VLDB 2026 Research / reviewers in the wild / expert
Manuel Egele
dblp:27/3108
· DBLP profile ↗
74ranked-venue papers
9as first author
33since 2021 · last 2026
0000-0001-5038-2682ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 54 · 7 first-author · 24 since 2021Systems, architecture and hardware · 14 · 1 first-author · 7 since 2021Software engineering, systems software and programming languages · 7 · 4 since 2021Computer networks · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The Cost of Convenience: Identifying, Analyzing, and Mitigating Predatory Loan Applications on AndroidabstractDigital lending applications, commonly referred to as loan apps, have become a primary channel for microcredit in emerging markets. However, many of these apps demand excessive permissions and misuse sensitive user data for coercive debt-recovery practices, including harassment, blackmail, and public shaming that affect both borrowers and their contacts. Olawale Amos Akanji, Manuel Egele, Gianluca Stringhini |
AsiaCCS | 2 |
| 2026 | A Comparative Analysis of NVD, JVNDB and CNVD: Insights into Global and Regional Vulnerability ReportingabstractVulnerability management relies on databases that record, classify, and disseminate information on software weaknesses. The National Vulnerability Database (NVD), the Chinese National Vulnerability Database (CNVD), and the Japanese Vulnerability Notes Database (JVNDB) are three prominent resources, each reflecting distinct regional and institutional contexts. NVD, maintained by the U.S. National Institute of Standards and Technology (NIST), provides a globally standardized framework. CNVD, managed by the China Information Technology Security Evaluation Center (CNIT-SEC), emphasizes Chinese software and incidents, often publishing disclosures rapidly. JVNDB, jointly operated by JPCERT/CC and the Information-technology Promotion Agency (IPA) of Japan since 2007, aggregates vulnerabilities reported by Japanese vendors, the JVN portal, and NVD, with content offered in both Japanese and English to serve domestic industries. Juehao Lin, Xuanxiang William Wang, Manuel Egele, Gianluca Stringhini |
AsiaCCS | 3 |
| 2025 | Zeus-IoT: Comprehensive Code Signing to Prevent IoT Device WeaponizationabstractThe explosive growth of IoT devices has not been matched by equivalent security efforts, as manufacturers often ship devices with limited built-in defenses. Existing host-based malware detection & prevention systems for IoT face three fundamental limitations. First, they depend on runtime profiling to learn normal behavior, a process that inevitably misses legitimate but infrequent code paths and can break functionality when those paths execute. Second, they ignore interpreter-level execution, meaning that both scripting engines such as Lua or Python, and the ELF interpreter (dynamic linker) can be used to run malicious payloads undetected. Third, they struggle to scale across diverse firmware platforms without per-device tuning. In this paper, we propose Zeus-IoT to address these challenges. Zeus-IoT removes the need for profiling by leveraging the insight that IoT devices run a small, fixed set of binaries and scripts that rarely change once deployed. Zeus-IoT builds an allowlist by hashing every binary, shared library, and script that exists on the firmware image the vendor has built and is ready to flash onto the device. At run time, Zeus-IoT enforces this allowlist for all executions, including native binaries, shared libraries, and scripts, closing interpreter-level gaps. By integrating Zeus-IoT directly into the manufacturer's build pipeline (as demonstrated with our OpenWrt implementation), the framework scales to any Linux-based firmware platform without per-device profiling or manual configuration. We evaluate Zeus-IoT, a prototype on OpenWrt, against 81,152 real-world IoT malware samples and achieve 100% prevention. Zeus-IoT adds virtually no memory overhead and incurs a modest CPU cost. During one-time initialization (running 220 shell scripts, loading 2,790 shared libraries, and executing 751 binaries), Zeus-IoT adds 25 seconds to setup time, paid once per boot and negligible in practice. After the device reaches steady state, it shows zero measurable overhead over a five-minute window. We also measure the performance overhead that Zeus-IoT could introduce on core IoT device functionality (e.g., routing on a router) and find the impact to be negligible. These results demonstrate that comprehensive static allowlist enforcement is both practical and highly effective for resource-constrained IoT environments. Alireza Roshandel, Manuel Egele |
ACSAC | 2 |
| 2025 | Job Grouping Based Intelligent Resource Prediction Framework
Beste Oztop, Benjamin Schwaller, Vitus J. Leung, Jim M. Brandt, Brian Kulis, Manuel Egele, Ayse K. Coskun |
JSSPP | 6 |
| 2024 | IOMMU Deferred Invalidation Vulnerability: Exploit and DefenseabstractDirect Memory Access (DMA) introduces a security vulnerability as peripherals are given direct access to system memory, exposing privileged data to potentially malicious Input/Output (IO) devices. Modern systems are equipped with an IO Memory Management Unit (IOMMU) to mitigate such DMA attacks. The OS uses the IOMMU and IO page tables to map and unmap a designated memory region before and after the DMA operation, constraining each DMA request to the approved region. IOMMU protection comes at the cost of reduced throughput in IO-intensive workloads, mainly due to the high IOTLB invalidation latency. The Linux OS eliminates this bottleneck by deferring the IOTLB invalidation requests to a later time. This opens a vulnerability window during which a memory region is unmapped but the relevant IOTLB entry remains. In this paper, we present a proof-of-concept exploit, empirically demonstrating that a malicious DMA-capable device can use this vulnerability window to leak data used by other devices. Furthermore, we propose hardware-assisted mitigation for the deferred invalidation vulnerability by making minor changes to the existing IOMMU hardware and OS software. We implemented the proposed mitigation in the Intel IOMMU implementation in QEMU and the Linux kernel. Our security evaluation showed that our proposed mitigation successfully mitigated the deferred invalidation vulnerability and provided 12.7% higher throughput compared to the strict invalidation mode. Chathura Rajapaksha, Leila Delshadtehrani, Richard Muri, Manuel Egele, Ajay Joshi |
DATE | 4 |
| 2024 | EasyCSPeasy: A Server-Side and Language-Agnostic XSS Mitigation by Devising and Ensuring Compliance with CSP
Beliz Kaleli, Manuel Egele, Gianluca Stringhini |
SecureComm (3) | 2 |
| 2024 | Pandawan: Quantifying Progress in Linux-based Firmware Rehosting
Ioannis Angelakopoulos, Gianluca Stringhini, Manuel Egele |
USENIX Security Symposium | 3 |
| 2024 | HYPERPILL: Fuzzing for Hypervisor-bugs by leveraging the Hardware Virtualization Interface
Alexander Bulekov, Qiang Liu 0034, Manuel Egele, Mathias Payer |
USENIX Security Symposium | 3 |
| 2024 | Argus: All your (PHP) Injection-sinks are belong to us
Rasoul Jahanshahi, Manuel Egele |
USENIX Security Symposium | 2 |
| 2024 | PellucidAttachment: Protecting Users From Attacks via E-Mail AttachmentsabstractMalicious email attachments are a common and successful attack vector on today's Internet. Sophisticated at- tackers can craft highly-targeted attachments, using publicly available information about potential victims to create convincing documents that contain hidden malicious payloads. Users who open these attachments using vulnerable applications are at a high risk of infection. Unfortunately, current mitigations are unreliable, relying either on fallible malware detection techniques or user education. In this work, we propose adopting a default policy of isolated attachment rendering. Emails bearing attachments are transpar- ently rewritten (in a sandboxed virtual machine environment) to contain static renderings of the attachments. Users who wish to obtain the original attachment are explicitly warned of the dan- gers of doing so – akin to TLS warnings as used in web browsers before being allowed to access the requested documents. We implement this technique in a system we call PellucidAttachment. We further report on an extensive user study that measures the usability and effectiveness of PellucidAttachment in shielding users from attacks. Our evaluation shows that adopting email attachment security indicators and an isolation-by-default policy results in a significant increase in user security, while maintaining the usability of email attachments. Sevtap Duman, Matthias Büchler, Manuel Egele, Engin Kirda |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Runtime Performance Anomaly Diagnosis in Production HPC Systems Using Active LearningabstractWith the increasing scale and complexity of High-Performance Computing (HPC) systems, performance variations in applications caused by anomalies have become significant bottlenecks in system health and operational efficiency. As we move towards exascale systems, these variations become more prominent due to the increased sharing of resources. Such variations lead to lower energy efficiency and higher operational costs. To mitigate these problems, one must quickly and accurately diagnose the root cause of the anomalies at scale. One way to evaluate system health and identify the underlying causes is by manually examining certain performance metrics in telemetry data or using rule-based methods. Due to the daily size of telemetry data reaching terabytes and the fact that the numeric telemetry data contains thousands of metrics, manual analysis of telemetry to diagnose problems becomes challenging. Given these limitations, Machine Learning (ML)-based approaches have been gaining popularity as they have been shown to be effective and practical in diagnosing previously encountered performance anomalies. One primary challenge for supervised ML models is that they require a significant amount of labeled samples during training. However, obtaining many labels for anomalies is extremely difficult and costly, considering anomalies occur infrequently and real-world numeric system telemetry data is hard to label since it contains thousands of metrics. This paper proposes a novel active learning-based framework that diagnoses performance anomalies (i.e., identifying the type of an anomaly) in HPC systems at runtime using significantly fewer labeled samples compared to state-of-the-art ML-based approaches. We show that the proposed framework achieves the same F1-score compared to a supervised approach using much fewer labeled samples (i.e., 16x fewer samples for achieving a 0.78 F1-score, 11x fewer samples for achieving a 0.82 F1-score), even when there are previously unseen applications and application inputs in the test dataset. Burak Aksar, Efe Sencan, Benjamin Schwaller, Omar Aaziz, Vitus J. Leung, Jim M. Brandt, Brian Kulis, Manuel Egele, Ayse K. Coskun |
IEEE Trans. Parallel Distributed Syst. | 8 |
| 2023 | ThreadLock: Native Principal Isolation Through Memory Protection KeysabstractInter-process isolation has been deployed in operating systems for decades, but secure intra-process isolation remains an active research topic. Achieving secure intra-process isolation within an operating system process is notoriously difficult. However, viable solutions that securely consolidate workloads into the same process have the potential to be extremely valuable. William Blair, William K. Robertson, Manuel Egele |
AsiaCCS | 3 |
| 2023 | SIGFuzz: A Framework for Discovering Microarchitectural Timing Side ChannelsabstractTiming side channels can be inadvertently introduced into processor microarchitecture during the design process, mainly due to optimizations carried out to improve processor performance. These timing side channels have been used in various attacks including transient execution attacks on recent commodity proces-sors. Hence, we need a tool to detect timing side channels during the design process. This paper presents SIGFuzz, a fuzzing-based framework for detecting microarchitectural timing side channels. A designer can use SIGFuzz to detect side channels early in the design flow and mitigate potential vulnerabilities associated with them. SIGFuzz generates a cycle-accurate microarchitectural trace for a program that executes on the target processor, it then uses two trace properties to identify side channels that would have been formed by the program. These two trace properties evaluate the effect of each instruction in the program, on the timing of its prior and later instructions, respectively. SIGFuzz also uses a statistical distribution of execution delays of instructions with the same mnemonic to flag potential side channels that manifest with different operands of an instruction. Furthermore, SIGFuzz automatically groups the detected side channels based on the microarchitectural activity trace (i.e. signature) of the instruction that triggered it. We evaluated SIGFuzz on two real-world open-source processor designs: Rocket and BOOM, and found three new side channels and two known side channels. We present a novel Spectre-style attack on BOOM based on one of the newly detected side channel. Chathura Rajapaksha, Leila Delshadtehrani, Manuel Egele, Ajay Joshi |
DATE | 3 |
| 2023 | No Grammar, No Problem: Towards Fuzzing the Linux Kernel without System-Call Descriptions
Alexander Bulekov, Bandan Das, Stefan Hajnoczi, Manuel Egele |
NDSS | 4 |
| 2023 | Prodigy: Towards Unsupervised Anomaly Detection in Production HPC SystemsabstractPerformance variations caused by anomalies in modern High Performance Computing (HPC) systems lead to decreased efficiency, impaired application performance, and increased operational costs. While machine learning (ML)-based frameworks for automated anomaly detection (often based on time series telemetry data) are gaining popularity in the literature, practical deployment challenges are often overlooked. Some ML-based frameworks require extensive customization, while others need a rich set of labeled samples, none of which are feasible for a production HPC system. Burak Aksar, Efe Sencan, Benjamin Schwaller, Omar Aaziz, Vitus J. Leung, Jim M. Brandt, Brian Kulis, Manuel Egele, Ayse K. Coskun |
SC | 8 |
| 2023 | FirmSolo: Enabling dynamic analysis of binary Linux-based IoT kernel modules
Ioannis Angelakopoulos, Gianluca Stringhini, Manuel Egele |
USENIX Security Symposium | 3 |
| 2023 | AnimateDead: Debloating Web Applications Using Concolic Execution
Babak Amin Azad, Rasoul Jahanshahi, Chris Tsoukaladelis, Manuel Egele, Nick Nikiforakis |
USENIX Security Symposium | 4 |
| 2023 | Minimalist: Semi-automated Debloating of PHP Web Applications through Static Analysis
Rasoul Jahanshahi, Babak Amin Azad, Nick Nikiforakis, Manuel Egele |
USENIX Security Symposium | 4 |
| 2022 | TargetFuzz: Using DARTs to Guide Directed Greybox FuzzersabstractSoftware development is a continuous and incremental process. Developers continuously improve their software in small batches rather than in one large batch. The high frequency of small batches makes it essential to use effective testing methods that detect bugs under limited testing time. To this end, researchers propose directed greybox fuzzing (DGF) which aims to generate test cases towards stressing certain target sites. Different from the coverage-based greybox fuzzing (CGF) which aims to maximize code coverage in the whole program, the goal of DGF is to cover potentially buggy code regions (e.g., a recently modified program region). While prior works improve several aspects of DGF (such as power scheduling, input prioritization, and target selection), little attention has been given to improving the seed selection process. Existing DGF tools use seed corpora mainly tailored for CGF (i.e., a set of seeds that cover different regions of the program). We observe that using CGF-based corpora limits the bug-finding capability of a directed greybox fuzzer. To mitigate this shortcoming, we propose TargetFuzz, a mechanism that provides a DGF tool with a target-oriented seed corpus. We refer to this corpus as DART corpus, which contains only 'close' seeds to the targets. This way, DART corpus guides DGF to the targets, thereby exposing bugs even under limited fuzzing time. Evaluations on 34 real bugs show that AFLGo (a state-of-the-art directed greybox fuzzer), when equipped with DART corpus, finds 10 additional bugs and achieves $4.03x speedup, on average, in the time-to-exposure compared to a generic CGF-based corpus. Sadullah Canakci, Nikolay Matyunin, Kalman Graffi, Ajay Joshi, Manuel Egele |
AsiaCCS | 5 |
| 2022 | Evocatio: Conjuring Bug Capabilities from a Single PoCabstractThe popularity of coverage-guided greybox fuzzers has led to a tsunami of security-critical bugs that developers must prioritize and fix. Knowing the capabilities a bug exposes (e.g., type of vulnerability, number of bytes read/written) enables prioritization of bug fixes. Unfortunately, understanding a bug's capabilities is a time consuming process, requiring (a) an understanding of the bug's root cause, (b) an understanding how an attacker may exploit the bug, and (c) the development of a patch mitigating these threats. This is a mostly-manual process that is qualitative and arbitrary, potentially leading to a misunderstanding of the bug's capabilities. Zhiyuan Jiang, Shuitao Gan, Adrian Herrera, Flavio Toffalini, Lucio Romerio, Chaojing Tang, Manuel Egele, Chao Zhang 0008, Mathias Payer |
CCS | 7 |
| 2022 | MPKAlloc: Efficient Heap Meta-data Integrity Through Hardware Memory Protection Keys
William Blair, William K. Robertson, Manuel Egele |
DIMVA | 3 |
| 2022 | Morphuzz: Bending (Input) Space to Fuzz Virtual Devices
Alexander Bulekov, Bandan Das, Stefan Hajnoczi, Manuel Egele |
USENIX Security Symposium | 4 |
| 2022 | HotFuzz: Discovering Temporal and Spatial Denial-of-Service Vulnerabilities Through Guided Micro-FuzzingabstractFuzz testing repeatedly assails software with random inputs in order to trigger unexpected program behaviors, such as crashes or timeouts, and has historically revealed serious security vulnerabilities. In this article, we present HotFuzz, a framework for automatically discovering Algorithmic Complexity (AC) time and space vulnerabilities in Java libraries. HotFuzz uses micro-fuzzing, a genetic algorithm that evolves arbitrary Java objects in order to trigger the worst-case performance for a method under test. We define Small Recursive Instantiation (SRI) as a technique to derive seed inputs represented as Java objects to micro-fuzzing. After micro-fuzzing, HotFuzz synthesizes test cases that triggered AC vulnerabilities into Java programs and monitors their execution in order to reproduce vulnerabilities outside the fuzzing framework. HotFuzz outputs those programs that exhibit high resource utilization as witnesses for AC vulnerabilities in a Java library. We evaluate HotFuzz over the Java Runtime Environment (JRE), the 100 most popular Java libraries on Maven, and challenges contained in the DARPA Space and Time Analysis for Cybersecurity (STAC) program. We evaluate SRI’s effectiveness by comparing the performance of micro-fuzzing with SRI, measured by the number of AC vulnerabilities detected, to simply using empty values as seed inputs. In this evaluation, we verified known AC vulnerabilities, discovered previously unknown AC vulnerabilities that we responsibly reported to vendors, and received confirmation from both IBM and Oracle. Our results demonstrate that micro-fuzzing finds AC vulnerabilities in real-world software, and that micro-fuzzing with SRI-derived seed inputs outperforms using empty values in both the temporal and spatial domains. William Blair, Andrea Mambretti, Sajjad Arshad, Michael Weissbacher, William K. Robertson, Engin Kirda, Manuel Egele |
ACM Trans. Priv. Secur. | 7 |
| 2021 | FlexFilt: Towards Flexible Instruction Filtering for SecurityabstractAs the complexity of software applications increases, there has been a growing demand for intra-process memory isolation. The commercially available intra-process memory isolation mechanisms in modern processors, e.g., Intel’s memory protection keys, trade-off between efficiency and security guarantees. Recently, researchers have tended to leverage the features with low security guarantees for intra-process memory isolation. Subsequently, they have relied on binary scanning and runtime binary rewriting to prevent the execution of unsafe instructions, which improves the security guarantees. Such intra-process memory isolation mechanisms are not the only security solutions that have to prevent the execution of unsafe instructions in untrusted parts of the code. In fact, we identify a similar requirement in a variety of other security solutions. Although binary scanning and runtime binary rewriting approaches can be leveraged to address this requirement, it is challenging to efficiently implement these approaches. Leila Delshadtehrani, Sadullah Canakci, William Blair, Manuel Egele, Ajay Joshi |
ACSAC | 4 |
| 2021 | Oversharing Is Not Caring: How CNAME Cloaking Can Expose Your Session CookiesabstractIn modern web ecosystem, online businesses often leverage third-party web analytics services to gain insights into the behavior of their users. Due to the recent privacy enhancements in major browsers that restrict third-party cookie usage for tracking, these businesses were urged to disguise third-party analytics infrastructure as regular subdomains of their websites [3]. The integration technique referred to as CNAME cloaking allows the businesses to continue monitoring user activity on their websites. However, it also opens up the possibility for severe security infractions as the businesses often share their session cookies with the analytics providers, thus putting online user accounts in danger. Assel Aliyeva, Manuel Egele |
AsiaCCS | 2 |
| 2021 | SoK: Enabling Security Analyses of Embedded Systems via RehostingabstractClosely monitoring the behavior of a software system during its execution enables developers and analysts to observe, and ultimately understand, how it works. This kind of dynamic analysis can be instrumental to reverse engineering, vulnerability discovery, exploit development, and debugging. While these analyses are typically well-supported for homogeneous desktop platforms (e.g., x86 desktop PCs), they can rarely be applied in the heterogeneous world of embedded systems. One approach to enable dynamic analyses of embedded systems is to move software stacks from physical systems into virtual environments that sufficiently model hardware behavior. This process which we call "rehosting" poses a significant research challenge with major implications for security analyses. Although rehosting has traditionally been an unscientific and ad-hoc endeavor undertaken by domain experts with varying time and resources at their disposal, researchers are beginning to address rehosting challenges systematically and in earnest. In this paper, we establish that emulation is insufficient to conduct large-scale dynamic analysis of real-world hardware systems and present rehosting as a firmware-centric alternative. Furthermore, we taxonomize preliminary rehosting efforts, identify the fundamental components of the rehosting process, and propose directions for future research. Andrew Fasano, Tiemoko Ballo, Marius Muench, Tim Leek, Alexander Bulekov, Brendan Dolan-Gavitt, Manuel Egele, Aurélien Francillon, Long Lu, Nick Gregory, Davide Balzarotti, William K. Robertson |
AsiaCCS | 7 |
| 2021 | DirectFuzz: Automated Test Generation for RTL Designs using Directed Graybox FuzzingabstractA critical challenge in RTL verification is to generate effective test inputs. Recently, RFUZZ proposed to use an automated software testing technique, namely Graybox Fuzzing, to effectively generate test inputs to maximize the coverage of the whole hardware design. For a scenario where a tiny fraction of a large hardware design needs to be tested, the RFUZZ approach is extremely time consuming. In this work, we present DirectFuzz, a directed test generation mechanism. DirectFuzz uses Directed Graybox Fuzzing to generate test inputs targeted towards a module instance, which enables targeted testing. Our experimental results show that DirectFuzz covers the target sites up to 17.5 × faster (2.23 × on average) than RFUZZ on a variety of RTL designs. Sadullah Canakci, Leila Delshadtehrani, Furkan Eris, Michael B. Taylor, Manuel Egele, Ajay Joshi |
DAC | 5 |
| 2021 | SealPK: Sealable Protection Keys for RISC-VabstractWith the continuous increase in the number of software-based attacks, there has been a growing effort towards isolating sensitive data and trusted software components from untrusted third-party components. Recently, Intel introduced a new hardware feature for intra-process memory isolation, called Memory Protection Keys (MPK). The limited number of unique domains (16) provided by Intel MPK prohibits its use in cases where a large number of domains are required. Moreover, Intel MPK suffers from the protection key use-after-free vulnerability. To address these shortcomings, in this paper, we propose an efficient intra-process isolation technique for the RISC-V open ISA, called SeaIPK, which supports up to 1024 unique domains. Additionally, we devise three novel sealing features to protect the allocated domains, their associated pages, and their permissions from modifications or tampering by an attacker. We demonstrate the efficiency of SealPK by leveraging it to implement an isolated secure shadow stack on an FPGA prototype. Leila Delshadtehrani, Sadullah Canakci, Manuel Egele, Ajay Joshi |
DATE | 3 |
| 2021 | E2EWatch: An End-to-End Anomaly Diagnosis Framework for Production HPC Systems
Burak Aksar, Benjamin Schwaller, Omar Aaziz, Vitus J. Leung, Jim M. Brandt, Manuel Egele, Ayse K. Coskun |
Euro-Par | 6 |
| 2021 | AppJitsu: Investigating the Resiliency of Android ApplicationsabstractThe Android platform gives mobile device users the opportunity to extend the capabilities of their systems by installing developer-authored apps. Companies leverage this capability to reach their customers and conduct business operations such as financial transactions. End-users can obtain custom Android applications (apps) from the Google Play, some of which are security-sensitive due to the nature of the data that they handle, such as apps from the FINANCE category. Although there are recommendations and standardized guidelines for secure app development with various self-defense techniques, the adoption of such methods is not mandatory and is left to the discretion of developers. Unfortunately, malicious actors can tamper with the app runtime environment and then exploit the attack vectors which arise from the tampering, such as executing foreign code with elevated privileges on the mobile platform. In this paper, we present AppJITSU, a dynamic app analysis framework that evaluates the resiliency of security-critical apps. We exercise the most popular 455 financial apps in attack-specific hostile environments to demonstrate the current state of resiliency against known tampering methods. Our results indicate that 25.05% of the tested apps have no resiliency against any common hostile methods or tools, whereas only 10.77% employed all defensive methods. Onur Zungur, Antonio Bianchi, Gianluca Stringhini, Manuel Egele |
EuroS&P | 4 |
| 2021 | To Err.Is Human: Characterizing the Threat of Unintended URLs in Social Media
Beliz Kaleli, Brian Kondracki, Manuel Egele, Nick Nikiforakis, Gianluca Stringhini |
NDSS | 3 |
| 2021 | Saphire: Sandboxing PHP Applications with Tailored System Call Allowlists
Alexander Bulekov, Rasoul Jahanshahi, Manuel Egele |
USENIX Security Symposium | 3 |
| 2021 | The Art, Science, and Engineering of Fuzzing: A SurveyabstractAmong the many software testing techniques available today,fuzzinghas remained highly popular due to its conceptual simplicity, its low barrier to deployment, and its vast amount of empirical evidence in discovering real-world software vulnerabilities. At a high level, fuzzing refers to a process of repeatedly running a program with generated inputs that may be syntactically or semantically malformed. While researchers and practitioners alike have invested a large and diverse effort towards improving fuzzing in recent years, this surge of work has also made it difficult to gain a comprehensive and coherent view of fuzzing. To help preserve and bring coherence to the vast literature of fuzzing, this paper presents a unified, general-purpose model of fuzzing together with a taxonomy of the current fuzzing literature. We methodically explore the design decisions at every stage of our model fuzzer by surveying the related literature and innovations in the art, science, and engineering that make modern-day fuzzers effective. Valentin J. M. Manès, HyungSeok Han, Choongwoo Han, Sang Kil Cha, Manuel Egele, Edward J. Schwartz, Maverick Woo |
IEEE Trans. Software Eng. | 5 |
| 2020 | You shall not pass: Mitigating SQL Injection Attacks on Legacy Web ApplicationsabstractSQL injection (SQLi) attacks pose a significant threat to the security of web applications. Existing approaches do not support object-oriented programming that renders these approaches unable to protect the real-world web apps such as Wordpress, Joomla, or Drupal against SQLi attacks. We propose a novel hybrid static-dynamic analysis for PHP web applications that limits each PHP function for accessing the database. Our tool, SQLBlock, reduces the attack surface of the vulnerable PHP functions in a web application to a set of query descriptors that demonstrate the benign functionality of the PHP function. We implement SQLBlock as a plugin for MySQL and PHP. Our approach does not require any modification to the web app. We evaluate SQLBlock on 11 SQLi vulnerabilities in Wordpress, Joomla, Drupal, Magento, and their plugins. We demonstrate that SQLBlock successfully prevents all 11 SQLi exploits with negligible performance overhead (i.e., a maximum of 3% on a heavily-loaded web server). Rasoul Jahanshahi, Adam Doupé, Manuel Egele |
AsiaCCS | 3 |
| 2020 | Efficient Context-Sensitive CFI Enforcement Through a Hardware Monitor
Sadullah Canakci, Leila Delshadtehrani, Boyou Zhou, Ajay Joshi, Manuel Egele |
DIMVA | 5 |
| 2020 | Libspector : Context-Aware Large-Scale Network Traffic Analysis of Android ApplicationsabstractAndroid applications (apps) are a combination of code written by the developers as well as third-party libraries that carry out most commonly used functionalities such as advertisement and payments. Running apps in a monitoring environment allows researchers to measure how much network traffic is exchanged between an app and remote endpoints. However, current systems currently do not have the ability to reliably distinguish traffic that is generated by different libraries. This is important, because while mobile users are paying for data traffic without distinctions, some of this traffic is useful (e.g., data for core app functionalities), whereas the rest of the traffic can be considered a nuisance (e.g., excessive advertisements). In this paper, we present Libspector, a system that precisely attributes network traffic coming from an Android app to the library that generated it. To this end, we instrument the Android Framework to inspect the network connections initiated by apps, provide fine-grained information on the libraries in use, and calculate method coverage information while performing dynamic analysis. We then perform a measurement on 25,000 popular Android apps and investigate the relation between different categories of apps with the use of specific libraries. We analyze the method coverage of our dynamic analysis method, and further characterize the endpoint connections established by the Android apps. Our results indicate that advertisement libraries account for over a quarter of the total data transmission. We further observe that there is no strict 1-to-1 correlation between the similar categories of network endpoints and libraries which initiated the data transfer. Onur Zungur, Gianluca Stringhini, Manuel Egele |
DSN | 3 |
| 2020 | HotFuzz: Discovering Algorithmic Denial-of-Service Vulnerabilities Through Guided Micro-Fuzzing
William Blair, Andrea Mambretti, Sajjad Arshad, Michael Weissbacher, William K. Robertson, Engin Kirda, Manuel Egele |
NDSS | 7 |
| 2020 | Meddling Middlemen: Empirical Analysis of the Risks of Data-Saving Mobile BrowsersabstractMobile browsers have become one of the main mediators of our online activities. However, as web pages continue to increase in size and streaming media on-the-go has become commonplace, mobile data plan constraints remain a significant concern for users. As a result, data-saving features can be a differentiating factor when selecting a mobile browser. In this paper, we present a comprehensive exploration of the security and privacy threat that data-saving functionality presents to users. We conduct the first analysis of Android's data-saving browser (DSB) ecosystem across multiple dimensions, including the characteristics of the various browsers' infrastructure, their application and protocol-level behavior, and their effect on users' browsing experience. Our research unequivocally demonstrates that enabling data-saving functionality in major browsers results in significant degradation of the user's security posture by introducing severe vulnerabilities that are not otherwise present in the browser during normal operation. In summary, our experiments show that enabling data savings exposes users to (i) proxy servers running outdated software, (ii) man-in-the-middle attacks due to problematic validation of TLS certificates, (iii) weakened TLS cipher suite selection, (iv) lack of support of security headers like HSTS, and (v) a higher likelihood of being labelled as bots. While the discovered issues can be addressed, we argue that data-saving functionality presents inherent risks in an increasingly-encrypted Web, and users should be alerted of the critical savings-vs-security trade-off that they implicitly accept every time they enable such functionality. Brian Kondracki, Assel Aliyeva, Manuel Egele, Iasonas Polakis, Nick Nikiforakis |
SP | 3 |
| 2020 | PHMon: A Programmable Hardware Monitor and Its Security Use Cases
Leila Delshadtehrani, Sadullah Canakci, Boyou Zhou, Schuyler Eldridge, Ajay Joshi, Manuel Egele |
USENIX Security Symposium | 6 |
| 2019 | Towards Practical Record and Replay for Mobile ApplicationsabstractThe ability to repeat the execution of a program is a fundamental requirement in evaluating computer systems and apps. Reproducing executions of mobile apps has proven difficult under real-life scenarios due to different sources of external inputs and interactive nature of the apps. We present a new practical record/replay framework for Android, RandR, which handles multiple sources of input and provides cross-device replay capabilities through a dynamic instrumentation approach. We demonstrate the feasibility of RandR by recording and replaying a set of real-world apps. Onur Sahin, Assel Aliyeva, Hariharan Mathavan, Ayse K. Coskun, Manuel Egele |
DAC | 5 |
| 2019 | On the Perils of Leaking Referrers in Online Collaboration Services
Beliz Kaleli, Manuel Egele, Gianluca Stringhini |
DIMVA | 2 |
| 2019 | BorderPatrol: Securing BYOD using Fine-Grained Contextual InformationabstractCompanies adopt Bring Your Own Device (BYOD) policies extensively, for both convenience and cost management. The compelling way of putting private and business related applications (apps) on the same device leads to the widespread usage of employee owned devices to access sensitive company data and services. Such practices create a security risk as a legitimate app may send business-sensitive data to third party servers through detrimental app functions or packaged libraries. In this paper, we propose BorderPatrol, a system for extracting contextual data that businesses can leverage to enforce access control in BYOD-enabled corporate networks through fine-grained policies. BorderPatrol extracts contextual information, which is the stack trace of the app function that generated the network traffic, on provisioned user devices and transfers this data in IP headers to enforce desired policies at network routers. BorderPatrol provides a way to selectively prevent undesired functionalities, such as analytics activities or advertisements, and help enforce information dissemination policies of the company while leaving other functions of the app intact. Using 2,000 apps, we demonstrate that BorderPatrol is effective in preventing packets which originate from previously identified analytics and advertisement libraries from leaving the network premises. In addition, we show BorderPatrol's capability in selectively preventing undesirable app functions using case studies. Onur Zungur, Guillermo Suarez-Tangil, Gianluca Stringhini, Manuel Egele |
DSN | 4 |
| 2019 | HPAS: An HPC Performance Anomaly Suite for Reproducing Performance VariationsabstractModern high performance computing (HPC) systems, including supercomputers, routinely suffer from substantial performance variations. The same application with the same input can have more than 100% performance variation, and such variations cause reduced efficiency and wasted resources. There have been recent studies on performance variability and on designing automated methods for diagnosing "anomalies" that cause performance variability. These studies either observe data collected from HPC systems, or they rely on synthetic reproduction of performance variability scenarios. However, there is no standardized way of creating performance variability inducing synthetic anomalies; so, researchers rely on designing ad-hoc methods for reproducing performance variability. Emre Ates, Yijia Zhang 0002, Burak Aksar, Jim M. Brandt, Vitus J. Leung, Manuel Egele, Ayse K. Coskun |
ICPP | 6 |
| 2019 | RANDR: Record and Replay for Android Applications via Targeted Runtime InstrumentationabstractThe ability to repeat the execution of a program is a fundamental requirement in many areas of computing from computer system evaluation to software engineering. Reproducing executions of mobile apps, in particular, has proven difficult under real-life scenarios due to multiple sources of external inputs and interactive nature of the apps. Previous works that provide record/replay functionality for mobile apps are restricted to particular input sources (e.g., touchscreen events) and present deployment challenges due to intrusive modifications to the underlying software stack. Moreover, due to their reliance on record and replay of device specific events, the recorded executions cannot be reliably reproduced across different platforms. In this paper, we present a new practical approach, RandR, for record and replay of Android applications. RandR captures and replays multiple sources of input (i.e., UI and network) without requiring source code (OS or app), administrative device privileges, or any special platform support. RandR achieves these qualities by instrumenting a select set of methods at runtime within an application's own sandbox. In addition, to enable portability of recorded executions across different platforms for replay, RandR contextualizes UI events as interactions with particular UI components (e.g., a button) as opposed to relying on platform specific features (e.g., screen coordinates). We demonstrate RandR's accurate cross-platform record and replay capabilities using over 30 real-world Android apps across a variety of platforms including emulators as well as commercial off-the-shelf mobile devices deployed in real life. Onur Sahin, Assel Aliyeva, Hariharan Mathavan, Ayse K. Coskun, Manuel Egele |
ASE | 5 |
| 2019 | Online Diagnosis of Performance Variation in HPC Systems Using Machine LearningabstractAs the size and complexity of high performance computing (HPC) systems grow in line with advancements in hardware and software technology, HPC systems increasingly suffer from performance variations due to shared resource contention as well as software- and hardware-related problems. Such performance variations can lead to failures and inefficiencies, which impact the cost and resilience of HPC systems. To minimize the impact of performance variations, one must quickly and accurately detect and diagnose the anomalies that cause the variations and take mitigating actions. However, it is difficult to identify anomalies based on the voluminous, high-dimensional, and noisy data collected by system monitoring infrastructures. This paper presents a novel machine learning based framework to automatically diagnose performance anomalies at runtime. Our framework leverages historical resource usage data to extract signatures of previously-observed anomalies. We first convert collected time series data into easy-to-compute statistical features. We then identify the features that are required to detect anomalies, and extract the signatures of these anomalies. At runtime, we use these signatures to diagnose anomalies with negligible overhead. We evaluate our framework using experiments on a real-world HPC supercomputer and demonstrate that our approach successfully identifies 98 percent of injected anomalies and consistently outperforms existing anomaly diagnosis techniques. Ozan Tuncer, Emre Ates, Yijia Zhang 0002, Ata Turk, Jim M. Brandt, Vitus J. Leung, Manuel Egele, Ayse K. Coskun |
IEEE Trans. Parallel Distributed Syst. | 7 |
| 2018 | Hardware Performance Counters Can Detect Malware: Myth or Fact?abstractThe ever-increasing prevalence of malware has led to the explorations of various detection mechanisms. Several recent works propose to use Hardware Performance Counters (HPCs) values with machine learning classification models for malware detection. HPCs are hardware units that record low-level micro-architectural behavior, such as cache hits/misses, branch (mis)prediction, and load/store operations. However, this information does not reliably capture the nature of the application, i.e. whether it is benign or malicious. In this paper, we claim and experimentally support that using the micro-architectural level information obtained from HPCs cannot distinguish between benignware and malware. We evaluate the fidelity of malware detection using HPCs. We perform quantitative analysis using Principal Component Analysis (PCA) to systematically select micro-architectural events that have the most predictive powers. We then run 1,924 programs, 962 benignware and 962 malware, on our experimental setups. We achieve 83.39%, 84.84%, 83.59%, 75.01%, 78.75%, and 14.32% F1-score (a metric of detection rates) of Decision Tree (DT), Random Forest (RF), K Nearest Neighbors (KNN), Adaboost, Neural Net (NN), and Naive Bayes, respectively. We cross-validate our models 1,000 times to show the distributions of detection rates in various models. Our cross-validation analysis shows that many of the experiments produce low F1-scores. The F1-score of models in DT, RF, KNN, Adaboost, NN, and Naive Bayes is 80.22%, 81.29%, 80.22%, 70.32%, 35.66%, and 9.903%, respectively. To further highlight the incapability of malware detection using HPCs, we show that one benignware (Notepad++) infused with malware (ransomware) cannot be detected by HPC-based malware detection. Boyou Zhou, Anmol Gupta, Rasoul Jahanshahi, Manuel Egele, Ajay Joshi |
AsiaCCS | 4 |
| 2018 | Taxonomist: Application Detection Through Rich Monitoring Data
Emre Ates, Ozan Tuncer, Ata Turk, Vitus J. Leung, Jim M. Brandt, Manuel Egele, Ayse K. Coskun |
Euro-Par | 6 |
| 2018 | Proteus: Detecting Android Emulators from Instruction-Level Profiles
Onur Sahin, Ayse K. Coskun, Manuel Egele |
RAID | 3 |
| 2017 | PayBreak: Defense Against Cryptographic RansomwareabstractSimilar to criminals in the physical world, cyber-criminals use a variety of illegal and immoral means to achieve monetary gains. Recently, malware known as ransomware started to leverage strong cryptographic primitives to hold victims' computer files "hostage" until a ransom is paid. Victims, with no way to defend themselves, are often advised to simply pay. Existing defenses against ransomware rely on ad-hoc mitigations that target the incorrect use of cryptography rather than generic live protection. To fill this gap in the defender's arsenal, we describe the approach, prototype implementation, and evaluation of a novel, automated, and most importantly proactive defense mechanism against ransomware. Our prototype, called PayBreak, effectively combats ransomware, and keeps victims' files safe. Eugene Kolodenker, William Koch, Gianluca Stringhini, Manuel Egele |
AsiaCCS | 4 |
| 2017 | Semi-automated discovery of server-based information oversharing vulnerabilities in Android applicationsabstractModern applications are often split into separate client and server tiers that communicate via message passing over the network. One well-understood threat to privacy for such applications is the leakage of sensitive user information either in transit or at the server. In response, an array of defensive techniques have been developed to identify or block unintended or malicious information leakage. However, prior work has primarily considered privacy leaks originating at the client directed at the server, while leakage in the reverse direction -- from the server to the client -- is comparatively under-studied. The question of whether and to what degree this leakage constitutes a threat remains an open question. We answer this question in the affirmative with Hush, a technique for semi-automatically identifying Server-based InFormation OvershariNg (SIFON) vulnerabilities in multi-tier applications. In particular, the technique detects SIFON vulnerabilities using a heuristic that overshared sensitive information from server-side APIs will not be displayed by the application's user interface. The technique first performs a scalable static program analysis to screen applications for potential vulnerabilities, and then attempts to confirm these candidates as true vulnerabilities with a partially-automated dynamic analysis. Our evaluation over a large corpus of Android applications demonstrates the effectiveness of the technique by discovering several previously-unknown SIFON vulnerabilities in eight applications. William Koch, Abdelberi Chaabane, Manuel Egele, William K. Robertson, Engin Kirda |
ISSTA | 3 |
| 2017 | What's in a Name?: Understanding Profile Name Reuse on TwitterabstractUsers on Twitter are commonly identified by their profile names. These names are used when directly addressing users on Twitter, are part of their profile page URLs, and can become a trademark for popular accounts, with people referring to celebrities by their real name and their profile name, interchangeably. Twitter, however, has chosen to not permanently link profile names to their corresponding user accounts. In fact, Twitter allows users to change their profile name, and afterwards makes the old profile names available for other users to take. Enrico Mariconti, Jeremiah Onaolapo, Syed Sharique Ahmad, Nicolas Nikiforou, Manuel Egele, Nick Nikiforakis, Gianluca Stringhini |
WWW | 5 |
| 2017 | Towards Detecting Compromised Accounts on Social NetworksabstractCompromising social network accounts has become a profitable course of action for cybercriminals. By hijacking control of a popular media or business account, attackers can distribute their malicious messages or disseminate fake information to a large user base. The impacts of these incidents range from a tarnished reputation to multi-billion dollar monetary losses on financial markets. In our previous work, we demonstrated how we can detect large-scale compromises (i.e., so-called campaigns) of regular online social network users. In this work, we show how we can use similar techniques to identify compromises of individual high-profile accounts. High-profile accounts frequently have one characteristic that makes this detection reliable-they show consistent behavior over time. We show that our system, were it deployed, would have been able to detect and prevent three real-world attacks against popular companies and news agencies. Furthermore, our system, in contrast to popular media, would not have fallen for a staged compromise instigated by a US restaurant chain for publicity reasons. Manuel Egele, Gianluca Stringhini, Christopher Krügel, Giovanni Vigna |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2016 | EmailProfiler: Spearphishing Filtering with Header and Stylometric Features of EmailsabstractSpearphishing is a prominent targeted attack vector in today's Internet. By impersonating trusted email senders through carefully crafted messages and spoofed metadata, adversaries can trick victims into launching attachments containing malicious code or into clicking on malicious links that grant attackers a foothold into otherwise well-protected networks. Spearphishing is effective because it is fundamentally difficult for users to distinguish legitimate emails from spearphishing emails without additional defensive mechanisms. However, such mechanisms, such as cryptographic signatures, have found limited use in practice due to their perceived difficulty of use for normal users. In this paper, we present a novel automated approach to defending users against spearphishing attacks. The approach first builds probabilistic models of both email metadata and stylometric features of email content. Then, subsequent emails are compared to these models to detect characteristic indicators of spearphishing attacks. Several instantiations of this approach are possible, including performing model learning and evaluation solely on the receiving side, or senders publishing models that can be checked remotely by the receiver. Our evaluation of a real data set drawn from 20 email users demonstrates that the approach effectively discriminates spearphishing attacks from legitimate email while providing significant ease-of-use benefits over traditional defenses. Sevtap Duman, Kubra Kalkan-Cakmakci, Manuel Egele, William K. Robertson, Engin Kirda |
COMPSAC | 3 |
| 2016 | Towards Automated Dynamic Analysis for Linux-based Embedded Firmware
Daming D. Chen, Maverick Woo, David Brumley, Manuel Egele |
NDSS | 4 |
| 2015 | Drops for Stuff: An Analysis of Reshipping Mule ScamsabstractCredit card fraud has seen rampant increase in the past years, as customers use credit cards and similar financial instruments frequently. Both online and brick-and-mortar outfits repeatedly fall victim to cybercriminals who siphon off credit card information in bulk. Despite the many and creative ways that attackers use to steal and trade credit card information, the stolen information can rarely be used to withdraw money directly, due to protection mechanisms such as PINs and cash advance limits. As such, cybercriminals have had to devise more advanced monetization schemes to work around the current restrictions. One monetization scheme that has been steadily gaining traction are reshipping scams. In such scams, cybercriminals purchase high-value or highly-demanded products from online merchants using stolen payment instruments, and then ship the items to a credulous citizen. This person, who has been recruited by the scammer under the guise of "work-from-home" opportunities, then forwards the received products to the cybercriminals, most of whom are located overseas. Once the goods reach the cybercriminals, they are then resold on the black market for an illicit profit. Due to the intricacies of this kind of scam, it is exceedingly difficult to trace, stop, and return shipments, which is why reshipping scams have become a common means for miscreants to turn stolen credit cards into cash. Shuang Hao 0001, Kevin Borgolte, Nick Nikiforakis, Gianluca Stringhini, Manuel Egele, Michael Eubanks, Brian Krebs, Giovanni Vigna |
CCS | 5 |
| 2015 | On the Security and Engineering Implications of Finer-Grained Access Controls for Android Developers and Users
Yanick Fratantonio, Antonio Bianchi, William K. Robertson, Manuel Egele, Christopher Krügel, Engin Kirda, Giovanni Vigna |
DIMVA | 4 |
| 2015 | EdgeMiner: Automatically Detecting Implicit Control Flow Transitions through the Android Framework
Yinzhi Cao, Yanick Fratantonio, Antonio Bianchi, Manuel Egele, Christopher Krügel, Giovanni Vigna, Yan Chen 0004 |
NDSS | 4 |
| 2015 | EVILCOHORT: Detecting Communities of Malicious Accounts on Online Services
Gianluca Stringhini, Pierre Mourlanne, Grégoire Jacob, Manuel Egele, Christopher Krügel, Giovanni Vigna |
USENIX Security Symposium | 4 |
| 2014 | Blanket Execution: Dynamic Similarity Testing for Program Binaries and Components
Manuel Egele, Maverick Woo, Peter Chapman, David Brumley |
USENIX Security Symposium | 1 |
| 2013 | An empirical study of cryptographic misuse in android applicationsabstractDevelopers use cryptographic APIs in Android with the intent of securing data such as passwords and personal information on mobile devices. In this paper, we ask whether developers use the cryptographic APIs in a fashion that provides typical cryptographic notions of security, e.g., IND-CPA security. We develop program analysis techniques to automatically check programs on the Google Play marketplace, and find that 10.327 out of 11,748 applications that use cryptographic APIs -- 88% overall -- make at least one mistake. These numbers show that applications do not use cryptographic APIs in a fashion that maximizes overall security. We then suggest specific remediations based on our analysis towards improving overall cryptographic security in Android applications. Manuel Egele, David Brumley, Yanick Fratantonio, Christopher Krügel |
CCS | 1 |
| 2013 | Follow the green: growth and dynamics in twitter follower marketsabstractThe users of microblogging services, such as Twitter, use the count of followers of an account as a measure of its reputation or influence. For those unwilling or unable to attract followers naturally, a growing industry of "Twitter follower markets" provides followers for sale. Some markets use fake accounts to boost the follower count of their customers, while others rely on a pyramid scheme to turn non-paying customers into followers for each other, and into followers for paying customers. In this paper, we present a detailed study of Twitter follower markets, report in detail on both the static and dynamic properties of customers of these markets, and develop and evaluate multiple techniques for detecting these activities. We show that our detection system is robust and reliable, and can detect a significant number of customers in the wild. Gianluca Stringhini, Gang Wang 0011, Manuel Egele, Christopher Krügel, Giovanni Vigna, Haitao Zheng 0001, Ben Y. Zhao |
Internet Measurement Conference | 3 |
| 2013 | COMPA: Detecting Compromised Accounts on Social Networks
Manuel Egele, Gianluca Stringhini, Christopher Krügel, Giovanni Vigna |
NDSS | 1 |
| 2012 | MoCFI: A Framework to Mitigate Control-Flow Attacks on Smartphones
Lucas Davi, Alexandra Dmitrienko, Manuel Egele, Thomas Fischer 0005, Thorsten Holz, Ralf Hund, Stefan Nürnberger, Ahmad-Reza Sadeghi |
NDSS | 3 |
| 2012 | B@bel: Leveraging Email Delivery for Spam Mitigation
Gianluca Stringhini, Manuel Egele, Apostolis Zarras, Thorsten Holz, Christopher Krügel, Giovanni Vigna |
USENIX Security Symposium | 2 |
| 2012 | PoX: Protecting users from malicious Facebook applications
Manuel Egele, Andreas Moser, Christopher Krügel, Engin Kirda |
Comput. Commun. | 1 |
| 2011 | Hit 'em where it hurts: a live security exercise on cyber situational awarenessabstractLive security exercises are a powerful educational tool to motivate students to excel and foster research and development of novel security solutions. Our insight is to design a live security exercise to provide interesting datasets in a specific area of security research. In this paper we validated this insight, and we present the design of a novel kind of live security competition centered on the concept of Cyber Situational Awareness. The competition was carried out in December 2010, and involved 72 teams (900 students) spread across 16 countries, making it the largest educational live security exercise ever performed. We present both the innovative design of this competition and the novel dataset we collected. In addition, we define Cyber Situational Awareness metrics to characterize the toxicity and effectiveness of the attacks performed by the participants with respect to the missions carried out by the targets of the attack. Adam Doupé, Manuel Egele, Benjamin Caillat, Gianluca Stringhini, Gorkem Yakin, Ali Zand, Ludovico Cavedon, Giovanni Vigna |
ACSAC | 2 |
| 2011 | Poster: control-flow integrity for smartphones
Lucas Davi, Alexandra Dmitrienko, Manuel Egele, Thomas Fischer 0005, Thorsten Holz, Ralf Hund, Stefan Nürnberger, Ahmad-Reza Sadeghi |
CCS | 3 |
| 2011 | PiOS: Detecting Privacy Leaks in iOS Applications
Manuel Egele, Christopher Krügel, Engin Kirda, Giovanni Vigna |
NDSS | 1 |
| 2010 | A solution for the automated detection of clickjacking attacksabstractClickjacking is a web-based attack that has recently received a wide media coverage. In a clickjacking attack, a malicious page is constructed such that it tricks victims into clicking on an element of a different page that is only barely (or not at all) visible. By stealing the victim's clicks, an attacker could force the user to perform an unintended action that is advantageous for the attacker (e.g., initiate an online money transaction). Although clickjacking has been the subject of many discussions and alarming reports, it is currently unclear to what extent clickjacking is being used by attackers in the wild, and how significant the attack is for the security of Internet users. Marco Balduzzi, Manuel Egele, Engin Kirda, Davide Balzarotti, Christopher Krügel |
AsiaCCS | 2 |
| 2010 | Organizing Large Scale Hacking Competitions
Nicholas Childers, Bryce Boe, Lorenzo Cavallaro, Ludovico Cavedon, Marco Cova, Manuel Egele, Giovanni Vigna |
DIMVA | 6 |
| 2009 | Defending Browsers against Drive-by Downloads: Mitigating Heap-Spraying Code Injection Attacks
Manuel Egele, Peter Würzinger, Christopher Krügel, Engin Kirda |
DIMVA | 1 |
| 2007 | Panorama: capturing system-wide information flow for malware detection and analysisabstractMalicious programs spy on users' behavior and compromise their privacy. Even software from reputable vendors, such as Google Desktop and Sony DRM media player, may perform undesirable actions. Unfortunately, existing techniques for detecting malware and analyzing unknown code samples are insufficient and have significant shortcomings. We observe that malicious information access and processing behavior is the fundamental trait of numerous malware categories breaching users' privacy (including keyloggers, password thieves, network sniffers, stealth backdoors, spyware and rootkits), which separates these malicious applications from benign software. We propose a system, Panorama, to detect and analyze malware by capturing this fundamental trait. In our extensive experiments, Panorama successfully detected all the malware samples and had very few false positives. Furthermore, by using Google Desktop as a case study, we show that our system can accurately capture its information access and processing behavior, and we can confirm that it does send back sensitive information to remote servers in certain settings. We believe that a system such as Panorama will offer indispensable assistance to code analysts and malware researchers by enabling them to quickly comprehend the behavior and innerworkings of an unknown sample. Heng Yin 0001, Dawn Song, Manuel Egele, Christopher Krügel, Engin Kirda |
CCS | 3 |
| 2007 | Dynamic Spyware Analysis
Manuel Egele, Christopher Krügel, Engin Kirda, Heng Yin 0001, Dawn Song |
USENIX ATC | 1 |
| 2006 | Using Static Program Analysis to Aid Intrusion Detection
Manuel Egele, Martin Szydlowski, Engin Kirda, Christopher Krügel |
DIMVA | 1 |