Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Deepa Srinivasan

dblp:44/3119 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
0since 2021 · last 2011
0009-0006-0674-4280ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-authorComputer networks · 2 · 2 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Systems and software security · 100%
Software engineering, system software, and programming languages
2 papers
Operating systems · 50% Compilers and program optimization · 50%

Topics — the 6 heaviest of 7, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › memory safety › control-flow integrity
kernel control-flow integrity
0.112011
Comprehensive and Efficient Protection of Kernel Control Data · IEEE Trans. Inf. Forensics Secur. 2011
Systems and software security
operating system security
0.112011
Comprehensive and Efficient Protection of Kernel Control Data · IEEE Trans. Inf. Forensics Secur. 2011
Systems and software security
semantic gap
0.112011
Process out-grafting: an efficient "out-of-VM" approach for fine-grained process execution monitoring · CCS 2011
Systems and software security › virtualization security
virtualization-based security
0.112011
Process out-grafting: an efficient "out-of-VM" approach for fine-grained process execution monitoring · CCS 2011
Compilers and program optimization › program instrumentation
compiler instrumentation
0.012011
Comprehensive and Efficient Protection of Kernel Control Data · IEEE Trans. Inf. Forensics Secur. 2011
Operating systems › virtualization
virtual machine introspection
0.012011
Process out-grafting: an efficient "out-of-VM" approach for fine-grained process execution monitoring · CCS 2011

Methods — techniques the papers use, named apart from their topics

process out-grafting · 0.2control flow graph · 0.2compiler-based transformation · 0.2KVM · 0.2
YearPublicationVenuePosition
2011 Process out-grafting: an efficient "out-of-VM" approach for fine-grained process execution monitoring
abstract
Recent rapid malware growth has exposed the limitations of traditional in-host malware-defense systems and motivated the development of secure virtualization-based out-of-VM solutions. By running vulnerable systems as virtual machines (VMs) and moving security software from inside the VMs to outside, the out-of-VM solutions securely isolate the anti-malware software from the vulnerable system. However, the presence of semantic gap also leads to the compatibility problem in not supporting existing defense software. In this paper, we present process out-grafting, an architectural approach to address both isolation and compatibility challenges in out-of-VM approaches for fine-grained process-level execution monitoring. Specifically, by relocating a suspect process from inside a VM to run side-by-side with the out-of-VM security tool, our technique effectively removes the semantic gap and supports existing user-mode process monitoring tools without any modification. Moreover, by forwarding the system calls back to the VM, we can smoothly continue the execution of the out-grafted process without weakening the isolation of the monitoring tool. We have developed a KVM-based prototype and used it to natively support a number of existing tools without any modification. The evaluation results including measurement with benchmark programs show it is effective and practical with a small performance overhead.
Deepa Srinivasan, Zhi Wang 0004, Xuxian Jiang, Dongyan Xu
CCS1
2011 Time-Traveling Forensic Analysis of VM-Based High-Interaction Honeypots
Deepa Srinivasan, Xuxian Jiang
SecureComm1
2011 Comprehensive and Efficient Protection of Kernel Control Data
abstract
Protecting kernel control data (e.g., function pointers and return addresses) has been a serious issue plaguing rootkit defenders. In particular, rootkit authors only need to compromise one piece of control data to launch their attacks, while defenders need to protect thousands of such values widely scattered across kernel memory space. Worse, some of this data (e.g., return addresses) is volatile and can be dynamically generated at run time. Existing solutions, however, offer either incomplete protection or excessive performance overhead. To overcome these limitations, we present indexed hooks, a scheme that greatly facilitates kernel control-flow enforcement by thoroughly transforming and restricting kernel control data to take only legal jump targets (allowed by the kernel's control-flow graph). By doing so, we can severely limit the attackers' possibility of exploiting them as an infection vector to launch rootkit attacks. To validate our approach, we have developed a compiler-based prototype that implements this technique in the FreeBSD 8.0 kernel, transforming 49 025 control transfer instructions (~7.25% of the code base) to use indexed hooks instead of direct pointers. Our evaluation results indicate that our approach is generic, effective, and can be implemented on commodity hardware with a low performance overhead (<;5% based on benchmarks).
Jinku Li, Zhi Wang 0004, Tyler K. Bletsch, Deepa Srinivasan, Michael C. Grace, Xuxian Jiang
IEEE Trans. Inf. Forensics Secur.4
2010 Transparent Protection of Commodity OS Kernels Using Hardware Virtualization
Michael C. Grace, Zhi Wang 0004, Deepa Srinivasan, Jinku Li, Xuxian Jiang, Zhenkai Liang, Siarhei Liakh
SecureComm3
2010 DKSM: Subverting Virtual Machine Introspection for Fun and Profit
abstract
Virtual machine (VM) introspection is a powerful technique for determining the specific aspects of guest VM execution from outside the VM. Unfortunately, existing introspection solutions share a common questionable assumption. This assumption is embodied in the expectation that original kernel data structures are respected by the untrusted guest and thus can be directly used to bridge the well-known semantic gap. In this paper, we assume the perspective of the attacker, and exploit this questionable assumption to subvert VM introspection. In particular, we present an attack called DKSM (Direct Kernel Structure Manipulation), and show that it can effectively foil existing VM introspection solutions into providing false information. By assuming this perspective, we hope to better understand the challenges and opportunities for the development of future reliable VM introspection solutions that are not vulnerable to the proposed attack.
Sina Bahram, Xuxian Jiang, Zhi Wang 0004, Mike Grace, Jinku Li, Deepa Srinivasan, Junghwan Rhee, Dongyan Xu
SRDS6
2005 Performance analysis of multi-dimensional packet classification on programmable network processors
Deepa Srinivasan, Wu-chang Feng
Comput. Commun.1
2004 Performance Analysis of Multi-dimensional Packet Classification on Programmable Network Processors
abstract
Multi-field packet classification is frequently performed by network devices such as edge routers and firewalls - such devices can utilize programmable network processors to perform this computation-intensive task at nearly line speeds. The architectures of programmable network processors are typically highly parallel and a single algorithm can be mapped in different ways onto the hardware. We study the performance of two different design mappings of the bit vector packet classification algorithm on the Intel/sup /spl reg// IXP1200 network processor. We show that: (i) overall, parallel mapping has a better packet processing rate (25% more) than pipelined mapping; (ii) in parallel mapping, a processing element's utilization can be considerably affected by code complexity, in terms of branching, because of significant time wasted (as much as 40% more) due to aborting instruction execution pipelines; (iii) in pipelined mapping, multiple memory reads per packet can lower the overall performance.
Deepa Srinivasan, Wu-chang Feng
LCN1