William Kosasih

dblp:175/2898 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
4since 2021 · last 2024
0000-0003-1527-1519ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2024 SoK: Can We Really Detect Cache Side-Channel Attacks by Monitoring Performance Counters?
abstract
Sharing microarchitectural components between co-resident programs leads to potential information leaks, with devastating implications on security. Over the last decade, multiple proposals suggested monitoring hardware performance counters as a method for detecting such attacks.
William Kosasih, Yusi Feng, Chitchanok Chuengsatiansup, Yuval Yarom
AsiaCCS1
2023 CacheFX: A Framework for Evaluating Cache Security
abstract
Over the last two decades, the danger of sharing resources between programs has been repeatedly highlighted. Multiple side-channel attacks, which seek to exploit shared components for leaking information, have been devised, mostly targeting shared caching components. In response, the research community has proposed multiple cache designs that aim at curbing the source of side channels.
Daniel Genkin, William Kosasih, Fangfei Liu, Anna Trikalinou, Thomas Unterluggauer, Yuval Yarom
AsiaCCS2
2023 The Gates of Time: Improving Cache Attacks with Transient Execution
Daniel Katzman, William Kosasih, Chitchanok Chuengsatiansup, Eyal Ronen, Yuval Yarom
USENIX Security Symposium2
2022 Simulating cyber security management: A gamified approach to executive decision making
abstract
Executive managers are not all equipped with the cyber security expertise necessary to enable them to make business decisions that accurately represent the status and needs of the cyber security side of the business. Unfortunately, the lack of understanding between the business and cyber security domains contribute to structurally endorsed vulnerabilities within a business context, where either the business needs were considered without understanding the impact on cyber security, or alternatively, the cyber security needs were considered without fully understanding the impact this would have on the business strategy and financial stability. To combat this dilemma, a gamified approach to cyber security training for executives is proposed as a solution to not only minimise the realisation of cyber vulnerabilities within a business context, but also to improve business outcomes that are supported by cyber security measures. We developed a serious game software platform, Aurelius, to simulate an executive decision maker’s role in managing the everyday cyber security investment decisions, and linking that to business metrics to incorporate the business and cyber security understanding. Our game includes simulated cyber security attacks that would require the executive decision maker (the player) to respond appropriately. The algorithms underpinning our simulated cyber security game are a product of a complex systems approach, as this most accurately models an executive’s experience. In our design, we set up Aurelius to fulfil eight of the nine criteria specified for a state of the art serious game in the cyber security domain.
Adam Tonkin, William Kosasih, Marthie Grobler, Mehwish Nasim
ASE2
2015 Exploring the Distance, Location, and Style of "Selfies" with the Self-Pano Mobile Application
Phoey Lee Teh, William Kosasih
WorldCIST (1)2