Hayawardh Vijayakumar

dblp:24/687 · DBLP profile ↗
← Back
16ranked-venue papers
5as first author
1since 2021 · last 2021
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 4 first-author · 1 since 2021Systems, architecture and hardware · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
9 papers
Systems and software security · 76% Web and mobile security · 15% Hardware security and side channels · 10%
Software engineering, system software, and programming languages
6 papers
Software testing · 38% Operating systems · 34% Program analysis · 29%

Topics — the 18 heaviest of 20, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
vulnerability discovery
0.832021
PolyScope: Multi-Policy Access Control Analysis to Compute Authorized Attack Operations in Android Systems · USENIX Security Symposium 2021
STING: Finding Name Resolution Vulnerabilities in Programs · USENIX Security Symposium 2012
FuzzFactory: domain-specific fuzzing with waypoints · Proc. ACM Program. Lang. 2019
Systems and software security
memory safety
0.522017
NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64 · IEEE Symposium on Security and Privacy 2017
JIGSAW: Protecting Resource Access by Inferring Programmer Expectations · USENIX Security Symposium 2014
Hardware security and side channels
trusted execution environments
0.412020
PARTEMU: Enabling Dynamic Analysis of Real-World TrustZone Software Using Emulation · USENIX Security Symposium 2020
Program analysis
dynamic analysis
0.412020
PARTEMU: Enabling Dynamic Analysis of Real-World TrustZone Software Using Emulation · USENIX Security Symposium 2020
Software testing › fuzzing
coverage-guided fuzzing
0.412019
FuzzFactory: domain-specific fuzzing with waypoints · Proc. ACM Program. Lang. 2019
Software testing
fuzzing
0.412019
FuzzFactory: domain-specific fuzzing with waypoints · Proc. ACM Program. Lang. 2019
Web and mobile security › mobile security
android security
0.312018
ATtention Spanned: Comprehensive Vulnerability Analysis of AT Commands Within the Android Ecosystem · USENIX Security Symposium 2018
Systems and software security › vulnerability patching
hot patching
0.312018
InstaGuard: Instantly Deployable Hot-patches for Vulnerable System Programs on Android · NDSS 2018
Web and mobile security
mobile security
0.312018
ATtention Spanned: Comprehensive Vulnerability Analysis of AT Commands Within the Android Ecosystem · USENIX Security Symposium 2018
Systems and software security
vulnerability patching
0.312018
InstaGuard: Instantly Deployable Hot-patches for Vulnerable System Programs on Android · NDSS 2018
Systems and software security › return-oriented programming defense
code reuse attack defense
0.312017
NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64 · IEEE Symposium on Security and Privacy 2017
Systems and software security › memory protection
execute-only memory
0.312017
NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64 · IEEE Symposium on Security and Privacy 2017
Systems and software security
exploitation
0.312017
NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64 · IEEE Symposium on Security and Privacy 2017
Operating systems › system security › operating system security
access control
0.212014
JIGSAW: Protecting Resource Access by Inferring Programmer Expectations · USENIX Security Symposium 2014
Operating systems › system security › operating system security
process protection
0.212013
Process firewalls: protecting processes during resource access · EuroSys 2013
Program analysis
static analysis
0.112012
STING: Finding Name Resolution Vulnerabilities in Programs · USENIX Security Symposium 2012
Systems and software security › memory safety
address space layout randomization
0.112017
NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64 · IEEE Symposium on Security and Privacy 2017
Systems and software security › operating system security
system call filtering
0.012013
Process firewalls: protecting processes during resource access · EuroSys 2013

Methods — techniques the papers use, named apart from their topics

emulation · 0.9mutation heuristics · 0.8coverage-guided fuzzing · 0.8binary patching · 0.7graph analysis · 0.5access control policy analysis · 0.5kernel mechanism · 0.3static binary transformation · 0.3in-place randomization · 0.3system-call interception · 0.2system call interception · 0.2
YearPublicationVenuePosition
2021 PolyScope: Multi-Policy Access Control Analysis to Compute Authorized Attack Operations in Android Systems
Yu Tsung Lee, William Enck, Haining Chen, Hayawardh Vijayakumar, Ninghui Li 0001, Zhiyun Qian, Daimeng Wang, Giuseppe Petracca, Trent Jaeger
USENIX Security Symposium4
2020 PARTEMU: Enabling Dynamic Analysis of Real-World TrustZone Software Using Emulation
Lee Harrison, Hayawardh Vijayakumar, Rohan Padhye, Koushik Sen, Michael Grace
USENIX Security Symposium2
2019 FuzzFactory: domain-specific fuzzing with waypoints
abstract
Coverage-guided fuzz testing has gained prominence as a highly effective method of finding security vulnerabilities such as buffer overflows in programs that parse binary data. Recently, researchers have introduced various specializations to the coverage-guided fuzzing algorithm for different domain-specific testing goals, such as finding performance bottlenecks, generating valid inputs, handling magic-byte comparisons, etc. Each such solution can require non-trivial implementation effort and produces a distinct variant of a fuzzing tool. We observe that many of these domain-specific solutions follow a common solution pattern. In this paper, we present FuzzFactory, a framework for developing domain-specific fuzzing applications without requiring changes to mutation and search heuristics. FuzzFactory allows users to specify the collection of dynamic domain-specific feedback during test execution, as well as how such feedback should be aggregated. FuzzFactory uses this information to selectively save intermediate inputs, called waypoints, to augment coverage-guided fuzzing. Such waypoints always make progress towards domain-specific multi-dimensional objectives. We instantiate six domain-specific fuzzing applications using FuzzFactory: three re-implementations of prior work and three novel solutions, and evaluate their effectiveness on benchmarks from Google's fuzzer test suite. We also show how multiple domains can be composed to perform better than the sum of their parts. For example, we combine domain-specific feedback about strict equality comparisons and dynamic memory allocations, to enable the automatic generation of LZ4 bombs and PNG bombs.
Rohan Padhye, Caroline Lemieux, Koushik Sen, Laurent Simon 0001, Hayawardh Vijayakumar
Proc. ACM Program. Lang.5
2018 InstaGuard: Instantly Deployable Hot-patches for Vulnerable System Programs on Android
Yaohui Chen 0001, Long Lu, Yueh-Hsun Lin, Hayawardh Vijayakumar, Zhi Wang 0004, Xinming Ou
NDSS5
2018 ATtention Spanned: Comprehensive Vulnerability Analysis of AT Commands Within the Android Ecosystem
Jing (Dave) Tian, Grant Hernandez, Joseph I. Choi, Vanessa Frost, Christie Ruales, Patrick Traynor, Hayawardh Vijayakumar, Lee Harrison, Amir Rahmati, Michael Grace, Kevin R. B. Butler
USENIX Security Symposium7
2017 NORAX: Enabling Execute-Only Memory for COTS Binaries on AArch64
abstract
Code reuse attacks exploiting memory disclosure vulnerabilities can bypass all deployed mitigations. One promising defense against this class of attacks is to enable execute-only memory (XOM) protection on top of fine-grained address space layout randomization (ASLR). However, recent works implementing XOM, despite their efficacy, only protect programs that have been (re)built with new compiler support, leaving commercial-off-the-shelf (COTS) binaries and source-unavailable programs unprotected. We present the design and implementation of NORAX, a practical system that retrofits XOM into stripped COTS binaries on AArch64 platforms. Unlike previous techniques, NORAX requires neither source code nor debugging symbols. NORAX statically transforms existing binaries so that during runtime their code sections can be loaded into XOM memory pages with embedded data relocated and data references properly updated. NORAX allows transformed binaries to leverage the new hardware-based XOM support—a feature widely available on AArch64 platforms (e.g., recent mobile devices) yet virtually unused due to the incompatibility of existing binaries. Furthermore, NORAX is designed to co-exist with other COTS binary hardening techniques, such as in-place randomization (IPR). We apply NORAX to the commonly used Android system binaries running on SAMSUNG Galaxy S6 and LG Nexus 5X devices. The results show that NORAX on average slows down the execution of transformed binaries by 1.18% and increases their memory footprint by 2.21%, suggesting NORAX is practical for real-world adoption.
Yaohui Chen 0001, Dongli Zhang, Ruowen Wang, Ahmed M. Azab, Long Lu, Hayawardh Vijayakumar, Wenbo Shen
IEEE Symposium on Security and Privacy7
2015 Cloud Armor: Protecting Cloud Commands from Compromised Cloud Services
abstract
Infrastructure-as-a-Service (IaaS) clouds can be viewed as distributed systems of cloud services that are entrusted to execute users' cloud commands to provision and manage clouds computing resources (e.g., VM). However, recent vulnerabilities found in cloud services show that this trust is often misplaced. By exploiting a vulnerability in a cloud service, an adversary can hijack or forge commands to modify user VMs, exfiltrate sensitive information, and even modify other service hosts. This paper introduces Cloud Armor, a system that detects and blocks the tampering of user commands without the need for modifications to cloud services. Our insight is that we can construct state machine models to limit the system call sequences executed by cloud services. By applying constraints over system call arguments, we can restrict the way user commands are executed, blocking unauthorized operations from compromised cloud services. We implemented a prototype Cloud Armor system for Open Stack, a widely adopted open source cloud platform. Results show that Cloud Armor can greatly limit attack options available for adversaries while imposing less than 1% overhead for user VMs. As a result, cloud users can leverage Cloud Armor to execute user commands safely even in presence of compromised cloud services.
Yuqiong Sun, Giuseppe Petracca, Trent Jaeger, Hayawardh Vijayakumar, Joshua Schiffman
CLOUD4
2014 Policy models to protect resource retrieval
abstract
Processes need a variety of resources from their operating environment in order to run properly, but adversary may control the inputs to resource retrieval or the end resource itself, leading to a variety of vulnerabilities. Conventional access control methods are not suitable to prevent such vulnerabilities because they use one set of permissions for all system call invocations. In this paper, we define a novel policy model for describing when resource retrievals are unsafe, so they can be blocked. This model highlights two contributions: (1) the explicit definition of adversary models as adversarial roles, which list the permissions that dictate whether one subject is an adversary of another, and (2) the application of data-flow to determine the adversary control of the names used to retrieve resources. An evaluation using multiple adversary models shows that data-flow is necessary to authorize resource retrieval in over 90% of system calls. By making adversary models and the adversary accessibility of all aspects of resource retrieval explicit, we can block resource access attacks system-wide.
Hayawardh Vijayakumar, Xinyang Ge, Trent Jaeger
SACMAT1
2014 JIGSAW: Protecting Resource Access by Inferring Programmer Expectations
Hayawardh Vijayakumar, Xinyang Ge, Mathias Payer, Trent Jaeger
USENIX Security Symposium1
2013 Process firewalls: protecting processes during resource access
abstract
Processes retrieve a variety of resources from the operating system in order to execute properly, but adversaries have several ways to trick processes into retrieving resources of the adversaries' choosing. Such resource access attacks use name resolution, race conditions, and/or ambiguities regarding which resources are controlled by adversaries, accounting for 5-10% of CVE entries over the last four years. programmers have found these attacks extremely hard to eliminate because resources are managed externally to the program, but the operating system does not provide a sufficiently rich system-call API to enable programs to block such attacks. In this paper, we present the Process Firewall, a kernel mechanism that protects processes in manner akin to a network firewall for the system-call interface. Because the Process Firewall only protects processes -- rather than sandboxing them -- it can examine their internal state to identify the protection rules necessary to block many of these attacks without the need for program modification or user configuration. We built a prototype Process Firewall for Linux demonstrating: (1) the prevention of several vulnerabilities, including two that were previously-unknown; (2) that this defense can be provided system-wide for less than 4% overhead in a variety of macrobenchmarks; and (3) that it can also improve program performance, shown by Apache handling 3-8% more requests when program resource access checks are replaced by Process Firewall rules. These results show that it is practical for the operating system to protect processes by preventing a variety of resource access attacks system-wide.
Hayawardh Vijayakumar, Joshua Schiffman, Trent Jaeger
EuroSys1
2013 Cloud Verifier: Verifiable Auditing Service for IaaS Clouds
abstract
Cloud computing has commoditized compute, storage, and networking resources creating an on-demand utility. Despite the attractiveness of this new paradigm, its adoption has been stymied by cloud platform's lack of transparency, which leaves customers unsure if their sensitive data and computation can be entrusted to the cloud. While techniques like encryption can protect customers' data at rest, clouds still lack mechanisms for customers to verify that their computations are being executed as expected, a guarantee one could obtain if they were running the computation in their own data center. In this paper, we present the cloud verifier (CV), a flexible framework that cloud vendors can configure to provide cloud monitoring services for customers to validate that their computations are configured and being run as expected in Infrastructure as a Service (IaaS) clouds. The CV builds a chain of trust from the customer to their hosted virtual machine (VM) instances through the cloud platform, enabling it to check customer-specified requirements against a comprehensive view of both the VM's load-time and run-time properties. In addition, the CV enables cloud vendors to provide more responsive remediation techniques than traditional attestation mechanisms. We built a proof of concept CV for the OpenStack cloud platform whose evaluation demonstrates that a single CV enables over 20,000 simultaneous customers to verify numerous properties with little impact on cloud application performance. As a result, the CV gives cloud customers a low-overhead method for assuring that their instances are running according to their requirements.
Joshua Schiffman, Yuqiong Sun, Hayawardh Vijayakumar, Trent Jaeger
SERVICES3
2012 Transforming commodity security policies to enforce Clark-Wilson integrity
abstract
Modern distributed systems are composed from several off-the-shelf components, including operating systems, virtualization infrastructure, and application packages, upon which some custom application software (e.g., web application) is often deployed. While several commodity systems now include mandatory access control (MAC) enforcement to protect the individual components, the complexity of such MAC policies and the myriad of possible interactions among individual hosts in distributed systems makes it difficult to identify the attack paths available to adversaries. As a result, security practitioners react to vulnerabilities as adversaries uncover them, rather than proactively protecting the system's data integrity. In this paper, we develop a mostly-automated method to transform a set of commodity MAC policies into a system-wide policy that proactively protects system integrity, approximating the Clark-Wilson integrity model. The method uses the insights from the Clark-Wilson model, which requires integrity verification of security-critical data and mediation at program entrypoints, to extend existing MAC policies with the proactive mediation necessary to protect system integrity. We demonstrate the practicality of producing Clark-Wilson policies for distributed systems on a web application running on virtualized Ubuntu SELinux hosts, where our method finds: (1) that only 27 additional entrypoint mediators are sufficient to mediate the threats of remote adversaries over the entire distributed system and (2) and only 20 additional local threats require mediation to approximate Clark-Wilson integrity comprehensively. As a result, available security policies can be used as a foundation for proactive integrity protection from both local and remote threats.
Divya Muthukumaran, Sandra Julieta Rueda, Nirupama Talele, Hayawardh Vijayakumar, Jason Teutsch, Trent Jaeger
ACSAC4
2012 Integrity walls: finding attack surfaces from mandatory access control policies
abstract
Protecting host system integrity in the face of determined adversaries remains a major problem. Despite advances in program development and access control, attackers continue to compromise systems forcing security practitioners to regularly react to such breaches. While security practitioners may eventually learn which entry points in programs must be defended over a software's lifetime, new software and configuration options are frequently introduced, opening additional vulnerabilities to adversaries. The application developers' problem is to identify the program entry points accessible to adversaries and provide necessary defenses at these entry points before the adversaries use these to compromise the program. Unfortunately, this is a race that developers often lose. While some program vulnerable entry points are well-known (mostly network), the complexity of host systems makes it difficult to prevent local exploits should attackers gain control of any unprivileged processing. The question we explore in this paper is whether the program entry points accessible to adversaries can be found proactively, so defenses at these entry points can also be developed proactively.
Hayawardh Vijayakumar, Guruprasad Jakka, Sandra Julieta Rueda, Joshua Schiffman, Trent Jaeger
AsiaCCS1
2012 STING: Finding Name Resolution Vulnerabilities in Programs
Hayawardh Vijayakumar, Joshua Schiffman, Trent Jaeger
USENIX Security Symposium1
2009 Analysis of virtual machine system policies
abstract
The recent emergence of mandatory access (MAC) enforcement for virtual machine monitors (VMMs) presents an opportunity to enforce a security goal over all its virtual machines (VMs). However, these VMs also have MAC enforcement, so to determine whether the overall system (VM-system) is secure requires an evaluation of whether this combination of MAC policies, as a whole, complies with a given security goal. Previous MAC policy analyses either consider a single policy at a time or do not represent the interaction between different policy layers (VMM and VM). We observe that we can analyze the VMM policy and the labels used for communications between VMs to create an inter-VM flow graph that we use to identify safe, unsafe, and ambiguous VM interactions. A VM with only safe interactions is compliant with the goal, a VM with any unsafe interaction violates the goal. For a VM with ambiguous interactions we analyze its local MAC policy to determine whether it is compliant or not with the goal. We used this observation to develop an analytical model of a VM-system, and evaluate if it is compliant with a security goal. We implemented the model and an evaluation tool in Prolog. We evaluate our implementation by checking whether a VM-system running XSM/Flask policy at the VMM layer and SELinux policies at the VM layer satisfies a given integrity goal. This work is the first step toward developing layered, multi-policy analyses.
Sandra Julieta Rueda, Hayawardh Vijayakumar, Trent Jaeger
SACMAT2
2007 A scalable parallelization of all-pairs shortest path algorithm for a high performance cluster environment
abstract
We present a parallelization of the Floyd-Warshall all pairs shortest path algorithm for a distributed environment. A lot of versions of the Floyd-Warshall algorithm have been proposed for a uniprocessor environment, optimizing cache performance and register usage. However, in a distributed environment, communication costs between nodes have to be taken into consideration. We present a novel algorithm, Phased Floyd-Warshall, for a distributed environment, which optimally overlaps computation and communication. Our algorithm is compared with a register optimized version of the blocked all pairs shortest path algorithm [6, 4, 1] which is adapted for a distributed environment. We report speedups of 2.8 in a 16-node cluster and 1.2 in a 32-node cluster for a matrix size of 4096.
T. Srinivasan 0001, S. A. Gangadharan, Hayawardh Vijayakumar
ICPADS4