Open Access. Powered by Scholars. Published by Universities.®

Computer Sciences Commons™

Open Access. Powered by Scholars. Published by Universities.®

Research Collection School Of Computing and Information Systems

Discipline
Keyword
Publication Year
File Type

Articles 4171 - 4200 of 8481

Full-Text Articles in Computer Sciences

Static Analysis Of Context Leaks In Android Applications, Flavio Toffalini, Jun Sun, Martín Cohoa Jun 2018

Static Analysis Of Context Leaks In Android Applications, Flavio Toffalini, Jun Sun, Martín Cohoa

Research Collection School Of Computing and Information Systems

Android native applications, written in Java and distributed in APK format, are widely used in mobile devices. Their specific pattern of use lets the operating system control the creation and destruction of key resources, such as activities and services (contexts). Programmers are not supposed to interfere with such lifecycle events. Otherwise contexts might be leaked, i.e. they will never be deallocated from memory, or be deallocated too late, leading to memory exhaustion and frozen applications. In practice, it is easy to write incorrect code, which hinders garbage collection of contexts and subsequently leads to context leakage.In this work, we present …


Towards Optimal Concolic Testing, Xinyu Wang, Jun Sun, Zhenbang Chen, Peixin Zhang, Jingyi Wang, Yun Lin Jun 2018

Towards Optimal Concolic Testing, Xinyu Wang, Jun Sun, Zhenbang Chen, Peixin Zhang, Jingyi Wang, Yun Lin

Research Collection School Of Computing and Information Systems

Concolic testing integrates concrete execution (e.g., random testing) and symbolic execution for test case generation. It is shown to be more cost-effective than random testing or symbolic execution sometimes. A concolic testing strategy is a function which decides when to apply random testing or symbolic execution, and if it is the latter case, which program path to symbolically execute. Many heuristics-based strategies have been proposed. It is still an open problem what is the optimal concolic testing strategy. In this work, we make two contributions towards solving this problem. First, we show the optimal strategy can be defined based on …


Effect Of Temporality, Physical Activity, And Cognitive Load On Spatiotemporal Vibrotactile Pattern Recognition, Qin Chen, Simon T. Perrault, Quentin Xavier Louis Roy, Lonce Wyse Jun 2018

Effect Of Temporality, Physical Activity, And Cognitive Load On Spatiotemporal Vibrotactile Pattern Recognition, Qin Chen, Simon T. Perrault, Quentin Xavier Louis Roy, Lonce Wyse

Research Collection School Of Computing and Information Systems

Previous research demonstrated the ability for users to accurately recognize Spatiotemporal Vibrotactile Patterns (SVP): sequences of vibrations on different motors occurring either sequentially or simultaneously. However, the experiments were only run in a lab setting and the ability for users to recognize SVP in a real-world environment remains unclear. In this paper, we investigate how several factors may affect recognition: (1) physical activity (running), (2) cognitive task (i.e. primary task, typing), (3) distribution of the vibration motors across body parts and (4) temporality of the patterns. Our results suggest that physical activity has very little impact, specifically compared to cognitive …


Table Of Interest: Activity Recognition And Behaviour Analysis Using A Battery Lesswearable Sensor, Dibyanshu Jaiswal, Andrew Gigie, Tapas Chakravarty, Avik Ghose, Archan Misra Jun 2018

Table Of Interest: Activity Recognition And Behaviour Analysis Using A Battery Lesswearable Sensor, Dibyanshu Jaiswal, Andrew Gigie, Tapas Chakravarty, Avik Ghose, Archan Misra

Research Collection School Of Computing and Information Systems

Energy overheads continue to be a major impediment for wearable based activity recognition systems. We proposed a hybrid approach, which combines wearable-based human sensing with object interaction tracking, for robust detection of ADLs in smart homes. Our proposed framework includes: (a) battery less, low sampling rate, wearable RF sensor tags, that are powered intermittently by an RFID reader, and (b) additional passive RF tags, mounted on daily use objects, that capture the presence and use of specific objects while performing such ADLs. Using an initial experimental set up, we show the ability to recognize activities like eating, typing and reading, …


Towards Easy Comparison Of Local Businesses Using Online Reviews, Yong Wang, Hammad Haleem, Conglei Shi, Yanhong Wu, Xun Zhao, Siwei Fu, Huamin Qu Jun 2018

Towards Easy Comparison Of Local Businesses Using Online Reviews, Yong Wang, Hammad Haleem, Conglei Shi, Yanhong Wu, Xun Zhao, Siwei Fu, Huamin Qu

Research Collection School Of Computing and Information Systems

With the rapid development of e-commerce, there is an increasing number of online review websites, such as Yelp, to help customers make better purchase decisions. Viewing online reviews, including the rating score and text comments by other customers, and conducting a comparison between different businesses are the key to making an optimal decision. However, due to the massive amount of online reviews, the potential difference of user rating standards, and the significant variance of review time, length, details and quality, it is difficult for customers to achieve a quick and comprehensive comparison. In this paper, we present E-Comp, a carefully-designed …


Fimce: A Fully Isolated Micro-Computing Environment For Multicore Systems, Siqi Zhao, Xuhua Ding Jun 2018

Fimce: A Fully Isolated Micro-Computing Environment For Multicore Systems, Siqi Zhao, Xuhua Ding

Research Collection School Of Computing and Information Systems

Virtualization-based memory isolation has been widely used as a security primitive in various security systems to counter kernel-level attacks. In this article, our in-depth analysis on this primitive shows that its security is significantly undermined in the multicore setting when other hardware resources for computing are not enclosed within the isolation boundary. We thus propose to construct a fully isolated micro-computing environment (FIMCE) as a new primitive. By virtue of its architectural niche, FIMCE not only offers stronger security assurance than its predecessor, but also features a flexible and composable environment with support for peripheral device isolation, thus greatly expanding …


Towards Model Checking Android Applications, Guangdong Bai, Quanqi Ye, Yongzheng Wu, Heila Botha, Jun Sun, Yang Liu, Jin Song Dong, Willem Visser Jun 2018

Towards Model Checking Android Applications, Guangdong Bai, Quanqi Ye, Yongzheng Wu, Heila Botha, Jun Sun, Yang Liu, Jin Song Dong, Willem Visser

Research Collection School Of Computing and Information Systems

As feature-rich Android applications (apps for short) are increasingly popularized in security-sensitive scenarios, methods to verify their security properties are highly desirable. Existing approaches on verifying Android apps often have limited effectiveness. For instance, static analysis often suffers from a high false-positive rate, whereas approaches based on dynamic testing are limited in coverage. In this work, we propose an alternative approach, which is to apply the software model checking technique to verify Android apps. We have built a general framework named DroidPF upon Java PathFinder (JPF), towards model checking Android apps. In the framework, we craft an executable mock-up Android …


How Does Developer Interaction Relate To Software Quality? An Examination Of Product Development Data, Subhajit Datta Jun 2018

How Does Developer Interaction Relate To Software Quality? An Examination Of Product Development Data, Subhajit Datta

Research Collection School Of Computing and Information Systems

Industrial software systems are being increasingly developed by large and distributed teams. Tools like collaborative development environments (CDE) are used to facilitate interaction between members of such teams, with the expectation that social factors around the interaction would facilitate team functioning. In this paper, we first identify typically social characteristics of interaction in a software development team: reachability, connection, association, and clustering. We then examine how these factors relate to the quality of software produced by a team, in terms of the number of defects, through an empirical study of 70+ teams, involving 900+ developers in total, spread across 30+ …


Analysing Multi-Point Multi-Frequency Machine Vibrations Using Optical Sampling, Dibyendu Roy, Avik Ghose, Tapas Chakravarty, Sushovan Mukherjee, Arpan Pal, Archan Misra Jun 2018

Analysing Multi-Point Multi-Frequency Machine Vibrations Using Optical Sampling, Dibyendu Roy, Avik Ghose, Tapas Chakravarty, Sushovan Mukherjee, Arpan Pal, Archan Misra

Research Collection School Of Computing and Information Systems

Vibration analysis is a key troubleshooting methodology for assessing the health of factory machinery. We propose an unobtrusive framework for at-a-distance visual estimation of such (possibly high frequency) vibrations, using a low fps (frames-per-second) camera that may, for example, be mounted on a worker's smart-glass. Our key innovation is to use an external stroboscopic light source (that, for example, may be provided by an assistive robot), to illuminate the machine with multiple mutually-prime strobing frequencies, and use the resulting aliased signals to efficiently estimate the different vibration frequencies via an enhanced version of the Chinese Remainder Theorem. Experimental results show …


Dimensionality's Blessing: Clustering Images By Underlying Distribution, Wen-Yan Lin, Jian-Huang Lai, Siying Liu, Yasuyuki Matsushita Jun 2018

Dimensionality's Blessing: Clustering Images By Underlying Distribution, Wen-Yan Lin, Jian-Huang Lai, Siying Liu, Yasuyuki Matsushita

Research Collection School Of Computing and Information Systems

Many high dimensional vector distances tend to a constant. This is typically considered a negative “contrastloss” phenomenon that hinders clustering and other machine learning techniques. We reinterpret “contrast-loss” as a blessing. Re-deriving “contrast-loss” using the law of large numbers, we show it results in a distribution’s instances concentrating on a thin “hyper-shell”. The hollow center means apparently chaotically overlapping distributions are actually intrinsically separable. We use this to develop distribution-clustering, an elegant algorithm for grouping of data points by their (unknown) underlying distribution. Distribution-clustering, creates notably clean clusters from raw unlabeled data, estimates the number of clusters for itself and …


Natural And Effective Obfuscation By Head Inpainting, Qianru Sun, Liqian Ma, Seong Joon Oh, Luc Van Gool, Bernt Schiele, Mario Fritz Jun 2018

Natural And Effective Obfuscation By Head Inpainting, Qianru Sun, Liqian Ma, Seong Joon Oh, Luc Van Gool, Bernt Schiele, Mario Fritz

Research Collection School Of Computing and Information Systems

As more and more personal photos are shared online, being able to obfuscate identities in such photos is becoming a necessity for privacy protection. People have largely resorted to blacking out or blurring head regions, but they result in poor user experience while being surprisingly ineffective against state of the art person recognizers. In this work, we propose a novel head inpainting obfuscation technique. Generating a realistic head inpainting in social media photos is challenging because subjects appear in diverse activities and head orientations. We thus split the task into two sub-tasks: (1) facial landmark generation from image context (e.g. …


Satd Detector: A Text-Mining-Based Self-Admitted Technical Debt Detection Tool, Zhongxin Liu, Qiao Huang, Xin Xia, Emad Shihab, David Lo, Shanping Li Jun 2018

Satd Detector: A Text-Mining-Based Self-Admitted Technical Debt Detection Tool, Zhongxin Liu, Qiao Huang, Xin Xia, Emad Shihab, David Lo, Shanping Li

Research Collection School Of Computing and Information Systems

In software projects, technical debt metaphor is used to describe the situation where developers and managers have to accept compromises in long-Term software quality to achieve short-Term goals. There are many types of technical debt, and self-Admitted technical debt (SATD) was proposed recently to consider debt that is introduced intentionally (e.g., through temporaryfi x) and admitted by developers themselves. Previous work has shown that SATD can be successfully detected using source code comments. However, most current state-of-The-Art approaches identify SATD comments through pattern matching, which achieve high precision but very low recall. That means they may miss many SATD comments …


H-Securebox: A Hardened Memory Data Protection Framework On Arm Devices, Zhangkai Zhang, Zhoujun Li, Chunhe Xia, Jinhua Cui, Jinxin Ma Jun 2018

H-Securebox: A Hardened Memory Data Protection Framework On Arm Devices, Zhangkai Zhang, Zhoujun Li, Chunhe Xia, Jinhua Cui, Jinxin Ma

Research Collection School Of Computing and Information Systems

ARM devices (mobile phone, IoT devices) are getting more popular in our daily life due to the low power consumption and cost. These devices carry a huge number of user's private information, which attracts attackers' attention and increase the security risk. The operating systems (e.g., Android, Linux) works out many memory data protection strategies on user's private information. However, the monolithic OS may contain security vulnerabilities that are exploited by the attacker to get root or even kernel privilege. Once the kernel privilege is obtained by the attacker, all data protection strategies will be gone and user's private information can …


Applying Spatial Database Techniques To Other Domains: A Case Study On Top-K And Computational Geometric Operators, Kyriakos Mouratidis Jun 2018

Applying Spatial Database Techniques To Other Domains: A Case Study On Top-K And Computational Geometric Operators, Kyriakos Mouratidis

Research Collection School Of Computing and Information Systems

In this seminar, we will explore how processing rich spatial data is not the only practical (and research-wise promising) application domain for traditional spatial database techniques. An equally promising direction, possibly with low-hanging fruits for research innovation, may be to apply the spatial data management expertise of our community to non-spatial types of queries, and to extend standard, more theoretical operators to large scale datasets with the objective of practical solutions (as opposed to favorable asymptotic complexity alone). As a case study, we will review spatial database work on top-k-related operators (i.e., non-spatial problems) and how it integrates fundamental computational …


Reserved Optimisation: Handling Incident Priorities In Emergency Response Systems, Muralidhar Konda, Supriyo Ghosh, Pradeep Varakantham Jun 2018

Reserved Optimisation: Handling Incident Priorities In Emergency Response Systems, Muralidhar Konda, Supriyo Ghosh, Pradeep Varakantham

Research Collection School Of Computing and Information Systems

Emergency (medical, fire or criminal) Management Systems(EMSs) are crucial for ensuring public safety and security. Typically in many cities, less than 20% of the cases received by EMSs belong to the extremely serious category and require immediate help. Rest of the incidents typically are less serious and thereby allow more flexibility in response time. Therefore, for efficient management of EMS requests, several EMSs now categorise an incoming emergency request into apriority level based on well studied “triaging” methods. Leading research on optimising emergency response has either focussed on data-driven models for settings with homogenous incidents or on generic heuristics (that …


Crrn: Multi-Scale Guided Concurrent Reflection Removal Network, Renjie Wan, Boxin Shi, Ling-Yu Duan, Ah-Hwee Tan, Alex C. Kot Jun 2018

Crrn: Multi-Scale Guided Concurrent Reflection Removal Network, Renjie Wan, Boxin Shi, Ling-Yu Duan, Ah-Hwee Tan, Alex C. Kot

Research Collection School Of Computing and Information Systems

Removing the undesired reflections from images taken through the glass is of broad application to various computer vision tasks. Non-learning based methods utilize different handcrafted priors such as the separable sparse gradients caused by different levels of blurs, which often fail due to their limited description capability to the properties of real-world reflections. In this paper, we propose the Concurrent Reflection Removal Network (CRRN) to tackle this problem in a unified framework. Our proposed network integrates image appearance information and multi-scale gradient information with human perception inspired loss function, and is trained on a new dataset with 3250 reflection images …


Covariance Pooling For Facial Expression Recognition, D. Acharya, Zhiwu Huang, D. Paudel, Gool L. Van Jun 2018

Covariance Pooling For Facial Expression Recognition, D. Acharya, Zhiwu Huang, D. Paudel, Gool L. Van

Research Collection School Of Computing and Information Systems

Classifying facial expressions into different categories requires capturing regional distortions of facial landmarks. We believe that second-order statistics such as covariance is better able to capture such distortions in regional facial features. In this work, we explore the benefits of using a manifold network structure for covariance pooling to improve facial expression recognition. In particular, we first employ such kind of manifold networks in conjunction with traditional convolutional networks for spatial pooling within individual image feature maps in an end-to-end deep learning manner. By doing so, we are able to achieve a recognition accuracy of 58.14% on the validation set …


Column Generation Approach For Feeder Vessel Routing And Synchronization At A Congested Transshipment Port, Jian G. Jin, Qiang Meng, Hai Wang Jun 2018

Column Generation Approach For Feeder Vessel Routing And Synchronization At A Congested Transshipment Port, Jian G. Jin, Qiang Meng, Hai Wang

Research Collection School Of Computing and Information Systems

With increasing container-shipping traffic in major transshipment ports, unsynchronized shipping services at hub ports usually lead to loss of transshipment connections, significant vessel port-stay time, and congestion. This calls for the design of feeder vessel services to pick up from and deliver containers to neighboring local ports, and, at the same time, synchronize them with long-haul services in a manner that enables efficient container transshipment. In this paper, we present a mixed integer linear programming model to optimize the feeder vessel routes and hub port synchronization with an objective to minimize the total operating and connection cost. We exploit the …


Dynamic Pricing In Spatial Crowdsourcing: A Matching-Based Approach, Yongxin Tong, Libin Wang, Zimu Zhou, Lei Chen, Bowen Du, Jieping Ye Jun 2018

Dynamic Pricing In Spatial Crowdsourcing: A Matching-Based Approach, Yongxin Tong, Libin Wang, Zimu Zhou, Lei Chen, Bowen Du, Jieping Ye

Research Collection School Of Computing and Information Systems

In spatial crowdsourcing, requesters submit their task-related locations and increase the demand of a local area. The platform prices these tasks and assigns spatial workers to serve if the prices are accepted by requesters. There exist mature pricing strategies which specialize in tackling the imbalance between supply and demand in a local market. However, in global optimization, the platform should consider the mobility of workers; that is, any single worker can be the potential supply for several areas, while it can only be the true supply of one area when assigned by the platform. The hardness lies in the uncertainty …


On-Demand Deep Model Compression For Mobile Devices: A Usage-Driven Model Selection Framework, Sicong Liu, Yingyan Lin, Zimu Zhou, Kaiming Nan, Hui Liu, Junzhao Du Jun 2018

On-Demand Deep Model Compression For Mobile Devices: A Usage-Driven Model Selection Framework, Sicong Liu, Yingyan Lin, Zimu Zhou, Kaiming Nan, Hui Liu, Junzhao Du

Research Collection School Of Computing and Information Systems

Recent research has demonstrated the potential of deploying deep neural networks (DNNs) on resource-constrained mobile platforms by trimming down the network complexity using different compression techniques. The current practice only investigate stand-alone compression schemes even though each compression technique may be well suited only for certain types of DNN layers. Also, these compression techniques are optimized merely for the inference accuracy of DNNs, without explicitly considering other application-driven system performance (e.g. latency and energy cost) and the varying resource availabilities across platforms (e.g. storage and processing capability). In this paper, we explore the desirable tradeoff between performance and resource constraints …


Region-Aware Reflection Removal With Unified Content And Gradient Priors, Renjie Wan, Boxin Shi, Ling-Yu Duan, Ah-Hwee Tan, Wen Gao, Alex C. Kot Jun 2018

Region-Aware Reflection Removal With Unified Content And Gradient Priors, Renjie Wan, Boxin Shi, Ling-Yu Duan, Ah-Hwee Tan, Wen Gao, Alex C. Kot

Research Collection School Of Computing and Information Systems

Removing the undesired reflections in images taken through the glass is of broad application to various image processing and computer vision tasks. Existing single image-based solutions heavily rely on scene priors such as separable sparse gradients caused by different levels of blur, and they are fragile when such priors are not observed. In this paper, we notice that strong reflections usually dominant a limited region in the whole image, and propose a region-aware reflection removal approach by automatically detecting and heterogeneously processing regions with and without reflections. We integrate content and gradient priors to jointly achieve missing contents restoration, as …


Inference Of Development Activities From Interaction With Uninstrumented Applications, Lingfeng Bao, Zhenchang Xing, Xin Xia, David Lo, Ahmed E. Hassan Jun 2018

Inference Of Development Activities From Interaction With Uninstrumented Applications, Lingfeng Bao, Zhenchang Xing, Xin Xia, David Lo, Ahmed E. Hassan

Research Collection School Of Computing and Information Systems

Studying developers’ behavior in software development tasks is crucial for designing effective techniques and tools to support developers’ daily work. In modern software development, developers frequently use different applications including IDEs, Web Browsers, documentation software (such as Office Word, Excel, and PDF applications), and other tools to complete their tasks. This creates significant challenges in collecting and analyzing developers’ behavior data. Researchers usually instrument the software tools to log developers’ behavior for further studies. This is feasible for studies on development activities using specific software tools. However, instrumenting all software tools commonly used in real work settings is difficult and …


Verifiably Encrypted Cascade-Instantiable Blank Signatures To Secure Progressive Decision Management, Yujue Wang, Hwee Hwa Pang, Robert H. Deng Jun 2018

Verifiably Encrypted Cascade-Instantiable Blank Signatures To Secure Progressive Decision Management, Yujue Wang, Hwee Hwa Pang, Robert H. Deng

Research Collection School Of Computing and Information Systems

In this paper, we introduce the notion of verifiably encrypted cascade-instantiable blank signatures (CBS) in a multi-user setting. In CBS, there is a delegation chain that starts with an originator and is followed by a sequence of proxies. The originator creates and signs a template, which may comprise fixed fields and exchangeable fields. Thereafter, each proxy along the delegation chain is able to make an instantiation of the template from the choices passed down from her direct predecessor, before generating a signature for her instantiation. First, we present a non-interactive basic CBS construction that does not rely on any shared …


Security And Privacy In Smart Health: Efficient Policy-Hiding Attribute-Based Access Control, Yinghui Zhang, Dong Zheng, Robert H. Deng Jun 2018

Security And Privacy In Smart Health: Efficient Policy-Hiding Attribute-Based Access Control, Yinghui Zhang, Dong Zheng, Robert H. Deng

Research Collection School Of Computing and Information Systems

With the rapid development of the Internet of Things (IoT) and cloud computing technologies, smart health (s-health) is expected to significantly improve the quality of health care. However, data security and user privacy concerns in s-health have not been adequately addressed. As a well-received solution to realize fine-grained access control, ciphertext-policy attribute-based encryption (CP-ABE) has the potential to ensure data security in s-health. Nevertheless, direct adoption of the traditional CP-ABE in s-health suffers two flaws. For one thing, access policies are in cleartext form and reveal sensitive health-related information in the encrypted s-health records (SHRs). For another, it usually supports …


Empath-D: Vr-Based Empathetic App Design For Accessibility, Wonjung Kim, Kenny Tsu Wei Choo, Youngki Lee, Archan Misra, Rajesh Krishna Balan Jun 2018

Empath-D: Vr-Based Empathetic App Design For Accessibility, Wonjung Kim, Kenny Tsu Wei Choo, Youngki Lee, Archan Misra, Rajesh Krishna Balan

Research Collection School Of Computing and Information Systems

With app-based interaction increasingly permeating all aspects of daily living, it is essential to ensure that apps are designed to be inclusive and are usable by a wider audience such as the elderly, with various impairments (e.g., visual, audio and motor). We propose Empath-D, a system that fosters empathetic design, by allowing app designers, in-situ, to rapidly evaluate the usability of their apps, from the perspective of impaired users. To provide a truly authentic experience, Empath-D carefully orchestrates the interaction between a smartphone and a VR device, allowing the user to experience simulated impairments in a virtual world while interacting …


Effectiveness Of Bite-Sized Lecture On Student Learning Outcomes, Noi Sian Koh, Swapna Gottipati, Venky Shankararaman Jun 2018

Effectiveness Of Bite-Sized Lecture On Student Learning Outcomes, Noi Sian Koh, Swapna Gottipati, Venky Shankararaman

Research Collection School Of Computing and Information Systems

Bite-Sized teaching approach uses relatively small learning units with short term focused activities. The paper presents the effectiveness of Bite-Sized lecture pedagogy on learning outcomes for an analytics course offered by the School of Information Technology at Nanyang Polytechnic. The methodology involves breaking a typical 1 hour lecture into 3 to 4 short lectures followed by related tutorial / practical exercises relevant to each respective short lecture. The results from the exercises shows statistically significant improvements in the assessed learning outcomes for the Bite-Sized lecture over the traditional one hour lecture. 75% of the surveyed respondents agreed that the speed …


Social Stream Classification With Emerging New Labels, Xin Mu, Feida Zhu, Yue Liu, Ee-Peng Lim, Zhi-Hua Zhou Jun 2018

Social Stream Classification With Emerging New Labels, Xin Mu, Feida Zhu, Yue Liu, Ee-Peng Lim, Zhi-Hua Zhou

Research Collection School Of Computing and Information Systems

As an important research topic with well-recognized practical values, classification of social streams has been identified with increasing popularity with social data, such as the tweet stream generated by Twitter users in chronological order. A salient, and perhaps also the most interesting, feature of such user-generated content is its never-failing novelty, which, unfortunately, would challenge most traditional pre-trained classification models as they are built based on fixed label set and would therefore fail to identify new labels as they emerge. In this paper, we study the problem of classification of social streams with emerging new labels, and propose a novel …


Towards Dynamically Monitoring Android Applications On Non-Rooted Devices In The Wild, Xiaoxiao Tang, Daoyuan Wu, Yan Lin, Debin Gao Jun 2018

Towards Dynamically Monitoring Android Applications On Non-Rooted Devices In The Wild, Xiaoxiao Tang, Daoyuan Wu, Yan Lin, Debin Gao

Research Collection School Of Computing and Information Systems

Dynamic analysis is an important technique to reveal sensitive behavior of Android apps. Current works require access to the code-level and system-level events (e.g., API calls and system calls) triggered by the running apps and consequently they can only be conducted on in-lab running environments (e.g., emulators and modified OS). The strict requirement of running environment hinders their deployment in scale and makes them vulnerable to anti-analysis techniques. Furthermore, current dynamic analysis of Android apps exploits input generators to invoke app behavior, which, however, cannot provide sufficient code coverage. We propose to dynamically analyze app behavior on non-rooted devices used …


Mobiceal: Towards Secure And Practical Plausibly Deniable Encryption On Mobile Devices, Bing Chang, Fengwei Zhang, Bo Chen, Yingjiu Li, Wen Tao Zhu, Yangguang Tian, Zhan Wang, Albert Ching Jun 2018

Mobiceal: Towards Secure And Practical Plausibly Deniable Encryption On Mobile Devices, Bing Chang, Fengwei Zhang, Bo Chen, Yingjiu Li, Wen Tao Zhu, Yangguang Tian, Zhan Wang, Albert Ching

Research Collection School Of Computing and Information Systems

We introduce MobiCeal, the first practical Plausibly Deniable Encryption (PDE) system for mobile devices that can defend against strong coercive multi-snapshot adversaries, who may examine the storage medium of a user's mobile device at different points of time and force the user to decrypt data. MobiCeal relies on 'dummy write' to obfuscate the differences between multiple snapshots of storage medium due to existence of hidden data. By incorporating PDE in block layer, MobiCeal supports a broad deployment of any block-based file systems on mobile devices. More importantly, MobiCeal is secure against side channel attacks which pose a serious threat to …


To Detect Stack Buffer Overflow With Polymorphic Canaries, Zhilong Wang, Xuhua Ding, Chengbin Pang, Jian Guo, Jun Zhu, Bing Mao Jun 2018

To Detect Stack Buffer Overflow With Polymorphic Canaries, Zhilong Wang, Xuhua Ding, Chengbin Pang, Jian Guo, Jun Zhu, Bing Mao

Research Collection School Of Computing and Information Systems

Stack Smashing Protection (SSP) is a simple and highly efficient technique widely used in practice as the front line defense against stack buffer overflow attacks. Unfortunately, SSP is known to be vulnerable to the so-called byte-by-byte attack. Although several remedy schemes are proposed in the recent literature, their security is achieved at the price of practicality, because their complex logics ruin SSP's simplicity and high-efficiency. In this paper, we present an elegant solution named as Polymorphic SSP (P-SSP) that attains the same security without sacrificing SSP's strengths. We also propose three extensions of the basic scheme for better compatibility, stronger …