VLDB 2026 Research / reviewers in the wild / expert
Scott A. Carr
dblp:176/5333
· DBLP profile ↗
7ranked-venue papers
2as first author
0since 2021 · last 2018
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
4 papers |
Systems and software security · 100% | |
| Software engineering, system software, and programming languages
3 papers |
Program analysis · 35% Program verification · 28% Software testing · 28% |
Topics — the 7 heaviest of 8, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
memory safety |
0.9 | 3 | 2018 | CFIXX: Object Type Integrity for C++ · NDSS 2018 Venerable Variadic Vulnerabilities Vanquished · USENIX Security Symposium 2017 HexType: Efficient Detection of Type Confusion Errors for C++ · CCS 2017 |
Systems and software security › memory safety
control-flow integrity |
0.6 | 2 | 2018 | CFIXX: Object Type Integrity for C++ · NDSS 2018 VTrust: Regaining Trust on Virtual Calls · NDSS 2016 |
Program analysis
static analysis |
0.4 | 2 | 2017 | Automatic Contract Insertion with CCBot · IEEE Trans. Software Eng. 2017 VTrust: Regaining Trust on Virtual Calls · NDSS 2016 |
Systems and software security › memory safety › memory error detection
type confusion detection |
0.3 | 1 | 2017 | HexType: Efficient Detection of Type Confusion Errors for C++ · CCS 2017 |
Systems and software security
vulnerability discovery |
0.3 | 1 | 2017 | HexType: Efficient Detection of Type Confusion Errors for C++ · CCS 2017 |
Program verification
contract verification |
0.3 | 1 | 2017 | Automatic Contract Insertion with CCBot · IEEE Trans. Software Eng. 2017 |
Software testing
fault detection |
0.3 | 1 | 2017 | Automatic Contract Insertion with CCBot · IEEE Trans. Software Eng. 2017 |
Methods — techniques the papers use, named apart from their topics
precondition/postcondition inference · 0.3object invariants · 0.3compiler optimization · 0.3compiler hardening · 0.3code instrumentation · 0.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2018 | CUP: Comprehensive User-Space Protection for C/C++abstractMemory corruption vulnerabilities in C/C++ applications enable attackers to execute code, change data, and leak information. Current memory sanitizers do not provide comprehensive coverage of a program»s data. In particular, existing tools focus primarily on heap allocations with limited support for stack allocations and globals. Orthogonally, existing tools focus on the main executable with limited support for system libraries. Existing tools also suffer from both false positives and false negatives. We present Comprehensive User-Space Protection for C/C++, \sysname, an LLVM sanitizer that provides complete spatial and probabilistic temporal memory safety for C/C++ programs on 64-bit architectures (with a prototype implementation for x86\_64). \sysname uses a hybrid metadata scheme that supports all program data including globals, heap, or stack and maintains Application Binary Interface (ABI) compatibility. Existing approaches have false positives and 8%-25% false negatives on the NIST Juliet test suite. In contrast, \sysname has no false negatives or false positives. \sysname instruments all user-space code, including libc and other system libraries, removing these libraries from the trusted computing base. Supporting all of user space allows \sysname to treat a missed check as a failed check, leading to no false negatives for \sysname. The overhead introduced by \sysname is half that of the state-of-the-art full memory protection on benchmarks where both mechanisms run, and imposes 1.58x overhead when compared to baseline on all benchmarks. Consequently, \sysname is intended as a sanitizer for use by system developers, and to protect truly critical systems. Nathan Burow, Derrick Paul McKee, Scott A. Carr, Mathias Payer |
AsiaCCS | 3 |
| 2018 | CFIXX: Object Type Integrity for C++
Nathan Burow, Derrick Paul McKee, Scott A. Carr, Mathias Payer |
NDSS | 3 |
| 2017 | DataShield: Configurable Data Confidentiality and IntegrityabstractApplications written in C/C++ are prone to memory corruption, which allows attackers to extract secrets or gain control of the system. With the rise of strong control-flow hijacking defenses, non-control data attacks have become the dominant threat. As vulnerabilities like HeartBleed have shown, such attacks are equally devastating. Data Confidentiality and Integrity (DCI) is a low-overhead non-control-data protection mechanism for systems software. DCI augments the C/C++ programming languages with an- notations, allowing the programmer to protect selected data types. The DCI compiler and runtime system prevent illegal reads (confidentiality) and writes (integrity) to instances of these types. The programmer selects types that contain security critical information such as passwords, cryptographic keys, or identification tokens. Protecting only this critical data greatly reduces performance overhead relative to complete memory safety. Scott A. Carr, Mathias Payer |
AsiaCCS | 1 |
| 2017 | HexType: Efficient Detection of Type Confusion Errors for C++abstractType confusion, often combined with use-after-free, is the main attack vector to compromise modern C++ software like browsers or virtual machines. Typecasting is a core principle that enables modularity in C++. For performance, most typecasts are only checked statically, i.e., the check only tests if a cast is allowed for the given type hierarchy, ignoring the actual runtime type of the object. Using an object of an incompatible base type instead of a derived type results in type confusion. Attackers abuse such type confusion issues to attack popular software products including Adobe Flash, PHP, Google Chrome, or Firefox. We propose to make all type checks explicit, replacing static checks with full runtime type checks. To minimize the performance impact of our mechanism HexType, we develop both low-overhead data structures and compiler optimizations. To maximize detection coverage, we handle specific object allocation patterns, e.g., placement new or reinterpret_cast which are not handled by other mechanisms. Our prototype results show that, compared to prior work, HexType has at least 1.1 -- 6.1 times higher coverage on Firefox benchmarks. For SPEC CPU2006 benchmarks with overhead, we show a 2 -- 33.4 times reduction in overhead. In addition, HexType discovered 4 new type confusion bugs in Qt and Apache Xerces-C++. Yuseok Jeon, Priyam Biswas, Scott A. Carr, Byoungyoung Lee, Mathias Payer |
CCS | 3 |
| 2017 | Venerable Variadic Vulnerabilities Vanquished
Priyam Biswas, Alessandro Di Federico, Scott A. Carr, Prabhu Rajasekaran, Stijn Volckaert, Yeoul Na, Michael Franz, Mathias Payer |
USENIX Security Symposium | 3 |
| 2017 | Automatic Contract Insertion with CCBotabstractExisting static analysis tools require significant programmer effort. On large code bases, static analysis tools produce thousands of warnings. It is unrealistic to expect users to review such a massive list and to manually make changes for each warning. To address this issue we propose CCBot (short for CodeContracts Bot), a new tool that applies the results of static analysis to existing code through automatic code transformation. Specifically, CCBot instruments the code with method preconditions, postconditions, and object invariants which detect faults at runtime or statically using a static contract checker. The only configuration the programmer needs to perform is to give CCBot the file paths to code she wants instrumented. This allows the programmer to adopt contract-based static analysis with little effort. CCBot's instrumented version of the code is guaranteed to compile if the original code did. This guarantee means the programmer can deploy or test the instrumented code immediately without additional manual effort. The inserted contracts can detect common errors such as null pointer dereferences and out-of-bounds array accesses. CCBot is a robust large-scale tool with an open-source C# implementation. We have tested it on real world projects with tens of thousands of lines of code. We discuss several projects as case studies, highlighting undiscovered bugs found by CCBot, including 22 new contracts that were accepted by the project authors. Scott A. Carr, Francesco Logozzo, Mathias Payer |
IEEE Trans. Software Eng. | 1 |
| 2016 | VTrust: Regaining Trust on Virtual Calls
Chao Zhang 0008, Dawn Song, Scott A. Carr, Mathias Payer, Tongxin Li 0002, Chengyu Song |
NDSS | 3 |