EDBT 2026 Demo / reviewers in the wild / expert
Dingding Wang 0003
dblp:88/4782-3
· DBLP profile ↗
3ranked-venue papers
2as first author
3since 2021 · last 2026
0000-0003-2339-8050ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The Dark Side of Upgrades: Uncovering Insecurity in Smart Contract Upgrades
Dingding Wang 0003, Jianting He, Siwei Wu, Yajin Zhou, Lei Wu 0012, Cong Wang 0001 |
ACISP (1) | 1 |
| 2024 | An Empirical Study on the Insecurity of End-of-Life (EoL) IoT DevicesabstractResearchers actively work on the security of Internet of Things (IoT) devices when IoT devices become popular. However, previous works ignore the insecurity about a special category of devices, i.e., the end-of-life (EoL) devices. Once a product becomes EoL, vendors no longer maintain its firmware, which makes it susceptible to attacks. In this article, we conduct the first empirical study to shed light on the (in)security of EoL devices. Our study performs two types of analysis, including theliveness analysisand thevulnerability analysis. The first one aims to detect the scale of EoL devices that are still alive in the wild in the long term. The second one is to evaluate the vulnerabilities existing in (active) EoL devices. We analyzed 894 EoL models from three vendors (i.e.,D-Link,Tp-Link, andNetgear) for more thantwo years. Our study reveals some worrisome facts that were unknown by the community. There exist more than three million active EoL devices, while more than one million of them have been alive for more than five years. Furthermore, more than half of the vulnerabilities are discovered after the EoL date. Although vendors may release security patches after the EoL date, the process is ad hoc and incomplete, with limited functionality. In summary, more than three million active EoL devices are vulnerable, and nearly half of them are threatened by high-risk vulnerabilities. By compromising EoL devices, attackers can achieve a minimum of 8.67 Tbps DDoS attack. Dingding Wang 0003, Muhui Jiang, Yajin Zhou, Baolei Hou, Lei Wu 0012, Xiapu Luo |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | EnBinDiff: Identifying Data-Only Patches for BinariesabstractIn this article, we focus ondata-onlypatches, a specific type of security patchesnot incurring any structural changes. As one of the most significant causes leading to false negatives, data-only patches become a fundamental problem that affects all state-of-the-art binary diffing approaches/tools. To this end, we first systematically study data-only patches, and thoroughly illustrate the essence and adverse effect on existing tools. Based on the observations, we further propose and implement a system namedEnBinDiffbased on Value Set Analysis (VSA) to effectively identify data-only patches. Specifically,EnBinDifffirst precisely identifies functions from binaries, and then efficiently locates all “matched” function pairs based on structural binary diffing. After that,EnBinDiffperformsdata-only patch analysis, including stack frame matching and constant value matching, to identify data-only patches from the matched functions. To demonstrate the effectiveness ofEnBinDiff, we conduct an extensive evaluation with multiple datasets. The results demonstrate that the proposed system outperforms state-of-the-art binary diffing tools, and the false negative rate is reduced from 11.02% to 1.63%. Furthermore, we applyEnBinDiffto analyze real-world binaries, and successfully identify 20 1-day vulnerabilities. Jian Lin 0007, Dingding Wang 0003, Lei Wu 0012, Yajin Zhou, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |