Scott A. Carr

dblp:176/5333 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
0since 2021 · last 2018
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
4 papers
Systems and software security · 100%
Software engineering, system software, and programming languages
3 papers
Program analysis · 35% Program verification · 28% Software testing · 28%

Topics — the 7 heaviest of 8, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
memory safety
0.932018
CFIXX: Object Type Integrity for C++ · NDSS 2018
Venerable Variadic Vulnerabilities Vanquished · USENIX Security Symposium 2017
HexType: Efficient Detection of Type Confusion Errors for C++ · CCS 2017
Systems and software security › memory safety
control-flow integrity
0.622018
CFIXX: Object Type Integrity for C++ · NDSS 2018
VTrust: Regaining Trust on Virtual Calls · NDSS 2016
Program analysis
static analysis
0.422017
Automatic Contract Insertion with CCBot · IEEE Trans. Software Eng. 2017
VTrust: Regaining Trust on Virtual Calls · NDSS 2016
Systems and software security › memory safety › memory error detection
type confusion detection
0.312017
HexType: Efficient Detection of Type Confusion Errors for C++ · CCS 2017
Systems and software security
vulnerability discovery
0.312017
HexType: Efficient Detection of Type Confusion Errors for C++ · CCS 2017
Program verification
contract verification
0.312017
Automatic Contract Insertion with CCBot · IEEE Trans. Software Eng. 2017
Software testing
fault detection
0.312017
Automatic Contract Insertion with CCBot · IEEE Trans. Software Eng. 2017

Methods — techniques the papers use, named apart from their topics

precondition/postcondition inference · 0.3object invariants · 0.3compiler optimization · 0.3compiler hardening · 0.3code instrumentation · 0.3
YearPublicationVenuePosition
2018 CUP: Comprehensive User-Space Protection for C/C++
abstract
Memory corruption vulnerabilities in C/C++ applications enable attackers to execute code, change data, and leak information. Current memory sanitizers do not provide comprehensive coverage of a program»s data. In particular, existing tools focus primarily on heap allocations with limited support for stack allocations and globals. Orthogonally, existing tools focus on the main executable with limited support for system libraries. Existing tools also suffer from both false positives and false negatives. We present Comprehensive User-Space Protection for C/C++, \sysname, an LLVM sanitizer that provides complete spatial and probabilistic temporal memory safety for C/C++ programs on 64-bit architectures (with a prototype implementation for x86\_64). \sysname uses a hybrid metadata scheme that supports all program data including globals, heap, or stack and maintains Application Binary Interface (ABI) compatibility. Existing approaches have false positives and 8%-25% false negatives on the NIST Juliet test suite. In contrast, \sysname has no false negatives or false positives. \sysname instruments all user-space code, including libc and other system libraries, removing these libraries from the trusted computing base. Supporting all of user space allows \sysname to treat a missed check as a failed check, leading to no false negatives for \sysname. The overhead introduced by \sysname is half that of the state-of-the-art full memory protection on benchmarks where both mechanisms run, and imposes 1.58x overhead when compared to baseline on all benchmarks. Consequently, \sysname is intended as a sanitizer for use by system developers, and to protect truly critical systems.
Nathan Burow, Derrick Paul McKee, Scott A. Carr, Mathias Payer
AsiaCCS3
2018 CFIXX: Object Type Integrity for C++
Nathan Burow, Derrick Paul McKee, Scott A. Carr, Mathias Payer
NDSS3
2017 DataShield: Configurable Data Confidentiality and Integrity
abstract
Applications written in C/C++ are prone to memory corruption, which allows attackers to extract secrets or gain control of the system. With the rise of strong control-flow hijacking defenses, non-control data attacks have become the dominant threat. As vulnerabilities like HeartBleed have shown, such attacks are equally devastating. Data Confidentiality and Integrity (DCI) is a low-overhead non-control-data protection mechanism for systems software. DCI augments the C/C++ programming languages with an- notations, allowing the programmer to protect selected data types. The DCI compiler and runtime system prevent illegal reads (confidentiality) and writes (integrity) to instances of these types. The programmer selects types that contain security critical information such as passwords, cryptographic keys, or identification tokens. Protecting only this critical data greatly reduces performance overhead relative to complete memory safety.
Scott A. Carr, Mathias Payer
AsiaCCS1
2017 HexType: Efficient Detection of Type Confusion Errors for C++
abstract
Type confusion, often combined with use-after-free, is the main attack vector to compromise modern C++ software like browsers or virtual machines. Typecasting is a core principle that enables modularity in C++. For performance, most typecasts are only checked statically, i.e., the check only tests if a cast is allowed for the given type hierarchy, ignoring the actual runtime type of the object. Using an object of an incompatible base type instead of a derived type results in type confusion. Attackers abuse such type confusion issues to attack popular software products including Adobe Flash, PHP, Google Chrome, or Firefox. We propose to make all type checks explicit, replacing static checks with full runtime type checks. To minimize the performance impact of our mechanism HexType, we develop both low-overhead data structures and compiler optimizations. To maximize detection coverage, we handle specific object allocation patterns, e.g., placement new or reinterpret_cast which are not handled by other mechanisms. Our prototype results show that, compared to prior work, HexType has at least 1.1 -- 6.1 times higher coverage on Firefox benchmarks. For SPEC CPU2006 benchmarks with overhead, we show a 2 -- 33.4 times reduction in overhead. In addition, HexType discovered 4 new type confusion bugs in Qt and Apache Xerces-C++.
Yuseok Jeon, Priyam Biswas, Scott A. Carr, Byoungyoung Lee, Mathias Payer
CCS3
2017 Venerable Variadic Vulnerabilities Vanquished
Priyam Biswas, Alessandro Di Federico, Scott A. Carr, Prabhu Rajasekaran, Stijn Volckaert, Yeoul Na, Michael Franz, Mathias Payer
USENIX Security Symposium3
2017 Automatic Contract Insertion with CCBot
abstract
Existing static analysis tools require significant programmer effort. On large code bases, static analysis tools produce thousands of warnings. It is unrealistic to expect users to review such a massive list and to manually make changes for each warning. To address this issue we propose CCBot (short for CodeContracts Bot), a new tool that applies the results of static analysis to existing code through automatic code transformation. Specifically, CCBot instruments the code with method preconditions, postconditions, and object invariants which detect faults at runtime or statically using a static contract checker. The only configuration the programmer needs to perform is to give CCBot the file paths to code she wants instrumented. This allows the programmer to adopt contract-based static analysis with little effort. CCBot's instrumented version of the code is guaranteed to compile if the original code did. This guarantee means the programmer can deploy or test the instrumented code immediately without additional manual effort. The inserted contracts can detect common errors such as null pointer dereferences and out-of-bounds array accesses. CCBot is a robust large-scale tool with an open-source C# implementation. We have tested it on real world projects with tens of thousands of lines of code. We discuss several projects as case studies, highlighting undiscovered bugs found by CCBot, including 22 new contracts that were accepted by the project authors.
Scott A. Carr, Francesco Logozzo, Mathias Payer
IEEE Trans. Software Eng.1
2016 VTrust: Regaining Trust on Virtual Calls
Chao Zhang 0008, Dawn Song, Scott A. Carr, Mathias Payer, Tongxin Li 0002, Chengyu Song
NDSS3