VLDB 2026 Research / reviewers in the wild / expert
Pedro Bernardo
dblp:76/8574
· DBLP profile ↗
2ranked-venue papers
1as first author
2since 2021 · last 2024
0009-0002-6193-0730ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
2 papers |
Program verification · 74% Software testing · 26% | |
| Network and information security
2 papers |
Web and mobile security · 100% | |
| Theoretical computer science
1 paper |
Automated reasoning and model checking · 100% |
Topics — the 2 heaviest of 4, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Software testing
automated testing |
0.2 | 1 | 2024 | Web Platform Threats: Automated Detection of Web Security Issues With WPT · USENIX Security Symposium 2024 |
Automated reasoning and model checking › model checking › symbolic model checking
SMT-based model checking |
0.2 | 1 | 2023 | WebSpec: Towards Machine-Checked Analysis of Browser Security Mechanisms · SP 2023 |
Methods — techniques the papers use, named apart from their topics
z3 · 2.0coq · 2.0web platform tests · 1.5automated detection · 1.5SMT-lib · 1.3SMT-LIB · 0.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Web Platform Threats: Automated Detection of Web Security Issues With WPT
Pedro Bernardo, Lorenzo Veronese, Valentino Dalla Valle, Stefano Calzavara, Marco Squarcina, Pedro Adão, Matteo Maffei |
USENIX Security Symposium | 1 |
| 2023 | WebSpec: Towards Machine-Checked Analysis of Browser Security MechanismsabstractThe complexity of browsers has steadily increased over the years, driven by the continuous introduction and update of Web platform components, such as novel Web APIs and security mechanisms. Their specifications are manually reviewed by experts to identify potential security issues. However, this process has proved to be error-prone due to the extensiveness of modern browser specifications and the interplay between new and existing Web platform components. To tackle this problem, we developed WebSpec, the first formal security framework for the analysis of browser security mechanisms, which enables both the automatic discovery of logical flaws and the development of machine-checked security proofs. WebSpec, in particular, includes a comprehensive semantic model of the browser in the Coq proof assistant, a formalization in this model of ten Web security invariants, and a toolchain turning the Coq model and the Web invariants into SMT-lib formulas to enable model checking with the Z3 theorem prover. If a violation is found, the toolchain automatically generates executable tests corresponding to the discovered attack trace, which is validated across major browsers.We showcase the effectiveness of WebSpec by discovering two new logical flaws caused by the interaction of different browser mechanisms and by identifying three previously discovered logical flaws in the current Web platform, as well as five in old versions. Finally, we show how WebSpec can aid the verification of our proposed changes to amend the reported inconsistencies affecting the current Web platform. Lorenzo Veronese, Benjamin Farinier, Pedro Bernardo, Mauro Tempesta, Marco Squarcina, Matteo Maffei |
SP | 3 |