VLDB 2026 Research / reviewers in the wild / expert
Kostyantyn Vorobyov
dblp:84/11465
· DBLP profile ↗
11ranked-venue papers
7as first author
3since 2021 · last 2023
0000-0003-2443-4949ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 9 · 7 first-author · 3 since 2021Security and privacy · 2Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Crystallizer: A Hybrid Path Analysis Framework to Aid in Uncovering Deserialization VulnerabilitiesabstractApplications use serialization and deserialization to exchange data. Serialization allows developers to exchange messages or perform remote method invocation in distributed applications. However, the application logic itself is responsible for security. Adversaries may abuse bugs in the deserialization logic to forcibly invoke attacker-controlled methods by crafting malicious bytestreams (payloads). Crystallizer presents a novel hybrid framework to automatically uncover deserialization vulnerabilities by combining static and dynamic analyses. Our intuition is to first over-approximate possible payloads through static analysis (to constrain the search space). Then, we use dynamic analysis to instantiate concrete payloads as a proof-of-concept of a vulnerability (giving the analyst concrete examples of possible attacks). Our proof-of-concept focuses on Java deserialization as the imminent domain of such attacks. We evaluate our prototype on seven popular Java libraries against state-of-the-art frameworks for uncovering gadget chains. In contrast to existing tools, we uncovered 41 previously unknown exploitable chains. Furthermore, we show the real-world security impact of Crystallizer by using it to synthesize gadget chains to mount RCE and DoS attacks on three popular Java applications. We have responsibly disclosed all newly discovered vulnerabilities. Prashast Srivastava, Flavio Toffalini, Kostyantyn Vorobyov, François Gauthier 0001, Antonio Bianchi, Mathias Payer |
ESEC/SIGSOFT FSE | 3 |
| 2022 | Synthesis of Java Deserialisation Filters from ExamplesabstractJava natively supports serialisation and deserialisation, features that are necessary to enable distributed systems to exchange Java objects. Deserialisation of data from malicious sources can lead to security exploits including remote code execution because by default Java does not validate deserialised data. In the absence of validation, a carefully crafted payload can trigger arbitrary functionality. The state-of-the-art general mitigation strategy for deserialisation exploits in Java is deserialisation filtering that validates the contents of an object input stream before the object is deserialised using user-provided filters. In this paper we describe a novel technique called ds-prefix for automatic synthesis of deserialisation filters (as regular expressions) from examples. We focus on synthesis of allowlists (permitted behaviours) as they provide a better level of security. ds-prefix is based on deserialisation heuristics and specifically targets synthesis of deserialisation allowlists. We evaluate our approach by executing ds-prefix on popular open-source systems and show that ds-prefix can produce filters preventing real CVEs using a small number of training examples. We also compare our approach with other synthesis tools which demonstrates that ds-prefix outperforms existing tools and achieves better F1-score. Kostyantyn Vorobyov, François Gauthier 0001, Sora Bae, Padmanabhan Krishnan, Rebecca O'Donoghue |
COMPSAC | 1 |
| 2021 | MoScan: a model-based vulnerability scanner for web single sign-on servicesabstractVarious third-party single sign-on (SSO) services (e.g., Facebook Login and Twitter Login) are widely deployed by web applications to facilitate their authentication and authorization processes. Nevertheless, integrating these services in a secure manner remains challenging, such that security issues are continually reported in recent years. In this work, we develop MoScan, a model-based scanner that can be used by software testers and security analysts for detecting and reporting security vulnerabilities in SSO implementations. MoScan takes as input a state machine built based on an SSO standard and our empirical study to represent participants' states and transitions during the login process. In the testing process, it analyzes network traces captured during the execution of SSO services, and increments the state machine which is then used to generate payloads to test the protocol participants. We evaluate MoScan with 23 real-world websites which integrate the Facebook SSO service to test its capability of identifying security vulnerabilities. To show the adaptability of MoScan's state machine, we also test it on Twitter and LinkedIn’s SSO services, and Github's authentication plugin in Jenkins. It detects three known weaknesses and one new logic fault from them, showing a new perspective in testing stateful protocol implementations like SSO services. Our demonstration and the source code of MoScan are available at https://github.com/baigd/moscan. Hanlin Wei, Behnaz Hassanshahi, Guangdong Bai, Padmanabhan Krishnan, Kostyantyn Vorobyov |
ISSTA | 5 |
| 2017 | Shadow state encoding for efficient monitoring of block-level propertiesabstractMemory shadowing associates addresses from an application's memory to values stored in a disjoint memory space called shadow memory. At runtime shadow values store metadata about application memory locations they are mapped to. Shadow state encodings -- the structure of shadow values and their interpretation -- vary across different tools. Encodings used by the state-of-the-art monitoring tools have been proven useful for tracking memory at a byte-level, but cannot address properties related to memory block boundaries. Tracking block boundaries is however crucial for spatial memory safety analysis, where a spatial violation such as out-of-bounds access, may dereference an allocated location belonging to an adjacent block or a different struct member. Kostyantyn Vorobyov, Julien Signoles, Nikolai Kosmatov |
ISMM | 1 |
| 2017 | Runtime Detection of Temporal Memory Errors
Kostyantyn Vorobyov, Nikolai Kosmatov, Julien Signoles, Arvid Jakobsson |
RV | 1 |
| 2016 | A low-overhead, value-tracking approach to information flow security
Kostyantyn Vorobyov, Padmanabhan Krishnan, Phil Stocks |
Inf. Softw. Technol. | 1 |
| 2015 | Enforcement of privacy requirements
Padmanabhan Krishnan, Kostyantyn Vorobyov |
Comput. Secur. | 2 |
| 2013 | A Dynamic Approach to Locating Memory Leaks
Kostyantyn Vorobyov, Padmanabhan Krishnan, Phil Stocks |
ICTSS | 1 |
| 2013 | Enforcement of Privacy Requirements
Padmanabhan Krishnan, Kostyantyn Vorobyov |
SEC | 2 |
| 2012 | Combining Static Analysis and Constraint Solving for Automatic Test Case GenerationabstractWe present an approach in automatic test generation that combines features of static analysis and bounded symbolic computation that is capable of producing a test suite that can be used to declare a program under test safe within bounds. We first use the results produced by static analysis which will identify a list of potential errors in the program. We restrict our search to the locations where errors can exist and aim to find exactly one test case per real bug. We have built a prototype tool (called Batg) that implements our approach. We report the results of running it on a number of benchmarks from well known benchmarking suites. We compare Batgto KLEE (an automatic test generation framework) and CBMC(a bounded model checker). This comparison is based on the time taken by the tools, the number of bugs found and the number of generated test cases. We analyse the results of our experiment, demonstrating the benefits of our approach. Kostyantyn Vorobyov, Padmanabhan Krishnan |
ICST | 1 |
| 2012 | A Low-Overhead, Value-Tracking Approach to Information Flow Security
Kostyantyn Vorobyov, Padmanabhan Krishnan, Phil Stocks |
SEFM | 1 |