceive these detectors. Experimental results demonstrate the effectiveness of SiFMimicEvader, achieving an average attack success rate exceeding 50% across various detectors, significantly outperforming other attack methods, while also showing great performance in audio quality and query scale, indicating its high availability in real-world scenarios. Xuan Hai, Xin Liu 0050, Ziyao Yu, Song Li 0006, Weina Niu, Rui Zhou 0005, Qingguo Zhou |
ACM Multimedia | 6 |
| 2025 | Follow My Flow: Unveiling Client-Side Prototype Pollution Gadgets from One Million Real-World WebsitesabstractPrototype pollution vulnerability often has further consequences—such as Cross-site Scripting (XSS) and cookie manipulation—that are achieved via so-called gadgets, i.e., code snippets that change the control- or data-flow of a victim program for malicious purposes. Prior works face challenges in finding prototype pollution gadgets for such consequences because the control- or data-flow change sometimes needs the injection of complex property values to replace existing undefined ones through prototype pollution, which may not be seen before or cannot be solved by existing constraint solvers. In this paper, we design a dynamic analysis framework, called Gala, to automatically detect client-side prototype pollution gadgets among real-world websites, and implement an open-source version of Gala. Our key insight is to borrow existing defined values on non-vulnerable websites to victim ones where such values are undefined, thus guiding the property injection to flow to the sinks in gadgets. Our evaluation of Gala against one-million websites reveals 133 zero-day gadgets that are not found by prior works. For example, one gadget was from Meta's software and another from the Vue framework. Both have acknowledged and fixed it, with Meta rewarding us a bug bounty and Vue assigning CVE-2024-6783. Our evaluation also shows that 23 websites with prototype pollution vulnerabilities—which do not have further consequences as reported by prior works—have consequences due to gadgets found by Gala. In addition to the Meta and Vue gadgets, we also responsibly disclosed all the zero-day gadgets and those newly-discovered prototype pollution consequences to their developers. Zifeng Kang, Muxi Lyu, Jianjia Yu, Runqi Fan, Song Li 0006, Yinzhi Cao |
SP | 6 |
| 2025 | SigScope: Detecting and Understanding Off-Chain Message Signing-related Vulnerabilities in Decentralized ApplicationsabstractIn Web 3.0, an emerging paradigm of building decentralized applications or DApps is off-chain message signing, which has advantages in performance, cost efficiency, and usability compared to conventional transaction-signing schemes. However, message signing burdens DApp developers with extra coding complexity and message designing, leading to new security risks. Sajad Meisami, Hugo Dabadie, Song Li 0006, Yuzhe Tang, Yue Duan |
WWW | 3 |
| 2025 | BPFDex: Enabling Robust Android Apps Unpacking via Android KernelabstractMalware developers exploit packing techniques to protect malicious apps from analysis. These evolving techniques, coupled with diverse anti-unpacker strategies, often render current studies ineffective in unpacking Android apps. In this study, we introduce BPFDex, a novel Android unpacking framework that leverages eBPF, a kernel component of the Android system. We successfully apply eBPF’s excellent kernel observability and tracing capability to Android unpacking, both on real devices and emulators. Operating within the kernel space, BPFDex avoids drawbacks of common unpacking techniques. BPFDex monitors apps across both native and kernel layers, restores Dex data from memory, and adapts to different packing strategies according to observed packing behaviors. Furthermore, we summarize patterns in anti-unpacker behaviors among Android packers, establishing criteria to improve existing unpacking strategies. We conduct extensive experiments on BPFDex by leveraging more than 3k apps packed by over eight different packers. The results demonstrate that BPFDex successfully bypasses anti-unpacker strategies and unpacks apps packed by various packers, in contrast to other unpackers that can handle at most two packers. Weina Niu, Jiacheng Gong, Song Li 0006, Mingxue Zhang 0001, Xiaosong Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | SQLStateGuard: Statement-Level SQL Injection Defense Based on Learning-Driven MiddlewareabstractSQL injection is a significant and persistent threat to web services. Most existing protections against SQL injections rely on traffic-level anomaly detection, which often results in high false-positive rates and can be easily bypassed by attackers. This paper introduces SQLStateGuard, the world's first middleware-driven statement-level SQL injection defense approach, to address these issues. The SQLStateGuard uses a custom SQL middleware based on the idea of Runtime Application Self-Protection to capture raw SQL statements. These statements are then analyzed by SQLSG-Net, a database-oriented detection network based on gated linear units. If SQLSG-Net detects malicious SQL statements, the SQL middleware will block them. Experiments show that the detection accuracy of SQLStateGuard exceeds 99%, outperforming existing approaches, and it can identify the type of a specific SQL injection. Additionally, SQLStateGuard has no fingerprint and does not respond to SQL syntax errors, making it more challenging for attackers to gather information. This paper also presents a novel dataset generation process for SQLStateGuard and shares two statement-level SQL injection datasets with the research community, including over 145,000 malicious SQL statements categorized by the type of SQL injection. Xin Liu 0050, Song Li 0006, Weina Niu, Jun Shen 0001, Qingguo Zhou, Xiaokang Zhou |
SoCC | 4 |
| 2024 | Ghost-in-Wave: How Speaker-Irrelative Features Interfere DeepFake Voice DetectorsabstractRecent speech synthesis technology can generate high-quality speech indistinguishable from human speech, thus introducing various security and privacy risks. Numerous recent studies have focused on fake voice detection to address these risks, with many claiming to achieve ideal performance. However, is this really the case? A recent research work introduced Speaker-Irrelative-Features (SiFs), unrelated to the information in speech files but capable of influencing fake detectors. This means that existing detectors may rely on SiFs to a certain extent to distinguish real and fake speech. In this paper, we introduce an evaluation framework to evaluate the influence of SiFs in existing fake voice detectors in depth. We evaluate three SiFs which include background noise, the mute parts before and after voice, and the sampling rate on ASVspoof2019 and FoR. Our results confirm the substantial influence of SiFs on fake voice detection performance, and we delve into the analysis of the underlying mechanisms. Xuan Hai, Xin Liu 0050, Zhaorun Chen, Yuan Tan 0003, Song Li 0006, Weina Niu, Rui Zhou 0005, Qingguo Zhou |
ICME | 5 |
| 2024 | LiScopeLens: An Open-Source License Incompatibility Analysis Tool Based on Scope Representation of License TermsabstractOpen-source software has emerged as a pivotal force in the advancement of information technology. Robust open-source compliance governance is essential for the sustainable and healthy growth of both open-source software and its communities. License incompatibility analysis, in particular, represents a critical challenge hindering the progress of open-source software. Traditional methods of incompatibility analysis often fail to account for diverse usage scenarios or are tailored to a limited subset of scenarios. This limitation obstructing their ability to handle the intricate compatibility arising from varied programming language interactions, leading to a high false positives. Our study embarks from an examination of license exceptions, delving into the incompatibility analysis challenges through extensive empirical research on these exceptions. We discovered that the majority of exceptions are, in fact, detectable. Leveraging this empirical insight, our research further develops the license compatibility analysis model by introducing a new, refined legal terminology representation alongside a novel method for license compatibility reasoning. This approach begins with modeling different scenarios to represent license compatibility variably. Furthermore, based on these modeling outcomes, we have designed and implemented LiScopeLens, a tool capable of discerning dependency behaviors for granular compatibility assessment, starting with binary dependencies. Our experimental findings affirm that LiScopeLens proficiently determines the license compatibility status of open-source software across various usage scenarios, demonstrating its significant practical utility. Ziang Liu 0006, Xin Liu 0050, Yingli Zhang, Song Li 0006, Weina Niu, Qingguo Zhou, Rui Zhou 0005, Xiaokang Zhou |
ISSRE | 5 |
| 2024 | What's the Real: A Novel Design Philosophy for Robust AI-Synthesized Voice DetectionabstractVoice is one of the most widely used media for information transmission in human society. While high-quality synthetic voices are extensively utilized in various applications, they pose significant risks to content security and trust building. Numerous studies have concentrated on AI-synthesized voice detection to mitigate these risks, with many claiming to achieve promising performance. However, recent research has demonstrated that fake voice detectors suffer from serious overfitting to speaker-irrelative features (SiFs) and cannot be used in real-world scenarios. In this paper, we analyze the limitations of existing fake voice detectors and propose a new design philosophy, guiding the detection model to prioritize learning human voice features rather than the difference between the human voice and the synthetic voice. Based on this philosophy, we propose a novel AI-synthesized voice detection framework named SiFSafer, which uses pre-trained speech representation models to enhance the learning of feature distribution in human voices and the adapter fine-tuning to optimize the performance. The evaluation shows that the average EERs of existing fake voice detectors in the ASVspoof datasets can exceed 20% if the SiFs like silence segments are removed, while SiFSafer achieves an EER of less than 8%, indicating that SiFSafer is robust to SiFs and strongly resistant to existing attacks. Xuan Hai, Xin Liu 0050, Yuan Tan 0003, Song Li 0006, Weina Niu, Rui Zhou 0005, Xiaokang Zhou |
ACM Multimedia | 5 |
| 2024 | GraphTunnel: Robust DNS Tunnel Detection Based on DNS Recursive Resolution GraphabstractDNS tunnels, due to their versatility and concealment, have become a preferred method for attackers to execute Command and Control (C&C) attacks, posing a significant security threat to terminal devices. Therefore, the efficient and accurate detection of DNS tunnels is important in reducing the economic losses and privacy risks faced by both enterprises and individuals. Despite notable advancements in the research of intelligent detection of DNS tunnels, existing model-based approaches predominantly concentrate on the surface-level features of domain names or packet payloads. This narrow focus leads to low detection accuracy when dealing with unknown DNS tunnel attacks and traffic from wildcard DNS. Furthermore, these methods struggle with accurately identifying DNS tunneling tools, complicating the task of swiftly locating and mitigating malware for analysts. This paper proposes GraphTunnel, a framework based on graph neural networks for detecting DNS tunnels and identifying tunneling tools. It delves into the correlations among DNS resolutions to construct paths that represent the recursive resolution process of DNS. By using central nodes that denote the gateways, these paths are connected and transformed into graph structures. Concurrently, it employs GraphSage to aggregate the features of nodes and their edges in the graph, enabling effective detection of DNS tunnels. Additionally, GraphTunnel utilizes the G2M algorithm to capture the statistical features of nodes in the graph and maps them into grayscale images, which are then processed by a CNN for multi-class identification of DNS tunneling tools. Experimental results demonstrate that in non-wildcard DNS scenarios, GraphTunnel achieves a 100% accuracy in DNS tunnel detection, encompassing unknown DNS tunnels. Even in high false-positive environments caused by wildcard DNS, GraphTunnel maintains an F1-Score of 99.78%. Moreover, GraphTunnel can identify DNS tunneling tools with an accuracy rate exceeding 98.57%, enhancing the rapid mitigation capabilities of emergency responders in dealing with malicious DNS tunnels. Guangyuan Gao, Weina Niu, Jiacheng Gong, Dujuan Gu, Song Li 0006, Mingxue Zhang 0001, Xiaosong Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Sensitive Behavioral Chain-Focused Android Malware Detection Fused With AST SemanticsabstractThe proliferation of Android malware poses a substantial security threat to mobile devices. Thus, achieving efficient and accurate malware detection and malware family identification is crucial for safeguarding users’ individual property and privacy. Graph-based approaches have demonstrated remarkable detection performance in the realm of intelligent Android malware detection methods. This is attributed to the robust representation capabilities of graphs and the rich semantic information. The function call graph (FCG) is the most widely used graph in intelligent Android malware detection. However, existing FCG-based malware detection methods face challenges, such as the enormous computational and storage costs of modeling large graphs. Additionally, the ignorance of code semantics also makes them susceptible to structured attacks. In this paper, we proposed AndroAnalyzer, which embeds abstract syntax tree (AST) code semantics while focusing on sensitive behavior chains. It leverages FCGs to represent the macroscopic behavior of the application, and employs structured code semantics to represent the microscopic behavior of functions. Furthermore, we proposed the sensitive function call graph (SFCG) generation algorithm to narrow down the analysis scope to sensitive function calls, and the AST vectorization algorithm (AST2Vec) to capture structured code semantics. Experimental results demonstrate that the proposed SFCG generation algorithm noticeably reduces graph size while ensuring robust detection performance. AndroAnalyzer outperforms the baseline methods in binary and multiclass classification tasks, achieving F1-scores of 99.21% and 98.45% respectively. Moreover, AndroAnalyzer (trained with samples of 2010-2018) exhibits good generalization capabilities in detecting samples of 2019-2022. Jiacheng Gong, Weina Niu, Song Li 0006, Mingxue Zhang 0001, Xiaosong Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | CoCo: Efficient Browser Extension Vulnerability Detection via Coverage-guided, Concurrent Abstract InterpretationabstractExtensions complement web browsers with additional functionalities and also bring new vulnerability venues, allowing privilege escalations from adversarial web pages to use extension APIs. Prior works on extension vulnerability detection adopt classic static analysis, which is unable to handle dynamic JavaScript features such as those function calls as part of array lookups. At the same time, prior abstract interpretation focuses on lightweight server-side JavaScript, which often cannot scale to client-side extension code due to object explosions in the abstract domain. Jianjia Yu, Song Li 0006, Junmin Zhu, Yinzhi Cao |
CCS | 2 |
| 2023 | Scaling JavaScript Abstract Interpretation to Detect and Exploit Node.js Taint-style VulnerabilityabstractTaint-style vulnerabilities, such as OS command injection and path traversal, are common and severe software weaknesses. There exists an inherent trade-off between analysis scalability and accuracy in detecting such vulnerabilities. On one hand, existing syntax-directed approaches often make compromises in the analysis accuracy on dynamic features like bracket syntax. On the other hand, existing abstract interpretation often faces the issue of state explosion in the abstract domain, thus leading to a scalability problem.In this paper, we present a novel approach, called FAST, to scale the vulnerability discovery of JavaScript packages via a novel abstract interpretation approach that relies on two new techniques, called bottom-up and top-down abstract interpretation. The former abstractly interprets functions based on scopes instead of call sequences to construct dynamic call edges. Then, the latter follows specific control-flow paths and prunes the program to skip statements unrelated to the sink. If an end-to-end data-flow path is found, FAST queries the satisfiability of constraints along the path and verifies the exploitability to reduce human efforts.We implement a prototype of FAST and evaluate it against real-world Node.js packages. We show that FAST is able to find 242 zero-day vulnerabilities in NPM with 21 CVE identifiers being assigned. Our evaluation also shows that FAST can scale to real-world applications such as NodeBB and popular frameworks such as total.js and strapi in finding legacy vulnerabilities that no prior works can. Mingqing Kang, Yichao Xu, Song Li 0006, Rigel Gjomemo, Jianwei Hou, V. N. Venkatakrishnan, Yinzhi Cao |
SP | 3 |
| 2022 | GraphTrack: A Graph-based Cross-Device Tracking FrameworkabstractCross-device tracking has drawn growing attention from both commercial companies and the general public because of its privacy implications and applications for user profiling, personalized services, etc. One particular, wide-used type of cross-device tracking is to leverage browsing histories of user devices, e.g., characterized by a list of IP addresses used by the devices and domains visited by the devices. However, existing browsing history based methods have three drawbacks. First, they cannot capture latent correlations among IPs and domains. Second, their performance degrades significantly when labeled device pairs are unavailable. Lastly, they are not robust to uncertainties in linking browsing histories to devices. Binghui Wang, Song Li 0006, Yinzhi Cao, Neil Zhenqiang Gong |
AsiaCCS | 3 |
| 2022 | Probe the Proto: Measuring Client-Side Prototype Pollution Vulnerabilities of One Million Real-world Websites
Zifeng Kang, Song Li 0006, Yinzhi Cao |
NDSS | 2 |
| 2022 | Mining Node.js Vulnerabilities via Object Dependence Graph and Query
Song Li 0006, Mingqing Kang, Jianwei Hou, Yinzhi Cao |
USENIX Security Symposium | 1 |
| 2021 | Detecting Node.js prototype pollution vulnerabilities via object lookup analysisabstractPrototype pollution is a type of vulnerability specific to prototype-based languages, such as JavaScript, which allows an adversary to pollute a base object’s property, leading to a further consequence such as Denial of Service (DoS), arbitrary code execution, and session fixation. On one hand, the only prior work in detecting prototype pollution adopts dynamic analysis to fuzz package inputs, which inevitably has code coverage issues in triggering some deeply embedded vulnerabilities. On the other hand, it is challenging to apply state-of-the-art static analysis in detecting prototype pollution because of the involvement of prototype chains and fine-grained object relations including built-in ones. Song Li 0006, Mingqing Kang, Jianwei Hou, Yinzhi Cao |
ESEC/SIGSOFT FSE | 1 |
| 2020 | Who Touched My Browser Fingerprint?: A Large-scale Measurement Study and Classification of Fingerprint DynamicsabstractBrowser fingerprints are dynamic, evolving with feature values changed over time. Previous fingerprinting datasets are either small-scale with only thousands of browser instances or without considering fingerprint dynamics. Thus, it remains unclear how an evolution-aware fingerprinting tool behaves in a real-world setting, e.g., on a website with millions of browser instances, let alone how fingerprint dynamics implicate privacy and security. Song Li 0006, Yinzhi Cao |
Internet Measurement Conference | 1 |
| 2019 | Rendered Private: Making GLSL Execution Uniform to Prevent WebGL-based Browser Fingerprinting
Shujiang Wu, Song Li 0006, Yinzhi Cao, Ningfei Wang |
USENIX Security Symposium | 2 |
| 2017 | Deterministic BrowserabstractTiming attacks have been a continuous threat to users' privacy in modern browsers. To mitigate such attacks, existing approaches, such as Tor Browser and Fermata, add jitters to the browser clock so that an attacker cannot accurately measure an event. However, such defenses only raise the bar for an attacker but do not fundamentally mitigate timing attacks, i.e., it just takes longer than previous to launch a timing attack. In this paper, we propose a novel approach, called deterministic browser, which can provably prevent timing attacks in modern browsers. Borrowing from Physics, we introduce several concepts, such as an observer and a reference frame. Specifically, a snippet of JavaScript, i.e., an observer in JavaScript reference frame, will always obtain the same, fixed timing information so that timing attacks are prevented; at contrast, a user, i.e., an oracle observer, will perceive the JavaScript differently and do not experience the performance slowdown. We have implemented a prototype called DeterFox and our evaluation shows that the prototype can defend against browser-related timing attacks. Yinzhi Cao, Zhanhao Chen, Song Li 0006, Shujiang Wu |
CCS | 3 |
| 2017 | (Cross-)Browser Fingerprinting via OS and Hardware Level Features
Yinzhi Cao, Song Li 0006, Erik Wijmans |
NDSS | 2 |