VLDB 2026 Research / reviewers in the wild / expert
Daniel Luchaup
dblp:17/7429
· DBLP profile ↗
9ranked-venue papers
5as first author
0since 2021 · last 2016
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 first-authorSoftware engineering, systems software and programming languages · 3Computer networks · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
3 papers |
Program analysis · 89% Software testing · 7% Empirical software engineering · 4% | |
| Network and information security
6 papers |
Network security · 63% Cryptographic primitives and cryptanalysis · 22% Web and mobile security · 8% |
Topics — the 19 heaviest of 20, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Program analysis › data flow analysis
constant propagation |
0.5 | 2 | 2016 | Composite Constant Propagation and its Application to Android Program Analysis · IEEE Trans. Software Eng. 2016 Composite Constant Propagation: Application to Android Inter-Component Communication Analysis · ICSE (1) 2015 |
Program analysis
static analysis |
0.5 | 2 | 2016 | Composite Constant Propagation and its Application to Android Program Analysis · IEEE Trans. Software Eng. 2016 Composite Constant Propagation: Application to Android Inter-Component Communication Analysis · ICSE (1) 2015 |
Program analysis › static analysis
interprocedural analysis |
0.3 | 2 | 2016 | Composite Constant Propagation and its Application to Android Program Analysis · IEEE Trans. Software Eng. 2016 Composite Constant Propagation: Application to Android Inter-Component Communication Analysis · ICSE (1) 2015 |
Network security › intrusion detection and prevention › intrusion detection › pattern matching
regular expression matching |
0.3 | 2 | 2014 | Deep packet inspection with DFA-trees and parametrized language overapproximation · INFOCOM 2014 Speculative Parallel Pattern Matching · IEEE Trans. Inf. Forensics Secur. 2011 |
Program analysis › data flow analysis
context-sensitive dataflow analysis |
0.2 | 1 | 2016 | Composite Constant Propagation and its Application to Android Program Analysis · IEEE Trans. Software Eng. 2016 |
Network security › intrusion detection and prevention › intrusion detection
deep packet inspection |
0.2 | 1 | 2014 | Deep packet inspection with DFA-trees and parametrized language overapproximation · INFOCOM 2014 |
Cryptographic primitives and cryptanalysis › encryption › property-preserving encryption
format-preserving encryption |
0.2 | 1 | 2014 | Formatted Encryption Beyond Regular Languages · CCS 2014 |
Network security › intrusion detection and prevention › intrusion detection
intrusion prevention system |
0.2 | 1 | 2014 | Deep packet inspection with DFA-trees and parametrized language overapproximation · INFOCOM 2014 |
Network security › intrusion detection and prevention › intrusion detection › pattern matching
signature matching |
0.2 | 1 | 2014 | Deep packet inspection with DFA-trees and parametrized language overapproximation · INFOCOM 2014 |
Network security
intrusion detection and prevention |
0.1 | 1 | 2011 | Speculative Parallel Pattern Matching · IEEE Trans. Inf. Forensics Secur. 2011 |
Systems and software security
vulnerability discovery |
0.1 | 1 | 2011 | Automatic partial loop summarization in dynamic test generation · ISSTA 2011 |
Software testing › test generation
dynamic test generation |
0.1 | 1 | 2011 | Automatic partial loop summarization in dynamic test generation · ISSTA 2011 |
Program analysis › symbolic execution
path explosion mitigation |
0.1 | 1 | 2011 | Automatic partial loop summarization in dynamic test generation · ISSTA 2011 |
Empirical software engineering › mining software repositories › mobile app analysis
android app analysis |
0.1 | 1 | 2016 | Composite Constant Propagation and its Application to Android Program Analysis · IEEE Trans. Software Eng. 2016 |
Web and mobile security › mobile security
android inter-component communication analysis |
0.1 | 1 | 2015 | Composite Constant Propagation: Application to Android Inter-Component Communication Analysis · ICSE (1) 2015 |
Web and mobile security
mobile security |
0.1 | 1 | 2015 | Composite Constant Propagation: Application to Android Inter-Component Communication Analysis · ICSE (1) 2015 |
Network security › anonymity networks
traffic analysis resistance |
0.1 | 1 | 2014 | LibFTE: A Toolkit for Constructing Practical, Format-Abiding Encryption Schemes · USENIX Security Symposium 2014 |
Automata and formal languages
regular languages |
0.1 | 1 | 2014 | Formatted Encryption Beyond Regular Languages · CCS 2014 |
Parallel and multicore computing
speculative parallelization |
0.0 | 1 | 2011 | Speculative Parallel Pattern Matching · IEEE Trans. Inf. Forensics Secur. 2011 |
Methods — techniques the papers use, named apart from their topics
constraint solving · 0.5symbolic execution · 0.2speculation · 0.2parallel pattern matching · 0.2loop summarization · 0.2declarative specification · 0.2parametrized language overapproximation · 0.2format-transforming encryption · 0.2DFA overapproximation · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2016 | Composite Constant Propagation and its Application to Android Program AnalysisabstractMany program analyses require statically inferring the possible values of composite types. However, current approaches either do not account for correlations between object fields or do so in an ad hoc manner. In this paper, we introduce the problem of composite constant propagation. We develop the first generic solver that infers all possible values of complex objects in an interprocedural, flow and context-sensitive manner, taking field correlations into account. Composite constant propagation problems are specified using COAL, a declarative language. We apply our COAL solver to the problem of inferring Android Inter-Component Communication (ICC) values, which is required to understand how the components of Android applications interact. Using COAL, we model ICC objects in Android more thoroughly than the state-of-the-art. We compute ICC values for 489 applications from the Google Play store. The ICC values we infer are substantially more precise than previous work. The analysis is efficient, taking two minutes per application on average. While this work can be used as the basis for many whole-program analyses of Android applications, the COAL solver can also be used to infer the values of composite objects in many other contexts. Damien Octeau, Daniel Luchaup, Somesh Jha, Patrick D. McDaniel |
IEEE Trans. Software Eng. | 2 |
| 2015 | Composite Constant Propagation: Application to Android Inter-Component Communication AnalysisabstractMany program analyses require statically inferring the possible values of composite types. However, current approaches either do not account for correlations between object fields or do so in an ad hoc manner. In this paper, we introduce the problem of composite constant propagation. We develop the first generic solver that infers all possible values of complex objects in an interprocedural, flow and context-sensitive manner, taking field correlations into account. Composite constant propagation problems are specified using COAL, a declarative language. We apply our COAL solver to the problem of inferring Android Inter-Component Communication (ICC) values, which is required to understand how the components of Android applications interact. Using COAL, we model ICC objects in Android more thoroughly than the state-of-the-art. We compute ICC values for 460 applications from the Play store. The ICC values we infer are substantially more precise than previous work. The analysis is efficient, taking slightly over two minutes per application on average. While this work can be used as the basis for many whole-program analyses of Android applications, the COAL solver can also be used to infer the values of composite objects in many other contexts. Damien Octeau, Daniel Luchaup, Matthew L. Dering, Somesh Jha, Patrick D. McDaniel |
ICSE (1) | 2 |
| 2014 | Formatted Encryption Beyond Regular LanguagesabstractFormat-preserving and format-transforming encryption (FPE and FTE, respectively) are relatively new cryptographic primitives, yet are already being used in a broad range of real-world applications. The most flexible existing FPE and FTE implementations use regular expressions to specify plaintext and/or ciphertext formats. These constructions rely on the ability to efficiently map strings accepted by a regular expression to integers and back, called ranking and unranking, respectively. Daniel Luchaup, Thomas Shrimpton, Thomas Ristenpart, Somesh Jha |
CCS | 1 |
| 2014 | Deep packet inspection with DFA-trees and parametrized language overapproximationabstractIPSs determine whether incoming traffic matches a database of vulnerability signatures defined as regular expressions. DFA representations are popular, but suffer from the state-explosion problem. We introduce a new matching structure: a tree of DFAs where the DFA associated with a node over-approximates those at its children, and the DFAs at the leaves represent the signature set. Matching works top-down, starting at the root of the tree and stopping at the first node whose DFA does not match. In the common case (benign traffic) matching does not reach the leaves. DFA-trees are built using Compact Overapproximate DFAs (CODFAs). A CODFA D' for D over-approximates the language accepted by D, has a smaller number of states than D, and has a low false-match rate. Although built from approximate DFAs, DFA-trees perform exact matching faster than a commonly used method, have a low memory overhead and a guaranteed good worst case performance. Daniel Luchaup, Lorenzo De Carli, Somesh Jha, Eric Bach 0001 |
INFOCOM | 1 |
| 2014 | LibFTE: A Toolkit for Constructing Practical, Format-Abiding Encryption Schemes
Daniel Luchaup, Kevin P. Dyer, Somesh Jha, Thomas Ristenpart, Thomas Shrimpton |
USENIX Security Symposium | 1 |
| 2011 | Using Cell Processors for Intrusion Detection through Regular Expression Matching with SpeculationabstractThe main purpose of network intrusion detection systems is to determine whether incoming network traffic matches known attack signatures. To achieve this goal each of the stored signatures represents a description of an attack or an undesired event in the monitored network. The main weakness with existing signature matching algorithms is that they are essentially serial operations and it is hard for them to keep up with the growing network speed. The major bottleneck in intrusion detection systems is that they are able to scan only one byte at a time, which leads to increased latency and low throughput. Thus, there is a need for a novel approach which takes advantage of the increased computing power of newer architectures. This paper presents a method which uses the Cell architecture to run an adapted speculative parallel pattern matching algorithm. Furthermore, we demonstrate that the advantages brought by our of our approach are significant compared to the serial implementation and other parallel ones. We also emphasize the advantages brought by the characteristics of the Cell architecture. Catalin Radu, Catalin Adrian Leordeanu, Valentin Cristea, Daniel Luchaup |
CISIS | 4 |
| 2011 | Automatic partial loop summarization in dynamic test generationabstractWhitebox fuzzing extends dynamic test generation based on symbolic execution and constraint solving from unit testing to whole-application security testing. Unfortunately, input-dependent loops may cause an explosion in the number of constraints to be solved and in the number of execution paths to be explored. In practice, whitebox fuzzers arbitrarily bound the number of constraints and paths due to input-dependent loops, at the risk of missing code and bugs. Patrice Godefroid, Daniel Luchaup |
ISSTA | 2 |
| 2011 | Speculative Parallel Pattern MatchingabstractIntrusion prevention systems (IPSs) determine whether incoming traffic matches a database of signatures, where each signature is a regular expression and represents an attack or a vulnerability. IPSs need to keep up with ever-increasing line speeds, which has lead to the use of custom hardware. A major bottleneck that IPSs face is that they scan incoming packets one byte at a time, which limits their throughput and latency. In this paper, we present a method to search for arbitrary regular expressions by scanning multiple bytes in parallel using speculation. We break the packet in several chunks, opportunistically scan them in parallel, and if the speculation is wrong, correct it later. We present algorithms that apply speculation in single-threaded software running on commodity processors as well as algorithms for parallel hardware. Experimental results show that speculation leads to improvements in latency and throughput in both cases. Daniel Luchaup, Randy Smith, Cristian Estan, Somesh Jha |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2009 | Multi-byte Regular Expression Matching with Speculation
Daniel Luchaup, Randy Smith, Cristian Estan, Somesh Jha |
RAID | 1 |