VLDB 2026 Research / reviewers in the wild / expert
Santiago Torres-Arias
dblp:185/1711
· DBLP profile ↗
21ranked-venue papers
4as first author
15since 2021 · last 2026
0000-0002-9283-3557ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 4 first-author · 13 since 2021Computer networks · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: A Defense-Oriented Evaluation of Software Supply Chain Security
Eman Abu Ishgair, Juanita Gomez, Marcela S. Melara, Alvaro A. Cárdenas, Santiago Torres-Arias |
EuroS&P | 5 |
| 2025 | SCORED '25: Workshop on Software Supply Chain Offensive Research and Ecosystem DefensesabstractAttacks on the software supply chain have shed light on the fragility and importance of ensuring the security and integrity of this vital ecosystem. Addressing the technical and social challenges to building trustworthy software (including AI applications) requires innovative solutions and an interdisciplinary approach. The Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED) is the leading venue for academics, industry practitioners, and policymakers to present and discuss security vulnerabilities, novel defenses against attacks, deployment experiences, adoption requirements and best practices in the software supply chain. The complete SCORED '25 workshop proceedings are available at: https://doi.org/10.1145/3733827 Aditya Sirish A Yelgundhalli, Behnaz Hassanshahi, Dennis Roellke, Drew Davidson, Kathleen Moriarty, Lorenzo De Carli, Marcela S. Melara, Santiago Torres-Arias, Sarah Evans, Yuchen Zhang 0006 |
CCS | 8 |
| 2025 | $ZTD_{\text{JAVA}}$: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust DependenciesabstractThird-party libraries like Log4j accelerate software application development but introduce substantial risk. Vulnerabilities in these libraries have led to Software Supply Chain (SSC) attacks that compromised resources within the host system. These attacks benefit from current application permissions approaches: third-party libraries are implicitly trusted in the application runtime. An application runtime designed with ZeroTrust Architecture (ZTA) principles - secure access to resources, continuous monitoring, and least-privilege enforcement - could mitigate SSC attacks, as it would give zero implicit trust to these libraries. However, no individual security defense incorporates these principles at a low runtime cost. This paper proposes Zero-Trust Dependencies to mitigate SSC vulnerabilities: we apply the NIST ZTA to software applications. First, we assess the expected effectiveness and configuration cost of Zero-Trust Dependencies using a study of third-party software libraries and their vulnerabilities. Then, we present a system design,$\text{ZTD}_{\text{Sys}}$, that enables the application of Zero-Trust Dependencies to software applications and a prototype,$\text{ZTD}_{\text{JAVA}}$, for Java applications. Finally, with evaluations on recreated vulnerabilities and realistic applications, we show that$\text{ZTD}_{\text{JAVA}}$can defend against prevalent vulnerability classes, introduces negligible cost, and is easy to configure and use. Paschal C. Amusuo, Kyle A. Robinson, Tanmay Singla, Huiyun Peng, Aravind Machiry, Santiago Torres-Arias, James C. Davis 0001 |
ICSE | 6 |
| 2025 | An Industry Interview Study of Software Signing for Supply Chain Security
Kelechi G. Kalu, Tanmay Singla, Chinenye Okafor, Santiago Torres-Arias, James C. Davis 0001 |
USENIX Security Symposium | 4 |
| 2024 | Rust for Embedded Systems: Current State and Open Problems
Ayushi Sharma 0001, Shashank Sharma 0003, Sai Ritvik Tanksalkar, Santiago Torres-Arias, Aravind Machiry |
CCS | 4 |
| 2024 | SCORED '24: Workshop on Software Supply Chain Offensive Research and Ecosystem DefensesabstractRecent attacks on the software supply chain have shed light on the fragility and importance of ensuring the security and integrity of this vital ecosystem. Addressing the technical and social challenges to building trustworthy software for deployment in sensitive and/or large-scale enterprise or governmental settings requires innovative solutions and an interdisciplinary approach. The Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED) is the leading venue for bringing together industry practitioners, academics, and policymakers to present and discuss security vulnerabilities, novel defenses against attacks, project demos, adoption requirements and best practices in the software supply chain. The complete SCORED '24 workshop proceedings are available at: https://doi.org/10.1145/3689944 Santiago Torres-Arias, Marcela S. Melara |
CCS | 1 |
| 2024 | Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing FactorsabstractMany software applications incorporate open-source third-party packages distributed by public package registries. Guaranteeing authorship along this supply chain is a challenge. Package maintainers can guarantee package authorship through software signing. However, it is unclear how common this practice is, and whether the resulting signatures are created properly. Prior work has provided raw data on registry signing practices, but only measured single platforms, did not consider quality, did not consider time, and did not assess factors that may influence signing. We do not have up-to-date measurements of signing practices nor do we know the quality of existing signatures. Furthermore, we lack a comprehensive understanding of factors that influence signing adoption.This study addresses this gap. We provide measurements across three kinds of package registries: traditional software (Maven, PyPI), container images (Docker Hub), and machine learning models (Hugging Face). For each registry, we describe the nature of the signed artifacts as well as the current quantity and quality of signatures. Then, we examine longitudinal trends in signing practices. Finally, we use a quasi-experiment to estimate the effect that various factors had on software signing practices. To summarize our findings: (1) mandating signature adoption improves the quantity of signatures; (2) providing dedicated tooling improves the quality of signing; (3) getting started is the hard part — once a maintainer begins to sign, they tend to continue doing so; and (4) although many supply chain attacks are mitigable via signing, signing adoption is primarily affected by registry policy rather than by public knowledge of attacks, new engineering standards, etc. These findings highlight the importance of software package registry managers and signing infrastructure. Taylor R. Schorlemmer, Kelechi G. Kalu, Luke Chigges, Kyung Myung Ko, Eman Abu Ishgair, Saurabh Bagchi, Santiago Torres-Arias, James C. Davis 0001 |
SP | 7 |
| 2023 | SCORED '23: Workshop on Software Supply Chain Offensive Research and Ecosystem DefensesabstractRecent attacks on the software supply chain have shed light on the fragility and importance of ensuring the security and integrity of this vital ecosystem. Addressing the technical and social challenges to building trustworthy software for deployment in sensitive and/or large-scale enterprise or governmental settings requires innovative solutions and an interdisciplinary approach. The Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED) is a venue that brings together industry practitioners, academics, and policymakers to present and discuss security vulnerabilities, novel defenses against attacks, project demos, adoption requirements and best practices in the software supply chain. The complete SCORED'23 workshop proceedings are available at: https://dl.acm.org/doi/proceedings/10.1145/3576915 Marcela S. Melara, Santiago Torres-Arias |
CCS | 2 |
| 2023 | Speranza: Usable, Privacy-friendly Software SigningabstractSoftware repositories, used for wide-scale open software distribution, are a significant vector for security attacks. Software signing provides authenticity, mitigating many such attacks. Developer-managed signing keys pose usability challenges, but certificate-based systems introduce privacy problems. This work, Speranza, uses certificates to verify software authenticity but still provides anonymity to signers using zero-knowledge identity co-commitments. Kelsey Merrill, Zachary Newman, Santiago Torres-Arias, Karen R. Sollins |
CCS | 3 |
| 2023 | Behind the Scenes: Uncovering TLS and Server Certificate Practice of IoT Device Vendors in the WildabstractIoT devices are increasingly used in consumer homes. Despite recent works in characterizing IoT TLS usage for a limited number of in-lab devices, there exists a gap in quantitatively understanding TLS behaviors from devices in the wild and server-side certificate management. Hongying Dong, Yizhe Zhang 0006, Muhammad Talha Paracha, David R. Choffnes, Santiago Torres-Arias, Danny Yuxing Huang, Yixin Sun 0004 |
IMC | 7 |
| 2023 | Towards verifiable web-based code review systemsabstractAlthough code review is an essential step for ensuring the quality of software, it is surprising that current code review systems do not have mechanisms to protect the integrity of the code review process. We uncover multiple attacks against the code review infrastructure which are easy to execute, stealthy in nature, and can have a significant impact, such as allowing malicious or buggy code to be merged and propagated to future releases. To improve this status quo, in this work we lay the foundations for securing the code review process. Towards this end, we first identify a set of key design principles necessary to secure the code review process. We then use these principles to propose SecureReview , a security mechanism that can be applied on top of a Git-based code review system to ensure the integrity of the code review process and provide verifiable guarantees that the code review process followed the intended review policy. We implement SecureReview as a Chrome browser extension for GitHub and Gerrit. Our security analysis shows that SecureReview is effective in mitigating the aforementioned attacks. An experimental evaluation shows that the SecureReview implementation only adds a slight storage overhead ( i.e., less than 0.0006 of the repository size). Hammad Afzali, Santiago Torres-Arias, Reza Curtmola, Justin Cappos |
J. Comput. Secur. | 2 |
| 2022 | Sigstore: Software Signing for EverybodyabstractSoftware supply chain compromises are on the rise. From the effects of XCodeGhost to SolarWinds, hackers have identified that targeting weak points in the supply chain allows them to compromise high-value targets such as U.S. government agencies and corporate targets such as Google and Microsoft. Software signing, a promising mitigation for many of these attacks, has seen limited adoption in open-source and enterprise ecosystems. Zachary Newman, John Speed Meyers, Santiago Torres-Arias |
CCS | 3 |
| 2022 | SCORED '22: ACM Workshop on Software Supply Chain Offensive Research and Ecosystem DefensesabstractRecent attacks on the software supply chain have shed light on the fragility and importance of ensuring the security and integrity of this vital ecosystem. Addressing the technical and social challenges to building trustworthy software for deployment in sensitive and/or large-scale enterprise or governmental settings requires innovative solutions and an interdisciplinary approach. The Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED) is a venue that brings together industry practitioners, academics, and policymakers to present and discuss security vulnerabilities, novel defenses against attacks, project demos, adoption requirements and best practices in the software supply chain. The complete SCORED'22 workshop proceedings are available at: https://dl.acm.org/doi/proceedings/10.1145/3560835 Santiago Torres-Arias, Marcela S. Melara |
CCS | 1 |
| 2022 | Bootstrapping Trust in Community Repository Projects
Sangat Vaidya, Santiago Torres-Arias, Justin Cappos, Reza Curtmola |
SecureComm | 2 |
| 2021 | COLBAC: Shifting Cybersecurity from Hierarchical to Horizontal DesignsabstractCybersecurity suffers from an oversaturation of centralized, hierarchical systems and a lack of exploration in the area of horizontal security, or security techniques and technologies which utilize democratic participation for security decision-making. Because of this, many horizontally governed organizations such as activist groups, worker cooperatives, trade unions, not-for-profit associations, and others are not represented in current cybersecurity solutions, and are forced to adopt hierarchical solutions to cybersecurity problems. This causes power dynamic mismatches that lead to cybersecurity and organizational operations failures. In this work we introduce COLBAC, a collective based access control system aimed at addressing this lack. COLBAC uses democratically authorized capability tokens to express access control policies. It allows for a flexible and dynamic degree of horizontality to meet the needs of different horizontally governed organizations. After introducing COLBAC, we finish with a discussion on future work needed to realize more horizontal security techniques, tools, and technologies. Kevin Gallagher 0001, Santiago Torres-Arias, Nasir Memon, Jessica Feldman |
NSPW | 2 |
| 2020 | Towards adding verifiability to web-based Git repositoriesabstractWeb-based Git hosting services such as GitHub and GitLab are popular choices to manage and interact with Git repositories. However, they lack an important security feature – the ability to sign Git commits. Users instruct the server to perform repository operations on their behalf and have to trust that the server will execute their requests faithfully. Such trust may be unwarranted though because a malicious or a compromised server may execute the requested actions in an incorrect manner, leading to a different state of the repository than what the user intended. In this paper, we show a range of high-impact attacks that can be executed stealthily when developers use the web UI of a Git hosting service to perform common actions such as editing files or merging branches. We then propose le-git-imate , a defense against these attacks, which enables users to protect their commits using Git’s standard commit signing mechanism. We implement le-git-imate as a Chrome browser extension. le-git-imate does not require changes on the server side and can thus be used immediately. It also preserves current workflows used in Github/GitLab and does not require the user to leave the browser, and it allows anyone to verify that the server’s actions faithfully follow the user’s requested actions. Moreover, experimental evaluation using the browser extension shows that le-git-imate has comparable performance with Git’s standard commit signature mechanism. With our solution in place, users can take advantage of GitHub/GitLab’s web-based features without sacrificing security, thus paving the way towards verifiable web-based Git repositories. Hammad Afzali, Santiago Torres-Arias, Reza Curtmola, Justin Cappos |
J. Comput. Secur. | 2 |
| 2019 | Commit Signatures for Centralized Version Control Systems
Sangat Vaidya, Santiago Torres-Arias, Reza Curtmola, Justin Cappos |
SEC | 2 |
| 2019 | in-toto: Providing farm-to-table guarantees for bits and bytes
Santiago Torres-Arias, Hammad Afzali, Trishank Karthik Kuppusamy, Reza Curtmola, Justin Cappos |
USENIX Security Symposium | 1 |
| 2018 | le-git-imate: Towards Verifiable Web-based Git RepositoriesabstractWeb-based Git hosting services such as GitHub and GitLab are popular choices to manage and interact with Git repositories. However, they lack an important security feature - the ability to sign Git commits. Users instruct the server to perform repository operations on their behalf and have to trust that the server will execute their requests faithfully. Such trust may be unwarranted though because a malicious or a compromised server may execute the requested actions in an incorrect manner, leading to a different state of the repository than what the user intended. Hammad Afzali, Santiago Torres-Arias, Reza Curtmola, Justin Cappos |
AsiaCCS | 2 |
| 2016 | Diplomat: Using Delegations to Protect Community Repositories
Trishank Karthik Kuppusamy, Santiago Torres-Arias, Vladimir Diaz, Justin Cappos |
NSDI | 2 |
| 2016 | On Omitting Commits and Committing Omissions: Preventing Git Metadata Tampering That (Re)introduces Software Vulnerabilities
Santiago Torres-Arias, Anil Kumar Ammula, Reza Curtmola, Justin Cappos |
USENIX Security Symposium | 1 |