VLDB 2026 Research / reviewers in the wild / expert
Anthony Gavazzi
dblp:331/2536
· DBLP profile ↗
6ranked-venue papers
2as first author
6since 2021 · last 2025
0009-0005-4559-2577ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 5 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | H2Fuzz: Guided, Black-box, Differential Fuzzing for HTTP/2-to-HTTP/1 Conversion AnomaliesabstractHTTP/2 is by far the most popular HTTP version, yet in practice, HTTP connections rarely occur over end-toend HTTP/2. This is due in large part to the fact that reverse proxies such as Content Delivery Networks (CDNs) between the client and server universally support HTTP/2 on the client side of the connection, but rarely on the server side. Proxies must therefore dynamically convert between HTTP/2 and HTTP/1, and anomalies in this conversion process can lead to critical vulnerabilities. Prior work proposed generational fuzzing techniques to discover these anomalies. However, such an approach lacks meaningful feedback, limiting the expressiveness of the generated requests and the number of anomalies it can induce. We, therefore, propose H2Fuzz, a black-box differential fuzzer for HTTP/2 which uses a comprehensive mutator and novel feedback system to drive a set of reverse proxies to increasingly divergent behavior, uncovering conversion anomalies in the process. We fuzz a set of 11 standalone reverse proxies and 5 CDNs with H2FUZZ, and find that it induces $50 \%$ more conversion anomalies than the state-of-the-art, many of which have immediate security implications. Anthony Gavazzi, Weixin Kong, Engin Kirda |
RAID | 1 |
| 2024 | Enhancing Network Security Through Vulnerability Monitoring
Anthony Gavazzi, Engin Kirda |
NSS | 2 |
| 2024 | Gudifu: Guided Differential Fuzzing for HTTP Request Parsing DiscrepanciesabstractModern web applications involve multiple HTTP processors on the traffic path, each acting as a reverse proxy and processing client requests. Even when such proxies are secure in isolation, when combined into complex systems, minor HTTP parsing discrepancies between them can lead to various severe attacks such as cache poisoning and HTTP request smuggling attacks. Bahruz Jabiyev, Anthony Gavazzi, Kaan Onarlioglu, Engin Kirda |
RAID | 2 |
| 2023 | A Study of Multi-Factor and Risk-Based Authentication Availability
Anthony Gavazzi, Engin Kirda, Long Lu, Andre King, Andy Davis, Tim Leek |
USENIX Security Symposium | 1 |
| 2023 | Solder: Retrofitting Legacy Code with Cross-Language PatchesabstractInternet-of-things devices are widely deployed, and suffer from easy-to-exploit security issues. Due to code and platform reuse, the same vulnerability oftentimes ends up affecting a large installed base. Because patch deployments tend to be focused on server-side vulnerabilities, client software in large codebases such as Apache may remain largely unpatched, and hence, vulnerable. This problem is exacerbated by the prevalent use of some of these large codebases in IoT deployments, making their use more widespread.In this paper, we address this issue of leaving latent vulnerabilities in legacy codebases. We propose Solder, a framework to patch or retrofit legacy C/C++ code by replacing any target function with a newly-implemented one in a safe language such as Rust. This allows application users to freely patch their software in a safe language whenever a patch becomes available, without the need for waiting on developers to release an official patch. When dealing with mission-critical systems, it may be infeasible to wait the months it takes, on average, for patches to be released. Internally, Solder performs this function swapping on LLVM bitcode, and can either target source code directly to generate the IR, or if source is unavailable, can lift a binary to LLVM bitcode before running the analyses and then recompiling back to binary.Evaluation on 5 popular codebases shows that Solder produces a valid patched binary that is 2.3% smaller, on average, and mitigates 11 known exploitable vulnerabilities, while introducing limited overhead and no new bugs. Anthony Gavazzi, Engin Kirda |
SANER | 2 |
| 2022 | FRAMESHIFTER: Security Implications of HTTP/2-to-HTTP/1 Conversion Anomalies
Bahruz Jabiyev, Steven Sprecher, Anthony Gavazzi, Tommaso Innocenti, Kaan Onarlioglu, Engin Kirda |
USENIX Security Symposium | 3 |