09.02.2013 Views

Archives of Peking University News - PKU English - 北京大学

Archives of Peking University News - PKU English - 北京大学

Archives of Peking University News - PKU English - 北京大学

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>北京大学</strong>英语新闻网/<strong>Peking</strong> <strong>University</strong> <strong>News</strong><br />

<strong>PKU</strong> PhD Candidate Awarded at IEEE<br />

Symposium on Security & Privacy 2010<br />

<strong>PKU</strong> NEWS 2010--06--07<br />

http://ennews.pku.edu.cn/news.php?s=275981504<br />

<strong>Peking</strong> <strong>University</strong>, Beijing, June 7, 2010: On May 19, Wang Tielei, PhD candidate<br />

under the guidance <strong>of</strong> Pr<strong>of</strong>. Zou Wei from the Institute <strong>of</strong> Computer Science <strong>of</strong><br />

<strong>Peking</strong> <strong>University</strong>, reported his paper at IEEE Symposium on Security & Privacy<br />

2010 (IEEE S&P‘ 10), which is the top academic symposium in the information<br />

security field. This is the first time in 31 years for Chinese mainland researchers to<br />

publish a paper in this symposium. Wang Tielei was also given the Best Student<br />

Paper Award.<br />

Since 1980, the IEEE Symposium on Security and Privacy (IEEE S&P) has been the<br />

premier forum for the presentation <strong>of</strong> developments in computer security and<br />

electronic privacy. The IEEE S&P has always been held at Oakland, California, so it<br />

is also known as the Oakland forum. Reviewing <strong>of</strong> submitted papers is so strict that<br />

the accepting ratio has only been 11% in the past five years.<br />

The Engineering Research Center <strong>of</strong> Information Security <strong>of</strong> Institute <strong>of</strong> Computer<br />

Science is committed to the research on internet security monitoring and s<strong>of</strong>tware<br />

security vulnerability analysis. Fuzz testing is an important way on finding security<br />

vulnerabilities in large programs. However, they are ineffective if most generated<br />

malformed inputs are rejected in the early stage <strong>of</strong> program running, especially when<br />

target programs employ checksum mechanisms to verify the integrity <strong>of</strong> inputs. In<br />

Wang Tielei‘s paper, he presents TaintScope, an automatic fuzzing system using<br />

dynamic taint analysis and symbolic execution techniques, to tackle the problem<br />

mentioned above. ―TaintScope: A Checksum-Aware Directed Fuzzing Tool for<br />

Automatic S<strong>of</strong>tware Vulnerability Detection‖, the submitted paper by Wang Tielei,<br />

was accepted by IEEE S&P‘ 10 after five rounds <strong>of</strong> rigorous reviews, and was named<br />

as the best student paper.<br />

Wang Tielei finished his work in the group <strong>of</strong> s<strong>of</strong>tware security vulnerability analysis<br />

<strong>of</strong> Engineering Research Center <strong>of</strong> Information Security. The group is interested in<br />

the fields <strong>of</strong> s<strong>of</strong>tware reverse analysis and dynamic and static security vulnerabilities<br />

finding technologies under the guidance <strong>of</strong> Pr<strong>of</strong>. Wei Tao. They have already found a<br />

number <strong>of</strong> security vulnerabilities in some popular s<strong>of</strong>tware, and these vulnerabilities<br />

have been admitted by s<strong>of</strong>tware vulnerability regulatory agencies, such as CVE and<br />

10

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!