学习、批判、守正、创新

研究

近几年发表的部分论文

[1] Gu, Yacong, Lingyun Ying, Yingyuan Pu, Xiao Hu, Huajun Chai, Ruimin Wang, Xing Gao, and Haixin Duan. Investigating Package Related Security Threats in Software Registries. In 2023 IEEE Symposium on Security and Privacy (SP), pp. 1151-1168. IEEE Computer Society, 2022.

[2] Zhang, Mingyu, Wenqiang Ge, Ruichun Tang, and Peishun Liu. Hard Disk Failure Prediction Based on Blending Ensemble Learning. Applied Sciences 13, no. 5 (2023): 3288.

[3] Xiaoqi Zhao, Haipeng Qu, Jianliang Xu, Shuo Li, Gai-Ge Wang. AMSFuzz: An adaptive mutation schedule for fuzzing. Expert Systems with Applications 208 (2022): 118162.

[4] Qi Zhan, You Wu, Haipeng Qu, Xiaoqi Zhao. AcoFuzz: Adaptive energy allocation for greybox fuzzing. 2022 IEEE International Conference on Software Testing, Verification and Validation Workshops (ICSTW). IEEE 2022.

[5] Liu, Peishun, Bing Tian, Xiaobao Liu, Shijing Gu, Li Yan, Leon Bullock, Chao Ma, Yin Liu, and Wenbin Zhang. Construction of Power Fault Knowledge Graph Based on Deep Learning. Applied Sciences 12, no. 14 (2022): 6993.

[6] Shao, Yangyi, Wenbin Zhang, Peishun Liu, Ren Huyue, Ruichun Tang, Qilin Yin, and Qi Li. Log Anomaly Detection method based on BERT model optimization. In 2022 7th International Conference on Cloud Computing and Big Data Analytics (ICCCBDA), pp. 161-166. IEEE, 2022.

[7] Xiaoqi Zhao, Haipeng Qu, Wenjie Lv, Shuo Li, Jianliang Xu. MooFuzz: Many-objective optimization seed schedule for fuzzer. Mathematics 9.3 (2021): 205.

[8] Lin, X.-J., Sun, L. and Qu, H. (2021) 'Cryptanalysis of an anonymous and traceable group data sharing in cloud computing.' IEEE Transactions on Information Forensics and Security, 16, pp. 2773–2775. Available at: https://doi.org/10.1109/tifs.2021.3065505.

[9] Lin, X.-J., Wang, Q., Sun, L. and Qu, H. (2021) 'Identity-based encryption with Equality Test and Datestamp-based authorization mechanism.' Theoretical Computer Science, 861, pp. 117–132. Available at: https://doi.org/10.1016/j.tcs.2021.02.015.

[10] Lin, X.-J., Sun, L., H. Qu., and X. Zhang (2021) 'Public key encryption supporting equality test and flexible authorization without bilinear pairings.' Computer Communications, 170, pp. 190–199. Available at: https://doi.org/10.1016/j.comcom.2021.02.006.

[11] Gu, Shijing, Yuchun Chu, Wenbin Zhang, Peishun Liu, Qilin Yin, and Qi Li. Research on System Log Anomaly Detection Combining Two-way Slice GRU and GA-Attention Mechanism. In 2021 4th International Conference on Artificial Intelligence and Big Data (ICAIBD), pp. 577-583. IEEE, 2021.

[12] Lin, X. J., Wang, Q., Sun, L., Yan, Z., & Liu, P. (2020) 'Security analysis of the first certificateless proxy signature scheme against malicious-but-passive KGC attacks.' The Computer Journal, 64(4), pp. 653–660. Available at: https://doi.org/10.1093/comjnl/bxaa105.

[13] Lingni Kong, Yanyu Zhang. A disaster caused by a Bug: A black box escape of Qemu based on the USB device. Hack In The Box Security Conference (HITBSECCONF). 2021. (video)

[14] Xumei Li, Lei Sun, Ruobing Jiang, Haipeng Qu, Zhen Yan. OTA: An operation-oriented time allocation strategy for greybox fuzzing. 2021 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER). IEEE, 2021.

[15] Lin, X.-J., Sun, L. and Qu, H. (2020) 'Leakage-free ID-based signature, revisited.' The Computer Journal, 63(8), pp. 1263–1270. Available at: https://doi.org/10.1093/comjnl/bxz160.

[16] Lin, X. J., Sun, L., Yan, Z., Zhang, X., & Qu, H. (2020) 'On the security of a certificateless signcryption with known session-specific temporary information security in the standard model.' The Computer Journal, 63(8), pp. 1259–1262. Available at: https://doi.org/10.1093/comjnl/bxz157.

[17] Lin, Xi-Jun, Qihui Wang, Lin Sun, Zhen Yan, and Peishun Liu. Security analysis of the first certificateless proxy signature scheme against malicious-but-passive KGC attacks. The Computer Journal 64, no. 4 (2021): 653-660.

[18] Lei Sun, Xumei Li, Haipeng Qu, Xiaoshuai Zhang. AFLTurbo: Speed up path discovery for greybox fuzzing. 2020 IEEE 31st International Symposium on Software Reliability Engineering (ISSRE). IEEE, 2020.

[19] Lin, X. J., Sun, L., Qu, H., & Xian, H. Q. (2018) 'Cryptanalysis of a compact anonymous hibe with constant size private keys.' The Computer Journal, 62(8), pp. 1087–1091. Available at: https://doi.org/10.1093/comjnl/bxy130.

[20] Lin, X. J., Sun, L., Qu, H., & Liu, D. (2018) 'On the security of secure server-designation public key encryption with Keyword Search.' The Computer Journal, 61(12), pp. 1791–1793. Available at: https://doi.org/10.1093/comjnl/bxy073.

[21] Qu, H., Zhen, Y., Lin, X. J., Qi, Z., & Sun, L. (2018) 'Certificateless public key encryption with Equality Test.' Information Sciences, 462, pp. 76–92. Available at: https://doi.org/10.1016/j.ins.2018.06.025.

[22] Lin, X.-J., Sun, L. and Qu, H. (2018) 'Generic construction of public key encryption, identity-based encryption and signcryption with Equality Test.' Information Sciences, 453, pp. 111–126. Available at: https://doi.org/10.1016/j.ins.2018.04.035.

[23] Xi-Jun, L., Sun, L., Qu, H., & Liu, D. (2017) 'Cryptanalysis of a pairing-free certificateless signcryption scheme.' The Computer Journal, 61(4), pp. 539–544. Available at: https://doi.org/10.1093/comjnl/bxx104.

近几年提交的部分安全漏洞(CVE)

1. ffjpeg:CVE-2019-19887; CVE-2019-19888

2. libIEC61850:CVE-2019-19930; CVE-2019-19931; CVE-2019-19944; CVE-2019-19957; CVE-2019-19958; CVE-2020-7054

3. stb:CVE-2020-6617; CVE-2020-6618; CVE-2020-6619; CVE-2020-6620; CVE-2020-6621; CVE-2020-6622; CVE-2020-6623

4. libsixel:CVE-2019-20056; CVE-2019-20205; CVE-2020-11721

5. gnuplot:CVE-2020-23512; CVE-2021-44917

6. libcroco:CVE-2020-12825

7. libavif:CVE-2020-17369

8. MediaInfoLib:CVE-2020-15395

9. libraw:CVE-2020-24865; CVE-2020-24866; CVE-2020-24867; CVE-2020-24868; CVE-2020-24869; CVE-2020-24870; CVE-2020-24889

10. ropium:CVE-2021-45761

11. GPAC:CVE-2021-44918; CVE-2021-44919; CVE-2021-44920; CVE-2021-44921; CVE-2021-44922; CVE-2021-44923; CVE-2021-44924; CVE-2021-44925; CVE-2021-44926; CVE-2021-44927; CVE-2021-45258; CVE-2021-45259; CVE-2021-45260; CVE-2021-45262; CVE-2021-45263; CVE-2021-45266; CVE-2021-45267; CVE-2021-45759; CVE-2021-45762; CVE-2021-45763; CVE-2021-45764; CVE-2021-45767; CVE-2021-45768; CVE-2021-45291; CVE-2021-45288; CVE-2021-45292; CVE-2021-45289; CVE-2021-45297; CVE-2021-45831; CVE-2021-46039; CVE-2021-46038; CVE-2021-46043; CVE-2021-46042; CVE-2021-46040; CVE-2021-46041; CVE-2021-46046; CVE-2021-46044; CVE-2021-46045; CVE-2021-46047; CVE-2021-46051; CVE-2021-32134; CVE-2021-46049; CVE-2021-46234; CVE-2021-46236; CVE-2021-44922; CVE-2021-46239; CVE-2021-46238; CVE-2021-46240; CVE-2022-22855; CVE-2021-46237; CVE-2021-46311; CVE-2021-46313; CVE-2022-24577; CVE-2022-24578; CVE-2022-24574; CVE-2022-24575; CVE-2022-24576; CVE-2022-4202; CVE-2022-45343

12. vim:CVE-2022-0216; CVE-2022-0318; CVE-2022-0158; CVE-2022-0156; CVE-2022-0213; CVE-2022-3520; CVE-2022-4293; CVE-2022-4292; CVE-2022-3491

13. binaryen:CVE-2021-45290; CVE-2021-45293; CVE-2021-46050; CVE-2021-46053; CVE-2021-46054; CVE-2021-46052; CVE-2021-46048; CVE-2021-46055

14. UPX:CVE-2021-44928; CVE-2021-39604

15. NASM:CVE-2021-45256; CVE-2021-45257

16. GNU Inetutils:CVE-2021-45777

17. mruby:CVE-2021-4188; CVE-2021-46020

18. libmodbus:CVE-2022-0367

19. HDF5:CVE-2021-45833; CVE-2021-45830; CVE-2021-45832; CVE-2021-45829; CVE-2021-46243; CVE-2021-46244; CVE-2021-46242

20. GNU recutils:CVE-2021-46019; CVE-2021-46021; CVE-2021-46022

21. Jerryscript:CVE-2021-46170

22. lib60870:CVE-2021-45773

23. libiec61850:CVE-2021-45769

24. Libmodbus:CVE-2022-0367

25. tsMuxer:CVE-2021-45860; CVE-2021-45861; CVE-2021-45863; CVE-2021-45864

26. rtl_433:CVE-2022-25050; CVE-2022-25051

27. Xpdf:CVE-2022-43295; CVE-2022-45586; CVE-2022-45587

2021级-刘珂:CVE-2022-43101; CVE-2022-43102; CVE-2022-43103; CVE-2022-43104; CVE-2022-43105; CVE-2022-43106; CVE-2022-43107; CVE-2022-43108; CVE-2022-43109

2021级-李逢天:CVE-2022-27374; CVE-2022-27375; CVE-2022-42077; CVE-2022-42078; CVE-2022-42079; CVE-2022-42080; CVE-2022-42081; CVE-2022-42082; CVE-2022-42084; CVE-2022-42085; CVE-2022-42086

团队成员发起的开源项目

[1] AFLTurbo:https://github.com/sleicasper/aflturbo

[2] OTA:https://github.com/lxumei/OTA

[3] AcoFuzz:https://github.com/Half-Quarter/AcoFuzz