Mikhail Kazdagli

dblp:151/7523 · DBLP profile ↗
← Back
3ranked-venue papers
2as first author
1since 2021 · last 2022
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 2 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Authentication and access control · 50% Malware analysis · 22% Network security · 19%
Theoretical computer science
2 papers
Mathematical optimization · 72% Information theory · 28%

Topics — the 8 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Authentication and access control
access control
0.612022
Using Constraint Programming and Graph Representation Learning for Generating Interpretable Cloud Security Policies · IJCAI 2022
Malware analysis › malware detection
hardware-based malware detection
0.212016
Quantifying and improving the efficiency of hardware-based mobile malware detectors · MICRO 2016
Malware analysis
malware detection
0.212016
Quantifying and improving the efficiency of hardware-based mobile malware detectors · MICRO 2016
Network security
covert channel
0.212015
Understanding contention-based channels and using them for defense · HPCA 2015
Network security › intrusion detection and prevention
covert channel detection
0.212015
Understanding contention-based channels and using them for defense · HPCA 2015
Hardware security and side channels
microarchitectural side channel
0.212015
Understanding contention-based channels and using them for defense · HPCA 2015
Mathematical optimization
constraint programming
0.212022
Using Constraint Programming and Graph Representation Learning for Generating Interpretable Cloud Security Policies · IJCAI 2022
Information theory
channel capacity
0.112015
Understanding contention-based channels and using them for defense · HPCA 2015

Methods — techniques the papers use, named apart from their topics

graph representation learning · 1.1constraint programming · 1.1information-theoretic modeling · 0.4unsupervised learning · 0.2supervised learning · 0.2discrete wavelet transform · 0.2
YearPublicationVenuePosition
2022 Using Constraint Programming and Graph Representation Learning for Generating Interpretable Cloud Security Policies
abstract
Modern software systems rely on mining insights from business sensitive data stored in public clouds. A data breach usually incurs significant (monetary) loss for a commercial organization. Conceptually, cloud security heavily relies on Identity Access Management (IAM) policies that IT admins need to properly configure and periodically update. Security negligence and human errors often lead to misconfiguring IAM policies which may open a backdoor for attackers. To address these challenges, first, we develop a novel framework that encodes generating optimal IAM policies using constraint programming (CP). We identify reducing dormant permissions of cloud users as an optimality criterion, which intuitively implies minimizing unnecessary datastore access permissions. Second, to make IAM policies interpretable, we use graph representation learning applied to historical access patterns of users to augment our CP model with similarity constraints: similar users should be grouped together and share common IAM policies. Third, we describe multiple attack models and show that our optimized IAM policies significantly reduce the impact of security attacks using real data from 8 commercial organizations, and synthetic instances.
Mikhail Kazdagli, Mohit Tiwari, Akshat Kumar
IJCAI1
2016 Quantifying and improving the efficiency of hardware-based mobile malware detectors
abstract
Hardware-based malware detectors (HMDs) are a key emerging technology to build trustworthy systems, especially mobile platforms. Quantifying the efficacy of HMDs against malicious adversaries is thus an important problem. The challenge lies in that real-world malware adapts to defenses, evades being run in experimental settings, and hides behind benign applications. Thus, realizing the potential of HMDs as a small and battery-efficient line of defense requires a rigorous foundation for evaluating HMDs. We introduce Sherlock — a white-box methodology that quantifies an HMD's ability to detect malware and identify the reason why. Sherlock first deconstructs malware into atomic, orthogonal actions to synthesize a diverse malware suite. Sherlock then drives both malware and benign programs with real user-inputs, and compares their executions to determine an HMD's operating range, i.e., the smallest malware actions an HMD can detect. We show three case studies using Sherlock to not only quantify HMDs' operating ranges but design better detectors. First, using information about concrete malware actions, we build a discrete-wavelet transform based unsupervised HMD that outperforms prior work based on power transforms by 24.7% (AUC metric). Second, training a supervised HMD using Sherlock's diverse malware dataset yields 12.5% better HMDs than past approaches that train on ad-hoc subsets of malware. Finally, Sherlock shows why a malware instance is detectable. This yields a surprising new result — obfuscation techniques used by malware to evade static analyses makes them more detectable using HMDs.
Mikhail Kazdagli, Vijay Janapa Reddi, Mohit Tiwari
MICRO1
2015 Understanding contention-based channels and using them for defense
abstract
Microarchitectural resources such as caches and predictors can be used to leak information across security domains. Significant prior work has demonstrated attacks and defenses for specific types of such microarchitectural side and covert channels. In this paper, we introduce a general mathematical study of microarchitectural channels using information theory. Our conceptual contribution is a simple mathematical abstraction that captures the common characteristics of all microarchitectural channels. We call this the Bucket model and it reveals that microarchitectural channels are fundamentally different from side and covert channels in networking. We then quantify the communication capacity of several microarchitectural covert channels (including channels that rely on performance counters, AES hardware and memory buses) and measure bandwidths across both KVM based heavy-weight virtualization and light-weight operating-system level isolation. We demonstrate channel capacities that are orders of magnitude higher compared to what was previously considered possible. Finally, we introduce a novel way of detecting intelligent adversaries that try to hide while running covert channel eavesdropping attacks. Our method generalizes a prior detection scheme (that modeled static adversaries) by introducing noise that hides the detection process from an intelligent eavesdropper.
Casen Hunger, Mikhail Kazdagli, Ankit Singh Rawat, Alexandros G. Dimakis, Sriram Vishwanath, Mohit Tiwari
HPCA2