VLDB 2026 Research / reviewers in the wild / expert
Matthew Finifter
dblp:11/6892
· DBLP profile ↗
6ranked-venue papers
3as first author
0since 2021 · last 2013
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
3 papers |
Systems and software security · 73% Web and mobile security · 27% | |
| Software engineering, system software, and programming languages
2 papers |
Operating systems · 50% Program verification · 38% Programming languages and type systems · 12% | |
| Interdisciplinary, comprehensive, and emerging computing
1 paper |
Computational social science and digital humanities · 100% |
Topics — the 5 heaviest of 8, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security › vulnerability management
vulnerability disclosure |
0.2 | 1 | 2013 | An Empirical Study of Vulnerability Rewards Programs · USENIX Security Symposium 2013 |
Web and mobile security
javascript security |
0.1 | 1 | 2010 | Preventing Capability Leaks in Secure JavaScript Subsets · NDSS 2010 |
Systems and software security
language-based security |
0.1 | 1 | 2010 | Preventing Capability Leaks in Secure JavaScript Subsets · NDSS 2010 |
Operating systems › system security › operating system security › protection mechanism
capability-based protection |
0.1 | 1 | 2010 | Preventing Capability Leaks in Secure JavaScript Subsets · NDSS 2010 |
Systems and software security › isolation
isolation of untrusted code |
0.0 | 1 | 2008 | Verifiable functional purity in java · CCS 2008 |
Methods — techniques the papers use, named apart from their topics
interviews · 0.3empirical study · 0.3static verification · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2013 | An Empirical Study of Vulnerability Rewards Programs
Matthew Finifter, Devdatta Akhawe, David A. Wagner 0001 |
USENIX Security Symposium | 1 |
| 2012 | How to Ask for Permission
Adrienne Porter Felt, Serge Egelman, Matthew Finifter, Devdatta Akhawe, David A. Wagner 0001 |
HotSec | 3 |
| 2011 | Diesel: applying privilege separation to database accessabstractDatabase-backed applications typically grant complete database access to every part of the application. In this scenario, a flaw in one module can expose data that the module never uses for legitimate purposes. Drawing parallels to traditional privilege separation, we argue that database data should be subject to limitations such that each section of code receives access to only the data it needs. We call this data separation. Data separation defends against SQL-based errors including buggy queries and SQL injection attacks and facilitates code review, since a module's policy makes the extent of its database access explicit to programmers and code reviewers. We construct a system called Diesel, which implements data separation by intercepting database queries and applying modules' restrictions to the queries. We evaluate Diesel on three widely-used applications: Drupal, JForum, and WordPress. Adrienne Porter Felt, Matthew Finifter, Joel Weinberger, David A. Wagner 0001 |
AsiaCCS | 2 |
| 2011 | A Systematic Analysis of XSS Sanitization in Web Application Frameworks
Joel Weinberger, Prateek Saxena, Devdatta Akhawe, Matthew Finifter, Richard Shin, Dawn Song |
ESORICS | 4 |
| 2010 | Preventing Capability Leaks in Secure JavaScript Subsets
Matthew Finifter, Joel Weinberger, Adam Barth |
NDSS | 1 |
| 2008 | Verifiable functional purity in javaabstractProving that particular methods within a code base are functionally pure--deterministic and side-effect free--would aid verification of security properties including function invertibility, reproducibility of computation, and safety of untrusted code execution. Until now it has not been possible to automatically prove a method is functionally pure within a high-level imperative language in wide use, such as Java. We discuss a technique to prove that methods are functionally pure by writing programs in a subset of Java called Joe-E; a static verifier ensures that programs fall within the subset. In Joe-E, pure methods can be trivially recognized from their method signature. To demonstrate the practicality of our approach, we refactor an AES library, an experimental voting machine implementation, and an HTML parser to use our techniques. We prove that their top-level methods are verifiably pure and show how this provides high-level security guarantees about these routines. Our approach to verifiable purity is an attractive way to permit functional-style reasoning about security properties while leveraging the familiarity, convenience, and legacy code of imperative languages. Matthew Finifter, Adrian Mettler, Naveen Sastry, David A. Wagner 0001 |
CCS | 1 |