Steve Hanna

dblp:12/3772 · DBLP profile ↗
← Back
7ranked-venue papers
1as first author
0since 2021 · last 2012
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
4 papers
Web and mobile security · 50% Systems and software security · 33% Authentication and access control · 17%
Software engineering, system software, and programming languages
4 papers
Program analysis · 73% Operating systems · 15% Software maintenance and evolution · 12%

Topics — the 9 heaviest of 12, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Web and mobile security › mobile security
android permission analysis
0.112011
Android permissions demystified · CCS 2011
Web and mobile security
mobile security
0.112011
Android permissions demystified · CCS 2011
Authentication and access control › access control › permission management
permission systems
0.112011
Android permissions demystified · CCS 2011
Systems and software security
vulnerability discovery
0.112010
A Symbolic Execution Framework for JavaScript · IEEE Symposium on Security and Privacy 2010
Program analysis
symbolic execution
0.112010
A Symbolic Execution Framework for JavaScript · IEEE Symposium on Security and Privacy 2010
Operating systems › system security › operating system security
access control
0.012011
Permission Re-Delegation: Attacks and Defenses · USENIX Security Symposium 2011
Program analysis
static analysis
0.012010
FLAX: Systematic Discovery of Client-side Validation Vulnerabilities in Rich Web Applications · NDSS 2010
Program analysis › constraint solving
string constraint solving
0.012010
A Symbolic Execution Framework for JavaScript · IEEE Symposium on Security and Privacy 2010
Program analysis › static analysis
dependency analysis
0.012001
Building Certifications Paths: Forward vs. Reverse · NDSS 2001

Methods — techniques the papers use, named apart from their topics

static analysis · 0.3symbolic execution · 0.2API-permission mapping · 0.1string constraint solvers · 0.1string constraint solver · 0.1graph analysis · 0.0
YearPublicationVenuePosition
2012 Juxtapp: A Scalable System for Detecting Code Reuse among Android Applications
Steve Hanna, Ling Huang 0001, Edward XueJun Wu, Saung Li, Dawn Song
DIMVA1
2011 Android permissions demystified
abstract
Android provides third-party applications with an extensive API that includes access to phone hardware, settings, and user data. Access to privacy- and security-relevant parts of the API is controlled with an install-time application permission system. We study Android applications to determine whether Android developers follow least privilege with their permission requests. We built Stowaway, a tool that detects overprivilege in compiled Android applications. Stowaway determines the set of API calls that an application uses and then maps those API calls to permissions. We used automated testing tools on the Android API in order to build the permission map that is necessary for detecting overprivilege. We apply Stowaway to a set of 940 applications and find that about one-third are overprivileged. We investigate the causes of overprivilege and find evidence that developers are trying to follow least privilege but sometimes fail due to insufficient API documentation.
Adrienne Porter Felt, Erika Chin, Steve Hanna, Dawn Song, David A. Wagner 0001
CCS3
2011 Permission Re-Delegation: Attacks and Defenses
Adrienne Porter Felt, Helen J. Wang, Alexander Moshchuk, Steve Hanna, Erika Chin
USENIX Security Symposium4
2010 HookScout: Proactive Binary-Centric Hook Detection
Heng Yin 0001, Pongsin Poosankam, Steve Hanna, Dawn Song
DIMVA3
2010 FLAX: Systematic Discovery of Client-side Validation Vulnerabilities in Rich Web Applications
Prateek Saxena, Steve Hanna, Pongsin Poosankam, Dawn Song
NDSS2
2010 A Symbolic Execution Framework for JavaScript
abstract
As AJAX applications gain popularity, client-side JavaScript code is becoming increasingly complex. However, few automated vulnerability analysis tools for JavaScript exist. In this paper, we describe the first system for exploring the execution space of JavaScript code using symbolic execution. To handle JavaScript code's complex use of string operations, we design a new language of string constraints and implement a solver for it. We build an automatic end-to-end tool, Kudzu, and apply it to the problem of finding client-side code injection vulnerabilities. In experiments on 18 live web applications, Kudzu automatically discovers 2 previously unknown vulnerabilities and 9 more that were previously found only with a manually-constructed test suite.
Prateek Saxena, Devdatta Akhawe, Steve Hanna, Feng Mao, Stephen McCamant, Dawn Song
IEEE Symposium on Security and Privacy3
2001 Building Certifications Paths: Forward vs. Reverse
Yassir Elley, Anne H. Anderson, Steve Hanna, Sean Mullan, Radia J. Perlman, Seth Proctor
NDSS3