Bennet Yee

dblp:87/7397 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
0since 2021 · last 2011
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
4 papers
Systems and software security · 83% Web and mobile security · 17%
Software engineering, system software, and programming languages
3 papers
Runtime systems and virtual machines · 65% Operating systems · 12% Concurrent programming · 12%

Topics — the 8 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › operating system security
sandboxing
0.222011
Language-independent sandboxing of just-in-time compilation and self-modifying code · PLDI 2011
Native Client: A Sandbox for Portable, Untrusted x86 Native Code · SP 2009
Systems and software security › isolation
software fault isolation
0.222010
Adapting Software Fault Isolation to Contemporary CPU Architectures · USENIX Security Symposium 2010
Native Client: A Sandbox for Portable, Untrusted x86 Native Code · SP 2009
Runtime systems and virtual machines › dynamic compilation
just-in-time compilation
0.112011
Language-independent sandboxing of just-in-time compilation and self-modifying code · PLDI 2011
Web and mobile security
browser security
0.112009
Native Client: A Sandbox for Portable, Untrusted x86 Native Code · SP 2009
Runtime systems and virtual machines
binary translation
0.112009
Native Client: A Sandbox for Portable, Untrusted x86 Native Code · SP 2009
Concurrent programming › concurrency bug detection
data race detection
0.012003
Dynamic Detection and Prevention of Race Conditions in File Accesses · USENIX Security Symposium 2003
Operating systems › resource management › storage management
file systems
0.012003
Dynamic Detection and Prevention of Race Conditions in File Accesses · USENIX Security Symposium 2003
Programming languages and type systems
language-based security
0.012011
Language-independent sandboxing of just-in-time compilation and self-modifying code · PLDI 2011

Methods — techniques the papers use, named apart from their topics

sandboxing · 0.4code generation · 0.2software fault isolation · 0.2secure runtime · 0.2dynamic detection · 0.1
YearPublicationVenuePosition
2011 Language-independent sandboxing of just-in-time compilation and self-modifying code
abstract
When dealing with dynamic, untrusted content, such as on the Web, software behavior must be sandboxed, typically through use of a language like JavaScript. However, even for such specially-designed languages, it is difficult to ensure the safety of highly-optimized, dynamic language runtimes which, for efficiency, rely on advanced techniques such as Just-In-Time (JIT) compilation, large libraries of native-code support routines, and intricate mechanisms for multi-threading and garbage collection. Each new runtime provides a new potential attack surface and this security risk raises a barrier to the adoption of new languages for creating untrusted content.
Jason Ansel, Petr Marchenko, Úlfar Erlingsson, Elijah Taylor, Brad Chen, Derek L. Schuff, David Sehr, Cliff Biffle, Bennet Yee
PLDI9
2010 Adapting Software Fault Isolation to Contemporary CPU Architectures
David Sehr, Robert Muth, Cliff Biffle, Victor Khimenko, Egor Pasko, Karl Schimpf, Bennet Yee, Brad Chen
USENIX Security Symposium7
2009 Native Client: A Sandbox for Portable, Untrusted x86 Native Code
abstract
This paper describes the design, implementation and evaluation of Native Client, a sandbox for untrusted x86 native code. Native Client aims to give browser-based applications the computational performance of native applications without compromising safety. Native Client uses software fault isolation and a secure runtime to direct system interaction and side effects through interfaces managed by Native Client. Native Client provides operating system portability for binary code while supporting performance-oriented features generally absent from Web application programming environments, such as thread support, instruction set extensions such as SSE, and use of compiler intrinsics and hand-coded assembler. We combine these properties in an open architecture that encourages community review and 3rd-party tools.
Bennet Yee, David Sehr, Gregory Dardyk, J. Bradley Chen, Robert Muth, Tavis Ormandy, Shiki Okasaka, Neha Narula, Nicholas Fullagar
SP1
2003 Dynamic Detection and Prevention of Race Conditions in File Accesses
Eugene Tsyrklevich, Bennet Yee
USENIX Security Symposium2