12 citations · 35 across the 7 of their papers we have counts for
9 papers
The Hitchhiker's Guide to Program Analysis: A Journey with Large Language Models
Haonan Li, Yu Hao, Yizhuo Zhai +1
Static analysis is a widely used technique in software engineering for identifying and mitigating bugs. However, a significant hurdle lies in achieving a delicate balance between p…
PolyScope: Multi-Policy Access Control Analysis to Triage Android Scoped Storage
Yu-Tsung Lee, Haining Chen, William Enck +5
Android's filesystem access control is a crucial aspect of its system integrity. It utilizes a combination of mandatory access controls, such as SELinux, and discretionary access c…
Unsafe at Any Copy: Name Collisions from Mixing Case Sensitivities
Aditya Basu, John Sampson, Zhiyun Qian +1
File name confusion attacks, such as malicious symbolic links and file squatting, have long been studied as sources of security vulnerabilities. However, a recently emerged type, i…
SyzScope: Revealing High-Risk Security Impacts of Fuzzer-Exposed Bugs in Linux kernel
Xiaochen Zou, Guoren Li, Weiteng Chen +2
Fuzzing has become one of the most effective bug finding approach for software. In recent years, 24*7 continuous fuzzing platforms have emerged to test critical pieces of software,…
You Do (Not) Belong Here: Detecting DPI Evasion Attacks with Context Learning
Shitong Zhu, Shasha Li, Zhongjie Wang +5
As Deep Packet Inspection (DPI) middleboxes become increasingly popular, a spectrum of adversarial attacks have emerged with the goal of evading such middleboxes. Many of these att…
PolyScope: Multi-Policy Access Control Analysis to Triage Android Systems
Yu-Tsung Lee, William Enck, Haining Chen +6
Android filesystem access control provides a foundation for Android system integrity. Android utilizes a combination of mandatory (e.g., SEAndroid) and discretionary (e.g., UNIX pe…