Golden G. Richard III

dblp:64/775 · DBLP profile ↗
← Back
39ranked-venue papers
7as first author
5since 2021 · last 2025
0000-0001-8981-4446ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 27 · 6 first-author · 5 since 2021Computer networks · 9Software engineering, systems software and programming languages · 2Systems, architecture and hardware · 1 · 1 first-author
YearPublicationVenuePosition
2025 REx86: A Local Large Language Model for Assisting in x86 Assembly Reverse Engineering
abstract
Reverse engineering (RE) of x86 binaries is indis- pensable for malware and firmware analysis, but remains slow due to stripped metadata and adversarial obfuscation. Large Language Models (LLMs) offer potential for improving RE efficiency through automated comprehension and commenting, but cloud-hosted, closed-weight models pose privacy and security risks and cannot be used in closed-network facilities. We evaluate parameter-efficient fine-tuned local LLMs for assisting with x86 RE tasks in these settings. Eight open-weight models across the CodeLlama, Qwen2.5-Coder, and CodeGemma series are fine-tuned on a custom curated dataset of 5,981 x 86 assembly examples. We evaluate them quantitatively and identify the fine-tuned Qwen2.5-Coder-7B as the top performer, which we name REx86. REx86 reduces test-set cross-entropy loss by 64.2% and improves semantic cosine similarity against ground truth by 20.3% over its base model. In a limited user case study (n=43), REx86 significantly enhanced line-level code understanding (p = 0.031) and increased the correct-solve rate from 31% to 53% (p = 0.189), though the latter did not reach statistical significance. Qualitative analysis shows more accurate, concise comments with fewer hallucinations. REx86 delivers state-of-the-art assistance in x86 RE among local, open-weight LLMs. Our findings demonstrate the value of domain-specific fine-tuning, and highlight the need for more commented disassembly data to further enhance LLM performance in RE. REx86, its dataset, and LoRA adapters are publicly available at https://github.com/dlea8/REx86 and https://zenodo.org/records/15420461.
Darrin Lea, James Ghawaly, Golden G. Richard III, Aisha I. Ali-Gombe, Andrew Case
ACSAC3
2023 Memory Forensics of the OpenDaylight Software-Defined Networking (SDN) Controller
abstract
Software-Defined Networking (SDN) abstracts the underlying networking hardware by keeping the control plane and the data separated. SDNs use the control plane to direct network traffic, while OpenFlow switches and routers play a passive role in the system by forwarding packets. The centralization of the control plane on virtualized systems provide Digital Forensics (DF) an opportunity at acquiring and analyzing the memory of a controller. This provides forensically relevant data regarding the SDN’s operation. In our work, we examined the OpenDaylight (ODL) SDN controller to determine what forensically relevant information may be extracted from the controller’s memory. This was accomplished by creating controller memory samples with different networking configurations, and analyzing the memory samples, then constructing an SDN-Controller-Network-Discovery-Tool (SCoNDT). SCoNDT searches a memory dump for the ODL controller’s host tracker service. This service holds information on each host connected to the network, such as its internal IP address, MAC address, and the dates and times of its first and last network connections. It then generates an HTML report. SCoNDT was evaluated on memory samples with various network configurations and showed high efficacy in reconstructing the host IPs, the usernames, and hashed passwords.
Abdullah Alshaya, Adam Kardorff, Christian Facundus, Ibrahim M. Baggili, Golden G. Richard III
ARES5
2023 Catch Me if You Can: Analysis of Digital Devices and Artifacts Used in Murder Cases
John Jankura, Hannah Catallo-Stooks, Ibrahim M. Baggili, Golden G. Richard III
ICDF2C (1)4
2022 Checkmate '22: Research on offensive and defensive techniques in the context of Man At The End (MATE) attacks
abstract
The MATE (Man-At-The-End) model, in which an attacker has access to the target software and/or hardware environment to be exploited and the ability to observe and modify that environment, poses unique challenges for both defense and offense. The CheckMATE workshop focuses on exploration of both offensive and defensives techniques under this model. CheckMATE will provide a discussion forum for researchers and industrial practitioners that are exploring theorentical, practical, and emperical studies in this interesting area of security.
Golden G. Richard III, Tim Blazytko
CCS1
2022 The Hermes BFT for Blockchains
Mohammad M. Jalalzai, Chen Feng 0001, Costas Busch, Golden G. Richard III, Jianyu Niu
IEEE Trans. Dependable Secur. Comput.4
2020 App-Agnostic Post-Execution Semantic Analysis of Android In-Memory Forensics Artifacts
abstract
Over the last decade, userland memory forensics techniques and algorithms have gained popularity among practitioners, as they have proven to be useful in real forensics and cybercrime investigations. These techniques analyze and recover objects and artifacts from process memory space that are of critical importance in investigations. Nonetheless, the major drawback of existing techniques is that they cannot determine the origin and context within which the recovered object exists without prior knowledge of the application logic.
Aisha I. Ali-Gombe, Alexandra Tambaoan, Angela Gurfolino, Golden G. Richard III
ACSAC4
2020 Hooktracer: Automatic Detection and Analysis of Keystroke Loggers Using Memory Forensics
Andrew Case, Ryan D. Maggio, Md Firoz-Ul-Amin, Mohammad M. Jalalzai, Aisha I. Ali-Gombe, Mingxuan Sun 0001, Golden G. Richard III
Comput. Secur.7
2020 Gaslight revisited: Efficient and powerful fuzzing of digital forensics tools
Shravya Paruchuri, Andrew Case, Golden G. Richard III
Comput. Secur.3
2019 DroidScraper: A Tool for Android In-Memory Object Recovery and Reconstruction
Aisha I. Ali-Gombe, Sneha Sudhakaran, Andrew Case, Golden G. Richard III
RAID4
2018 Tipped Off by Your Memory Allocator: Device-Wide User Activity Sequencing from Android Memory Images
Rohit Bhatia, Brendan Saltaformaggio, Seung Jei Yang, Aisha I. Ali-Gombe, Xiangyu Zhang 0001, Dongyan Xu, Golden G. Richard III
NDSS7
2018 Toward a more dependable hybrid analysis of android malware using aspect-oriented programming
Aisha I. Ali-Gombe, Brendan Saltaformaggio, J. Ramanujam, Dongyan Xu, Golden G. Richard III
Comput. Secur.5
2016 AspectDroid: Android App Analysis System
abstract
The growing threat to user privacy related to Android applications (apps) has tremendously increased the need for more reliable and accessible app analysis systems. This paper presents AspectDroid, an application-level system designed to investigate Android applications for possible unwanted activities. AspectDroid is comprised of app instrumentation, automated testing and containment systems. By using static bytecode instrumentation, The growing threat to user privacy related to Android applications (apps) has tremendously increased the need for more reliable and accessible app analysis systems. This paper presents AspectDroid, an application-level system designed to investigate Android applications for possible unwanted activities. AspectDroid is comprised of app instrumentation, automated testing and containment systems. By using static bytecode instrumentation, AspectDroid weaves monitoring code into an existing application and provides data flow and sensitive API usage as well as dynamic instrumentation capabilities. The newly repackaged app is then executed either manually or via an automated testing module. Finally, the flexible containment provided by AspectDroid adds a layer of protection so that malicious activities can be prevented from affecting other devices. The accuracy score of AspectDroid when tested on 105 DroidBench corpus shows it can detect tagged data with 95.29\%. We further tested our system on 100 real malware families from the Drebin dataset \cite{drebin2014}. The result of our analysis showed AspectDroid incurs approximately 1MB average total memory size overhead and 5.9\% average increase in CPU-usage.
Aisha I. Ali-Gombe, Irfan Ahmed 0001, Golden G. Richard III, Vassil Roussev
CODASPY3
2016 SPICE: A Software Tool for Bridging the Gap Between End-user's Insecure Cyber Behavior and Personality Traits
abstract
End users are prone to insecure cyber behavior that may lead them to compromise the integrity, availability or confidentiality of their computer systems. For instance, replying to a phishing email may compromise an end user's login credentials. Identifying tendency toward insecure cyber behavior is critically important to improve cyber security posture and thesis of this paper is that the susceptibility of end-users to be a victim of a cyber-attack may be predicted using personality traits such as trait anxiety and callousness.
Anjila Tamrakar, Justin D. Russell, Irfan Ahmed 0001, Golden G. Richard III, Carl F. Weems
CODASPY4
2016 Screen after Previous Screens: Spatial-Temporal Recreation of Android App Displays from Memory Images
Brendan Saltaformaggio, Rohit Bhatia, Xiangyu Zhang 0001, Dongyan Xu, Golden G. Richard III
USENIX Security Symposium5
2016 Don't Touch that Column: Portable, Fine-Grained Access Control for Android's Native Content Providers
abstract
Android applications access native SQLite databases through their Universal Resource Identifiers (URIs), exposed by the Content provider library. By design, the SQLite engine used in the Android system does not enforce access restrictions on database content nor does it log database accesses. Instead, Android enforces read and write permissions on the native providers through which databases are accessed via the mandatory applications permissions system. This system is very coarse grained, however, and can allow applications far greater access to sensitive data than a user might intend.
Aisha I. Ali-Gombe, Golden G. Richard III, Irfan Ahmed 0001, Vassil Roussev
WISEC2
2013 Rule-Based Integrity Checking of Interrupt Descriptor Tables in Cloud Environments
Irfan Ahmed 0001, Aleksandar Zoranic, Salman Javaid, Golden G. Richard III, Vassil Roussev
IFIP Int. Conf. Digital Forensics4
2013 Integrity Checking of Function Pointers in Kernel Pools via Virtual Machine Introspection
Irfan Ahmed 0001, Golden G. Richard III, Aleksandar Zoranic, Vassil Roussev
ISC2
2009 A Cloud Computing Platform for Large-Scale Forensic Computing
Vassil Roussev, Golden G. Richard III, Lodovico Marziale
IFIP Int. Conf. Digital Forensics3
2008 Class-Aware Similarity Hashing for Data Classification
Vassil Roussev, Golden G. Richard III, Lodovico Marziale
IFIP Int. Conf. Digital Forensics2
2007 In-Place File Carving
Golden G. Richard III, Vassil Roussev, Lodovico Marziale
IFIP Int. Conf. Digital Forensics1
2006 File System Support for Digital Evidence Bags
Golden G. Richard III, Vassil Roussev
IFIP Int. Conf. Digital Forensics1
2006 dRamDisk: efficient RAM sharing on a commodity cluster
abstract
Recent work on distributed RAM sharing has largely focused on leveraging low-latency networking technologies to optimize remote memory access. In contrast, we revisit the idea of RAM sharing on a commodity cluster with an emphasis on the prevalent gigabit Ethernet technology. The main point of the paper is to present a practical solution-a distributed RAM disk (dRamDisk) with an adaptive read-ahead scheme-which demonstrates that spare RAM capacity can greatly benefit I/O-constrained applications. Specifically, our experiments show that sequential read/write operations can be sped up approximately 3.5 times relative to a commodity hard drive and that, for more random access patterns, such as the ones experienced on a server, the speedup can be much higher. Our experiments demonstrate that this speedup is approximately 90% of what is practically achievable for the tested system.
Vassil Roussev, Golden G. Richard III, Daniel Tingstrom
IPCCC2
2005 Automatically Creating Realistic Targets for Digital Forensics Investigation
Frank Adelstein, Golden G. Richard III
DFRWS3
2005 Scalpel: A Frugal, High Performance File Carver
Golden G. Richard III, Vassil Roussev
DFRWS1
2005 Content-Based Image Retrieval for Digital Forensics
Yixin Chen 0002, Vassil Roussev, Golden G. Richard III
IFIP Int. Conf. Digital Forensics3
2005 Reliable ad hoc group communication using local neighborhoods
abstract
In this paper an enhanced reliability protocol added to the ODMRP multicast ad hoc protocol is described. This protocol increases the overall data packet delivery ratio by adding packet storage and retransmission operations coordinated by the multicast source. Storage responsibilities are assigned based on localized 'neighborhoods' of nodes with minimal spanning hopcount, within the group. Simulation results are presented that reflect the protocol overhead of both ODMRP and the reliability component, broken down by operational phase.
Lawrence Klos, Golden G. Richard III
WiMob (3)2
2004 Load-balanced routing through virtual paths: highly adaptive and efficient routing scheme for ad hoc wireless networks
abstract
Routing protocols for ad hoc wireless networks consider the path with the minimum number of hops as the optimal path to any given destination. However, this strategy does not balance the traffic load over the network, and may create congested areas. These congested areas greatly degrade the performance of the routing protocols. In this paper, we propose a routing scheme that balances the load over the network by selecting a path based on traffic sizes. We present a simulation study to demonstrate the effectiveness of the proposed scheme.
Abdulrahman H. Altalhi, Golden G. Richard III
IPCCC2
2004 Message from the Program Co-Chairs
abstract
Presents the welcome message from the conference proceedings.
Hossam S. Hassanein, Golden G. Richard III
IPCCC2
2003 Distributed multicast tree generation with dynamic group membership
Frank Adelstein, Golden G. Richard III, Loren Schwiebert
Comput. Commun.2
2002 A User Level Framework for Ad Hoc Routing
abstract
The availability of inexpensive wireless networking hardware (e.g., based on the IEEE 802.11 standards) has generated interest in a large class of wireless applications. Many applications benefit from rapidly deployable networks for example, collaborative applications to support field research or emergency incident response. The need for networks that can be rapidly deployed has resulted in a substantial body of research in ad hoc routing protocols. Such protocols use intermediate nodes as routers and support highly dynamic network configurations. We have developed a portable, user-level framework for ad hoc routing in C++. In our current implementation of this framework a tailored SOCKS proxy handles client requests and uses an implementation of an ad hoc routing protocol to provide routing. So far, implementations of DSR and flooding are provided, but other routing protocol implementations can easily be incorporated. An integrated simulator allows new routing protocols to be tested, and the code can be moved to a production ad hoc deployment with no modification. Our framework is suitable for a number of purposes, from ad hoc routing protocol research, where new protocols can be rapidly developed and tested, to the deployment of real ad hoc networks. The system is easily installed on a wide variety of operating systems and requires no kernel hacking.
Jérémie Allard, Paul Gonin, Minoo Singh, Golden G. Richard III
LCN4
2002 Reliable Group Communication in an Ad Hoc Network
abstract
In this paper an enhancement to the reliability of the ODMRP multicast ad hoc protocol is described. The enhancement attempts to increase the overall data packet delivery ratio by adding packet storage and retransmit operations coordinated by the multicast source.
Lawrence Klos, Golden G. Richard III
LCN2
2001 Adaptive Header Compression for Wireless Networks
abstract
TCP/IP header compression has long been used to send information efficiently and to improve the response time of communication systems. It is also well known that errors on the link where header compression is used can deteriorate the performance. In addition, the previously noticed high frequency of some computer networking problems can make the performance of header compression even worse. These problems include packet reordering and packet errors that avoid link layer error detection. We analyze the influence of these problems on existing header compression algorithms. We also propose an adaptive header compression that gives better performance.
Changli Jiao, Loren Schwiebert, Golden G. Richard III
LCN3
2000 Julep: an environment for the evaluation of distributed process recovery protocols
abstract
Julep is an object-oriented testbed designed for implementation and analysis of process recovery protocols. It is written in Java, and runs as a layer underneath a Java-based distributed application. Only minor modifications to a typical distributed application are necessary to use Julep as a communication mechanism. Julep is designed to allow new process recovery mechanisms to be quickly incorporated, permitting accurate comparison between mechanisms for specific distributed applications on specific hardware platforms. A novel aspect of Julep is its UDP-based object communication service, which implements "unbreakable" communication channels. Julep can be used as a testbed to compare the performance of particular recovery mechanisms, as a framework within which new recovery mechanisms can be implemented and tested, or as an infrastructure to make existing distributed applications fault tolerant. In its most basic form, Julep can be used as a reliable object-based communication service.
Lawrence Klos, Golden G. Richard III
PRDC2
2000 An architecture for wireless LAN/WAN integration
abstract
To allow a seamless integration between wireless LANs and wireless WANs, we developed a full stack adaptation model and a simple subnet architecture that superimposes Mobile-IP on cellular-type wireless LANs. The idea is to use Mobile IP as an integrative layer atop different LAN/WAN networks. While Mobile-IP is widely used in wireless WANs, it is not known how well it performs under a wireless LAN environment, against native MAC-level handoff. Through experimentation using the 802.11 W-LAN, we found that under practical values of handoff frequencies, the performance of Mobile IP based W-LAN handoff is almost identical to the performance of W-LAN handoff. Further performance studies show the suitability of Mobile-IP as an integrative layer in this architecture.
Abdelsalam Helal, Choonhwa Lee, Yongguang Zhang, Golden G. Richard III
WCNC4
1998 Bessie: Portable Generation of Network Topologies for Simulation
abstract
The widespread use of computer networking has resulted in considerable attention being paid to a variety of network-related problems, the generation of efficient multicast trees being one. While many algorithms for generation of multicast trees have been proposed their relative effectiveness is difficult to assess. Some algorithms have never been implemented. Many have been simulated, but often using ad-hoc networking modeling and simulation tools, without consistent parameters, making direct comparisons difficult. In this paper we discuss a network topology generation tool named Bessie, written entirely in Java. Bessie generates descriptions of random point-to-point and hierarchical networks, based on user-specified statistical parameters. We introduce a modification to Waxman's (1988) parameters, commonly used in grid-based network topology generators, which eliminates undesirable increases in node degree as the number of nodes in a network increases. The modification improves on proposed fixed scale factors.
Frank Adelstein, Frederick A. Hosch, Golden G. Richard III, Loren Schwiebert
ICCCN3
1998 On Patterns for Practical Fault Tolerant Software in Java
abstract
Fault tolerance is important for both sequential and distributed software, and particularly so for long-running applications. The ability to stop an application and restart it, with minimal lost work, is especially useful. If components of the application can be restarted on arbitrary hosts, so much the better. In this paper, we explore Java's potential to support fault tolerant software design. We note that while there are "deficiencies" in these facilities, a little creativity can still yield solutions that would be quite difficult in other programming environments. The main contributions of the paper are several preliminary fault tolerant programming design patterns, aimed at easing the burden of application programmers who must write completely portable fault tolerant applications. This class of applications is growing, as Internet-domain software becomes increasingly prevalent. We expect that with further development the proposed patterns will be applicable to a wide range of sequential and parallel applications.
Golden G. Richard III, Shengru Tu
SRDS1
1998 Efficient Vector Time with Dynamic Process Creation and Termination
Golden G. Richard III
J. Parallel Distributed Comput.1
1994 A Distributed Graphics Library System
abstract
Abstract We present a set of library routines that allow easily parallelized graphics rendering routines that require no communication between each parallel task, such as ray‐tracing, to be run efficiently in an environment of distributed workstations. The presentation of the paper focuses on the problems encountered in implementing a distributed system under Unix and proposes solutions to each problem. Specifically, we discuss the challenges involved in overcoming the limits of communicating with a large number of processes in Unix and in providing fault tolerance when using sockets. Technical aspects of the implementation and some additional problems that were encountered are discussed. Finally, we compare the rendering times for a complex image with a renderer using the library and show that the library routines are able to exploit much of the existing parallelism. The library is presented using a graphics application, though the concepts are generic enough to be of use in designing any distributed system under Unix.
Frank Adelstein, Golden G. Richard III, Loren Schwiebert, Rick Parent, Mukesh Singhal
Softw. Pract. Exp.2
1993 Using Logging and Asynchronous Checkpointing to Implement Recoverable Distributed Shared Memory
abstract
Distributed shared memory provides a useful paradigm for developing distributed applications. As the number of processors in the system and running time of distributed applications increase, the likelihood of processor failure increases. A method of recovering processes running in a distributed shared memory environment which minimizes lost work and the cost of recovery is desirable so that long-running applications are not adversely affected by processor failure. A technique for achieving recoverable distributed shared memory which utilizes asynchronous process checkpoints and logging of pages accessed via read operations on the shared address space is presented. The scheme supports independent process recovery without forcing rollback of operational processes during recovery. The method is particularly useful in environments where taking process checkpoints is expensive.>
Golden G. Richard III, Mukesh Singhal
SRDS1