Matthew Finifter

dblp:11/6892 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
0since 2021 · last 2013
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Systems and software security · 73% Web and mobile security · 27%
Software engineering, system software, and programming languages
2 papers
Operating systems · 50% Program verification · 38% Programming languages and type systems · 12%
Interdisciplinary, comprehensive, and emerging computing
1 paper
Computational social science and digital humanities · 100%

Topics — the 5 heaviest of 8, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › vulnerability management
vulnerability disclosure
0.212013
An Empirical Study of Vulnerability Rewards Programs · USENIX Security Symposium 2013
Web and mobile security
javascript security
0.112010
Preventing Capability Leaks in Secure JavaScript Subsets · NDSS 2010
Systems and software security
language-based security
0.112010
Preventing Capability Leaks in Secure JavaScript Subsets · NDSS 2010
Operating systems › system security › operating system security › protection mechanism
capability-based protection
0.112010
Preventing Capability Leaks in Secure JavaScript Subsets · NDSS 2010
Systems and software security › isolation
isolation of untrusted code
0.012008
Verifiable functional purity in java · CCS 2008

Methods — techniques the papers use, named apart from their topics

interviews · 0.3empirical study · 0.3static verification · 0.2
YearPublicationVenuePosition
2013 An Empirical Study of Vulnerability Rewards Programs
Matthew Finifter, Devdatta Akhawe, David A. Wagner 0001
USENIX Security Symposium1
2012 How to Ask for Permission
Adrienne Porter Felt, Serge Egelman, Matthew Finifter, Devdatta Akhawe, David A. Wagner 0001
HotSec3
2011 Diesel: applying privilege separation to database access
abstract
Database-backed applications typically grant complete database access to every part of the application. In this scenario, a flaw in one module can expose data that the module never uses for legitimate purposes. Drawing parallels to traditional privilege separation, we argue that database data should be subject to limitations such that each section of code receives access to only the data it needs. We call this data separation. Data separation defends against SQL-based errors including buggy queries and SQL injection attacks and facilitates code review, since a module's policy makes the extent of its database access explicit to programmers and code reviewers. We construct a system called Diesel, which implements data separation by intercepting database queries and applying modules' restrictions to the queries. We evaluate Diesel on three widely-used applications: Drupal, JForum, and WordPress.
Adrienne Porter Felt, Matthew Finifter, Joel Weinberger, David A. Wagner 0001
AsiaCCS2
2011 A Systematic Analysis of XSS Sanitization in Web Application Frameworks
Joel Weinberger, Prateek Saxena, Devdatta Akhawe, Matthew Finifter, Richard Shin, Dawn Song
ESORICS4
2010 Preventing Capability Leaks in Secure JavaScript Subsets
Matthew Finifter, Joel Weinberger, Adam Barth
NDSS1
2008 Verifiable functional purity in java
abstract
Proving that particular methods within a code base are functionally pure--deterministic and side-effect free--would aid verification of security properties including function invertibility, reproducibility of computation, and safety of untrusted code execution. Until now it has not been possible to automatically prove a method is functionally pure within a high-level imperative language in wide use, such as Java. We discuss a technique to prove that methods are functionally pure by writing programs in a subset of Java called Joe-E; a static verifier ensures that programs fall within the subset. In Joe-E, pure methods can be trivially recognized from their method signature. To demonstrate the practicality of our approach, we refactor an AES library, an experimental voting machine implementation, and an HTML parser to use our techniques. We prove that their top-level methods are verifiably pure and show how this provides high-level security guarantees about these routines. Our approach to verifiable purity is an attractive way to permit functional-style reasoning about security properties while leveraging the familiarity, convenience, and legacy code of imperative languages.
Matthew Finifter, Adrian Mettler, Naveen Sastry, David A. Wagner 0001
CCS1