Dynamic binary program analysis plays a crucial role in software vulnerability discovery and malicious code analysis. While 64-bit computing environments have become prevalent, numerous applications still utilize their 32-bit counterparts due to factors such as compatibility considerations, including both regular software and malware. Traditional dynamic analysis frameworks are not optimized for the analysis of 32-bit and mixed-mode programs. As a result, they often encounter issues such as anomalies and performance problems when applied to specific application analysis. To address these issues, this paper proposes WOWAF, an enhanced dynamic binary analysis framework tailored for Windows-on-Windows 64-bit (WOW64) environments that enables efficient fine-grained analysis of target applications. The framework is implemented on the built-in emulator in 64-bit Windows operating systems, facilitating effective and stable analysis of both pure 32-bit programs and mixed applications. By leveraging kernel features, the framework facilitates dynamic instrumentation of target programs, while incorporating a novel shadow memory allocation management scheme to minimize impact on program execution, and demonstrates its good deployment feasibility. The effectiveness of WOWAF is validated through comprehensive evaluations of diverse applications in real-world environments, such as exploit programs and evasive malware samples. Additionally, systematic benchmark experiments further demonstrate its strong analytical performance.
- Article type
- Year
- Co-author
Hash functions are essential in cryptographic primitives such as digital signatures, key exchanges, and blockchain technology. SM3, built upon the Merkle-Damgard structure, is a crucial element in Chinese commercial cryptographic schemes. Optimizing hash function performance is crucial given the growth of Internet of Things (IoT) devices and the rapid evolution of blockchain technology. In this paper, we introduce a high-performance implementation framework for accelerating the SM3 cryptography hash function, short for HI-SM3, using heterogeneous GPU (graphics processing unit) parallel computing devices. HI-SM3 enhances the implementation of hash functions across four dimensions: parallelism, register utilization, memory access, and instruction efficiency, resulting in significant performance gains across various GPU platforms. Leveraging the NVIDIA RTX 4090 GPU, HI-SM3 achieves a remarkable peak performance of 454.74 GB/s, surpassing OpenSSL on a high-end server CPU (E5-2699V3) with 16 cores by over 150 times. On the Hygon DCU accelerator, a Chinese domestic graphics card, it achieves 113.77 GB/s. Furthermore, compared with the fastest known GPU-based SM3 implementation, HI-SM3 on the same GPU platform exhibits a 3.12x performance improvement. Even on embedded GPUs consuming less than 40W, HI-SM3 attains a throughput of 5.90 GB/s, which is twice as high as that of a server-level CPU. In summary, HI-SM3 provides a significant performance advantage, positioning it as a compelling solution for accelerating hash operations.
With the expansion and increasing complexity of data center networks (DCNs), network fault-tolerance has become increasingly important. RRect is a server-centered DCN with a good interconnection structure. In this paper, we propose a fault-tolerant routing algorithm RRFP under a conditional fault pattern of RRect, which can find a fault-free path between any two fault-free vertices. Firstly, we study a fault pattern of RRect in the case of restricted faulty vertex sets,
The rapid growth of the Internet of Things (IoT) demands efficient system architectures and protocols to ensure consistent performance at scale. This paper explores the scalability of IoT systems across three key layers: sensing, network, and control. IoT scalability is the ability of a system to maintain consistent and reliable performance despite a continuous increase in connected devices. To evaluate scalability, we introduce the scalability indicator (SI), a metric designed to assess an IoT system’s scalability capability. Through extensive research and real-world deployments, we identify key challenges in data sensing, routing, and system control. Our study presents a model to understand these challenges and proposes strategies to optimize resource utilization, ensuring efficient data collection. The findings also emphasize the key influencing factors for the stable performance of large-scale IoT systems, providing valuable insights for how to design scalable systems that can meet the growing demand for interconnected devices.
With the rapid development of operating systems, attacks on system vulnerabilities are increasing. Dynamic link library (DLL) hijacking is prevalent in installers on freeware platforms and is highly susceptible to exploitation by malware attackers. However, existing studies are based solely on the load paths of DLLs, ignoring the attributes of installers and invocation modes, resulting in low accuracy and weak generality of vulnerability detection. In this paper, we propose a novel model, AB-DHD, which is based on an attention mechanism and a bi-directional gated recurrent unit (BiGRU) neural network for DLL hijacking vulnerability discovery. While BiGRU is an enhancement of GRU and has been widely applied in sequence data processing, a double-layer BiGRU network is introduced to analyze the internal features of installers with DLL hijacking vulnerabilities. Additionally, an attention mechanism is incorporated to dynamically adjust feature weights, significantly enhancing the ability of our model to detect vulnerabilities in new installers. A comprehensive “List of Easily Hijacked DLLs” is developed to serve a reference for future studies. We construct an EXEFul dataset and a DLLVul dataset, using data from two publicly available authoritative vulnerability databases, Common Vulnerabilities & Exposures (CVE) and China National Vulnerability Database (CNVD), and mainstream installer distribution platforms. Experimental results show that our model outperforms popular automated tools like Rattler and DLLHSC, achieving an accuracy of 97.79% and a recall of 94.72%. Moreover, 17 previously unknown vulnerabilities have been identified, and corresponding vulnerability certifications have been assigned.
Echo state network (ESN) as a novel artificial neural network has drawn much attention from time series prediction in edge intelligence. ESN is slightly insufficient in long-term memory, thereby impacting the prediction performance. It suffers from a higher computational overhead when deploying on edge devices. We firstly introduce the knowledge distillation into the reservoir structure optimization, and then propose the echo state network based on improved knowledge distillation (ESN-IKD) for edge intelligence to improve the prediction performance and reduce the computational overhead. The model of ESN-IKD is constructed with the classic ESN as a student network, the long and short-term memory network as a teacher network, and the ESN with double loop reservoir structure as an assistant network. The student network learns the long-term memory capability of the teacher network with the help of the assistant network. The training algorithm of ESN-IKD is proposed to correct the learning direction through the assistant network and eliminate the redundant knowledge through the iterative pruning. It can solve the problems of error learning and redundant learning in the traditional knowledge distillation process. Extensive experimental simulation shows that ESN-IKD has a good time series prediction performance in both long-term and short-term memory, and achieves a lower computational overhead.
Open Access
Issue
Staff attendance information has always been an important part of corporate management. However, some opportunistic employees may consign others to punch their time cards, which hampers the authenticity of attendance and effectiveness of record keeping. Hence, it is necessary to develop an innovative anti-cheating system for office attendance. Radio-Frequency IDentification (RFID) offers new solutions to solve such problems because of its strong anti-interference capability and non-intrusiveness. In this paper, we present a smart attendance system that extracts distinguishable phase characteristics of individuals to enable recognition of various targets. A frequency distribution histogram is extracted as a fingerprint for recognition and the K-means clustering method is utilized for more fine-grained recognition of targets with similar features. Compared with traditional attendance mechanisms, RFID-based attendance systems are based on living biological characteristics, which greatly reduces the possibility of false records. To evaluate the performance of our system, we conducted extensive experiments. The results of which demonstrate the efficiency and accuracy of our system with an average accuracy of
Open Access
Issue
Device-free Passive (DfP) detection has received increasing attention for its ability to support various pervasive applications. Instead of relying on variable Received Signal Strength (RSS), most recent studies rely on finer-grained Channel State Information (CSI). However, existing methods have some limitations, in that they are effective only in the Line-Of-Sight (LOS) or for more than one moving individual. In this paper, we analyze the human motion effect on CSI and propose a novel scheme for Robust Passive Motion Detection (R-PMD). Since traditional low-pass filtering has a number of limitations with respect to data denoising, we adopt a novel Principal Component Analysis (PCA)-based filtering technique to capture the representative signals of human motion and extract the variance profile as the sensitive metric for human detection. In addition, existing schemes simply aggregate CSI values over all the antennas in MIMO systems. Instead, we investigate the sensing quality of each antenna and aggregate the best combination of antennas to achieve more accurate and robust detection. The R-PMD prototype uses off-the-shelf WiFi devices and the experimental results demonstrate that R-PMD achieves an average detection rate of 96.33% with a false alarm rate of 3.67%.
Open Access
Issue
Coverage is an important issue in the area of wireless sensor networks, which reflects the monitoring quality of the sensor networks in scenes. Most sensor coverage research focuses on the ideal two-dimensional (2-D) plane and full three-dimensional (3-D) space. However, in many real-world applications, the target field is a 3-D complex surface, which makes conventional methods unsuitable. In this paper, we study the coverage problem in directional sensor networks for complex 3-D terrains, and design a new surface coverage algorithm. Based on a 3-D directional sensing model of nodes, this algorithm employs grid division, simulated annealing, and local optimum ideas to improve the area coverage ratio by optimizing the position coordinates and the deviation angles of the nodes, which results in coverage enhancement for complex 3-D terrains. We also conduct extensive simulations to evaluate the performance of our algorithms.
京公网安备11010802044758号