Adebayo Omotosho

dblp:157/8241 · DBLP profile ↗
← Back
4ranked-venue papers
2as first author
4since 2021 · last 2025
0000-0002-1642-7610ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 ShadowGuard: Cryptographic Shadow Stack Protection with XOR Obfuscation and HMAC Integrity
abstract
Return-Oriented Programming (ROP) attacks, a persistent security threat for over a decade, pose significant risks to computing devices by exploiting vulnerabilities to hijack control flow and execute arbitrary code. While memory isolation and shadow stacks raise the bar, advanced memory disclosure attacks can still bypass these defenses. As a more resilient software-based defense against such advanced threats, we introduce ShadowGuard, a novel approach that leverages Low-Level Virtual Machine (LLVM) passes, programmatic transformations during compilation, to enhance return address protection and prevent ROP attacks on (embedded) systems that to not feature hardware support for control flow protection.ShadowGuard employs dual XOR-based obfuscation and a HMAC-SHA256 keyed hash algorithm to mask return addresses and ensure their integrity. This combination allows for the detection of tampering attempts. Additionally, a separate, secure shadow stack stores obfuscated addresses and their authentication hashed keys, preventing unauthorized access or modification by attackers.Through comprehensive evaluation using real-life applications and the Coreutils-8.32 benchmark, we demonstrate that our approach effectively detects and mitigates ROP attacks while maintaining practicality. The runtime overhead is approximately 31%, and the binary size increase 2%, on average. This solution offers a scalable and robust defense mechanism for securing return addresses in modern real-world applications.
Sirine Ilahi, Adebayo Omotosho, Christian Hammer 0001
ISSRE2
2024 Towards Anomaly Detection in Embedded Systems Application Using LLVM Passes
abstract
Software security exploits, such as Return-Oriented Programming (ROP) attacks, have persisted for more than a decade. ROP attacks inject malicious behaviors into programs, posing serious risks to computing devices, and they can be par-ticularly challenging to detect in systems with limited resources. In this paper, we introduce an approach that exploits Low-Level Virtual Machine (LLVM) passes, programmatic transformations applied during compilation, to detect ROP attacks in ARM-based embedded systems. By customizing LLVM passes, developers can integrate tailored security checks and optimizations into embedded systems requirements. Our approach is motivated by the use of Hardware Performance Counters (HPCs) for certain mitigations, which are not commonly available on all embedded systems. The experimental evaluation of our approach for de-tecting ROP attacks in real-world applications shows that it is feasible and can be extended to detect new attacks independently of an Operating System (OS). The storage overhead induced by our approach is approximately 55%.
Sirine Ilahi, Adebayo Omotosho, Christian Hammer 0001
COMPSAC2
2023 IDS-MA: Intrusion Detection System for IoT MQTT Attacks Using Centralized and Federated Learning
abstract
Yearly, the number of connected Internet of Things (IoT) devices is growing. The attack surface is also increasing because IoT is generally functionality-centric and security is usually an after-thought. Therefore, memory corruption attacks, man-in-the-middle attacks, and distributed denial of service attacks are a few of the attacks that have been widely exploited on these devices communicating via Message Queue Telemetry Transport (MQTT), which is the most commonly used messaging protocol in IoT. However, much of the research on MQTT intrusion detection has either covered a smaller number of attacks, completely ignored memory attacks, or used inadequate classification evaluation metrics (e.g., only accuracy). In this paper, we design and simulate an MQTT IoT network and present IDS-MA, an intrusion detection system for MQTT attacks by training both centralized and federated learning models. Seven different MQTT attacks were implemented with the models evaluated with metrics such as accuracy, precision, and recall. Our evaluation results show high detection scores on MQTT attacks (including memory attacks). We also obtain an average model detection accuracy of over 80% on 2,210,797 real attacks from the MQTT-IoT-IDS2020 benchmark for both centralized and federated models.
Adebayo Omotosho, Yaman Qendah, Christian Hammer 0001
COMPSAC1
2023 Evaluating the Hardware Performance Counters of an Xtensa Virtual Prototype
abstract
Embedded systems’ hardware and software stacks are becoming more complex requiring more development time, time to market, and cost, which contributes to delayed delivery of these silicon devices. A virtual prototype (VP) provides an embedded systems architecture simulator for application development and testing purposes. In this paper, we developed and present the first virtual prototype of the Xtensa LX7 microprocessor that evaluates the performance of its emulated hardware performance counters (HPCs) with those collected from an actual Xtensa LX7 hardware. Seven machine learning models were developed and trained to find the relationships between the two different datasets for the sample application of classifiying return-oriented programming (ROP) attacks. Our experiments show that the obtained micro-architectural characteristics on the VP are on average about 70% similar and thus permit early simulation capabilities for developers and testers.
Adebayo Omotosho, Sirine Ilahi, Ernesto Villegas Castillo, Christian Hammer 0001, Christian Sauer 0001
DDECS1