Shashank Sharma 0003

dblp:123/4533-3 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
3since 2021 · last 2024
0009-0005-4149-884XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2024 Fuzzing API Error Handling Behaviors using Coverage Guided Fault Injection
abstract
Incorrect handling of Software Application Programming Interfaces (APIs) errors results in bugs or security vulnerabilities that are hard to trigger during regular testing. Most of the existing techniques to detect such errors are based on static analysis and fail to identify certain cases where API return values are incorrectly handled. Furthermore, most of these techniques suffer from a very high false positive rate (≥50%), raising concerns regarding their practical use. We propose a dynamic analysis approach to detect API error handling bugs based on coverage-guided software fault injection. Specifically, we inject faults into APIs and observe how a program handles them. Our fault injection mechanism is generic and targeted to explore a given program's error handling behavior effectively. We avoid false positives by proactively filtering out crashes caused by infeasible faults. We implemented our technique in an automated pipeline called FuzzERR and applied it to 20 different programs spanning 444 APIs. Our evaluation shows that FuzzERR found 31 new and previously unknown bugs resulting from incorrect handling of API errors. Moreover, a comparative evaluation showed that FuzzERR significantly outperformed the state-of-the-art tools.
Shashank Sharma 0003, Sai Ritvik Tanksalkar, Sourag Cherupattamoolayil, Aravind Machiry
AsiaCCS1
2024 Rust for Embedded Systems: Current State and Open Problems
Ayushi Sharma 0001, Shashank Sharma 0003, Sai Ritvik Tanksalkar, Santiago Torres-Arias, Aravind Machiry
CCS2
2024 Aunor: Converting Rust crates to [no_std] at scale
abstract
Rust's high-performance memory safety features help eliminate an entire class of vulnerabilities, making it an attractive choice for mission-critical applications. Another important advantage of using Rust is the availability of a large number of libraries, i.e., crates, that make it easy to develop applications in Rust. However, crates need to be specially designed, i.e., no_std compatible, to be usable on embedded systems. Unfortunately, the majority of the crates are not no_std compatible. In this work, we tackle this problem by developing an automated code refactoring tool, Aunor, to specialize a given crate to be no_std compatible in a valid and backward compatible manner. Our preliminary evaluation shows Aunor is effective and could automatically convert 318 crates.
Shashank Sharma 0003, Ayushi Sharma 0001, Aravind Machiry
CODASPY1