Publications $Id: research.t2t, v1.0, last updated %%mtime(%c) Exp $ %! Target: %! Options: --toc --css-sugar --encoding=iso-8859-1 %! Style: tech.css %! PreProc: %! PostProc: %! include: ''ps.js'' Note: these publication materials are presented to ensure a timely dissemination of scholarly and technical work. Copyright and all rights therein are retained by authors or by other copyright holders. All persons copying this information are expected to adhere to the terms and constraints invoked by each paper's copyright (e.g., ACM Copyright Policy, IEEE Copyright Policy, ISOC Copyright Policy). --------------------------------------------------------------------------- === 2011 === - Junghwan Rhee, **Zhiqiang Lin**, and Dongyan Xu. "Characterizing Kernel Malware Behavior with Kernel Data Access Patterns". To appear in //Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security (**ASIACCS'11**)//, Hong Kong, March 2011 (35/217= 16.1%). [[Bibtex bib/asiaccs11.bib]] - **Zhiqiang Lin**, Junghwan Rhee, Xiangyu Zhang, Dongyan Xu, and Xuxian Jiang. "SigGraph: Brute Force Scanning of Kernel Data Structure Instances Using Graph-based Signatures". In //Proceedings of the 18th Network and Distributed System Security Symposium (**NDSS'11**)//, San Diego, CA, February 2011 (28/139 = 20.1%). [[Abstract ndss11.html]][[PDF file/SigGraph_NDSS11.pdf]][[Bibtex bib/ndss11.bib]][[Demo file/SigGraph.avi]][[Slides file/NDSS11.ppt]] === 2010 === - Tao Bao, Yunhui Zheng, **Zhiqiang Lin**, Xiangyu Zhang and Dongyan Xu. "Strict Control Dependence and its Effect on Dynamic Information Flow Analyses". In //Proceedings of the 2010 International Symposium on Software Testing and Analysis (**ISSTA'10**)//, Trento, Italy. July 2010 (24/105 = 23%). [[Bibtex bib/issta10.bib]][[PDF file/issta10.pdf]] - **Zhiqiang Lin**, Xiangyu Zhang, and Dongyan Xu. "Reuse-Oriented Camouflaging Trojan: Vulnerability Detection and Attack Construction". In //Proceedings of the 40th Annual IEEE/IFIP International Conference on Dependable Systems and Networks (**DSN-DCCS'10**)//, Chicago, IL, June 2010 (39/168=23.2%). [[Abstract dsn10.html]][[PDF file/DCCS10.pdf]][[Bibtex bib/dsn10.bib]][[Slides file/DCCS10.ppt]] - **Zhiqiang Lin**, Xiangyu Zhang, and Dongyan Xu. "Automatic Reverse Engineering of Data Structures from Binary Execution". //In Proceedings of the 17th Network and Distributed System Security Symposium (**NDSS'10**)//, San Diego, CA, February 2010 (24/156=15.4%). [[Abstract ndss10.html]][[PDF file/Rewards_NDSS10.pdf]][[Bibtex bib/ndss10.bib]][[Slides file/NDSS10.ppt]][[Demo file/rewards_demo.tar.gz]] - **Zhiqiang Lin**, Xiangyu Zhang, and Dongyan Xu. "Reverse Engineering Input Syntactic Structure from Program Execution and Its Applications". //**IEEE Transactions on Software Engineering**//. 36(5), 2010. [[PDF http://www.computer.org/portal/web/csdl/doi/10.1109/TSE.2009.54]][[Bibtex bib/tse10.bib]] === 2009 === - **Zhiqiang Lin**, Ryan Riley, and Dongyan Xu. "Polymorphing Software by Randomizing Data Structure Layout". In //Proceedings of the 6th SIG SIDAR Conference on Detection// //of Intrusions and Malware and Vulnerability Assessment (**DIMVA'09**)//. Milan, Italy, July 2009 ((10+3)/44=29.5%). [[Abstract dimva09.html]][[PDF file/DIMVA09.pdf]][[Bibtex bib/dimva09.bib]][[Code dimva09.html]] - Tielei Wang, Tao Wei, **Zhiqiang Lin**, and Wei Zou. "IntScope: Automatically Detecting Integer Overflow Vulnerability In X86 Binary Using Symbolic Execution". In //Proceedings of the 16th Network and Distributed System Security Symposium (**NDSS'09**)//, San Diego, CA, February 2009 (20/171=11.7%). [[Abstract ndss09.html]][[PDF file/IntScope_NDSS09.pdf]][[Bibtex bib/ndss09.bib]] === 2008 === - **Zhiqiang Lin**, and Xiangyu Zhang. "Deriving Input Syntactic Structure From Execution", in //Proceedings of the 16th ACM SIGSOFT International Symposium// //on Foundations of Software Engineering (**FSE'08**)//. Atlanta, Georgia, USA, November 2008 (31/152=20.5%). [[Abstract fse08.html]][[PDF file/FSE08.pdf]][[Bibtex bib/fse08.bib]][[Slides file/FSE08.ppt]] - **Zhiqiang Lin**, Xiangyu Zhang, and Dongyan Xu. "Convicting Exploitable Software Vulnerabilities: An Efficient Input Provenance Based Approach". In //Proceedings of the 38th Annual IEEE/IFIP International Conference on Dependable// //Systems and Networks (**DSN-DCCS'08**)//, Anchorage, Alaska, USA, June 2008 (34/149=23%). [[Abstract dsn08.html]][[PDF file/DSN08.pdf]][[Bibtex bib/dsn08.bib]][[Slides file/DSN08.ppt]] - **Zhiqiang Lin**, Xuxian Jiang, Dongyan Xu, and Xiangyu Zhang, "Automatic Protocol Format Reverse Engineering Through Context-Aware Monitored Execution", in //Proceedings of the 15th Network and Distributed System Security Symposium (**NDSS'08**)//, San Diego, CA, February 2008 (21/118=17.8%) [[Abstract ndss08.html]][[PDF file/AutoFormat_NDSS08.pdf]][[Bibtex bib/ndss08.bib]][[Slides file/NDSS08.ppt]] === 2007 === - **Zhiqiang Lin**, Xuxian Jiang, Dongyan Xu, Bing Mao, and Li Xie, "AutoPaG: Towards Automated Software Patch Generation with Source Code Root Cause Identification and Repair", in //Proceedings of ACM Symposium on InformAtion, Computer and Communications// //Security (**ASIACCS'07**)//, Singapore, March 2007 (Acceptance ratio: 33/188=17.6%). [[PDF file/AutoPaG.pdf]][[Bibtex bib/autopag_asiaccs07.bib]][[Slides file/ASIACCS07_AutoPaG.ppt]] === 2006 === - **Zhiqiang Lin**, Nai Xia, Guole Li, Bing Mao, and Li Xie. "Transparent Run-Time Prevention of Format-String Attacks via Dynamic Taint and Flexible Validation", in //Proceedings of the 9th Information Security Conference (**ISC'06**)//. Greece. Sept, 2006 (Acceptance ratio: 38/188=20.2%). [[PDF file/ISC06.pdf]][[Bibtex bib/isc06.bib]][[Code file/LibFormat.tar.gz]] - **Zhiqiang Lin**, Bing Mao, and Li Xie. "A Practical Framework for Dynamically Immunizing Software Security Vulnerabilities", in //Proceedings of the First International// //Conference on Availability, Reliability and Security (**ARES'06**)// Austria. April, 2006. [[PDF http://www.computer.org/portal/web/csdl/doi/10.1109/ARES.2006.11]][[Bibtex bib/ares06.bib]] - **Zhiqiang Lin**, Bing Mao, and Li Xie. "LibsafeXP: A Practical and Transparent Tool for Run-time Buffer Overflow Preventions", in //Proceedings of the 7th Annual IEEE// //Information Assurance Workshop (**IAW'06**)//. West Point, NY. USA. June, 2006. [[PDF file/IAW06.pdf]][[Bibtex bib/iaw06.bib]][[Slides file/LibsafeXP.pdf]][[Code file/LibsafeXP.tar.gz]] --------------------------------------------------------------------------- [HOME index.html] [SOURCE %%infile]