John Aycock

dblp:a/JohnAycock · DBLP profile ↗
← Back
34ranked-venue papers
21as first author
7since 2021 · last 2026
0000-0003-0352-489XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 19 · 13 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 4 first-author · 5 since 2021Software engineering, systems software and programming languages · 6 · 5 first-authorSecurity and privacy · 4Computer networks · 2Theory of computation · 2 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 LAVA: Large-scale Archaeological Videogame Analysis
abstract
Early videogames are foundational to the modern game industry, yet studying them is not straightforward. These games’ development is distant in time, their source code and knowledge of their creation frequently lost, and sometimes only fragmentary evidence remains – the precise conditions that archaeologists are used to working with.
John Aycock, Katie Biittner, Minori Olguin, Hira Asad
FDG1
2026 No Prototypical Prototypes: Prototypes as the Stone Tools of Game Development
abstract
Not all game prototypes are created equal. Over forty years ago at the start of the game industry, people were creating prototypes whose purpose was not a direct evolutionary step towards a finished game. Based on oral history and access to a set of unique physical and digital artifacts, we document some non-prototypical ways that prototypes were used at that time. Moreover, we examine this human-technology interaction in terms of the archaeological study of another human technology – stone tools – to refine our understanding of what a game prototype is.
Katie Biittner, Paul Allen Newell, John Aycock
FDG3
2025 AI vs. AI: Comparing Artificial Intelligence with Actual Intelligence for a Gameplay Task
abstract
Is AI always the best choice for every task? We conducted two user studies, one large-scale and one small-scale, to attempt a testing-related gameplay task, where the goal was to maximize the code and data coverage of a set of Atari 2600 games. This particular problem was previously addressed using an AI-based system published by Ganesh et al. in the 2023 IEEE Conference on Games. Our new, human-derived results not only replicate the coverage shown in the previous AI-based study, but more importantly, by using humans for gameplay we were able to get those results with much less time, effort, and resources.
John Aycock, Katie Biittner, Syeda Zainab Khaleel, Carl Therrien, Allie Querengesser, Hailey Sikstrom
CoG1
2023 FrAG: A Framework for the Analysis of Games
abstract
FrAG is a Framework for the Analysis of Games, allowing us to harness game-playing AI techniques to assist in the reverse engineering of historical video games for which the binary form of the game is the only thing remaining. Moreover, FrAG allows us to perform this task at scale, and search for patterns of game development that might otherwise be overlooked. Game development is done by humans, of course; our interdisciplinary approach is not exclusively technical, and also involves the field of archaeology and its well-established theories of humans and technology. Here we present FrAG’s architecture along with our preliminary results using the framework on a test suite of Atari 2600 games.
Shankar Ganesh, John Aycock, Katie Biittner
CoG2
2023 Binary Reverse Engineering for All
abstract
We report our experience with a novel course on binary reverse engineering, a university computer science course that was offered at the second-year level to both computer science majors as well as non-majors, with minimal prerequisites. While reverse engineering has known, important uses in computer security, this was pointedly not framed as a security course, because reverse engineering is a skill that has uses outside computer science and can be taught to a more diverse audience. The original course design intended students to perform hands-on exercises during an in-person class; we describe the systems we developed to support that, along with other online systems we used, which allowed a relatively easy pivot to online learning and back as necessitated by the pandemic. Importantly, we detail our application of "ungrading" within the course, an assessment philosophy that has gained some traction primarily in non-STEM disciplines but has seen little to no discussion in the context of computer science education. The combination of pedagogical methods we present has potential uses in other courses beyond reverse engineering.
John Aycock
ITiCSE (1)1
2022 The Sincerest Form of Flattery: Large-Scale Analysis of Code Re-Use in Atari 2600 Games
abstract
The Atari 2600 was a prominent early video game console that had broad cultural impact, and possessed an extensive catalog of games that undoubtedly helped shape the fledgling game industry. How were these games created? We examine one development practice, code re-use, across a large-scale corpus of 1,984 ROM images using an analysis system we have developed. Our system allows us to study code re-use at whole-corpus granularity in addition to finer-grained views of individual developers and companies. We combine this corpus analysis with a case study: one of the co-authors was a third-party developer for Atari 2600 games in the early 1980s, providing insight into why code re-use could occur through both oral history and artifacts preserved for over forty years. Finally, we frame our results about this development practice with an interdisciplinary, bigger-picture archaeological view of humans and technology.
John Aycock, Shankar Ganesh, Katie Biittner, Paul Allen Newell, Carl Therrien
FDG1
2021 Teaching Social Engineering Using Improv
abstract
Teaching social engineering in a computer security class is tractable in a lecture-based format, but presents challenges for a hands-on, active learning course, especially for instructors who aren't specialists in that area. I present a method for teaching social engineering in an ethical, approachable fashion that draws on improvisational theater.
John Aycock
ITiCSE (2)1
2020 LeGACy Code: Studying How (Amateur) Game Developers Used Graphic Adventure Creator
abstract
How did game programmers use early game development tools, and how does this fit into the bigger picture of how humans use tools and technology? To help answer these questions, we embark on an interdisciplinary collaboration between archaeology and computer science.
John Aycock, Katie Biittner
FDG1
2020 10 Binary Games for Computer Science Education
abstract
In the race to teach programming to large, diverse audiences, low-level topics have received short shrift. We address this gap by presenting two ("10") games we have designed - one a card game, the other an online game - to help students learn both binary manipulation and operations. These two games stand out from existing computer science 'edutainment' through their novel presentation and unique take on topics that are relatively unexplored in games.
Hannah Wright, John Aycock
SIGCSE2
2019 S4LVE: shareable videogame analysis and visualization
abstract
We describe a new browser-based tool for analyzing the behavior of computational systems, with worked examples for the Atari 2600. Our tool, S4LVE (System State Sequence Search Language and Visualization Environment), consists of three main parts. First, we define a domain-specific visualization language tailored for understanding low-level memory operations. Second, we leverage a discrete time-series pattern matching language inspired by regular expressions to capture states and memory locations of interest. Third, we integrate these little languages with an intuitive, spreadsheet-based visual interface juxtaposed with a live emulator. This combined system supports both the incremental exploration of complex emergent systems and rapid iteration on new visualizations.
Eric Kaltman, Joseph C. Osborn, John Aycock
FDG3
2018 Stick to the script: lightweight recording and playback of live coding
abstract
"Live coding" describes the creation of programs by the instructor during lecture, in front of a live student audience. But how can the performance be captured for later use by students? We present a simple and lightweight, yet remarkably effective system for recording and playback of live coding. It has been used since 2016 in two instances of CS1 and one other introductory programming course, and most importantly has been received well by students.
John Aycock
ITiCSE1
2018 Exercises for teaching reverse engineering
abstract
The ability to reverse engineer binary code is a skill of critical importance within computer security: deciding if an unknown piece of binary code is malicious and, if so, what it does. And yet, there is very little work in computer science education that considers how reverse engineering can be effectively taught. This is a timely area to examine, given that the demand for skilled security professionals continues to rise, while emphasis on low-level topics diminishes. How can we teach students the skills and thought processes underlying reverse engineering?
John Aycock, Andrew Groeneveldt, Hayden Kroepfl, Tara Copplestone
ITiCSE1
2015 Applied Computer History: Experience Teaching Systems Topics through Retrogames
abstract
Computing history need not be dry, useless, or boring. We describe a computer science course we taught, Retrogames, that used old computer games' implementation throughout to explain techniques and systems topics that modern students are not typically exposed to in any depth, ideas that are still applicable in both game and non-game settings. As a side effect, students also learned about how development was done and problems were solved in highly-constrained environments, which gave them useful tools to add to their toolbox.
John Aycock
ITiCSE1
2015 A Game Engine in Pure Python for CS1: Design, Experience, and Limits
abstract
Games are being increasingly used to create compelling assignments for students learning programming, and Python is often used as an initial programming language. To that end, we present a game engine written in pure Python. Not only does the engine integrate seamlessly with what students already know about Python, but the game engine code itself is not a "black box" -- it is readable and approachable for beginning students. We report on two years' worth of experience using our game engine in CS1 for both regular assignments as well as "master classes," the engine's design, and its limits.
John Aycock, Etienne Pitout, Sarah Storteboom
ITiCSE1
2015 Stringlish: improved English string searching in binary files
abstract
Summary When analyzing binary files, printable strings are easy to find, but a naïve approach yields a large number of false positives: ‘uninteresting’ string‐like sequences that occur by chance in the binary. We present a lightweight yet surprisingly effective method of filtering printable strings for English or English‐like sequences. Copyright © 2015 John Wiley & Sons Ltd.
John Aycock
Softw. Pract. Exp.1
2012 ThinAV: truly lightweight mobile cloud-based anti-malware
abstract
This paper introduces ThinAV, an anti-malware system for Android that uses pre-existing web-based file scanning services for malware detection. The goal in developing ThinAV was to assess the feasibility of providing real-time anti-malware scanning over a wide area network where resource limitation is a factor. As a result, our research provides a necessary counterpoint to many of the big-budget, resource-intensive idealized solutions that have been suggested in the area of cloud-based security. The evaluation of ThinAV shows that it functions well over a wide area network, resulting in a system which is highly practical for providing anti-malware security on smartphones.
Chris Jarabek, David Barrera 0003, John Aycock
ACSAC3
2012 μPython: non-majors programming from the very first lecture
abstract
We wanted to give first-year non-major students experience programming very early, right from the first lecture. To support this endeavor, we built a web-based subset of Python, called ¼Python. It allowed immediate use by students, overcame a number of practical constraints, and gave a gradual introduction and transition into the full version of Python.
John Aycock
ITiCSE1
2011 Does domain highlighting help people identify phishing sites?
abstract
Phishers are fraudsters that mimic legitimate websites to steal user's credenfitial information and exploit that information for identity theft and other criminal activities. Various anti-phishing techniques attempt to mitigate such attacks. Domain highlighting is one such approach recently incorporated by several popular web browsers. The idea is simple: the domain name of an address is highlighted in the address bar, so that users can inspect it to determine a web site's legitimacy. Our research asks a basic question: how well does domain highlighting work? To answer this, we showed 22 participants 16 web pages typical of those targeted for phishing attacks, where participants had to determine the page's legitimacy. In the first round, they judged the page's legitimacy by whatever means they chose. In the second round, they were directed specifically to look at the address bar. We found that participants fell into 3 types in terms of how they determined the legitimacy of a web page; while domain highlighting was somewhat effective for one user type, it was much less effective for others. We conclude that domain highlighting, while providing some benefit, cannot be relied upon as the sole method to prevent phishing attacks.
Eric Lin, Saul Greenberg, Eileah Trotter, David Ma, John Aycock
CHI5
2010 Enbug: when debuggers go bad
abstract
We have developed a tool, enbug, that intentionally induces errors into software in a controlled fashion. The robustness of students' code can be challenged by presenting exotic failure scenarios for testing, without Herculean efforts on the part of teaching assistants or instructors. Enbug also has applications in computer security and secure software courses, by being able to inject specific flaws into existing software for students to locate and exploit. The implementation of enbug is an example of tool reuse, through the automated (ab)use of a debugger.
David Williams-King, John Aycock, Daniel Medeiros Nunes de Castro
ITiCSE2
2010 SPoIM: A close look at pollution attacks in P2P live streaming
abstract
Peer-to-Peer (P2P) live streaming traffic has been growing at a phenomenal rate over the past few years. When the original streaming content is mixed with bogus data, the corresponding P2P streaming network is being subjected to a “pollution attack.” As the content is shared by peers, the bogus data can be spread widely in minutes. In this paper, we study the impact of a pollution attack in popular streaming models, under various network settings and configurations. The study was conducted in SPoIM, our emulation of real-world P2P streaming systems under pollution attacks, through which we observed that the feasibility of the attack is sensitive to the speed at which an attacker can modify content. Our experimental results showed that different streaming approaches are more vulnerable in one network configuration than the others, and that the impact and effectiveness of the attack is not dependent on the network size, but does highly depend on the network stability and the bandwidth availability of the polluters and the source. Based the experimental results, we suggested possible improvements in streaming models to defend themselves against the pollution attack. Finally, we examined possible defense mechanisms and demonstrated the effectiveness of a reputation-based defense mechanism against a typical pollution attack.
Eric Lin, Daniel Medeiros Nunes de Castro, Mea Wang, John Aycock
IWQoS4
2009 Early action in an Earley parser
John Aycock, Angelo Borsotti
Acta Informatica1
2008 Spamulator: the Internet on a laptop
abstract
We have developed an Internet simulator - the "Spamulator" - for a course on spam and spyware, a simulator that allows us to simulate the network services provided by a million domains. The Spamulator is lightweight in its resource usage, running on a single computer, and we currently have implementations for two different platforms.
John Aycock, Heather Crawford, Rennie deGraaf
ITiCSE1
2008 Kwyjibo: automatic domain name generation
abstract
Abstract Automatically generating ‘good’ domain names that are random yet pronounceable is a problem harder than it first appears. The problem is related to random word generation, and we survey and categorize existing techniques before presenting our own syllable‐based algorithm that produces higher‐quality results. Our results are also applicable elsewhere, in areas such as password generation, username generation, and even computer‐generated poetry. Copyright © 2008 John Wiley & Sons, Ltd.
Heather Crawford, John Aycock
Softw. Pract. Exp.2
2007 Inverse Geolocation: Worms with a Sense of Direction
abstract
Mapping Internet addresses into physical locations is accomplished through geolocation and reverse geolocation, two different but related problems. We introduce a third problem, inverse geolocation, which can be used by worms to locate potential targets. Techniques for inverse geolocation are presented, along with a discussion of defenses... assuming inverse geolocation can be prevented at all.
Randal Acton, Nathan Friess, John Aycock
IPCCC3
2007 Army of Botnets
Ryan Vogt, John Aycock, Michael J. Jacobson Jr.
NDSS2
2005 Improved Port Knocking with Strong Authentication
abstract
It is sometimes desirable to allow access to open ports on a firewall only to authorized external users and present closed ports to all others. We examine ways to construct an authentication service to achieve this goal, and then examine one such method, "port knocking", and its existing implementations, in detail. We improve upon these existing implementations by presenting a novel port knocking architecture that provides strong authentication while addressing the weaknesses of existing port knocking systems.
Rennie deGraaf, John Aycock, Michael J. Jacobson Jr.
ACSAC2
2005 Viruses 101
abstract
The University of Calgary introduced a controversial course in the fall of 2003 on computer viruses and malware. The primary objection about this course from the anti-virus community was that students were being taught how to create viruses in addition to defending against them. Unfortunately, the reaction to our course was based on a dearth of information, which we remedy in this paper by describing key pedagogical elements of the course.Specifically, we present four aspects of our course: how students are vetted for entry, operation of the course, course content, and the instructional materials used. In addition, we pay particular attention to the controversial course assignments, discussing the assignments and the need for balance, objectivity, security, and learning in a university environment. Our experiences with the course and future plans may be helpful for other institutions considering such course offerings. It should also provide opponents of the course with valuable information about the true nature of the course, the pedagogy used, and the value provided to the computer community as computer science graduates with this kind of expertise take their place as the next generation computer security experts.
John Aycock, Ken Barker 0001
SIGCSE1
2005 Timing is everything
Nathan Friess, Ryan Vogt, John Aycock
Comput. Secur.3
2002 Practical Earley Parsing
abstract
Earley's parsing algorithm is a general algorithm, able to handle any context-free grammar. As with most parsing algorithms, however, the presence of grammar rules having empty right-hand sides complicates matters. By analyzing why Earley's algorithm struggles with these grammar rules, we have devised a simple solution to the problem. Our empty-rule solution leads to a new type of finite automaton expressly suited for use in Earley parsers and to a new statement of Earley's algorithm. We show that this new form of Earley parser is much more time efficient in practice than the original.
John Aycock, R. Nigel Horspool
Comput. J.1
2001 Directly-Executable Earley Parsing
John Aycock, R. Nigel Horspool
CC1
2001 Even faster generalized LR parsing
John Aycock, R. Nigel Horspool, Jan Janousek, Borivoj Melichar
Acta Informatica1
2001 Schrödinger's token
abstract
Abstract A common problem when writing compilers for programming languages or little, domain‐specific languages is that an input token may have several interpretations, depending on context. Solutions to this problem demand programmer intervention, obfuscate the language's grammar, and may introduce subtle bugs. We present a technique which is simple and without the above drawbacks—allowing a token to simultaneously have different types—and show how it can be applied to areas such as little language processing and fuzzy parsing. We also describe ways that compiler tools can support this technique. Copyright © 2001 John Wiley & Sons, Ltd.
John Aycock, R. Nigel Horspool
Softw. Pract. Exp.1
2000 Simple Generation of Static Single-Assignment Form
John Aycock, R. Nigel Horspool
CC1
1999 Faster Generalized LR Parsing
abstract
Tomita devised a method of generalized LR (GLR) parsing to parse ambiguous grammars efficiently. A GLR parser uses linear-time LR parsing techniques as long as possible, falling back on more expensive general techniques when necessary.Much research has addressed speeding up LR parsers. However, we argue that this previous work is not transferable to GLR parsers. Instead, we speed up LR parsers by building larger pushdown automata, trading space for time. A variant of the GLR algorithm then incorporates our faster LR parsers.Our timings show that our new method for GLR parsing can parse highly ambiguous grammars significantly faster than a standard GLR parser.
John Aycock, R. Nigel Horspool
CC1