Amit Resh

dblp:175/7061 · DBLP profile ↗
← Back
4ranked-venue papers
0as first author
0since 2021 · last 2019
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Systems and software security · 50% Cryptographic primitives and cryptanalysis · 50%
Software engineering, system software, and programming languages
1 paper
Operating systems · 100%

Topics — the 3 heaviest of 3, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cryptographic primitives and cryptanalysis
obfuscation
0.412019
Hypervisor-Based Protection of Code · IEEE Trans. Inf. Forensics Secur. 2019
Systems and software security
software protection
0.412019
Hypervisor-Based Protection of Code · IEEE Trans. Inf. Forensics Secur. 2019
Operating systems
virtualization
0.412019
Hypervisor-Based Protection of Code · IEEE Trans. Inf. Forensics Secur. 2019

Methods — techniques the papers use, named apart from their topics

virtualization · 0.8cryptography · 0.8
YearPublicationVenuePosition
2019 Hypervisor-assisted Atomic Memory Acquisition in Modern Systems
abstract
Reliable memory acquisition is essential to forensic analysis of a cyber-crime. Various methods of memory acquisition have been proposed, ranging from tools based on a dedicated hardware to software only solutions. Recently, a hypervisor-based method for memory acquisition was proposed (Qi et al., 2017; Martignoni et al., 2010). This method obtains a reliable (atomic) memory image of a running system. The method achieves this by making all memory pages non-writable until they are copied to the memory image, thus preventing uncontrolled modification of these pages. Unfortunately, the proposed method has two deficiencies: (1) the method does not support multiprocessing and (2) the method does not support modern operating systems featuring address space layout randomization (ASLR). We describe a hypervisor-based memory acquisition method that solves the two aforementioned deficiencies. We analyze the memory usage and performance of the proposed method.
Michael Kiperberg, Roee Leon, Amit Resh, Asaf Algawi, Nezer Zaidenberg
ICISSP3
2019 Hypervisor-Based Protection of Code
abstract
The code of a compiled program is susceptible to reverse-engineering attacks on the algorithms and the business logic that are contained within the code. The main existing countermeasure to reverse-engineering is obfuscation. Generally, obfuscation methods suffer from two main deficiencies: 1) the obfuscated code is less efficient than the original and 2) with sufficient effort, the original code may be reconstructed. We propose a method that is based on cryptography and virtualization. The most valuable functions are encrypted and remain inaccessible even during their execution, thus preventing their reconstruction. A specially crafted hypervisor is responsible for decryption, execution, and protection of the encrypted functions. We claim that the system can provide protection even if the attacker: 1) has access to the operating system kernel and 2) can intercept communication over the system bus. The evaluation of the system's efficiency suggests that it can compete with and outperform obfuscation-based methods.
Michael Kiperberg, Roee Leon, Amit Resh, Asaf Algawi, Nezer Zaidenberg
IEEE Trans. Inf. Forensics Secur.3
2017 System for Executing Encrypted Java Programs
Michael Kiperberg, Amit Resh, Asaf Algawi, Nezer Zaidenberg
ICISSP2
2015 Remote Attestation of Software and Execution-Environment in Modern Machines
abstract
The research on network security concentrates mainly on securing the communication channels between two endpoints, which is insufficient if the authenticity of one of the endpoints cannot be determined with certainty. Previously presented methods that allow one endpoint, the authentication authority, to authenticate another remote machine. These methods are inadequate for modern machines that have multiple processors, introduce virtualization extensions, have a greater variety of side effects, and suffer from nondeterminism. This paper addresses the advances of modern machines with respect to the method presented by Kennell. The authors describe how a remote attestation procedure, involving a challenge, needs to be structured in order to provide correct attestation of a remote modern target system.
Michael Kiperberg, Amit Resh, Nezer Zaidenberg
CSCloud2