Wei Zhou 0026

dblp:69/5011-26 · DBLP profile ↗
← Back
10ranked-venue papers
5as first author
7since 2021 · last 2026
0000-0001-7834-0839ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 3 first-author · 5 since 2021Computer networks · 3 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Stop Starving or Stuffing Me: Boosting Firmware Fuzzing Efficiency with On-Demand Input Delivery
Shandian Shen, Wei Zhou 0026, Keming Zhao, Peng Liu 0005, Le Guan
SP2
2024 Unveiling IoT Security in Reality: A Firmware-Centric Journey
Nicolas Nino, Ruibo Lu, Wei Zhou 0026, Kyu Hyung Lee, Ziming Zhao 0001, Le Guan
USENIX Security Symposium3
2023 CEFI: Command Execution Flow Integrity for Embedded Devices
Anni Peng, Dongliang Fang, Wei Zhou 0026, Erik van der Kouwe, Yuqing Zhang 0001
DIMVA3
2022 What Your Firmware Tells You Is Not How You Should Emulate It: A Specification-Guided Approach for Firmware Emulation
abstract
Emulating firmware of microcontrollers is challenging due to the lack of peripheral models. Existing work finds out how to respond to peripheral read operations by analyzing the target firmware. This is problematic because the firmware sometimes does not contain enough clues to support the emulation or even contains misleading information (e.g., a buggy firmware). In this work, we propose a new approach that builds peripheral models from the peripheral specification. Using NLP, we translate peripheral behaviors in human language (documented in chip manuals) into a set of structured condition-action rules. By checking, executing, and chaining them at run time, we can dynamically synthesize a peripheral model for each firmware execution. The extracted condition-action rules might not be complete or even be wrong. We, therefore, propose incorporating symbolic execution to quickly pinpoint the root cause. This assists us in the manual correction of the problematic rules. We have implemented our idea for five popular MCU boards spanning three different chip vendors. Using a new edit-distance-based algorithm to calculate trace differences, our evaluation against a large firmware corpus confirmed that our prototype achieves much higher fidelity compared with state-of-the-art solutions. Benefiting from the accurate emulation, our emulator effectively avoids false positives observed in existing fuzzing work. We also designed a new dynamic analysis method to perform driver code compliance checks against the specification. We found some non-compliance which we later confirmed to be bugs caused by race conditions.
Wei Zhou 0026, Lan Zhang 0008, Le Guan, Peng Liu 0005, Yuqing Zhang 0001
CCS1
2022 Fingerprinting Mainstream IoT Platforms Using Traffic Analysis
abstract
The Internet of Things (IoT) platforms have been widely used in many application scenarios, especially for the smart home. Under the management of the IoT platform, a massive amount of IoT devices have been connected between remote cloud servers and users’ mobile terminals. While bringing unprecedented convenience for device manufacturers and smart home users, the existence of mainstream IoT platforms has also become the primary target for malicious attackers. Thus, many intrusion detection mechanisms of specific IoT platform traffic have been proposed. However, as a prerequisites work of intrusion detection or vulnerability assessment, identifying target IoT platform traffic among real-world network traffic has not been deeply studied. Given this situation, we first time proposed and achieved “fingerprinting” for IoT platform traffic. We designed a set of standardized workflows of traffic capturing, fingerprint feature extraction, and fingerprint model construction. Based on such workflow, we implemented a software tool named IoTPF for distinguishing the traffic between the mobile terminal and remote server of different mainstream IoT platforms among network traffic. We also tested the usability and performance of IoTPF. Finally, we discuss the application scenarios of fingerprinting on IoT platforms.
Xixun He, Yiyu Yang, Wei Zhou 0026, Peng Liu 0005, Yuqing Zhang 0001
IEEE Internet Things J.3
2021 Automatic Firmware Emulation through Invalidity-guided Knowledge Inference
Wei Zhou 0026, Le Guan, Peng Liu 0005, Yuqing Zhang 0001
USENIX Security Symposium1
2021 Reviewing IoT Security via Logic Bugs in IoT Platforms and Systems
abstract
In recent years, Internet-of-Things (IoT) platforms and systems have been rapidly emerging. Although IoT is a new technology, new does not mean simpler (than existing networked systems). Contrarily, the complexity (of IoT platforms and systems) is actually being increased in terms of the interactions between the physical world and cyberspace. The increased complexity indeed results in new vulnerabilities. This article seeks to provide a review of the recently discovered logic bugs that are specific to IoT platforms and systems and discuss the lessons we learned from these bugs. In particular, 20 logic bugs and one weakness falling into seven categories of vulnerabilities are reviewed in this survey.
Wei Zhou 0026, Chen Cao 0004, Dongdong Huo, Lan Zhang 0008, Le Guan, Yan Jia 0009, Yaowen Zheng, Yuqing Zhang 0001, Limin Sun 0001, Yazhe Wang, Peng Liu 0005
IEEE Internet Things J.1
2019 Identifying Privilege Separation Vulnerabilities in IoT Firmware with Symbolic Execution
Wei Zhou 0026, Yan Jia 0009, Lipeng Zhu 0003, Peng Liu 0005, Yuqing Zhang 0001
ESORICS (1)2
2019 Discovering and Understanding the Security Hazards in the Interactions between IoT Devices, Mobile Apps, and Clouds on Smart Home Platforms
Wei Zhou 0026, Yan Jia 0009, Lipeng Zhu 0003, Le Guan, Yuhang Mao, Peng Liu 0005, Yuqing Zhang 0001
USENIX Security Symposium1
2019 The Effect of IoT New Features on Security and Privacy: New Threats, Existing Solutions, and Challenges Yet to Be Solved
abstract
Internet of Things (IoT) is an increasingly popular technology that enables physical devices, vehicles, home appliances, etc., to communicate and even inter operate with one another. It has been widely used in industrial production and social applications including smart home, healthcare, and industrial automation. While bringing unprecedented convenience, accessibility, and efficiency, IoT has caused acute security and privacy threats in recent years. There are increasing research works to ease these threats, but many problems remain open. To better understand the essential reasons of new IoT threats and the challenges in current research, this survey first proposes the concept of “IoT features.” Then, we discuss the security and privacy effects of eight IoT features including the threats they cause, existing solutions to threats and research challenges yet to be solved. To help researchers follow the up-to-date works in this field, this paper finally illustrates the developing trend of IoT security research and reveals how IoT features affect existing security research by investigating most existing research works related to IoT security from 2013 to 2017.
Wei Zhou 0026, Yan Jia 0009, Anni Peng, Yuqing Zhang 0001, Peng Liu 0005
IEEE Internet Things J.1