防黑客盜個人資料 中大研程式 5秒揭社交網登入漏洞

現時不少網站容許網民使用社交網站帳戶登入,毋須於網站申請帳戶,方便網民不需記住大量帳戶登入資料。香港中文大學信息工程學系研發的自動測試工具,在相關軟件開發套件中發現了4種過去未被發現的漏洞,有可能讓黑客由此竊取網民在其他網站的私人資料。

Date: 
Wednesday, August 29, 2018
Media: 
Ming Pao Daily News

Name: 
HAN Dongkun
Title ( post ): 
Lecturer
Department: 
Mechanical and Automation Engineering
email: 
dkhan [at] mae.cuhk.edu.hk
phone: 
3943 3537
website: 
https://www4.mae.cuhk.edu.hk/peoples/han-dongkun/
Avatar: 
Class: 
faculty_member
Chinese Name: 
韓東昆
glossary_index: 
H

Information Engineering Team Discovers Vulnerabilities of Single Sign Code

Date: 
2018-08-28
Thumbnail: 
Body: 

A team of the Department of Information Engineering has recently won the third place of the 2018 Internet Defense Prize and a research grant of US$40,000 funded by Facebook at the 27th USENIX Security Symposium held in the US. Their award was for their contribution to the critical analysis of the security of Single Sign-On (SSO) Software Development Kits (SDKs) deployed in practice. The team comprised of Dr. Ronghai Yang, Prof. Wing Cheong Lau, Mr. Jiongyi Chen, and Prof. Kehuan Zhang of the Department of Information Engineering, CUHK. This is the first time for researchers from an Asian institution to receive this international award.

The winning paper authored by the CUHK team was titled Vetting Single Sign-On SDK Implementations via Symbolic Reasoning. SSO provides a partial solution to the Internet’s over-reliance on passwords. It enables users to use their Online Social Networking accounts/ credentials (such as those from Facebook, Google, Sina, Tencent and Baidu), to log into other third-party applications/ websites (such as OpenRice and IMDb) and thus providing a more convenient way for users to sign up and access different online services and applications. Since SSO has been serving hundreds of millions of Internet users every day, the security of related software development kits (SDKs) is of critical importance to online security.

SSO involves cooperation and coordination between ID providers, users and third-party applications/websites. The technology is complicated and poses many challenges in analysing  the security of SSO SDKs. The CUHK research team designed and implemented S3KVetter (Single-Sign-On SDK Vetter), an automated, efficient testing tool, to check the logical correctness and identify vulnerabilities of SSO SDKs in practice. To demonstrate the efficacy of S3KVetter, the team applied S3KVetter to test ten popular SSO SDKs which have been downloaded for millions of times by web-service/ application developers.

Among the SSO SDKs examined, S3KVetter has discovered 7 classes of logic flaws, 4 of which were previously unknown. The new vulnerabilities can lead to severe consequences, ranging from the sniffing of user activities to the hijacking of user accounts.

The team was thrilled with their work. Dr. Ronghai Yang, an alumnus of CUHK Department of Information Engineering said, “We have discovered multiple zero-day exploits among several popular SSO SDKs in practice. Until the vulnerabilities are mitigated, hackers can exploit them to cause severe breaches of the security and privacy of online users world-wide. This is an important issue that the industry must address.”

“Internet communications and cybersecurity have long been two of the key research areas of the CUHK Engineering Faculty. The award is a great encouragement to our team and a recognition of CUHK’s strength in cybersecurity research.  We will scale new heights in our ongoing work on applied cryptography, security and privacy in cyber systems, with the aim of making the cyberworld a safer place,” said Prof. Lau Wing Cheong of the Department of Information Engineering, CUHK.

For more details of the paper, please go to www.usenix.org/system/files/conference/usenixsecurity18/sec18-yang.pdf


About the Internet Defense Prize

Created in 2014, the Internet Defense Prize is funded by Facebook and offered in partnership with USENIX. It aims to celebrate technical contributions to the protection and defense of the Internet. 

(From left) Prof. Wing Cheong Lau, Mr. Jiongyi Chen of the Department of Information Engineering, and Dr. Nektarios Leontiadis, Threat Research Scientist, Facebook

 

 

Filter: Dept: 
Faculty
IE
Media Release

借鏡澳洲 推創新服務需釋疑慮

澳洲政府是全球最早推行個人健康紀錄數碼化的國家之一。
在過去6年已有約6萬名市民登記參與「我的健康紀錄」(My Health Record)計劃,佔全國人口之2.5%。但當地政府於今年7月推出「退出」(opt-out)政策,容許已登記市民取消其網上數碼建康紀錄。該項政策一出台便引發全國各地傳媒重新檢視「我的健康紀錄」的利與弊。
Date: 
Saturday, August 11, 2018
Media: 
HKET

港男北上搞電子支付|「錢方」創辦人:港人到國內工作沒核心優勢

在港搞初創企業雖不至受人白眼,但深感難以應付生活的80後港人李英豪(Tim),七年後的今天可謂衣錦榮歸。其帶著2011年於北京創立的移動支付平台「錢方好近」回港。公司除了是第一批跟微信支付及支付寶合作的企業外,更將申請成為香港首批虛擬銀行,讓FinTech真正落地。

Date: 
Wednesday, August 8, 2018
Media: 
Apple Daily

MIE Student Wins Bronze Award of the ASM Technology Competition

Date: 
2018-08-08
Thumbnail: 
Body: 

Mr. Ng Ka Lok from Mathematics and Information Engineering Programme has won the Bronze Award of the ASM Technology Competition with his project titled “A Secure Deep Neural Network Framework with Trusted Processors”.  He received a scholarship award of $20,000 and an invitation to a Technology Tour to Munich, Germany arranged by ASM in early December 2018.

About the winning project
Machine learning, especially the state-of-the-art neural networks, is getting more popular for its unpreceded performance. Naturally, the more data we use to train the network, the more useful it is. When no single party possesses enough data, we need multiple parties to contribute their data and train a model together. It raises a privacy concern that the training data can be sensitive and should not be revealed to others. Likewise, any individual query to the neural network can also be sensitive. Users may even decide not to enjoy the advances in machine learning at the price of their privacy. Ng's project solves these problems by developing a new privacy-preserving neural network framework using trusted processors such as Intel SGX and graphics processing unit (GPU). Our framework outperforms the traditional cryptographic approaches by orders of magnitude.



 

 

Filter: Dept: 
Faculty
IE
Name: 
AHN Dohyun
Title ( post ): 
Assistant Professor
Department: 
Systems Engineering and Engineering Management
email: 
dohyun [at] se.cuhk.edu.hk
phone: 
3943 8238
website: 
http://www.se.cuhk.edu.hk/people/academic-staff/prof-ahn-dohyun/
Area of expertise: 
Applied probability, optimization, and stochastic simulation, financial engineering, complex networks, and supply chain management
Avatar: 
Class: 
faculty_member
Chinese Name: 
安濤賢
glossary_index: 
A

半路棄文從理 成就科研事業

身兼中國工程院外籍院士及美國國家工程學院院士,汪正平的科研實力與地位無庸置疑。不過,這位在香港成長的優秀科學家原來在求學初期對中國文學興趣較大,中學畢業後更曾一度入讀中文大學中文系,卻因哥哥的一個邀請改變一生。

Date: 
Tuesday, August 7, 2018
Media: 
Wen Wei Po

工程有出路 科研前景好

汪正平憶述當年「棄文從理」赴美選修化學,其中一項考量是前景更佳。時至今日,出路成疑卻成了不少學子不敢投身科研的一大理由。擔任中大工程學院院長多年,汪正平強調所謂「工程無出路」只是一項誤解,尤其在國家與特區政府日益重視科研發展的大好勢頭下,前景很是理想。

Date: 
Tuesday, August 7, 2018
Media: 
Wen Wei Po

Pages