EDBT 2026 Demo / reviewers in the wild / expert
Long Lu
dblp:81/7428
· DBLP profile ↗
56ranked-venue papers
5as first author
23since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 44 · 5 first-author · 17 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 2Computer networks · 2Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A multi-view vision transformer integrated with progressive transfer learning for accurate identification of prenatal fetal coarctation of the aorta
Yuzhou Zeng, Jiajie Tang, Fanfan Zhu, Long Lu |
Eng. Appl. Artif. Intell. | 6 |
| 2026 | Medical knowledge-enhanced ICD coding prediction
Fanfan Zhu, Yuyang Gong, Jingxin Chen, Long Lu |
Expert Syst. Appl. | 5 |
| 2024 | CO3: Concolic Co-execution for Firmware
Changming Liu, Alejandro Mera, Engin Kirda, Long Lu |
USENIX Security Symposium | 5 |
| 2024 | SHiFT: Semi-hosted Fuzz Testing for Embedded Applications
Alejandro Mera, Changming Liu, Ruimin Sun, Engin Kirda, Long Lu |
USENIX Security Symposium | 5 |
| 2024 | AIM: Automatic Interrupt Modeling for Dynamic Firmware AnalysisabstractThe security of microcontrollers, which drive modern IoT and embedded devices, continues to raise major concerns. Within a microcontroller (MCU), the firmware is a monolithic piece of software that contains the whole software stack, whereas a variety of peripherals represent the hardware. As MCU firmware contains vulnerabilities, it is ideal to test firmware with off-the-shelf software testing techniques, such as dynamic symbolic execution and fuzzing. Nevertheless, no emulator can emulate the diverse MCU peripherals or execute/test the firmware. Specifically, the interrupt interface, among all I/O interfaces used by MCU peripherals, is extremely challenging to emulate. In this article, we presentAIM—a generic, scalable, and hardware-independent dynamic firmware analysis framework that supports unemulated MCU peripherals by a novel interrupt modeling mechanism.AIMeffectively and efficiently covers interrupt-dependent code in firmware by a novel, firmware-guided,Just-in-Time Interrupt Firingtechnique. We implemented our framework inangrand performed dynamic symbolic execution for eight real-world MCU firmware. According to testing results, our framework covered up to 11.2 times more interrupt-dependent code than state-of-the-art approaches while accomplishing several challenging goals not feasible previously. Finally, a comparison with a state-of-the-art firmware fuzzer demonstrates dynamic symbolic execution and fuzzing together can achieve better firmware testing coverage. Bo Feng 0002, Meng Luo 0002, Changming Liu, Long Lu, Engin Kirda |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | On the Complexity of the Web's PKI: Evaluating Certificate Validation of Mobile BrowsersabstractDigital certificates are frequently used to secure communications between users and web servers. Critical to the Web’s PKI is the secure validation of digital certificates. Nonetheless, certificate validation itself is complex and error-prone. Moreover, it is also undermined by particular constraints of mobile browsers. However, these issues have long been overlooked. In this article, we undertook the first systematic and large-scale study of the certificate validation mechanism within popular mobile browsers to highlight the necessity of reassessing it among all released browsers. To this end, we first compile a comprehensive test suite to identify security flaws in certificate validation from various aspects. By designing and implementing a generic, automated testing pipeline, we effectively evaluate 30 popular browsers on two mobile OS versions and compare them with five representative desktop browsers. We found the latest mobile browsersAcceptas many as 33.2% invalid certificates andRejectmerely 5.4% invalid ones on average, leaving the majority of them to be decided by users who usually have little expertise. Our findings shed light on the severity and inconsistency of certificate validation flaws across mobile browsers, which are likely to expose users to MITM attacks, spoofing attacks, and so forth. Meng Luo 0002, Bo Feng 0002, Long Lu, Engin Kirda, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | ShadowNet: A Secure and Efficient On-device Model Inference System for Convolutional Neural NetworksabstractWith the increased usage of AI accelerators on mobile and edge devices, on-device machine learning (ML) is gaining popularity. Thousands of proprietary ML models are being deployed today on billions of untrusted devices. This raises serious security concerns about model privacy. However, protecting model privacy without losing access to the untrusted AI accelerators is a challenging problem. In this paper, we present a novel on-device model inference system, ShadowNet. ShadowNet protects the model privacy with Trusted Execution Environment (TEE) while securely outsourcing the heavy linear layers of the model to the untrusted hardware accelerators. ShadowNet achieves this by transforming the weights of the linear layers before outsourcing them and restoring the results inside the TEE. The non-linear layers are also kept secure inside the TEE. ShadowNet’s design ensures efficient transformation of the weights and the subsequent restoration of the results. We build a ShadowNet prototype based on TensorFlow Lite and evaluate it on five popular CNNs, namely, MobileNet, ResNet-44, MiniVGG, ResNet-404, and YOLOv4-tiny. Our evaluation shows that ShadowNet achieves strong security guarantees with reasonable performance, offering a practical solution for secure on-device model inference. Zhichuang Sun, Ruimin Sun, Changming Liu, Amrita Roy Chowdhury 0001, Long Lu, Somesh Jha |
SP | 5 |
| 2023 | A Study of Multi-Factor and Risk-Based Authentication Availability
Anthony Gavazzi, Engin Kirda, Long Lu, Andre King, Andy Davis, Tim Leek |
USENIX Security Symposium | 4 |
| 2022 | D-Box: DMA-enabled Compartmentalization for Embedded Applications
Alejandro Mera, Yi Hui Chen, Ruimin Sun, Engin Kirda, Long Lu |
NDSS | 5 |
| 2022 | Breaking Embedded Software Homogeneity with Protocol Mutations
Tongwei Ren, Sirshendu Ganguly, Lorenzo De Carli, Long Lu |
SecureComm | 5 |
| 2022 | A novel self-learning semi-supervised deep learning network to detect fake news on social media
Peixin Lu, Lianting Hu, XiaoGuang Wang, Long Lu |
Multim. Tools Appl. | 5 |
| 2022 | Integrating genomic and resting State fMRI for efficient autism spectrum disorder classification
Peixin Lu, Lianting Hu, Long Lu |
Multim. Tools Appl. | 4 |
| 2022 | Guided Feature Identification and Removal for Resource-constrained FirmwareabstractIoT firmware oftentimes incorporates third-party components, such as network-oriented middleware and media encoders/decoders. These components consist of large and mature codebases, shipping with a variety of non-critical features. Feature bloat increases code size, complicates auditing/debugging, and reduces stability. This is problematic for IoT devices, which are severely resource-constrained and must remain operational in the field for years. Unfortunately, identification and complete removal of code related to unwanted features requires familiarity with codebases of interest, cumbersome manual effort, and may introduce bugs. We address these difficulties by introducing PRAT, a system that takes as input the codebase of software of interest, identifies and maps features to code, presents this information to a human analyst, and removes all code belonging to unwanted features. PRAT solves the challenge of identifying feature-related code through a novel form of differential dynamic analysis and visualizes results as user-friendly feature graphs . Evaluation on diverse codebases shows superior code removal compared to both manual feature deactivation and state-of-art debloating tools, and generality across programming languages. Furthermore, a user study comparing PRAT to manual code analysis shows that it can significantly simplify the feature identification workflow. Tongwei Ren, Lorenzo De Carli, Long Lu, Gillian Smith 0001 |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2021 | SoK: Enabling Security Analyses of Embedded Systems via RehostingabstractClosely monitoring the behavior of a software system during its execution enables developers and analysts to observe, and ultimately understand, how it works. This kind of dynamic analysis can be instrumental to reverse engineering, vulnerability discovery, exploit development, and debugging. While these analyses are typically well-supported for homogeneous desktop platforms (e.g., x86 desktop PCs), they can rarely be applied in the heterogeneous world of embedded systems. One approach to enable dynamic analyses of embedded systems is to move software stacks from physical systems into virtual environments that sufficiently model hardware behavior. This process which we call "rehosting" poses a significant research challenge with major implications for security analyses. Although rehosting has traditionally been an unscientific and ad-hoc endeavor undertaken by domain experts with varying time and resources at their disposal, researchers are beginning to address rehosting challenges systematically and in earnest. In this paper, we establish that emulation is insufficient to conduct large-scale dynamic analysis of real-world hardware systems and present rehosting as a firmware-centric alternative. Furthermore, we taxonomize preliminary rehosting efforts, identify the fundamental components of the rehosting process, and propose directions for future research. Andrew Fasano, Tiemoko Ballo, Marius Muench, Tim Leek, Alexander Bulekov, Brendan Dolan-Gavitt, Manuel Egele, Aurélien Francillon, Long Lu, Nick Gregory, Davide Balzarotti, William K. Robertson |
AsiaCCS | 9 |
| 2021 | SCRUTINIZER: Detecting Code Reuse in Malware via Decompilation and Machine Learning
Omid Mirzaei, Roman Vasilenko, Engin Kirda, Long Lu, Amin Kharraz |
DIMVA | 4 |
| 2021 | SoK: Attacks on Industrial Control Logic and Formal Verification-Based DefensesabstractProgrammable Logic Controllers (PLCs) play a critical role in the industrial control systems. Vulnerabilities in PLC programs might lead to attacks causing devastating consequences to the critical infrastructure, as shown in Stuxnet and similar attacks. In recent years, we have seen an exponential increase in vulnerabilities reported for PLC control logic. Looking back on past research, we found extensive studies explored control logic modification attacks, as well as formal verification-based security solutions. We performed systematization on these studies, and found attacks that can compromise a full chain of control and evade detection. However, the majority of the formal verification research investigated ad-hoc techniques targeting PLC programs. We discovered challenges in every aspect of formal verification, rising from (1) the ever-expanding attack surface from evolved system design, (2) the real-time constraint during the program execution, and (3) the barrier in security evaluation given proprietary and vendor-specific dependencies on different techniques. Based on the knowledge systematization, we provide a set of recommendations for future research directions, and we highlight the need of defending security issues besides safety issues. Ruimin Sun, Alejandro Mera, Long Lu, David R. Choffnes |
EuroS&P | 3 |
| 2021 | Browserprint: an Analysis of the Impact of Browser Features on Fingerprintability and Web Privacy
Seyed Ali Akhavani, Jordan Jueckstock, Junhua Su, Alexandros Kapravelos, Engin Kirda, Long Lu |
ISC | 6 |
| 2021 | KUBO: Precise and Scalable Detection of User-triggerable Undefined Behavior Bugs in OS Kernel
Changming Liu, Yaohui Chen 0001, Long Lu |
NDSS | 3 |
| 2021 | DICE: Automatic Emulation of DMA Input Channels for Dynamic Firmware AnalysisabstractMicrocontroller-based embedded devices are at the core of Internet-of-Things (IoT) and Cyber-Physical Systems (CPS). The security of these devices is of paramount importance. Among the approaches to securing embedded devices, dynamic firmware analysis (e.g., vulnerability detection) gained great attention lately, thanks to its offline nature and low false-positive rates. However, regardless of the analysis and emulation techniques used, existing dynamic firmware analyzers share a major limitation, namely the inability to handle firmware using DMA (Direct Memory Access). It severely limits the types of devices supported and firmware code coverage.We present DICE, a drop-in solution for firmware analyzers to emulate DMA input channels and generate or manipulate DMA inputs (from peripherals to firmware). DICE is designed to be hardware-independent (i.e., no actual peripherals or DMA controllers needed) and compatible with common MCU firmware (i.e., no firmware-specific DMA usages assumed) and embedded architectures. The high-level idea behind DICE is the identification and emulation of the abstract DMA input channels, rather than the highly diverse peripherals and controllers. DICE identifies DMA input channels as the firmware writes the source and destination DMA transfer pointers into the DMA controller. Then DICE manipulates the input transferred through DMA on behalf of the firmware analyzer. DICE does not require firmware source code or additional features from firmware analyzers.We integrated DICE to the recently proposed firmware analyzer P2IM (for ARM Cortex-M architecture) and a PIC32 emulator (for MIPS M4K/M-Class architecture). We evaluated it on 83 benchmarks and sample firmware, representing 9 different DMA controllers from 5 different vendors. DICE detected 33 out of 37 DMA input channels, with 0 false positives. It correctly supplied DMA inputs to 21 out of 22 DMA buffers that firmware actually use, which previous firmware analyzers cannot achieve due to the lack of DMA emulation. DICE’s overhead is fairly low, it adds 3.4% on average to P2IM execution time. We also fuzz-tested 7 real-world firmware using DICE and compared the results with the original P2IM. DICE uncovered tremendously more execution paths (as much as 79X) and found 5 unique previously-unknown bugs that are unreachable without DMA emulation. All our source code and dataset are publicly available. Alejandro Mera, Bo Feng 0002, Long Lu, Engin Kirda |
SP | 3 |
| 2021 | Finding Bugs Using Your Own Code: Detecting Functionally-similar yet Inconsistent Code
Mansour Ahmadi, Reza Mirzazade Farkhani, Long Lu |
USENIX Security Symposium | 4 |
| 2021 | PTAuth: Temporal Memory Safety via Robust Points-to Authentication
Reza Mirzazade Farkhani, Mansour Ahmadi, Long Lu |
USENIX Security Symposium | 3 |
| 2021 | Mind Your Weight(s): A Large-scale Study on Insufficient Machine Learning Model Protection in Mobile Apps
Zhichuang Sun, Ruimin Sun, Long Lu, Alan Mislove |
USENIX Security Symposium | 3 |
| 2021 | Splicing learning: A novel few-shot learning approach
Lianting Hu, Huiying Liang, Long Lu |
Inf. Sci. | 3 |
| 2020 | FEAST'20: Fifth Workshop on Forming an Ecosystem Around Software TransformationabstractThe Fifth Workshop on Forming an Ecosystem Around Software Transformation (FEAST) provides a forum for presentation and discussion of new tools, methodologies, and techniques facilitating the automated or semi-automated transformation and analysis of software executables for improving their security and efficiency without the benefit of any original source code whence they were developed. Late-stage software customization of this form is of particular benefit to security-conscious software consumers who must use closed-source or source-free binary software components in mission-critical settings, or who must harden software against newly emerging attacks not anticipated during the software's original design and development. However, code analysis and transformation becomes much more difficult without the aid of source-level information to provide a context for its intended operation. This outstanding challenge motivates the FEAST Workshop's goal of forming a robust ecosystem of strategies and tools for accomplishing source-free binary code transformation reliably and on-demand. Kevin W. Hamlen, Long Lu |
CCS | 2 |
| 2020 | MEUZZ: Smart Seed Scheduling for Hybrid Fuzzing
Yaohui Chen 0001, Mansour Ahmadi, Reza Mirzazade Farkhani, Long Lu |
RAID | 5 |
| 2020 | SAVIOR: Towards Bug-Driven Hybrid TestingabstractHybrid testing combines fuzz testing and concolic execution. It leverages fuzz testing to test easy-to-reach code regions and uses concolic execution to explore code blocks guarded by complex branch conditions. As a result, hybrid testing is able to reach deeper into program state space than fuzz testing or concolic execution alone. Recently, hybrid testing has seen significant advancement. However, its code coverage-centric design is inefficient in vulnerability detection. First, it blindly selects seeds for concolic execution and aims to explore new code continuously. However, as statistics show, a large portion of the explored code is often bug-free. Therefore, giving equal attention to every part of the code during hybrid testing is a non-optimal strategy. It slows down the detection of real vulnerabilities by over 43%. Second, classic hybrid testing quickly moves on after reaching a chunk of code, rather than examining the hidden defects inside. It may frequently miss subtle vulnerabilities despite that it has already explored the vulnerable code paths.We propose SAVIOR, a new hybrid testing framework pioneering a bug-driven principle. Unlike the existing hybrid testing tools, SAVIOR prioritizes the concolic execution of the seeds that are likely to uncover more vulnerabilities. Moreover, SAVIOR verifies all vulnerable program locations along the executing program path. By modeling faulty situations using SMT constraints, SAVIOR reasons the feasibility of vulnerabilities and generates concrete test cases as proofs. Our evaluation shows that the bug-driven approach outperforms mainstream automated testing techniques, including state-of-the-art hybrid testing systems driven by code coverage. On average, SAVIOR detects vulnerabilities 43.4% faster than DRILLER and 44.3% faster than QSYM, leading to the discovery of 88 and 76 more unique bugs, respectively. According to the evaluation on 11 well fuzzed benchmark programs, within the first 24 hours, SAVIOR triggers 481 UBSAN violations, among which 243 are real bugs. Yaohui Chen 0001, Jun Xu 0024, Shengjian Guo, Rundong Zhou, Tao Wei 0002, Long Lu |
SP | 8 |
| 2020 | OAT: Attesting Operation Integrity of Embedded DevicesabstractDue to the wide adoption of IoT/CPS systems, embedded devices (IoT frontends) become increasingly connected and mission-critical, which in turn has attracted advanced attacks (e.g., control-flow hijacks and data-only attacks). Unfortunately, IoT backends (e.g., remote controllers or in-cloud services) are unable to detect if such attacks have happened while receiving data, service requests, or operation status from IoT devices (remotely deployed embedded devices). As a result, currently, IoT backends are forced to blindly trust the IoT devices that they interact with.To fill this void, we first formulate a new security property for embedded devices, called "Operation Execution Integrity" or OEI. We then design and build a system, OAT, that enables remote OEI attestation for ARM-based bare-metal embedded devices. Our formulation of OEI captures the integrity of both control flow and critical data involved in an operation execution. Therefore, satisfying OEI entails that an operation execution is free of unexpected control and data manipulations, which existing attestation methods cannot check. Our design of OAT strikes a balance between prover's constraints (embedded devices' limited computing power and storage) and verifier's requirements (complete verifiability and forensic assistance). OAT uses a new control-flow measurement scheme, which enables lightweight and space-efficient collection of measurements (97% space reduction from the trace-based approach). OAT performs the remote control-flow verification through abstract execution, which is fast and deterministic. OAT also features lightweight integrity checking for critical data (74% less instrumentation needed than previous work). Our security analysis shows that OAT allows remote verifiers or IoT backends to detect both controlflow hijacks and data-only attacks that affect the execution of operations on IoT devices. In our evaluation using real embedded programs, OAT incurs a runtime overhead of 2.7%. Zhichuang Sun, Bo Feng 0002, Long Lu, Somesh Jha |
SP | 3 |
| 2020 | P2IM: Scalable and Hardware-independent Firmware Testing via Automatic Peripheral Interface Modeling
Bo Feng 0002, Alejandro Mera, Long Lu |
USENIX Security Symposium | 3 |
| 2019 | Detecting (absent) app-to-app authentication on cross-device short-distance channelsabstractShort-distance or near-field communication is increasingly used by mobile apps for interacting or exchanging data in a cross-device fashion. In this paper, we identify a security issue, namely cross-device app-to-app communication hijacking (or CATCH), that affect Android apps using short-distance channels (e.g., Bluetooth and Wi-Fi-Direct). This issue causes unauthenticated or malicious app-to-app interactions even when the underlying communication channels are authenticated and secured. In addition to discovering the security issue, we design an algorithm based on data-flow analysis for detecting the presence of CATCH in Android apps. Our algorithm checks if a given app contains an app-to-app authentication scheme, necessary for preventing CATCH. We perform experiments on a set of Android apps and show the CATCH problem is always present on the whole analyzed applications set. We also discuss the impact of the problem in real scenarios by presenting two real case studies. At the end of the paper we reported limitations of our model along with future improvements. Stefano Cristalli, Long Lu, Danilo Bruschi, Andrea Lanzi |
ACSAC | 2 |
| 2019 | PTrix: Efficient Hardware-Assisted Fuzzing for COTS BinaryabstractDespite its effectiveness in uncovering software defects, American Fuzzy Lop (AFL), one of the best grey-box fuzzers, is inefficient when fuzz-testing source-unavailable programs. AFL's binary-only fuzzing mode, QEMU-AFL, is typically 2-5× slower than its source- available fuzzing mode. The slowdown is largely caused by the heavy dynamic instrumentation. Recent fuzzing techniques use Intel Processor Tracing (PT), a light-weight tracing feature supported by recent Intel CPUs, to re- move the need of dynamic instrumentation. However, we found that these PT-based fuzzing techniques are even slower than QEMU-AFL when fuzzing real-world programs, making them less effective than QEMU-AFL. This poor performance is caused by the slow extraction of code coverage information from highly compressed PT traces. In this work, we present the design and implementation of PTrix, which fully unleashes the benefits of PT for fuzzing via three novel techniques. First, PTrix introduces a scheme to highly parallel the processing of PT trace and target program execution. Second, it directly takes decoded PT trace as feedback for fuzzing, avoiding the expensive reconstruction of code coverage information. Third, PTrix maintains the new feedback with stronger feedback than edge-based code coverage, which helps reach new code space and defects that AFL may not. We evaluated PTrix by comparing its performance with the state- of-the-art fuzzers. Our results show that, given the same amount of time, PTrix achieves a significantly higher fuzzing speed and reaches into code regions missed by the other fuzzers. In addition, PTrix identifies 35 new vulnerabilities in a set of previously well- fuzzed binaries, showing its ability to complement existing fuzzers. Yaohui Chen 0001, Dongliang Mu, Jun Xu 0024, Zhichuang Sun, Wenbo Shen, Xinyu Xing 0001, Long Lu, Bing Mao 0001 |
AsiaCCS | 7 |
| 2019 | An Analysis of Malware Trends in Enterprise Networks
Abbas Acar, Long Lu, A. Selcuk Uluagac, Engin Kirda |
ISC | 2 |
| 2019 | StreamBox-TZ: Secure Stream Analytics at the Edge with TrustZone
Heejin Park, Long Lu, Felix Xiaozhu Lin |
USENIX ATC | 3 |
| 2019 | TEEv: virtualizing trusted execution environments on mobile platformsabstractTrusted Execution Environments (TEE) are widely deployed, especially on smartphones. A recent trend in TEE development is the transition from vendor-controlled, single-purpose TEEs to open TEEs that host Trusted Applications (TAs) from multiple sources with independent tasks. This transition is expected to create a TA ecosystem needed for providing stronger and customized security to apps and OS running in the Rich Execution Environment (REE). However, the transition also poses two security challenges: enlarged attack surface resulted from the increased complexity of TAs and TEEs; the lack of trust (or isolation) among TAs and the TEE. Wenhao Li 0009, Yubin Xia, Long Lu, Haibo Chen 0001, Binyu Zang |
VEE | 3 |
| 2018 | VButton: Practical Attestation of User-driven Operations in Mobile AppsabstractMore and more malicious apps and mobile rootkits are found to perform sensitive operations on behalf of legitimate users without their awareness. Malware does so by either forging user inputs or tricking users into making unintended requests to online service providers. Such malware is hard to detect and generates large revenues for cybercriminals, which is often used for committing ad/click frauds, faking reviews/ratings, promoting people or business on social networks, etc. Wenhao Li 0009, Shiyu Luo, Zhichuang Sun, Yubin Xia, Long Lu, Haibo Chen 0001, Binyu Zang, Haibing Guan |
MobiSys | 5 |
| 2018 | InstaGuard: Instantly Deployable Hot-patches for Vulnerable System Programs on Android
Yaohui Chen 0001, Long Lu, Yueh-Hsun Lin, Hayawardh Vijayakumar, Zhi Wang 0004, Xinming Ou |
NDSS | 3 |
| 2018 | Compiler-Assisted Code RandomizationabstractDespite decades of research on software diversification, only address space layout randomization has seen widespread adoption. Code randomization, an effective defense against return-oriented programming exploits, has remained an academic exercise mainly due to i) the lack of a transparent and streamlined deployment model that does not disrupt existing software distribution norms, and ii) the inherent incompatibility of program variants with error reporting, whitelisting, patching, and other operations that rely on code uniformity. In this work we present compiler-assisted code randomization (CCR), a hybrid approach that relies on compiler-rewriter cooperation to enable fast and robust fine-grained code randomization on end-user systems, while maintaining compatibility with existing software distribution models. The main concept behind CCR is to augment binaries with a minimal set of transformation-assisting metadata, which i) facilitate rapid fine-grained code transformation at installation or load time, and ii) form the basis for reversing any applied code transformation when needed, to maintain compatibility with existing mechanisms that rely on referencing the original code. We have implemented a prototype of this approach by extending the LLVM compiler toolchain, and developing a simple binary rewriter that leverages the embedded metadata to generate randomized variants using basic block reordering. The results of our experimental evaluation demonstrate the feasibility and practicality of CCR, as on average it incurs a modest file size increase of 11.46% and a negligible runtime overhead of 0.28%, while it is compatible with link-time optimization and control flow integrity. Hyungjoon Koo, Yaohui Chen 0001, Long Lu, Vasileios P. Kemerlis, Michalis Polychronakis |
IEEE Symposium on Security and Privacy | 3 |
| 2018 | An Empirical Study of Web Resource Manipulation in Real-world Mobile Applications
Xiaohan Zhang 0001, Yuan Zhang 0009, Qianqian Mo, Zhemin Yang, Min Yang 0002, XiaoFeng Wang 0001, Long Lu, Hai-Xin Duan |
USENIX Security Symposium | 8 |
| 2017 | Secure Integration of Web Content and Applications on Commodity Mobile Operating SystemsabstractA majority of today's mobile apps integrate web content of various kinds. Unfortunately, the interactions between app code and web content expose new attack vectors: a malicious app can subvert its embedded web content to steal user secrets; on the other hand, malicious web content can use the privileges of its embedding app to exfiltrate sensitive information such as the user's location and contacts. In this paper, we discuss security weaknesses of the interface between app code and web content through attacks, then introduce defenses that can be deployed without modifying the OS. Our defenses feature WIREframe, a service that securely embeds and renders external web content in Android apps, and in turn, prevents attacks between em- bedded web and host apps. WIREframe fully mediates the interface between app code and embedded web content. Un- like the existing web-embedding mechanisms, WIREframe allows both apps and embedded web content to define simple access policies to protect their own resources. These policies recognize fine-grained security principals, such as origins, and control all interactions between apps and the web. We also introduce WIRE (Web Isolation Rewriting Engine), an offline app rewriting tool that allows app users to inject WIREframe protections into existing apps. Our evaluation, based on 7166 popular apps and 20 specially selected apps, shows these techniques work on complex apps and incur acceptable end-to-end performance overhead. Drew Davidson, Yaohui Chen 0001, Franklin George, Long Lu, Somesh Jha |
AsiaCCS | 4 |
| 2017 | Where Is the Weakest Link? A Study on Security Discrepancies Between Android Apps and Their Website Counterparts
Arash Alavi 0001, Alan Quach, Hang Zhang 0012, Bryan Marsh, Farhan Ul Haq, Zhiyun Qian, Long Lu, Rajiv Gupta 0001 |
PAM | 7 |
| 2017 | NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64abstractCode reuse attacks exploiting memory disclosure vulnerabilities can bypass all deployed mitigations. One promising defense against this class of attacks is to enable execute-only memory (XOM) protection on top of fine-grained address space layout randomization (ASLR). However, recent works implementing XOM, despite their efficacy, only protect programs that have been (re)built with new compiler support, leaving commercial-off-the-shelf (COTS) binaries and source-unavailable programs unprotected. We present the design and implementation of NORAX, a practical system that retrofits XOM into stripped COTS binaries on AArch64 platforms. Unlike previous techniques, NORAX requires neither source code nor debugging symbols. NORAX statically transforms existing binaries so that during runtime their code sections can be loaded into XOM memory pages with embedded data relocated and data references properly updated. NORAX allows transformed binaries to leverage the new hardware-based XOM support—a feature widely available on AArch64 platforms (e.g., recent mobile devices) yet virtually unused due to the incompatibility of existing binaries. Furthermore, NORAX is designed to co-exist with other COTS binary hardening techniques, such as in-place randomization (IPR). We apply NORAX to the commonly used Android system binaries running on SAMSUNG Galaxy S6 and LG Nexus 5X devices. The results show that NORAX on average slows down the execution of transformed binaries by 1.18% and increases their memory footprint by 2.21%, suggesting NORAX is practical for real-world adoption. Yaohui Chen 0001, Dongli Zhang, Ruowen Wang, Ahmed M. Azab, Long Lu, Hayawardh Vijayakumar, Wenbo Shen |
IEEE Symposium on Security and Privacy | 6 |
| 2016 | Sixth Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices (SPSM 2016)abstractMobile security and privacy issues are receiving significant attention from the research community. The SPSM workshop was created to provide a venue for researchers and practitioners interested in such issues to get together and exchange ideas. Following the success of the previous editions, we present the sixth edition of the workshop. It brings together the expertise of an international program committee, comprising of 22 mobile security experts from the academia and the industry. The workshop received 31 submissions (regular and short papers combined) from a diverge set of authors located in 19 countries. Long Lu, Mohammad Mannan |
CCS | 1 |
| 2016 | Remix: On-demand Live RandomizationabstractCode randomization is an effective defense against code reuse attacks. It scrambles program code to prevent attackers from locating useful functions or gadgets. The key to secure code randomization is achieving high entropy. A practical approach to boost entropy is on-demand live randomization that works on running processes. However, enabling live randomization is challenging in that it often requires manual efforts to solve ambiguity in identifying function pointers. Zhi Wang 0004, David B. Whalley, Long Lu |
CODASPY | 4 |
| 2016 | CASE: Comprehensive Application Security Enforcement on COTS Mobile DevicesabstractWithout violating existing app security enforcement, malicious modules inside apps, such as a library or an external class, can steal private data and abuse sensitive capabilities meant for other modules inside the same apps. These so-called "module-level attacks" are quickly emerging, fueled by the pervasive use of third-party code in apps and the lack of module-level security enforcement on mobile platforms. Suwen Zhu, Long Lu, Kapil Singh |
MobiSys | 2 |
| 2016 | Shreds: Fine-Grained Execution Units with Private MemoryabstractOnce attackers have injected code into a victim program's address space, or found a memory disclosure vulnerability, all sensitive data and code inside that address space are subject to thefts or manipulation. Unfortunately, this broad type of attack is hard to prevent, even if software developers wish to cooperate, mostly because the conventional memory protection only works at process level and previously proposed in-process memory isolation methods are not practical for wide adoption. We propose shreds, a set of OS-backed programming primitives that addresses developers' currently unmet needs for fine-grained, convenient, and efficient protection of sensitive memory content against in-process adversaries. A shred can be viewed as a flexibly defined segment of a thread execution (hence the name). Each shred is associated with a protected memory pool, which is accessible only to code running in the shred. Unlike previous works, shreds offer in-process private memory without relying on separate page tables, nested paging, or even modified hardware. Plus, shreds provide the essential data flow and control flow guarantees for running sensitive code. We have built the compiler toolchain and the OS module that together enable shreds on Linux. We demonstrated the usage of shreds and evaluated their performance using 5 non-trivial open source software, including OpenSSH and Lighttpd. The results show that shreds are fairly easy to use and incur low runtime overhead (4.67%). Yaohui Chen 0001, Sebassujeen Reymondjohnson, Zhichuang Sun, Long Lu |
IEEE Symposium on Security and Privacy | 4 |
| 2015 | WebCapsule: Towards a Lightweight Forensic Engine for Web BrowsersabstractPerforming detailed forensic analysis of real-world web security incidents targeting users, such as social engineering and phishing attacks, is a notoriously challenging and time-consuming task. To reconstruct web-based attacks, forensic analysts typically rely on browser cache files and system logs. However, cache files and logs provide only sparse information often lacking adequate detail to reconstruct a precise view of the incident. To address this problem, we need an always-on and lightweight (i.e., low overhead) forensic data collection system that can be easily integrated with a variety of popular browsers, and that allows for recording enough detailed information to enable a full reconstruction of web security incidents, including phishing attacks. Christopher Neasbitt, Bo Li 0058, Roberto Perdisci, Long Lu, Kapil Singh, Kang Li 0001 |
CCS | 4 |
| 2015 | Preventing Use-after-free with Dangling Pointers Nullification
Byoungyoung Lee, Chengyu Song, Yeongjin Jang, Tielei Wang, Taesoo Kim, Long Lu, Wenke Lee |
NDSS | 6 |
| 2015 | Checking More and Alerting Less: Detecting Privacy Leakages via Enhanced Data-flow Analysis and Peer Voting
Kangjie Lu, Zhichun Li, Vasileios P. Kemerlis, Zhenyu Wu 0003, Long Lu, Cong Zheng, Zhiyun Qian, Wenke Lee, Guofei Jiang |
NDSS | 5 |
| 2014 | From Zygote to Morula: Fortifying Weakened ASLR on AndroidabstractThere have been many research efforts to secure Android applications and the high-level system mechanisms. The low-level operating system designs have been overlooked partially due to the belief that security issues at this level are similar to those on Linux, which are well-studied. However, we identify that certain Android modifications are at odds with security and result in serious vulnerabilities that need to be addressed immediately. In this paper, we analyze the Zygote process creation model, an Android operating system design for speeding up application launches. Zygote weakens Address Space Layout Randomization (ASLR) because all application processes are created with largely identical memory layouts. We design both remote and local attacks capable of bypassing the weakened ASLR and executing return-oriented programming on Android. We demonstrate the attacks using real applications, such as the Chrome Browser and VLC Media Player. Further, we design and implement Morula, a secure replacement for Zygote. Morula introduces a small amount of code to the Android operating system and can be easily adopted by device vendors. Our evaluation shows that, compared to Zygote, Morula incurs a 13 MB memory increase for each running application but allows each Android process to have an individually randomized memory layout and even a slightly shorter average launch time. Byoungyoung Lee, Long Lu, Tielei Wang, Taesoo Kim, Wenke Lee |
IEEE Symposium on Security and Privacy | 2 |
| 2013 | Robust scareware image detectionabstractIn this paper, we propose an image-based detection method to identify web-based scareware attacks that is robust to evasion techniques. We evaluate the method on a large-scale data set that resulted in an equal error rate of 0.018%. Conceptually, false positives may occur when a visual element, such as a red shield, is embedded in a benign page. We suggest including additional orthogonal features or employing graders to mitigate this risk. A novel visualization technique is presented demonstrating the acquired classifier knowledge on a classified screenshot. Christian Seifert, Jack W. Stokes, Christina Colcernian, John C. Platt, Long Lu |
ICASSP | 5 |
| 2013 | Jekyll on iOS: When Benign Apps Become Evil
Tielei Wang, Kangjie Lu, Long Lu, Simon P. Chung, Wenke Lee |
USENIX Security Symposium | 3 |
| 2012 | CHEX: statically vetting Android apps for component hijacking vulnerabilitiesabstractAn enormous number of apps have been developed for Android in recent years, making it one of the most popular mobile operating systems. However, the quality of the booming apps can be a concern [4]. Poorly engineered apps may contain security vulnerabilities that can severally undermine users' security and privacy. In this paper, we study a general category of vulnerabilities found in Android apps, namely the component hijacking vulnerabilities. Several types of previously reported app vulnerabilities, such as permission leakage, unauthorized data access, intent spoofing, and etc., belong to this category. Long Lu, Zhichun Li, Zhenyu Wu 0003, Wenke Lee, Guofei Jiang |
CCS | 1 |
| 2011 | SURF: detecting and measuring search poisoningabstractSearch engine optimization (SEO) techniques are often abused to promote websites among search results. This is a practice known as blackhat SEO. In this paper we tackle a newly emerging and especially aggressive class of blackhat SEO, namely search poisoning. Unlike other blackhat SEO techniques, which typically attempt to promote a website's ranking only under a limited set of search keywords relevant to the website's content, search poisoning techniques disregard any term relevance constraint and are employed to poison popular search keywords with the sole purpose of diverting large numbers of users to short-lived traffic-hungry websites for malicious purposes. To accurately detect search poisoning cases, we designed a novel detection system called SURF. SURF runs as a browser component to extract a number of robust (i.e., difficult to evade) detection features from search-then-visit browsing sessions, and is able to accurately classify malicious search user redirections resulted from user clicking on poisoned search results. Our evaluation on real-world search poisoning instances shows that SURF can achieve a detection rate of 99.1% at a false positive rate of 0.9%. Furthermore, we applied SURF to analyze a large dataset of search-related browsing sessions collected over a period of seven months starting in September 2010. Through this long-term measurement study we were able to reveal new trends and interesting patterns related to a great variety of poisoning cases, thus contributing to a better understanding of the prevalence and gravity of the search poisoning problem. Long Lu, Roberto Perdisci, Wenke Lee |
CCS | 1 |
| 2010 | BLADE: an attack-agnostic approach for preventing drive-by malware infectionsabstractWeb-based surreptitious malware infections (i.e., drive-by downloads) have become the primary method used to deliver malicious software onto computers across the Internet. To address this threat, we present a browser independent operating system kernel extension designed to eliminate driveby malware installations. The BLADE (Block All Drive-by download Exploits) system asserts that all executable files delivered through browser downloads must result from explicit user consent and transparently redirects every unconsented browser download into a nonexecutable secure zone of disk. BLADE thwarts the ability of browser-based exploits to surreptitiously download and execute malicious content by remapping to the file system only those browser downloads to which a programmatically inferred user-consent is correlated, BLADE provides its protection without explicit knowledge of any exploits and is thus resilient against code obfuscation and zero-day threats that directly contribute to the pervasiveness of today's drive-by malware. We present the design of our BLADE prototype implementation for the Microsoft Windows platform, and report results from as extensive empirical evaluation of its effectiveness on popular browsers. Our evaluation includes multiple versions of IE and Firefox, against 1,934 active malicious URLs, representing a broad spectrum of web-based exploits not plaguing the Internet. BLADE successfully blocked all drive-by malware install attempts with zero false positives and a 3% worst-case performance cost. Long Lu, Vinod Yegneswaran, Phillip A. Porras, Wenke Lee |
CCS | 1 |
| 2010 | On the Combination of Cooperative Diversity and Multiuser Diversity in Multi-Source Multi-Relay Wireless NetworksabstractThis letter presents an analysis of the combined use of cooperative diversity and multiuser diversity (MUD) in multi-source multi-relay networks. A joint selection scheme, which selects the best source-relay pair to access the channel, is proposed. The main contribution of our work is the derivation of the exact and asymptotic expressions for the outage probability of the system with amplify-and-forward (AF) protocol. From these expressions it is indicated that the total diversity order ofM+Ncan be achieved, whereMandNare the number of source nodes and relay nodes, respectively. Based on the outage probability in high signal-to-noise-ratio (SNR) region, the optimum power allocation scheme is also given to improve the system performance. Li Sun 0001, Taiyi Zhang, Long Lu, Hao Niu 0001 |
IEEE Signal Process. Lett. | 3 |
| 2009 | Mapping kernel objects to enable systematic integrity checkingabstractDynamic kernel data have become an attractive target for kernel-mode malware. However, previous solutions for checking kernel integrity either limit themselves to code and static data or can only inspect a fraction of dynamic data, resulting in limited protection. Our study shows that previous solutions may reach only 28% of the dynamic kernel data and thus may fail to identify function pointers manipulated by many kernel-mode malware. Martim Carbone, Weidong Cui, Long Lu, Wenke Lee, Marcus Peinado, Xuxian Jiang |
CCS | 3 |
| 2009 | BLADE: Slashing the Invisible Channel of Drive-by Download Malware
Long Lu, Vinod Yegneswaran, Phillip A. Porras, Wenke Lee |
RAID | 1 |