Hans Liljestrand

dblp:188/5871 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
4since 2021 · last 2024
0000-0003-0485-679XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 first-authorComputer networks · 2Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2024 BliMe: Verifiably Secure Outsourced Computation with Hardware-Enforced Taint Tracking
Hossam ElAtali, Lachlan J. Gunn, Hans Liljestrand, N. Asokan
NDSS3
2023 Not All Data are Created Equal: Data and Pointer Prioritization for Scalable Protection Against Data-Oriented Attacks
Salman Ahmed 0001, Hans Liljestrand, Hani Jamjoom, Matthew Hicks, N. Asokan, Danfeng Yao
USENIX Security Symposium2
2021 PACStack: an Authenticated Call Stack
Hans Liljestrand, Thomas Nyman, Lachlan J. Gunn, Jan-Erik Ekberg, N. Asokan
USENIX Security Symposium1
2021 Exploitation Techniques for Data-oriented Attacks with Existing and Potential Defense Approaches
abstract
Data-oriented attacks manipulate non-control data to alter a program’s benign behavior without violating its control-flow integrity. It has been shown that such attacks can cause significant damage even in the presence of control-flow defense mechanisms. However, these threats have not been adequately addressed. In this survey article, we first map data-oriented exploits, including Data-Oriented Programming (DOP) and Block-Oriented Programming (BOP) attacks, to their assumptions/requirements and attack capabilities. Then, we compare known defenses against these attacks, in terms of approach, detection capabilities, overhead, and compatibility. It is generally believed that control flows may not be useful for data-oriented security. However, data-oriented attacks (especially DOP attacks) may generate side effects on control-flow behaviors in multiple dimensions (i.e., incompatible branch behaviors and frequency anomalies). We also characterize control-flow anomalies caused by data-oriented attacks. In the end, we discuss challenges for building deployable data-oriented defenses and open research questions.
Long Cheng 0005, Salman Ahmed 0001, Hans Liljestrand, Thomas Nyman, Haipeng Cai, Trent Jaeger, N. Asokan, Danfeng Yao
ACM Trans. Priv. Secur.3
2020 Camouflage: Hardware-assisted CFI for the ARM Linux kernel
abstract
Software control-flow integrity (CFI) solutions have been applied to the Linux kernel for memory protection. Due to performance costs, deployed software CFI solutions are coarse grained. In this work, we demonstrate a precise hardware-assisted kernel CFI running on widely-used off-the-shelf processors. Specifically, we use the ARMv8.3 pointer authentication (PAuth) extension and present a design that uses it to achieve strong security guarantees with minimal performance penalties. Furthermore, we show how deployment of such security primitives in the kernel can significantly differ from their user space application.
Rémi Denis-Courmont, Hans Liljestrand, Carlos Chinea Perez, Jan-Erik Ekberg
DAC2
2019 Authenticated Call Stack
abstract
Shadow stacks are the go-to solution for perfect backward-edge control-flow integrity (CFI). Software shadow stacks trade off security for performance. Hardware-assisted shadow stacks are efficient and secure, but expensive to deploy. We present authenticated call stack (ACS), a novel mechanism for precise verification of return addresses using aggregated message authentication codes. We show how ACS can be realized using ARMv8.3-A pointer authentication, a new low-overhead mechanism for protecting pointer integrity. Our solution achieves security comparable to hardware-assisted shadow stacks, while incurring negligible performance overhead (< 0.5%) but requiring no additional hardware support.
Hans Liljestrand, Thomas Nyman, Jan-Erik Ekberg, N. Asokan
DAC1
2019 PAC it up: Towards Pointer Integrity using ARM Pointer Authentication
Hans Liljestrand, Thomas Nyman, Carlos Chinea Perez, Jan-Erik Ekberg, N. Asokan
USENIX Security Symposium1
2018 Toward Linux kernel memory safety
abstract
Summary The security of billions of devices worldwide depends on the security and robustness of the mainline Linux kernel. However, the increasing number of kernel‐specific vulnerabilities, especially memory safety vulnerabilities, shows that the kernel is a popular and practically exploitable target. Two major causes of memory safety vulnerabilities are reference counter overflows (temporal memory errors) and lack of pointer bounds checking (spatial memory errors). To succeed in practice, security mechanisms for critical systems like the Linux kernel must also consider performance and deployability as critical design objectives. We present and systematically analyze two such mechanisms for improving memory safety in the Linux kernel, ie, (1) an overflow‐resistant reference counter data structure designed to securely accommodate typical reference counter usage in kernel source code and (2) runtime pointer bounds checking using Intel memory protection extension in the kernel. We have implemented both mechanisms and we analyze their security, performance, and deployability. We also reflect on our experience of engaging with Linux kernel developers and successfully integrating the new reference counter data structure into the mainline Linux kernel.
Elena Reshetova, Hans Liljestrand, Andrew Paverd, N. Asokan
Softw. Pract. Exp.2
2017 Implementing Prover-Side Proximity Verification for Strengthening Transparent Authentication
abstract
Transparent authentication schemes based on proximity verification over a wireless channel are susceptible to relay attacks. In recent literature several countermeasures have been proposed. However these come with drawbacks in terms of usability and deployability. In this demo, we show a prototype implementation of STASH, a scheme for securing transparent authentication schemes using prover-side proximity verification, presented at SECON 2017.
Mika Juuti, Christian Vaas, Hans Liljestrand, Ivo Sluganovic, N. Asokan, Ivan Martinovic
SECON3
2017 STASH: Securing Transparent Authentication Schemes Using Prover-Side Proximity Verification
abstract
Transparent authentication (TA) schemes are those in which a user's prover device authenticates him to a verifier without requiring explicit user interaction. By doing so, those schemes promise high usability and security simultaneously. Most TA implementations rely on the received signal strength as an indicator of the proximity of a user device (prover). However, such implicit proximity verification is not secure against an adversary who can relay messages over a larger distance. In this paper, we propose a novel approach for thwarting relay attacks on TA schemes: the prover permits access to authentication credentials only if it can confirm that it is near the verifier. We present STASH, a system for relay-resilient transparent authentication in which the prover does proximity verification by comparing its approach trajectory towards the intended verifier, with known authorized reference trajectories. Trajectories are measured using low-cost sensors commonly available on personal devices. By analyzing empirical data, collected using a STASH prototype, we demonstrate the security of STASH against a class of adversaries and its ease-of-use. STASH is efficient and can be easily integrated to complement existing TA schemes.
Mika Juuti, Christian Vaas, Ivo Sluganovic, Hans Liljestrand, N. Asokan, Ivan Martinovic
SECON4