Ioannis Papagiannis

dblp:45/4905 · DBLP profile ↗
← Back
8ranked-venue papers
1as first author
1since 2021 · last 2023
0009-0005-2304-3497ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 1 first-author · 1 since 2021Security and privacy · 2Systems, architecture and hardware · 1Computer networks · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Software maintenance and evolution · 56% Compilers and program optimization · 44%
Network and information security
3 papers
Privacy and data protection · 52% Authentication and access control · 34% Web and mobile security · 10%
Databases, data mining, and information retrieval
2 papers
Distributed and cloud data management · 55% Data stream processing · 46%

Topics — the 6 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Compilers and program optimization
dead code elimination
0.712023
Dead Code Removal at Meta: Automatically Deleting Millions of Lines of Code and Petabytes of Deprecated Data · ESEC/SIGSOFT FSE 2023
Software maintenance and evolution
software maintenance
0.712023
Dead Code Removal at Meta: Automatically Deleting Millions of Lines of Code and Petabytes of Deprecated Data · ESEC/SIGSOFT FSE 2023
Privacy and data protection › privacy-enhancing technologies
data deletion
0.412020
DELF: Safeguarding deletion correctness in Online Social Networks · USENIX Security Symposium 2020
Authentication and access control
authorization
0.312017
IVD: Automatic Learning and Enforcement of Authorization Rules in Online Social Networks · IEEE Symposium on Security and Privacy 2017
Software maintenance and evolution
software ecosystems
0.212023
Dead Code Removal at Meta: Automatically Deleting Millions of Lines of Code and Petabytes of Deprecated Data · ESEC/SIGSOFT FSE 2023
Web and mobile security
online social network security
0.112017
IVD: Automatic Learning and Enforcement of Authorization Rules in Online Social Networks · IEEE Symposium on Security and Privacy 2017

Methods — techniques the papers use, named apart from their topics

static analysis · 0.7automated code removal · 0.7invariant learning · 0.3dynamic enforcement · 0.3
YearPublicationVenuePosition
2023 Dead Code Removal at Meta: Automatically Deleting Millions of Lines of Code and Petabytes of Deprecated Data
abstract
Software constantly evolves in response to user needs: new features are built, deployed, mature and grow old, and eventually their usage drops enough to merit switching them off. In any large codebase, this feature lifecycle can naturally lead to retaining unnecessary code and data. Removing these respects users’ privacy expectations, as well as helping engineers to work efficiently. In prior software engineering research, we have found little evidence of code deprecation or dead-code removal at industrial scale. We describe Systematic Code and Asset Removal Framework (SCARF), a product deprecation system to assist engineers working in large codebases. SCARF identifies unused code and data assets and safely removes them. It operates fully automatically, including committing code and dropping database tables. It also gathers developer input where it cannot take automated actions, leading to further removals. Dead code removal increases the quality and consistency of large codebases, aids with knowledge management and improves reliability. SCARF has had an important impact at Meta. In the last year alone, it has removed petabytes of data across 12.8 million distinct assets, and deleted over 104 million lines of code.
Will Shackleton, Katriel Cohn-Gordon, Peter C. Rigby, Rui Abreu 0001, James Gill, Nachiappan Nagappan, Karim Nakad, Ioannis Papagiannis, Luke Petre, Giorgi Megreli, Patrick Riggs, James Saindon
ESEC/SIGSOFT FSE8
2020 DELF: Safeguarding deletion correctness in Online Social Networks
Katriel Cohn-Gordon, Georgios Damaskinos, Divino Neto, Joshi Cordova, Benoît Reitz, Benjamin Strahs, Daniel Obenshain, Paul Pearce, Ioannis Papagiannis, Available Media
USENIX Security Symposium9
2017 IVD: Automatic Learning and Enforcement of Authorization Rules in Online Social Networks
abstract
Authorization bugs, when present in online social networks, are usually caused by missing or incorrect authorization checks and can allow attackers to bypass the online social network's protections. Unfortunately, there is no practical way to fully guarantee that an authorization bug will never be introduced-even with good engineering practices-as a web application and its data model become more complex. Unlike other web application vulnerabilities such as XSS and CSRF, there is no practical general solution to prevent missing or incorrect authorization checks. In this paper we propose Invariant Detector (IVD), a defense-in-depth system that automatically learns authorization rules from normal data manipulation patterns and distills them into likely invariants. These invariants, usually learned during the testing or pre-release stages of new features, are then used to block any requests that may attempt to exploit bugs in the social network's authorization logic. IVD acts as an additional layer of defense, working behind the scenes, complementary to privacy frameworks and testing. We have designed and implemented IVD to handle the unique challenges posed by modern online social networks. IVD is currently running at Facebook, where it infers and evaluates daily more than 200,000 invariants from a sample of roughly 500 million client requests, and checks the resulting invariants every second against millions of writes made to a graph database containing trillions of entities. Thus far IVD has detected several high impact authorization bugs and has successfully blocked attempts to exploit them before code fixes were deployed.
Paul Marinescu, Chad Parry, Marjori Pomarole, Yuan Tian 0001, Patrick Tague, Ioannis Papagiannis
IEEE Symposium on Security and Privacy6
2016 BrowserFlow: Imprecise Data Flow Tracking to Prevent Accidental Data Disclosure
Ioannis Papagiannis, Pijika Watcharapichat, Divya Muthukumaran, Peter R. Pietzuch
Middleware1
2014 Information Flow Control for Secure Cloud Computing
abstract
Security concerns are widely seen as an obstacle to the adoption of cloud computing solutions. Information Flow Control (IFC) is a well understood Mandatory Access Control methodology. The earliest IFC models targeted security in a centralised environment, but decentralised forms of IFC have been designed and implemented, often within academic research projects. As a result, there is potential for decentralised IFC to achieve better cloud security than is available today. In this paper we describe the properties of cloud computing-Platform-as-a-Service clouds in particular-and review a range of IFC models and implementations to identify opportunities for using IFC within a cloud computing context. Since IFC security is linked to the data that it protects, both tenants and providers of cloud services can agree on security policy, in a manner that does not require them to understand and rely on the particulars of the cloud software stack in order to effect enforcement.
Jean Bacon, David M. Eyers, Thomas Pasquier, Jatinder Singh, Ioannis Papagiannis, Peter R. Pietzuch
IEEE Trans. Netw. Serv. Manag.5
2011 SafeWeb: A Middleware for Securing Ruby-Based Web Applications
Petr Hosek 0001, Matteo Migliavacca, Ioannis Papagiannis, David M. Eyers, David Evans 0002, Brian Shand, Jean Bacon, Peter R. Pietzuch
Middleware3
2010 Distributed Middleware Enforcement of Event Flow Security Policy
Matteo Migliavacca, Ioannis Papagiannis, David M. Eyers, Brian Shand, Jean Bacon, Peter R. Pietzuch
Middleware2
2010 DEFCON: High-Performance Event Processing with Information Security
Matteo Migliavacca, Ioannis Papagiannis, David M. Eyers, Brian Shand, Jean Bacon, Peter R. Pietzuch
USENIX ATC2