微小的工作

Publications


An Empirical Study of SDK Credential Misuse in iOS Apps
Wen Haohuang, Li Juanru, Zhang Yuanyuan, Gu Dawu
Asia-Pacific Software Engineering Conference (APSEC)
Nara, Japan. December 4-7, 2018

K-Hunt: Pinpointing Insecure Cryptographic Keys in Execution Traces
Li Juanru, Lin Zhiqiang, Juan Caballero, Zhang Yuanyuan, Gu Dawu
ACM Conference on Computer and Communications Security (CCS)
Toronto, Canada. October 15-19, 2018

BinMatch: A Semantics-based Hybrid Approach on Binary Code Clone Analysis
Hu Yikun, Zhang Yuanyuan, Li Juanru, Wang Hui, Li Bodong, Gu Dawu
International Conference on Software Maintenance and Evolution (ICSME)
Madrid, Spain. September 23-29, 2018

Burn After Reading: Expunging Execution Footprints of Android Apps
Shu Junliang, Li Juanru, Zhang Yuanyuan, Gu Dawu
International Conference on Network and System Security (NSS)
Hong Kong, China. August 27-29, 2018

Passwords in the Air: Harvesting Wi-Fi Credentials from SmartCfg Provisioning
Li Changyu, Cai Quanpu, Li Juanru, Zhang Yuanyuan, Gu Dawu, Yu Yu
ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec)
Stockholm, Sweden. June 18-20, 2018

AppSpear: Automating the Hidden-Code Extraction and Reassembling of Packed Android Malware
Li Bodong, Zhang Yuanyuan, Li Juanru, Yang Wenbo, Gu Dawu
Journal of Systems and Software
140: 3-16 (2018)

Why Data Deletion Fails? A Study on Deletion Flaws and Data Remanence in Android Systems
Shu Junliang, Zhang Yuanyuan, Li Juanru, Li Bodong, Gu Dawu
ACM Transactions on Embedded Computing Systems
Volume 16(2): 61:1-61:22 (2017)

Oh-Pwn-VPN! Security Analysis of OpenVPN-based Android Apps
Zhang Qi, Li Juanru, Zhang Yuanyuan, Wang Hui, Gu Dawu
International Conference on Cryptology And Network Security (CANS)
Hong Kong, China, November 29 - December 2, 2017

Nightingale: Translating Embedded VM Code in x86 Binary Executables
Xie Haijiang, Zhang Yuanyuan, Li Juanru, Gu Dawu
Information Security Conference (ISC)
Ho Chi Minh City, Vietnam, November 22-24, 2017

NativeSpeaker: Identifying Crypto Misuses in Android Native Code Libraries
Wang Qing, Li Juanru, Zhang Yuanyuan, Wang Hui, Hu Yikun, Li Bodong, Gu Dawu
International Conference on Information Security and Cryptology (INSCRYPT)
Xi'an, China, November 3-5, 2017

Smart Solution, Poor Protection: An Empirical Study of Security and Privacy Issues in Developing and Deploying Smart Home Devices
Liu Hui, Li Changyu, Jin Xuancheng, Li Juanru, Zhang Yuanyuan, Gu Dawu
Workshop on Internet of Things Security and Privacy (IoT S&P) Collocated with ACM CCS
Dallas, Texas, USA, November 3, 2017

Embroidery: Patching Vulnerable Binary Code of Fragmentized Android Devices
Zhang Xuewen, Zhang Yuanyuan, Li Juanru, Hu Yikun, Li Huayi, Gu Dawu
IEEE International Conference on Software Maintenance and Evolution (ICSME)
Shanghai, China, September 17-22, 2017

MIRAGE: Randomizing Large Chunk Allocation via Dynamic Binary Instrumentation
Hu Zhenghao, Zhang Yuanyuan, Wang Hui, Li Juanru, Yang Wenbo, Gu Dawu
IEEE Conference on Dependable and Secure Computing (DSC)
Taipei, Taiwan, China, August 7-10, 2017.

Binary Code Clone Detection across Architectures and Compiling Configurations
Hu Yikun, Zhang Yuanyuan, Li Juanru, Gu Dawu
International Conference on Program Comprehension (ICPC)
Buenos Aires, Argentina, May 22-23, 2017

Projects


  • 国家自然科学基金面上项目:可执行程序中私有密码系统定位与分析(61872237),2019.01-2019.12
  • 工业和信息化部重大专项:面向智能装备的工业互联网安全技术典型应用推广,2018.06-2020.12
  • 国家自然科学基金项目重点项目:移动智能终端系统的漏洞分析与对抗技术研究(U1636217),2017.01-2020.12
  • 国家重点研发计划“网络空间安全”重点专项(2016YFB0801200),2016.11-2019.10
  • 上海市科委重大项目课题(15511103002) :“移动智能终端应用程序安全测试与评估技术研究”Major program of Shanghai Science and Technology Commission (Grant No: 15511103002): “Research on Mobile Smart Device Application Security Testing and Evaluating”,2015.6.30-2017.6.30
  • 国家科技支撑计划(2012BAH46B02),2012-2015.
  • 国家科技重大专项(03专项)(2012ZX03002011):“移动智能终端安全评估技术研究”,2012.1-2013.12.
  • 上海市科委2013年度“科技创新行动计划”信息技术领域项目(13511504000):“移动智能终端安全防护技术研究与原型系统研制”,2013.07-2015.07

Activities


  • 上海交通大学蜚语安全研究组(G.O.S.S.I.P)Group Leader (G.O.S.S.I.P).
  • 上海掌御信息科技有限公司 联合创始人 Palmim.
  • 上海观源信息科技有限公司 合伙人 Viewsources.
  • 深圳市普乐特电子有限公司 首席科学家 Szplot.
  • 一路黔行支教活动 (2008-2014) 发起人、领队.

Awards


  • 上海市科技进步奖一等奖(2018),第三完成人.
  • Hack.lu CTF 2014, 2nd place.
  • Forensic Challenge 9 – “Mobile Malware” @ 2011, 2nd place.