activity
20182023
most citedSyzScope: Revealing High-Risk Security Impacts of Fuzzer-Exposed Bugs in Linux kernel

12 citations · 35 across the 7 of their papers we have counts for

collaborators

9 papers

cs.SE2023★ 11 cited

The Hitchhiker's Guide to Program Analysis: A Journey with Large Language Models

Haonan Li, Yu Hao, Yizhuo Zhai +1

Static analysis is a widely used technique in software engineering for identifying and mitigating bugs. However, a significant hurdle lies in achieving a delicate balance between p…

cs.CR2023★ 1 cited

PolyScope: Multi-Policy Access Control Analysis to Triage Android Scoped Storage

Yu-Tsung Lee, Haining Chen, William Enck +5

Android's filesystem access control is a crucial aspect of its system integrity. It utilizes a combination of mandatory access controls, such as SELinux, and discretionary access c…

cs.CR2022★ 2 cited

Unsafe at Any Copy: Name Collisions from Mixing Case Sensitivities

Aditya Basu, John Sampson, Zhiyun Qian +1

File name confusion attacks, such as malicious symbolic links and file squatting, have long been studied as sources of security vulnerabilities. However, a recently emerged type, i…

cs.CR2021★ 12 cited

SyzScope: Revealing High-Risk Security Impacts of Fuzzer-Exposed Bugs in Linux kernel

Xiaochen Zou, Guoren Li, Weiteng Chen +2

Fuzzing has become one of the most effective bug finding approach for software. In recent years, 24*7 continuous fuzzing platforms have emerged to test critical pieces of software,…

cs.CR2020★ 5 cited

You Do (Not) Belong Here: Detecting DPI Evasion Attacks with Context Learning

Shitong Zhu, Shasha Li, Zhongjie Wang +5

As Deep Packet Inspection (DPI) middleboxes become increasingly popular, a spectrum of adversarial attacks have emerged with the goal of evading such middleboxes. Many of these att…

cs.CR2020★ 1 cited

PolyScope: Multi-Policy Access Control Analysis to Triage Android Systems

Yu-Tsung Lee, William Enck, Haining Chen +6

Android filesystem access control provides a foundation for Android system integrity. Android utilizes a combination of mandatory (e.g., SEAndroid) and discretionary (e.g., UNIX pe…