EDBT 2026 Demo / reviewers in the wild / expert
Lei Wu 0012
dblp:68/5597-12
· DBLP profile ↗
40ranked-venue papers
2as first author
34since 2021 · last 2026
0000-0003-1675-5283ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 1 first-author · 18 since 2021Software engineering, systems software and programming languages · 9 · 8 since 2021Systems, architecture and hardware · 5 · 5 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The Dark Side of Upgrades: Uncovering Insecurity in Smart Contract Upgrades
Dingding Wang 0003, Jianting He, Siwei Wu, Yajin Zhou, Lei Wu 0012, Cong Wang 0001 |
ACISP (1) | 5 |
| 2026 | Minoris: Practical Out-of-Emulator Kernel Module FuzzingabstractVulnerabilities in the Linux kernel can be exploited to perform privilege escalation and take over the whole system. Fuzzing has been leveraged to detect Linux kernel vulnerabilities during the last decade. However, existing kernel fuzzing techniques highly use QEMU/KVM as the underlying infrastructure, thus suffering from unnecessary costs due to user-kernel context switch and kernel-emulator context switch. This degrades the fuzzing performance. In this paper, we propose a kernel module fuzzing framework namedMinoris. It moves the kernel module under testing (KMUT) out of both real kernel and emulator, thus eliminating unnecessary context switches. However, implementing such a system requires solving the dependency challenges. We solve these challenges by automatically linking kernel module with LKL, and performing initialization functions on-demand to prepare the required status. Besides, a hardware-emulation library is proposed to provide underlying hardware support. Our system not only improves the fuzzing speed but also can easily integrate mature fuzzing techniques, such as user-space memory sanitizer. We evaluateMinorison five different KMUTs. Compared with the state-of-the-art solution,Minorisachieves an average execution speedup from ×3.31 to ×7.38. It improves the fuzzing throughput (×102.58), explores more code coverage ($89.51\%$more branches), and detects 6 new bugs. Yangxi Xiang, Qiang Liu 0034, Haoyu Wang 0001, Jiashui Wang, Lei Wu 0012, Chaoyuan Chen, Yajin Zhou |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2025 | ParallelEVM: Operation-Level Concurrent Transaction Execution for EVM-Compatible BlockchainsabstractBlockchain systems, especially EVM-compatible ones that serially execute transactions, face a significant limitation in throughput. One promising solution is concurrent transaction execution, which accelerates transaction processing and increases the overall throughput. However, existing concurrency control algorithms fail to obtain adequate speedups in high-contention blockchain workloads, primarily due to their transaction-level conflict resolution strategies. Hang Feng, Yajin Zhou, Lei Wu 0012 |
EuroSys | 4 |
| 2025 | Unmasking the Shadow Economy: A Deep Dive into Drainer-as-a-Service Phishing on EthereumabstractThe prosperity of Ethereum gives rise to a new type of transaction-based phishing scam. Specifically, users are tempted to visit phishing websites and sign phishing transactions that allow scammers to withdraw their tokens. Meanwhile, to accelerate the deployment of phishing websites, scammers have introduced a business model, Drainer-as-a-Service (DaaS). In this model, drainer operators focus on crafting specialized phishing toolkits, named ''wallet drainers'', while drainer affiliates handle the deployment and promotion of phishing websites. After stealing victims' tokens, they will distribute profits. In this paper, we present the first systematic study of DaaS on Ethereum. To begin with, we propose a snowball sampling approach to build the first large-scale DaaS dataset, including 1,910 profit sharing contracts, 56 operator accounts, 6,087 affiliate accounts, and 87,077 profit-sharing transactions. Then, we analyze the scale of DaaS from the perspectives of victims, operators, and affiliates, and perform clustering analysis to uncover dominant DaaS families. Finally, we reported DaaS accounts in the dataset and 32,819 phishing websites deployed with DaaS toolkits to the community. Our work aims to serve as a guide for Ethereum service providers to enhance user protection against DaaS. Zhuo Chen 0023, Ting Yu 0001, Lei Wu 0012, Yajin Zhou |
IMC | 7 |
| 2025 | Dissecting Payload-based Transaction Phishing on Ethereum
Zhuo Chen 0023, Lei Wu 0012, Yajin Zhou |
NDSS | 5 |
| 2025 | Detecting DBMS bugs with context-sensitive instantiation and multi-plan execution
Jiaqi Li 0023, Ke Wang 0042, Yaoguang Chen, Yajin Zhou, Lei Wu 0012, Jiashui Wang |
Comput. Secur. | 5 |
| 2025 | A survey on EOSIO systems security: vulnerability, attack, and mitigation
Ningyu He, Haoyu Wang 0001, Lei Wu 0012, Xiapu Luo, Yao Guo 0001, Xiangqun Chen |
Frontiers Comput. Sci. | 3 |
| 2025 | MFGSCOPE: A Lightweight Framework for Efficient Graph-Based Analysis on BlockchainabstractWith the prosperity of the blockchain and the DeFi ecosystem, money flow activities in the blockchains are becoming increasingly frequent, complex, and diverse. The Money Flow Graph (MFG) serves as the foundation for various behavioral analysis, malicious activity detection, and money flow tracing tasks. However, traditional graph databases face the issue of storage requirement and performance when analyzing large-scale MFGs. In this work, we presentMFGScope, a lightweight domain-specific framework designed for graph-based analysis on EVM-compatible blockchains, with extensive optimizations for storage efficiency and query performance. The prototype ofMFGScopefor the Ethereum network achieves the storage of over 3 billion transfers and 1.7 billion relevant transactions in a single instance with less than 450 GB of disk usage. The evaluation shows that for common tasks,MFGScopeis more than 30 times faster and requires 78% less storage space than the commonly used graph database Neo4j. For the applications ofMFGScope, we present several use cases based on the MFG which cannot be performed efficiently using traditional graph databases and report interesting findings. To engage the community, the prototype ofMFGScopefor the Ethereum blockchain with the complete dataset will be open source. Yingshi Sun, Zhuo Chen 0023, Lei Wu 0012, Yajin Zhou |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Improving Multitasking DBMS Fuzzing With More Accurate Coverage and Testcase TrimmingabstractCoverage-guided fuzzing is prevalent in detecting DBMS (Database Management System) bugs. However, current coverage-guided DBMS fuzzers suffer from two limitations that prevent fuzzers from discovering bugs efficiently. First, the coverage feedback is imprecise which prevents fuzzers from making optimal decisions on fuzzing strategies. Second, DBMS fuzzers lack testcase trimming to control the increasing input sizes. The large input size makes DBMS execution slower and reduces the likelihood that a mutation would touch important structures. In this paper, we proposed corresponding methods to overcome these limitations. Specifically, the work-task coverage tracking and unstable edge filtering improve the coverage accuracy with low instrumentation overhead. Based on more accurate coverage, we further propose testcase trimming to improve the speed of bug detection. We implemented a prototype named Tuzz and evaluated it on three popular DBMSs. The evaluation result shows that Tuzz explores 16.3%, 26.1%, and 26.6% more edges than the state-of-the-art fuzzer in PostgreSQL, MySQL, and MariaDB, respectively. More importantly, Tuzz has discovered 10 and 4 previously unknown bugs in MySQL and MariaDB. Jiaqi Li 0023, Yajin Zhou, Lei Wu 0012 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | uBOX: A Lightweight and Hardware-Assisted Sandbox for Multicore Embedded SystemsabstractMulticore embedded systems employ a big.LITTLE architecture to combine different cores into a single microcontroller (MCU). However, resources sharing among cores raises security challenges. Once LITTLE cores (which often receive external inputs) are compromised, the whole system will be affected. Existing hardware-assisted isolation approaches use privilege separation and code instrumentation to enforce memory isolation, which suffer from inefficiencies. This paper presentsuBOX, a lightweight sandbox for multicore embedded systems. The goal ofuBOXis to enforce memory isolation over untrusted software (on LITTLE cores) at the same privileged level. Specifically, it uses the Memory Protection Unit (MPU) to restrict memory access by untrusted software. To protect sandbox policies,uBOXdeprives the write capability of untrusted software towards MPU configurations by replacing its regular store instructions with unprivileged counterparts. Additionally, to protectuBOX's necessary regular store instructions from being abused,uBOX's memory is set to read-only and non-executable when running untrusted software. For the normal operation ofuBOX, we use an overlooked feature of the MPU and develop secure gates that quickly disable and re-enable the MPU, allowinguBOXto execute at a permissive memory view. Our evaluation demonstrates thatuBOXeffectively enforces isolation with average 1.27% runtime overhead, 0.83X Flash overhead, and 36.50X SRAM overhead. Yujie Bu, Meng Xu 0025, Yajin Zhou, Lei Wu 0012 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Toss a Fault to BpfChecker: Revealing Implementation Flaws for eBPF runtimes with Differential FuzzingabstracteBPF is a revolutionary technology that can run sandboxed programs in a privileged context and has an extensive range of applications, such as network monitoring on Linux kernel, denial-of-service protection on Windows, and the execution mechanism of smart contracts on blockchain. However, implementation flaws in eBPF have broad-reaching impact and serious consequences. Prior studies primarily focus on the memory safety of the eBPF runtimes, but few can detect implementation flaws (i.e., whether the implementation is correct). Meanwhile, existing implementation flaws detecting methods predominantly address bugs in the verifier, neglecting bugs in other components (i.e., the interpreter and the JIT compiler). In this paper, we present BpfChecker, a differential fuzzing framework to detect implementation flaws in the eBPF runtimes. It utilizes eBPF programs as input, performing differential testing for the critical states across various eBPF runtimes to uncover implementation flaws. To enhance the semantics of generated programs, we devise a lightweight intermediate representation and perform constrained mutations under the guidance of error messages. We have implemented a prototype of BpfChecker and extensively evaluated it on the three eBPF runtimes (i.e., Solana rBPF, vanilla rBPF, Windows eBPF). As a result, we have uncovered 28 new implementation flaws, received 2 CVEs and 800,000 bounty with developers' acknowledgment. More importantly, 2 of the newly found bugs can be used to create divergences in the execution layer of the Solana network. Chaoyuan Peng, Muhui Jiang, Lei Wu 0012, Yajin Zhou |
CCS | 3 |
| 2024 | SlimArchive: A Lightweight Architecture for Ethereum Archive Nodes
Hang Feng, Yinghan Kou, Runhuai Li, Lei Wu 0012, Yajin Zhou |
USENIX ATC | 6 |
| 2024 | Unveiling the Paradox of NFT ProsperityabstractUnlike fungible tokens (e.g., cryptocurrency), a Non-Fungible Token (NFT) is unique and indivisible. As such, they can be used to authenticate ownership of digital assets (e.g., a photo) in a decentralized fashion. Given that NFTs have generated significant media attention since 2021, we perform a large-scale measurement study of the NFT ecosystem. We collect over 242M transfer logs and over 97M marketplace transactions until Aug 1st, 2023, by far the largest NFT dataset, to the best of our knowledge. We characterize the on-chain behavior of NFTs and their trading across five major marketplaces. We find that, although the NFT ecosystem is growing rapidly, it is driven by a relatively small set of dominant centralized players, with suspicious trade activities, e.g., over 23% of the monetary volume is generated by malicious wash trading and the ecosystem has experienced over 157K cases of NFT arbitrage, with a total sum of over \25M profit. Our observations motivate the need for more research efforts in the NFT security analysis. Pengcheng Xia 0001, Gareth Tyson, Xiapu Luo, Lei Wu 0012, Yajin Zhou, Wei Cai 0002, Haoyu Wang 0001 |
WWW | 7 |
| 2024 | Lifting the Grey Curtain: Analyzing the Ecosystem of Android Scam AppsabstractMobile applications (apps) are extensively involved in online scams. Previous studies mainly targetmaliciousapps that either compromise victims' devices (e.g., malware and ransomware), or lead to privacy leakage and abuse (e.g., creepware). Recently, an emerging kind of appmakes profits by providing scam services rather than compromising devices or abusing privacy. We name these apps asscamwaredue to their deceptive behavior, which poses a new threat to (mobile) users. However, the characteristics and the ecosystem of scamware remain mysterious. This paper takes the first step toward systematically studying scamware. In total, 1262 ground-truth scamware are collected from December 1, 2020, to May 1, 2022. Specifically, we first investigate the social tricks used by scamware, and then analyze the participants and their relationships to demystify the ecosystem behind scamware. Finally, we reveal the scamware development features to facilitate the detection of scamware. Our study also gives some interesting findings,e.g., 1) the crowd-sourcing strategy is adopted to develop scamware,i.e., thescammersare the core members, while other participants are hired as peripherals; and 2) the online app generators have been abused to facilitate development; and 3) the money mule based payment is prevalent, and the case study shows the money flow is around $ 2593346 per day. We believe that our findings will facilitate the community and law enforcement agencies to mitigate this threat, and we will release the source code of our tools to engage the community. Zhuo Chen 0023, Lei Wu 0012, Yubo Hu, Yajin Zhou, Zhushou Tang, Yexuan Chen, Jinku Li, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | An Empirical Study on the Insecurity of End-of-Life (EoL) IoT DevicesabstractResearchers actively work on the security of Internet of Things (IoT) devices when IoT devices become popular. However, previous works ignore the insecurity about a special category of devices, i.e., the end-of-life (EoL) devices. Once a product becomes EoL, vendors no longer maintain its firmware, which makes it susceptible to attacks. In this article, we conduct the first empirical study to shed light on the (in)security of EoL devices. Our study performs two types of analysis, including theliveness analysisand thevulnerability analysis. The first one aims to detect the scale of EoL devices that are still alive in the wild in the long term. The second one is to evaluate the vulnerabilities existing in (active) EoL devices. We analyzed 894 EoL models from three vendors (i.e.,D-Link,Tp-Link, andNetgear) for more thantwo years. Our study reveals some worrisome facts that were unknown by the community. There exist more than three million active EoL devices, while more than one million of them have been alive for more than five years. Furthermore, more than half of the vulnerabilities are discovered after the EoL date. Although vendors may release security patches after the EoL date, the process is ad hoc and incomplete, with limited functionality. In summary, more than three million active EoL devices are vulnerable, and nearly half of them are threatened by high-risk vulnerabilities. By compromising EoL devices, attackers can achieve a minimum of 8.67 Tbps DDoS attack. Dingding Wang 0003, Muhui Jiang, Yajin Zhou, Baolei Hou, Lei Wu 0012, Xiapu Luo |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2024 | DeFiRanger: Detecting DeFi Price Manipulation AttacksabstractThe rapid growth of Decentralized Finance (DeFi) boosts the blockchain ecosystem. At the same time, attacks on DeFi applications (apps) are increasing. However, to the best of our knowledge, existing smart contract vulnerability detection tools cannot directly detect DeFi attacks. That's because they lack the capability to recover and understand high-level DeFi semantics, e.g., a user trades a token pairXandYin a Decentralized EXchange (DEX). In this work, we focus on the detection of two new types of price manipulation attacks. To this end, we propose a platform-independent method to identify high-level DeFi semantics. Specifically, we first construct the Cash Flow Tree (CFT) from a raw transaction and then lifting the low-level semantics to high-level ones, including five advanced DeFi actions. Finally, we use patterns expressed with the recovered DeFi semantics to detect price manipulation attacks. We implemented a prototype namedDeFiRangerthat detected 14zero-daysecurity incidents. These findings were reported to affected parties or/and the community for the first time. Furthermore, the backtest experiment discovered 15 unknown historical security incidents. We further performed an attack analysis to shed light on the root causes of vulnerabilities incurring price manipulation attacks. Siwei Wu, Zhou Yu 0002, Dabao Wang, Yajin Zhou, Lei Wu 0012, Haoyu Wang 0001, Xingliang Yuan |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | DeFiGuard: A Price Manipulation Detection Service in DeFi Using Graph Neural NetworksabstractThe prosperity of Decentralized Finance (DeFi) unveils underlying risks, with reported losses surpassing 3.2 billion USD between 2018 and 2022 due to vulnerabilities in Decentralized Applications (DApps). One significant threat is the Price Manipulation Attack (PMA) that alters asset prices during transaction execution. As a result, PMA accounts for over 50 million USD in losses. To address the urgent need for efficient PMA detection, this article introduces a novel detection service,DeFiGuard, using Graph Neural Networks (GNNs). In this article, we propose cash flow graphs with four distinct features, which capture the trading behaviors from transactions. Moreover,DeFiGuardintegrates transaction parsing, graph construction, model training, and PMA detection. Evaluations on the collected transactions demonstrate thatDeFiGuardwith GNN models outperforms the baseline MLP model and classical classification models in Accuracy, TPR, FPR, and AUC-ROC. The results of ablation studies suggest that the combination of the four proposed node features enhancesDeFiGuard’s efficacy. Moreover,DeFiGuardclassifies transactions within 0.892 to 5.317 seconds, which provides sufficient time for the victims (DApps and users) to take action to rescue their vulnerable funds. In conclusion, this research offers a significant step towards safeguarding the DeFi landscape from PMAs using GNNs. Dabao Wang, Bang Wu 0004, Xingliang Yuan, Lei Wu 0012, Yajin Zhou, Helei Cui |
IEEE Trans. Serv. Comput. | 4 |
| 2023 | TxPhishScope: Towards Detecting and Understanding Transaction-based Phishing on EthereumabstractThe prosperity of Ethereum attracts many users to send transactions and trade crypto assets. However, this has also given rise to a new form of transaction-based phishing scam, named TxPhish. Specifically, tempted by high profits, users are tricked into visiting fake websites and signing transactions that enable scammers to steal their crypto assets. The past year has witnessed 11 large-scale TxPhish incidents causing a total loss of more than 70 million. Zhuo Chen 0023, Lei Wu 0012, Haoyu Wang 0001, Yajin Zhou |
CCS | 6 |
| 2023 | Poster: Uncovering Vulnerabilities in Wasm Smart ContractsabstractWebAssembly (Wasm) smart contracts have shown growing popularity across blockchains (e.g., EOSIO and NEAR) recently. Wasm smart contracts have been suffering from various attacks exploiting their vulnerabilities. Even worse, few developers released the source code of their Wasm smart contracts for security review, raising the bar for uncovering vulnerable contracts. Although a few approaches have been proposed to detect vulnerable Wasm smart contracts, they have several major limitations, e.g., low code coverage, low accuracy and lack of scalability, unable to produce exploit payloads, etc. To fill the gap, we design and implement WASAI,a new concolic fuzzer for uncovering vulnerabilities in Wasm smart contract. We conduct extensive experiments to evaluate WASAI,and the results show that it outperforms the state-of-the-art methods. WASAI achieves 2x code coverage than the baselines and surpasses them in detection accuracy, with an F1-measure of 99.2%. Applying WASAI to all deployed smart contracts in the wild, we find that over 707 smart contracts are vulnerable. One Fake EOS vulnerability reported to the EOSIO ecosystem was recently assigned a CVE identifier (CVE-2022-27134). Zihan Sun, Haoyu Wang 0001, Xiapu Luo, Haipeng Cai, Lei Wu 0012 |
ICDCS | 6 |
| 2023 | DeUEDroid: Detecting Underground Economy Apps Based on UTG SimilarityabstractIn recent years, the underground economy is proliferating in the mobile system. These underground economy apps (UEware for short) make profits from providing non-compliant services, especially in sensitive areas (e.g., gambling, porn, loan). Unlike traditional malware, most of them (over 80%) do not have malicious payloads. Due to their unique characteristics, existing detection approaches cannot effectively and efficiently mitigate this emerging threat. To address this problem, we propose a novel approach to effectively and efficiently detect UEware by considering their UI transition graphs (UTGs). Based on the proposed approach, we design and implement a system, named DeUEDroid, to perform the detection. To evaluate DeUEDroid, we collect 25, 717 apps and build up the first large-scale ground-truth dataset (1, 700 apps) of UEware. The evaluation result based on the ground-truth dataset shows that DeUEDroid can cover new UI features and statically construct precise UTG. It achieves 98.22% detection F1-score and 98.97% classification accuracy, a significantly better performance than the traditional approaches. The evaluation result involving 24, 017 apps demonstrates the effectiveness and efficiency of UEware detection in real-world scenarios. Furthermore, the result also reveals that UEware are prevalent, i.e., 54% apps in the wild and 11% apps in the app stores are UEware. Our work sheds light on the future work of analyzing and detecting UEware. To engage the community, we have made our prototype system and the dataset available online. Zhuo Chen 0023, Yubo Hu, Lei Wu 0012, Yajin Zhou, Yiling He, Xianhao Liao, Ke Wang 0042, Jinku Li, Zhan Qin |
ISSTA | 4 |
| 2023 | When Top-down Meets Bottom-up: Detecting and Exploiting Use-After-Cleanup Bugs in Linux KernelabstractWhen a device is detached from the system, Use-After-Cleanup (UAC) bugs can occur because a running kernel thread may be unaware of the device detachment and attempt to use an object that has been released by the cleanup thread. Our investigation suggests that an attacker can exploit the UAC bugs to obtain the capability of arbitrary code execution and privilege escalation, which receives little attention from the community. While existing tools mainly focus on well-known concurrency bugs like data race, few target UAC bugs.In this paper, we propose a tool named UACatcher to systematically detect UAC bugs. UACatcher consists of three main phases. It first scans the entire kernel to find target layers. Next, it adopts the context- and flow-sensitive inter-procedural analysis and the points-to analysis to locate possible free (deallocation) sites in the bottom-up cleanup thread and use (dereference) sites in the top-down kernel thread that can cause UAC bugs. Then, UACatcher uses the routine switch point algorithm which counts on the synchronizations and path constraints to detect UAC bugs among these sites and estimate exploitable ones. For exploitable bugs, we leverage the pseudoterminal-based device emulation technique to develop practical exploits.We have implemented a prototype of UACatcher and evaluated it on 5.11 Linux kernel. As a result, our tool successfully detected 346 UAC bugs, which were reported to the community (277 have been confirmed and fixed and 15 CVEs have been assigned). Additionally, 13 bugs are exploitable, which can be used to develop working exploits that gain the arbitrary code execution primitive in kernel space and achieve the privilege escalation. Finally, we discuss UACatcher’s limitations and propose possible solutions to fix and prevent UAC bugs. Lin Ma 0009, Duoming Zhou, Hanjie Wu, Yajin Zhou, Lei Wu 0012, Kui Ren 0001 |
SP | 7 |
| 2023 | MsDroid: Identifying Malicious Snippets for Android Malware DetectionabstractMachine learning has shown promise for improving the accuracy of Android malware detection in the literature. However, it is challenging to (1) stay robust towards real-world scenarios and (2) provide interpretable explanations for experts to analyse. In this article, we proposeMsDroid, an Androidmalware detection system that makes decisions by identifyingmalicioussnippets with interpretable explanations. We mimic a common practice of security analysts, i.e., filtering APIs before looking through each method, to focus on local snippets around sensitive APIs instead of the whole program. Each snippet is represented with a graph encoding both code attributes and domain knowledge and then classified by Graph Neural Network (GNN). The local perspective helps the GNN classifier to concentrate on code highly correlated with malicious behaviors, and the information contained in graphs benefit in better understanding of the behaviors. Hence,MsDroidis more robust and interpretable in nature. To identify malicious snippets, we present a semi-supervised learning approach that only requires app labeling. The key insight is that malicious snippets only exist in malwares and appear at least once in a malware. To make malicious snippets less opaque, we design an explanation mechanism to show the importance of control flows and to retrieve similarly implemented snippets from known malwares. A comprehensive comparison with 5 baseline methods is conducted on a dataset of more than 81K apps in 3 real-world scenarios, includingzero-day,evolution, andobfuscation. The experimental results show thatMsDroidis more robust than state-of-the-art systems in all cases, with 5.37% to 49.52% advantage in F1-score. Besides, we demonstrate that the provided explanations are effective and illustrate how the explanations facilitate malware analysis. Yiling He, Lei Wu 0012, Kui Ren 0001, Zhan Qin |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | EnBinDiff: Identifying Data-Only Patches for BinariesabstractIn this article, we focus ondata-onlypatches, a specific type of security patchesnot incurring any structural changes. As one of the most significant causes leading to false negatives, data-only patches become a fundamental problem that affects all state-of-the-art binary diffing approaches/tools. To this end, we first systematically study data-only patches, and thoroughly illustrate the essence and adverse effect on existing tools. Based on the observations, we further propose and implement a system namedEnBinDiffbased on Value Set Analysis (VSA) to effectively identify data-only patches. Specifically,EnBinDifffirst precisely identifies functions from binaries, and then efficiently locates all “matched” function pairs based on structural binary diffing. After that,EnBinDiffperformsdata-only patch analysis, including stack frame matching and constant value matching, to identify data-only patches from the matched functions. To demonstrate the effectiveness ofEnBinDiff, we conduct an extensive evaluation with multiple datasets. The results demonstrate that the proposed system outperforms state-of-the-art binary diffing tools, and the false negative rate is reduced from 11.02% to 1.63%. Furthermore, we applyEnBinDiffto analyze real-world binaries, and successfully identify 20 1-day vulnerabilities. Jian Lin 0007, Dingding Wang 0003, Lei Wu 0012, Yajin Zhou, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Demystifying Random Number in Ethereum Smart Contract: Taxonomy, Vulnerability Identification, and Attack DetectionabstractRecent years have witnessed explosive growth in blockchain smart contract applications. As smart contracts become increasingly popular and carry trillion dollars worth of digital assets, they become more of an appealing target for attackers, who have exploited vulnerabilities in smart contracts to cause catastrophic economic losses. Notwithstanding a proliferation of work that has been developed to detect an impressive list of vulnerabilities, the bad randomness vulnerability is overlooked by many existing tools. In this article, we make the first attempt to provide a systematic analysis of random numbers in Ethereum smart contracts, by investigating the principles behind pseudo-random number generation and organizing them into a taxonomy. We also lucubrate various attacks against bad random numbers and group them into four categories. Furthermore, we presentRNVulDet– a tool that incorporates taint analysis techniques to automatically identify bad randomness vulnerabilities and detect corresponding attack transactions. To extensively verify the effectiveness ofRNVulDet, we construct three new datasets: i) 34 well-known contracts that are reported to possess bad randomness vulnerabilities, ii) 214 popular contracts that have been rigorously audited before launch and are regarded as free of bad randomness vulnerabilities, and iii) a dataset consisting of 47,668 smart contracts and 49,951 suspicious transactions. We compareRNVulDetwith three state-of-the-art smart contract vulnerability detectors, and our tool significantly outperforms them. Meanwhile,RNVulDetspends 2.98 s per contract on average, in most cases orders-of-magnitude faster than other tools.RNVulDetsuccessfully reveals 44,264 attack transactions. Our implementation and datasets are released, hoping to inspire others. Jianting He, Lingling Lu, Siwei Wu, Zhipeng Lu 0001, Lei Wu 0012, Yajin Zhou, Qinming He |
IEEE Trans. Software Eng. | 6 |
| 2022 | EXAMINER: automatically locating inconsistent instructions between real devices and CPU emulators for ARMabstractEmulators are widely used to build dynamic analysis frameworks due to its fine-grained tracing capability, full system monitoring functionality, and scalability of running on different operating systems and architectures. However, whether emulators are consistent with real devices is unknown. To understand this problem, we aim to automatically locate inconsistent instructions, which behave differently between emulators and real devices. Muhui Jiang, Yajin Zhou, Ming Zhong 0009, Lei Wu 0012, Xiapu Luo, Kui Ren 0001 |
ASPLOS | 6 |
| 2022 | RegVault: hardware assisted selective data randomization for operating system kernelsabstractThis paper presents RegVault, a hardware-assisted lightweight data randomization scheme for OS kernels. RegVault introduces novel cryptographically strong hardware primitives to protect both the confidentiality and integrity of register-grained data. RegVault leverages annotations to mark sensitive data and instruments their loads and stores automatically. Moreover, RegVault also introduces new techniques to protect the interrupt context and safeguard the sensitive data spilling. We implement a prototype of RegVault by extending RISC-V architecture to protect six types of sensitive data in Linux kernel. Our evaluations show that RegVault can defend against the kernel data attacks effectively with a minimal performance overhead. Jinyan Xu, Wenbo Shen, Yajin Zhou, Lei Wu 0012, Kui Ren 0001 |
DAC | 7 |
| 2022 | WASAI: uncovering vulnerabilities in Wasm smart contractsabstractWebAssembly (Wasm) smart contracts have shown growing popularity across blockchains (e.g., EOSIO) recently. Similar to Ethereum smart contracts, Wasm smart contracts suffer from various attacks exploiting their vulnerabilities. Even worse, few developers released the source code of their Wasm smart contracts for security review, raising the bar for uncovering vulnerable contracts. Although a few approaches have been proposed to detect vulnerable Wasm smart contracts, they have several major limitations, e.g., low code coverage, low accuracy and lack of scalability, unable to produce exploit payloads, etc. To fill the gap, in this paper, we design and develop WASAI, a new concolic fuzzer for uncovering vulnerabilities in Wasm smart contract after tackling several challenging issues. We conduct extensive experiments to evaluate WASAI, and the results show that it outperforms the state-of-the-art methods. For example, it achieves 2x code coverage than the baselines and surpasses them in detection accuracy, with an F1-measure of 99.2%. Moreover, WASAI can handle complicated contracts (e.g., contracts with obfuscation and sophisticated verification). Applying WASAI to 991 deployed smart contracts in the wild, we find that over 70% of smart contracts are vulnerable. By the time of this study, over 300 vulnerable contracts have not been patched and are still operating on the EOSIO Mainnet. One fake EOS vulnerability reported to the EOSIO ecosystem was recently assigned a CVE identifier (CVE-2022-27134). Zihan Sun, Haoyu Wang 0001, Xiapu Luo, Haipeng Cai, Lei Wu 0012 |
ISSTA | 6 |
| 2022 | Penny Wise and Pound Foolish: Quantifying the Risk of Unlimited Approval of ERC20 Tokens on EthereumabstractThe prosperity of decentralized finance motivates many investors to profit via trading their crypto assets on decentralized applications (DApps for short) of the Ethereum ecosystem. Apart from Ether (the native cryptocurrency of Ethereum), many ERC20 (a widely used token standard on Ethereum) tokens obtain vast market value in the ecosystem. Specifically, the approval mechanism is used to delegate the privilege of spending users’ tokens to DApps. By doing so, the DApps can transfer these tokens to arbitrary receivers on behalf of the users. To increase the usability, unlimited approval is commonly adopted by DApps to reduce the required interaction between them and their users. However, as shown in existing security incidents, this mechanism can be abused to steal users’ tokens. Dabao Wang, Hang Feng, Siwei Wu, Yajin Zhou, Lei Wu 0012, Xingliang Yuan |
RAID | 5 |
| 2022 | Time-travel Investigation: Toward Building a Scalable Attack Detection Framework on EthereumabstractEthereum has been attracting lots of attacks, hence there is a pressing need to perform timely investigation and detect more attack instances. However, existing systems suffer from the scalability issue due to the following reasons. First, the tight coupling between malicious contract detection and blockchain data importing makes them infeasible to repeatedly detect different attacks. Second, the coarse-grained archive data makes them inefficient to replay transactions. Third, the separation between malicious contract detection and runtime state recovery consumes lots of storage. In this article, we propose a scalable attack detection framework named EthScope , which overcomes the scalability issue by neatly re-organizing the Ethereum state and efficiently locating suspicious transactions. It leverages the fine-grained state to support the replay of arbitrary transactions and proposes a well-designed schema to optimize the storage consumption. The performance evaluation shows that EthScope can solve the scalability issue, i.e., efficiently performing a large-scale analysis on billions of transactions, and a speedup of around \( \text{2,300}\times \) when replaying transactions. It also has lower storage consumption compared with existing systems. Further analysis shows that EthScope can help analysts understand attack behaviors and detect more attack instances. Siwei Wu, Lei Wu 0012, Yajin Zhou, Runhuai Li, Zhi Wang 0004, Xiapu Luo, Cong Wang 0001, Kui Ren 0001 |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2021 | ECMO: Peripheral Transplantation to Rehost Embedded Linux KernelsabstractDynamic analysis based on the full-system emulator QEMU is widely used for various purposes.However, it is challenging to run firmware images of embedded devices in QEMU, especially the process to boot the Linux kernel (we call this process rehosting the Linux kernel in this paper). That's because embedded devices usually use different system-on-chips (SoCs) from multiple vendors and only a limited number of SoCs are currently supported in QEMU. Muhui Jiang, Lin Ma 0009, Yajin Zhou, Qiang Liu 0034, Cen Zhang, Zhi Wang 0004, Xiapu Luo, Lei Wu 0012, Kui Ren 0001 |
CCS | 8 |
| 2021 | FirmGuide: Boosting the Capability of Rehosting Embedded Linux Kernels through Model-Guided Kernel ExecutionabstractLinux kernel is widely used in embedded systems. To understand practical threats to the Linux kernel, we need to perform dynamic analysis with a full-system emulator, e.g., QEMU. However, due to hardware fragmentation, e.g., various types of peripherals, most embedded systems are not currently supported by QEMU. Though some progress has been made on rehosting firmware, it mainly focuses on user space programs or simple real-time operating systems.The goal of this work is to boost the capability of rehosting the embedded Linux kernels in QEMU. By doing so, dynamic analysis systems can be firstly applied on embedded Linux kernels by leveraging off-the-shelf tools upon QEMU. Accordingly, we proposed a new technique called model-guided kernel execution. It combines the peripheral abstractions in the Linux kernel and kernel-peripheral interactions to semi-automatically generate peripheral models that are then used to synthesize new QEMU virtual machines to start the dynamic analysis.We have implemented a prototype called FirmGuide. It generates 9 peripheral models with full functionality and 64 with minimum functionality covering 26 SoCs. Our evaluation with 6,188 firmware images shows that it can successfully rehost more than 95% of Linux kernels in 2 architectures and 22 versions. None of them can be rehosted in the vanilla QEMU. The result of the LTP benchmark shows the reliability and robustness of the rehosted Linux kernels. We further conduct two security applications, i.e., vulnerability analysis and fuzzing, on the rehosted Linux kernels to demonstrate the usage scenarios. Qiang Liu 0034, Cen Zhang, Lin Ma 0009, Muhui Jiang, Yajin Zhou, Lei Wu 0012, Wenbo Shen, Xiapu Luo, Yang Liu 0003, Kui Ren 0001 |
ASE | 6 |
| 2021 | EOSAFE: Security Analysis of EOSIO Smart Contracts
Ningyu He, Ruiyi Zhang 0001, Haoyu Wang 0001, Lei Wu 0012, Xiapu Luo, Yao Guo 0001, Ting Yu 0001, Xuxian Jiang |
USENIX Security Symposium | 4 |
| 2021 | Towards Understanding and Demystifying Bitcoin Mixing ServicesabstractOne reason for the popularity of Bitcoin is due to its anonymity. Although several heuristics have been used to break the anonymity, new approaches are proposed to enhance its anonymity at the same time. One of them is the mixing service. Unfortunately, mixing services have been abused to facilitate criminal activities, e.g., money laundering. As such, there is an urgent need to systematically understand Bitcoin mixing services. Lei Wu 0012, Yajin Zhou, Haoyu Wang 0001, Xiapu Luo, Zhi Wang 0004, Fan Zhang 0010, Kui Ren 0001 |
WWW | 1 |
| 2021 | Beyond the virus: a first look at coronavirus-themed Android malware
Liu Wang 0002, Haoyu Wang 0001, Pengcheng Xia 0001, Yuanchun Li 0003, Lei Wu 0012, Yajin Zhou, Xiapu Luo, Yulei Sui, Yao Guo 0001, Guoai Xu |
Empir. Softw. Eng. | 6 |
| 2020 | DEPOSafe: Demystifying the Fake Deposit Vulnerability in Ethereum Smart ContractsabstractCryptocurrency has seen an explosive growth in recent years, thanks to the evolvement of blockchain technology and its economic ecosystem. Besides Bitcoin, thousands of cryptocur-rencies have been distributed on blockchains, while hundreds of cryptocurrency exchanges are emerging to facilitate the trading of digital assets. At the same time, it also attracts the attentions of attackers. Fake deposit, as one of the most representative attacks (vulnerabilities) related to exchanges and tokens, has been frequently observed in the blockchain ecosystem, causing large financial losses. However, besides a few security reports, our community lacks the understanding of this vulnerability, for example its scale and the impacts. In this paper, we take the first step to demystify the fake deposit vulnerability. Based on the essential patterns we have summarized, we implement DEPOSafe, an automated tool to detect and verify (exploit) the fake deposit vulnerability in ERC-20 smart contracts. DEPOSafe incorporates several key techniques including symbolic execution based static analysis and behavior modeling based dynamic verification. By applying DEPOSafe to 176,000 ERC-20 smart contracts, we have identified over 7,000 vulnerable contracts that may suffer from two types of attacks. Our findings demonstrate the urgency to identify and prevent the fake deposit vulnerability. Ru Ji, Ningyu He, Lei Wu 0012, Haoyu Wang 0001, Guangdong Bai, Yao Guo 0001 |
ICECCS | 3 |
| 2020 | Mobile App SquattingabstractDomain squatting, the adversarial tactic where attackers register domain names that mimic popular ones, has been observed for decades. However, there has been growing anecdotal evidence that this style of attack has spread to other domains. In this paper, we explore the presence of squatting attacks in the mobile app ecosystem. In “App Squatting”, attackers release apps with identifiers (e.g., app name or package name) that are confusingly similar to those of popular apps or well-known Internet brands. This paper presents the first in-depth measurement study of app squatting showing its prevalence and implications. We first identify 11 common deformation approaches of app squatters and propose “AppCrazy”, a tool for automatically generating variations of app identifiers. We have applied AppCrazy to the top-500 most popular apps in Google Play, generating 224,322 deformation keywords which we then use to test for app squatters on popular markets. Through this, we confirm the scale of the problem, identifying 10,553 squatting apps (an average of over 20 squatting apps for each legitimate one). Our investigation reveals that more than 51% of the squatting apps are malicious, with some being extremely popular (up to 10 million downloads). Meanwhile, we also find that mobile app markets have not been successful in identifying and eliminating squatting apps. Our findings demonstrate the urgency to identify and prevent app squatting abuses. To this end, we have publicly released all the identified squatting apps, as well as our tool AppCrazy. Yangyu Hu, Haoyu Wang 0001, Li Li 0029, Gareth Tyson, Ignacio Castro, Yao Guo 0001, Lei Wu 0012, Guoai Xu |
WWW | 8 |
| 2020 | Characterizing cryptocurrency exchange scams
Pengcheng Xia 0001, Haoyu Wang 0001, Ru Ji, Bingyu Gao, Lei Wu 0012, Xiapu Luo, Guoai Xu |
Comput. Secur. | 6 |
| 2015 | Hybrid User-level Sandboxing of Third-party Android AppsabstractUsers of Android phones increasingly entrust personal information to third-party apps. However, recent studies reveal that many apps, even benign ones, could leak sensitive information without user awareness or consent. Previous solutions either require to modify the Android framework thus significantly impairing their practical deployment, or could be easily defeated by malicious apps using a native library. Yajin Zhou, Kunal Patel, Lei Wu 0012, Zhi Wang 0004, Xuxian Jiang |
AsiaCCS | 3 |
| 2015 | Harvesting developer credentials in Android appsabstractDevelopers often integrate third-party services into their apps. To access a service, an app must authenticate itself to the service with a credential. However, credentials in apps are often not properly or adequately protected, and might be easily extracted by attackers. A leaked credential could pose serious privacy and security threats to both the app developer and app users. Yajin Zhou, Lei Wu 0012, Zhi Wang 0004, Xuxian Jiang |
WISEC | 2 |
| 2013 | The impact of vendor customizations on android securityabstractThe smartphone market has grown explosively in recent years, as more and more consumers are attracted to the sensor-studded multipurpose devices. Android is particularly ascendant; as an open platform, smartphone manufacturers are free to extend and modify it, allowing them to differentiate themselves from their competitors. However, vendor customizations will inherently impact overall Android security and such impact is still largely unknown. Lei Wu 0012, Michael C. Grace, Yajin Zhou, Chiachih Wu, Xuxian Jiang |
CCS | 1 |