Meni Orenbach

dblp:172/0911 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
3since 2021 · last 2025
0000-0002-8180-3598ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 4 · 3 first-author · 1 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2025 BlueGuard: Accelerated Host and Guest Introspection Using DPUs
Meni Orenbach, Rami Ailabouni, Nael Masalha, Ahmad Saleh, Frank Block, Fritz Alder, Ofir Arkin, Ahmad Atamli-Reineh
USENIX Security Symposium1
2024 One for All and All for One: GNN-based Control-Flow Attestation for Embedded Devices
abstract
Control-Flow Attestation (CFA) is a security service that allows an entity (verifier) to verify the integrity of code execution on a remote computer system (prover). Existing CFA schemes suffer from impractical assumptions, such as requiring access to the prover’s internal state (e.g., memory or code), the complete Control-flow graph (CFG) of the prover’s software, large sets of measurements, or tailor-made hardware. Moreover, current CFA schemes are inadequate for attesting embedded systems due to their high computational overhead and resource usage.In this paper, we overcome the limitations of existing CFA schemes for embedded devices by introducing RAGE, a novel, lightweight CFA approach with minimal requirements. RAGE can detect Code Reuse Attacks (CRA), including control-and non-control-data attacks. It efficiently extracts features from one execution trace and leverages Unsupervised Graph Neural Networks (GNNs) to identify deviations from benign executions. The core intuition behind RAGE is to exploit the correspondence between execution trace, execution graph, and execution embeddings to eliminate the unrealistic requirement of having access to a complete CFG.We evaluate RAGE on embedded benchmarks and demonstrate that (i) it detects 40 real-world attacks on embedded software; (ii) Further, we stress our scheme with synthetic returnoriented programming (ROP) and data-oriented programming (DOP) attacks on the real-world embedded software benchmark Embench, achieving 98.03% (ROP) and 91.01% (DOP) F1-Score while maintaining a low False Positive Rate of 3.19%; (iii) Additionally, we evaluate RAGE on OpenSSL, used by millions of devices and achieve 97.49% and 84.42% F1-Score for ROP and DOP attack detection, with an FPR of 5.47%.
Marco Chilese, Richard Mitev, Meni Orenbach, Robert Thorburn, Ahmad Atamli-Reineh, Ahmad-Reza Sadeghi
SP3
2023 Fuzzing LibraryOSes for Iago vulnerabilities
abstract
We present a new fuzzing approach for Iago vulnerabilities in Library OSes for SGX enclaves. Based on the filesystem model, it allows efficiently combining valid and malicious values to reach deeper paths in LibraryOS to identify more potential security vulnerabilities.
Leonid Dyachkov, Meni Orenbach, Mark Silberstein
SYSTOR2
2020 Autarky: closing controlled channels with self-paging enclaves
abstract
As the first widely-deployed secure enclave hardware, Intel SGX shows promise as a practical basis for confidential cloud computing. However, side channels remain SGX's greatest security weakness. Inparticular, the "controlled-channel attack" on enclave page faults exploits a longstanding architectural side channel and still lacks effective mitigation.
Meni Orenbach, Andrew Baumann, Mark Silberstein
EuroSys1
2019 CoSMIX: A Compiler-based System for Secure Memory Instrumentation and Execution in Enclaves
Meni Orenbach, Yan Michalevsky, Christof Fetzer, Mark Silberstein
USENIX ATC1
2017 Eleos: ExitLess OS Services for SGX Enclaves
abstract
Intel Software Guard extensions (SGX) enable secure and trusted execution of user code in an isolated enclave to protect against a powerful adversary. Unfortunately, running I/O-intensive, memory-demanding server applications in enclaves leads to significant performance degradation. Such applications put a substantial load on the in-enclave system call and secure paging mechanisms, which turn out to be the main reason for the application slowdown. In addition to the high direct cost of thousands-of-cycles long SGX management instructions, these mechanisms incur the high indirect cost of enclave exits due to associated TLB flushes and processor state pollution.
Meni Orenbach, Pavel Lifshits, Marina Minkin, Mark Silberstein
EuroSys1
2016 NearBucket-LSH: Efficient Similarity Search in P2P Networks
Naama Kraus, David Carmel, Idit Keidar, Meni Orenbach
SISAP4