VLDB 2026 Research / reviewers in the wild / expert
Hayawardh Vijayakumar
dblp:24/687
· DBLP profile ↗
16ranked-venue papers
5as first author
1since 2021 · last 2021
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 4 first-author · 1 since 2021Systems, architecture and hardware · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
9 papers |
Systems and software security · 76% Web and mobile security · 15% Hardware security and side channels · 10% | |
| Software engineering, system software, and programming languages
6 papers |
Software testing · 38% Operating systems · 34% Program analysis · 29% |
Topics — the 18 heaviest of 20, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
vulnerability discovery |
0.8 | 3 | 2021 | PolyScope: Multi-Policy Access Control Analysis to Compute Authorized Attack Operations in Android Systems · USENIX Security Symposium 2021 STING: Finding Name Resolution Vulnerabilities in Programs · USENIX Security Symposium 2012 FuzzFactory: domain-specific fuzzing with waypoints · Proc. ACM Program. Lang. 2019 |
Systems and software security
memory safety |
0.5 | 2 | 2017 | NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64 · IEEE Symposium on Security and Privacy 2017 JIGSAW: Protecting Resource Access by Inferring Programmer Expectations · USENIX Security Symposium 2014 |
Hardware security and side channels
trusted execution environments |
0.4 | 1 | 2020 | PARTEMU: Enabling Dynamic Analysis of Real-World TrustZone Software Using Emulation · USENIX Security Symposium 2020 |
Program analysis
dynamic analysis |
0.4 | 1 | 2020 | PARTEMU: Enabling Dynamic Analysis of Real-World TrustZone Software Using Emulation · USENIX Security Symposium 2020 |
Software testing › fuzzing
coverage-guided fuzzing |
0.4 | 1 | 2019 | FuzzFactory: domain-specific fuzzing with waypoints · Proc. ACM Program. Lang. 2019 |
Software testing
fuzzing |
0.4 | 1 | 2019 | FuzzFactory: domain-specific fuzzing with waypoints · Proc. ACM Program. Lang. 2019 |
Web and mobile security › mobile security
android security |
0.3 | 1 | 2018 | ATtention Spanned: Comprehensive Vulnerability Analysis of AT Commands Within the Android Ecosystem · USENIX Security Symposium 2018 |
Systems and software security › vulnerability patching
hot patching |
0.3 | 1 | 2018 | InstaGuard: Instantly Deployable Hot-patches for Vulnerable System Programs on Android · NDSS 2018 |
Web and mobile security
mobile security |
0.3 | 1 | 2018 | ATtention Spanned: Comprehensive Vulnerability Analysis of AT Commands Within the Android Ecosystem · USENIX Security Symposium 2018 |
Systems and software security
vulnerability patching |
0.3 | 1 | 2018 | InstaGuard: Instantly Deployable Hot-patches for Vulnerable System Programs on Android · NDSS 2018 |
Systems and software security › return-oriented programming defense
code reuse attack defense |
0.3 | 1 | 2017 | NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64 · IEEE Symposium on Security and Privacy 2017 |
Systems and software security › memory protection
execute-only memory |
0.3 | 1 | 2017 | NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64 · IEEE Symposium on Security and Privacy 2017 |
Systems and software security
exploitation |
0.3 | 1 | 2017 | NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64 · IEEE Symposium on Security and Privacy 2017 |
Operating systems › system security › operating system security
access control |
0.2 | 1 | 2014 | JIGSAW: Protecting Resource Access by Inferring Programmer Expectations · USENIX Security Symposium 2014 |
Operating systems › system security › operating system security
process protection |
0.2 | 1 | 2013 | Process firewalls: protecting processes during resource access · EuroSys 2013 |
Program analysis
static analysis |
0.1 | 1 | 2012 | STING: Finding Name Resolution Vulnerabilities in Programs · USENIX Security Symposium 2012 |
Systems and software security › memory safety
address space layout randomization |
0.1 | 1 | 2017 | NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64 · IEEE Symposium on Security and Privacy 2017 |
Systems and software security › operating system security
system call filtering |
0.0 | 1 | 2013 | Process firewalls: protecting processes during resource access · EuroSys 2013 |
Methods — techniques the papers use, named apart from their topics
emulation · 0.9mutation heuristics · 0.8coverage-guided fuzzing · 0.8binary patching · 0.7graph analysis · 0.5access control policy analysis · 0.5kernel mechanism · 0.3static binary transformation · 0.3in-place randomization · 0.3system-call interception · 0.2system call interception · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | PolyScope: Multi-Policy Access Control Analysis to Compute Authorized Attack Operations in Android Systems
Yu Tsung Lee, William Enck, Haining Chen, Hayawardh Vijayakumar, Ninghui Li 0001, Zhiyun Qian, Daimeng Wang, Giuseppe Petracca, Trent Jaeger |
USENIX Security Symposium | 4 |
| 2020 | PARTEMU: Enabling Dynamic Analysis of Real-World TrustZone Software Using Emulation
Lee Harrison, Hayawardh Vijayakumar, Rohan Padhye, Koushik Sen, Michael Grace |
USENIX Security Symposium | 2 |
| 2019 | FuzzFactory: domain-specific fuzzing with waypointsabstractCoverage-guided fuzz testing has gained prominence as a highly effective method of finding security vulnerabilities such as buffer overflows in programs that parse binary data. Recently, researchers have introduced various specializations to the coverage-guided fuzzing algorithm for different domain-specific testing goals, such as finding performance bottlenecks, generating valid inputs, handling magic-byte comparisons, etc. Each such solution can require non-trivial implementation effort and produces a distinct variant of a fuzzing tool. We observe that many of these domain-specific solutions follow a common solution pattern. In this paper, we present FuzzFactory, a framework for developing domain-specific fuzzing applications without requiring changes to mutation and search heuristics. FuzzFactory allows users to specify the collection of dynamic domain-specific feedback during test execution, as well as how such feedback should be aggregated. FuzzFactory uses this information to selectively save intermediate inputs, called waypoints, to augment coverage-guided fuzzing. Such waypoints always make progress towards domain-specific multi-dimensional objectives. We instantiate six domain-specific fuzzing applications using FuzzFactory: three re-implementations of prior work and three novel solutions, and evaluate their effectiveness on benchmarks from Google's fuzzer test suite. We also show how multiple domains can be composed to perform better than the sum of their parts. For example, we combine domain-specific feedback about strict equality comparisons and dynamic memory allocations, to enable the automatic generation of LZ4 bombs and PNG bombs. Rohan Padhye, Caroline Lemieux, Koushik Sen, Laurent Simon 0001, Hayawardh Vijayakumar |
Proc. ACM Program. Lang. | 5 |
| 2018 | InstaGuard: Instantly Deployable Hot-patches for Vulnerable System Programs on Android
Yaohui Chen 0001, Long Lu, Yueh-Hsun Lin, Hayawardh Vijayakumar, Zhi Wang 0004, Xinming Ou |
NDSS | 5 |
| 2018 | ATtention Spanned: Comprehensive Vulnerability Analysis of AT Commands Within the Android Ecosystem
Jing (Dave) Tian, Grant Hernandez, Joseph I. Choi, Vanessa Frost, Christie Ruales, Patrick Traynor, Hayawardh Vijayakumar, Lee Harrison, Amir Rahmati, Michael Grace, Kevin R. B. Butler |
USENIX Security Symposium | 7 |
| 2017 | NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64abstractCode reuse attacks exploiting memory disclosure vulnerabilities can bypass all deployed mitigations. One promising defense against this class of attacks is to enable execute-only memory (XOM) protection on top of fine-grained address space layout randomization (ASLR). However, recent works implementing XOM, despite their efficacy, only protect programs that have been (re)built with new compiler support, leaving commercial-off-the-shelf (COTS) binaries and source-unavailable programs unprotected. We present the design and implementation of NORAX, a practical system that retrofits XOM into stripped COTS binaries on AArch64 platforms. Unlike previous techniques, NORAX requires neither source code nor debugging symbols. NORAX statically transforms existing binaries so that during runtime their code sections can be loaded into XOM memory pages with embedded data relocated and data references properly updated. NORAX allows transformed binaries to leverage the new hardware-based XOM support—a feature widely available on AArch64 platforms (e.g., recent mobile devices) yet virtually unused due to the incompatibility of existing binaries. Furthermore, NORAX is designed to co-exist with other COTS binary hardening techniques, such as in-place randomization (IPR). We apply NORAX to the commonly used Android system binaries running on SAMSUNG Galaxy S6 and LG Nexus 5X devices. The results show that NORAX on average slows down the execution of transformed binaries by 1.18% and increases their memory footprint by 2.21%, suggesting NORAX is practical for real-world adoption. Yaohui Chen 0001, Dongli Zhang, Ruowen Wang, Ahmed M. Azab, Long Lu, Hayawardh Vijayakumar, Wenbo Shen |
IEEE Symposium on Security and Privacy | 7 |
| 2015 | Cloud Armor: Protecting Cloud Commands from Compromised Cloud ServicesabstractInfrastructure-as-a-Service (IaaS) clouds can be viewed as distributed systems of cloud services that are entrusted to execute users' cloud commands to provision and manage clouds computing resources (e.g., VM). However, recent vulnerabilities found in cloud services show that this trust is often misplaced. By exploiting a vulnerability in a cloud service, an adversary can hijack or forge commands to modify user VMs, exfiltrate sensitive information, and even modify other service hosts. This paper introduces Cloud Armor, a system that detects and blocks the tampering of user commands without the need for modifications to cloud services. Our insight is that we can construct state machine models to limit the system call sequences executed by cloud services. By applying constraints over system call arguments, we can restrict the way user commands are executed, blocking unauthorized operations from compromised cloud services. We implemented a prototype Cloud Armor system for Open Stack, a widely adopted open source cloud platform. Results show that Cloud Armor can greatly limit attack options available for adversaries while imposing less than 1% overhead for user VMs. As a result, cloud users can leverage Cloud Armor to execute user commands safely even in presence of compromised cloud services. Yuqiong Sun, Giuseppe Petracca, Trent Jaeger, Hayawardh Vijayakumar, Joshua Schiffman |
CLOUD | 4 |
| 2014 | Policy models to protect resource retrievalabstractProcesses need a variety of resources from their operating environment in order to run properly, but adversary may control the inputs to resource retrieval or the end resource itself, leading to a variety of vulnerabilities. Conventional access control methods are not suitable to prevent such vulnerabilities because they use one set of permissions for all system call invocations. In this paper, we define a novel policy model for describing when resource retrievals are unsafe, so they can be blocked. This model highlights two contributions: (1) the explicit definition of adversary models as adversarial roles, which list the permissions that dictate whether one subject is an adversary of another, and (2) the application of data-flow to determine the adversary control of the names used to retrieve resources. An evaluation using multiple adversary models shows that data-flow is necessary to authorize resource retrieval in over 90% of system calls. By making adversary models and the adversary accessibility of all aspects of resource retrieval explicit, we can block resource access attacks system-wide. Hayawardh Vijayakumar, Xinyang Ge, Trent Jaeger |
SACMAT | 1 |
| 2014 | JIGSAW: Protecting Resource Access by Inferring Programmer Expectations
Hayawardh Vijayakumar, Xinyang Ge, Mathias Payer, Trent Jaeger |
USENIX Security Symposium | 1 |
| 2013 | Process firewalls: protecting processes during resource accessabstractProcesses retrieve a variety of resources from the operating system in order to execute properly, but adversaries have several ways to trick processes into retrieving resources of the adversaries' choosing. Such resource access attacks use name resolution, race conditions, and/or ambiguities regarding which resources are controlled by adversaries, accounting for 5-10% of CVE entries over the last four years. programmers have found these attacks extremely hard to eliminate because resources are managed externally to the program, but the operating system does not provide a sufficiently rich system-call API to enable programs to block such attacks. In this paper, we present the Process Firewall, a kernel mechanism that protects processes in manner akin to a network firewall for the system-call interface. Because the Process Firewall only protects processes -- rather than sandboxing them -- it can examine their internal state to identify the protection rules necessary to block many of these attacks without the need for program modification or user configuration. We built a prototype Process Firewall for Linux demonstrating: (1) the prevention of several vulnerabilities, including two that were previously-unknown; (2) that this defense can be provided system-wide for less than 4% overhead in a variety of macrobenchmarks; and (3) that it can also improve program performance, shown by Apache handling 3-8% more requests when program resource access checks are replaced by Process Firewall rules. These results show that it is practical for the operating system to protect processes by preventing a variety of resource access attacks system-wide. Hayawardh Vijayakumar, Joshua Schiffman, Trent Jaeger |
EuroSys | 1 |
| 2013 | Cloud Verifier: Verifiable Auditing Service for IaaS CloudsabstractCloud computing has commoditized compute, storage, and networking resources creating an on-demand utility. Despite the attractiveness of this new paradigm, its adoption has been stymied by cloud platform's lack of transparency, which leaves customers unsure if their sensitive data and computation can be entrusted to the cloud. While techniques like encryption can protect customers' data at rest, clouds still lack mechanisms for customers to verify that their computations are being executed as expected, a guarantee one could obtain if they were running the computation in their own data center. In this paper, we present the cloud verifier (CV), a flexible framework that cloud vendors can configure to provide cloud monitoring services for customers to validate that their computations are configured and being run as expected in Infrastructure as a Service (IaaS) clouds. The CV builds a chain of trust from the customer to their hosted virtual machine (VM) instances through the cloud platform, enabling it to check customer-specified requirements against a comprehensive view of both the VM's load-time and run-time properties. In addition, the CV enables cloud vendors to provide more responsive remediation techniques than traditional attestation mechanisms. We built a proof of concept CV for the OpenStack cloud platform whose evaluation demonstrates that a single CV enables over 20,000 simultaneous customers to verify numerous properties with little impact on cloud application performance. As a result, the CV gives cloud customers a low-overhead method for assuring that their instances are running according to their requirements. Joshua Schiffman, Yuqiong Sun, Hayawardh Vijayakumar, Trent Jaeger |
SERVICES | 3 |
| 2012 | Transforming commodity security policies to enforce Clark-Wilson integrityabstractModern distributed systems are composed from several off-the-shelf components, including operating systems, virtualization infrastructure, and application packages, upon which some custom application software (e.g., web application) is often deployed. While several commodity systems now include mandatory access control (MAC) enforcement to protect the individual components, the complexity of such MAC policies and the myriad of possible interactions among individual hosts in distributed systems makes it difficult to identify the attack paths available to adversaries. As a result, security practitioners react to vulnerabilities as adversaries uncover them, rather than proactively protecting the system's data integrity. In this paper, we develop a mostly-automated method to transform a set of commodity MAC policies into a system-wide policy that proactively protects system integrity, approximating the Clark-Wilson integrity model. The method uses the insights from the Clark-Wilson model, which requires integrity verification of security-critical data and mediation at program entrypoints, to extend existing MAC policies with the proactive mediation necessary to protect system integrity. We demonstrate the practicality of producing Clark-Wilson policies for distributed systems on a web application running on virtualized Ubuntu SELinux hosts, where our method finds: (1) that only 27 additional entrypoint mediators are sufficient to mediate the threats of remote adversaries over the entire distributed system and (2) and only 20 additional local threats require mediation to approximate Clark-Wilson integrity comprehensively. As a result, available security policies can be used as a foundation for proactive integrity protection from both local and remote threats. Divya Muthukumaran, Sandra Julieta Rueda, Nirupama Talele, Hayawardh Vijayakumar, Jason Teutsch, Trent Jaeger |
ACSAC | 4 |
| 2012 | Integrity walls: finding attack surfaces from mandatory access control policiesabstractProtecting host system integrity in the face of determined adversaries remains a major problem. Despite advances in program development and access control, attackers continue to compromise systems forcing security practitioners to regularly react to such breaches. While security practitioners may eventually learn which entry points in programs must be defended over a software's lifetime, new software and configuration options are frequently introduced, opening additional vulnerabilities to adversaries. The application developers' problem is to identify the program entry points accessible to adversaries and provide necessary defenses at these entry points before the adversaries use these to compromise the program. Unfortunately, this is a race that developers often lose. While some program vulnerable entry points are well-known (mostly network), the complexity of host systems makes it difficult to prevent local exploits should attackers gain control of any unprivileged processing. The question we explore in this paper is whether the program entry points accessible to adversaries can be found proactively, so defenses at these entry points can also be developed proactively. Hayawardh Vijayakumar, Guruprasad Jakka, Sandra Julieta Rueda, Joshua Schiffman, Trent Jaeger |
AsiaCCS | 1 |
| 2012 | STING: Finding Name Resolution Vulnerabilities in Programs
Hayawardh Vijayakumar, Joshua Schiffman, Trent Jaeger |
USENIX Security Symposium | 1 |
| 2009 | Analysis of virtual machine system policiesabstractThe recent emergence of mandatory access (MAC) enforcement for virtual machine monitors (VMMs) presents an opportunity to enforce a security goal over all its virtual machines (VMs). However, these VMs also have MAC enforcement, so to determine whether the overall system (VM-system) is secure requires an evaluation of whether this combination of MAC policies, as a whole, complies with a given security goal. Previous MAC policy analyses either consider a single policy at a time or do not represent the interaction between different policy layers (VMM and VM). We observe that we can analyze the VMM policy and the labels used for communications between VMs to create an inter-VM flow graph that we use to identify safe, unsafe, and ambiguous VM interactions. A VM with only safe interactions is compliant with the goal, a VM with any unsafe interaction violates the goal. For a VM with ambiguous interactions we analyze its local MAC policy to determine whether it is compliant or not with the goal. We used this observation to develop an analytical model of a VM-system, and evaluate if it is compliant with a security goal. We implemented the model and an evaluation tool in Prolog. We evaluate our implementation by checking whether a VM-system running XSM/Flask policy at the VMM layer and SELinux policies at the VM layer satisfies a given integrity goal. This work is the first step toward developing layered, multi-policy analyses. Sandra Julieta Rueda, Hayawardh Vijayakumar, Trent Jaeger |
SACMAT | 2 |
| 2007 | A scalable parallelization of all-pairs shortest path algorithm for a high performance cluster environmentabstractWe present a parallelization of the Floyd-Warshall all pairs shortest path algorithm for a distributed environment. A lot of versions of the Floyd-Warshall algorithm have been proposed for a uniprocessor environment, optimizing cache performance and register usage. However, in a distributed environment, communication costs between nodes have to be taken into consideration. We present a novel algorithm, Phased Floyd-Warshall, for a distributed environment, which optimally overlaps computation and communication. Our algorithm is compared with a register optimized version of the blocked all pairs shortest path algorithm [6, 4, 1] which is adapted for a distributed environment. We report speedups of 2.8 in a 16-node cluster and 1.2 in a 32-node cluster for a matrix size of 4096. T. Srinivasan 0001, S. A. Gangadharan, Hayawardh Vijayakumar |
ICPADS | 4 |