David O. Manz

dblp:71/11352 · DBLP profile ↗
← Back
6ranked-venue papers
1as first author
1since 2021 · last 2023
0000-0001-6983-6023ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 1 since 2021Computer networks · 1Software engineering, systems software and programming languages · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Program analysis · 100%
Network and information security
1 paper
Systems and software security · 77% Network security · 23%

Topics — the 4 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Program analysis
data dependence analysis
0.412020
PCA: memory leak detection using partial call-path analysis · ESEC/SIGSOFT FSE 2020
Program analysis › error detection
memory leak detection
0.412020
PCA: memory leak detection using partial call-path analysis · ESEC/SIGSOFT FSE 2020
Program analysis
static analysis
0.412020
PCA: memory leak detection using partial call-path analysis · ESEC/SIGSOFT FSE 2020
Network security › moving target defense
cyber defense
0.112016
SafeConfig'16: Testing and Evaluation for Active and Resilient Cyber Systems · CCS 2016

Methods — techniques the papers use, named apart from their topics

points-to analysis · 0.4partial call-path analysis · 0.4data flow analysis · 0.4scientific method · 0.2reproducibility · 0.2
YearPublicationVenuePosition
2023 Assessing Risk in High Performance Computing Attacks
Erika A. Leal, Cimone Wright-Hamor, Joseph B. Manzano, Nicholas J. Multari, Kevin J. Barker, David O. Manz, Jiang Ming 0002
ICISSP6
2020 PCA: memory leak detection using partial call-path analysis
abstract
Data dependence analysis underlies various applications in software quality assurance, yet existing frameworks/tools for this analysis commonly suffer scalability challenges. We present PCA, a static interprocedural data dependence analyzer for real-world C programs. PCA performs interprocedural points-to and data-flow analyses with a lightweight design. Most of all, it features a partial call-path (PCA) analysis that consists of optimization options to further speed up data dependence computation. As an example application of it, PCA readily supports memory leak detection, for which it helps achieve close or better performance and precision relative to the same application based on a state-of-the-art value flow analysis. In particular, it found four more memory leaks in an industry-scale system which have been fixed by the developers. Through the data dependence it computes, PCA can enable other applications (e.g., impact analysis and taint analysis).
Wen Li 0007, Haipeng Cai, Yulei Sui, David O. Manz
ESEC/SIGSOFT FSE4
2016 SafeConfig'16: Testing and Evaluation for Active and Resilient Cyber Systems
abstract
The premise of this year's SafeConfig Workshop is existing tools and methods for security assessments are necessary but insufficient for scientifically rigorous testing and evaluation of resilient and active cyber systems. The objective for this workshop is the exploration and discussion of scientifically sound testing regimen(s) that will continuously and dynamically probe, attack, and "test" the various resilient and active technologies. This adaptation and change in focus necessitates at the very least modification, and potentially, wholesale new developments to ensure that resilient- and agile-aware security testing is available to the research community. All testing, validation and experimentation must also be repeatable, reproducible, subject to scientific scrutiny, measurable and meaningful to both researchers and practitioners.
Nicholas J. Multari, Anoop Singhal, David O. Manz
CCS3
2014 Enabling Collaborative Research for Security and Resiliency of Energy Cyber Physical Systems
abstract
The University of Illinois at Urbana Champaign (Illinois), Pacific Northwest National Labs (PNNL), and the University of Southern California Information Sciences Institute (USC-ISI) consortium is working toward providing tools and expertise to enable collaborative research to improve security and resiliency of cyber physical systems. In this extended abstract we discuss the challenges and the solution space. We demonstrate the feasibility of some of the proposed components through a wide-area situational awareness experiment for the power grid across the three sites.
Alefiya Hussain, Ted Faber, Bob Braden, Terry V. Benzel, Timothy M. Yardley, Jeremy Jones, David M. Nicol, William H. Sanders, Thomas W. Edgar, Thomas E. Carroll, David O. Manz, Laura Tinnel
DCOSS11
2010 A hybrid Authentication and authorization process for control system networks
abstract
This paper presents a new authentication protocol for control systems that draws from Extensible Authentication Protocol and Kerberos. Traditional authentication schemes do not meet control system requirements of very high availability, failsafe operation, noninterruption of devices and networks, and resilience to loss of connectivity. Our hybrid protocol meets the requirements and provides device-to-device authentication both within a remote station and between remote stations and control centers.
David O. Manz, Thomas W. Edgar, Glenn A. Fink
IAS1
2007 A communication-computation efficient group key algorithm for large and dynamic groups
Shanyu Zheng, David O. Manz, Jim Alves-Foss
Comput. Networks2