Christian Hammer 0001

dblp:h/ChristianHammer1 · DBLP profile ↗
← Back
33ranked-venue papers
4as first author
9since 2021 · last 2025
0000-0001-5955-3732ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 23 · 4 first-author · 7 since 2021Security and privacy · 9 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2025 ShadowGuard: Cryptographic Shadow Stack Protection with XOR Obfuscation and HMAC Integrity
abstract
Return-Oriented Programming (ROP) attacks, a persistent security threat for over a decade, pose significant risks to computing devices by exploiting vulnerabilities to hijack control flow and execute arbitrary code. While memory isolation and shadow stacks raise the bar, advanced memory disclosure attacks can still bypass these defenses. As a more resilient software-based defense against such advanced threats, we introduce ShadowGuard, a novel approach that leverages Low-Level Virtual Machine (LLVM) passes, programmatic transformations during compilation, to enhance return address protection and prevent ROP attacks on (embedded) systems that to not feature hardware support for control flow protection.ShadowGuard employs dual XOR-based obfuscation and a HMAC-SHA256 keyed hash algorithm to mask return addresses and ensure their integrity. This combination allows for the detection of tampering attempts. Additionally, a separate, secure shadow stack stores obfuscated addresses and their authentication hashed keys, preventing unauthorized access or modification by attackers.Through comprehensive evaluation using real-life applications and the Coreutils-8.32 benchmark, we demonstrate that our approach effectively detects and mitigates ROP attacks while maintaining practicality. The runtime overhead is approximately 31%, and the binary size increase 2%, on average. This solution offers a scalable and robust defense mechanism for securing return addresses in modern real-world applications.
Sirine Ilahi, Adebayo Omotosho, Christian Hammer 0001
ISSRE3
2025 Modular unification of unilingual pointer analyses to multilingual FFI-based programs
abstract
Modular analysis of polyglot applications is challenging because flows of heap objects must be resolved across language boundaries. The state-of-the-art analyses for polyglot applications have two fundamental limitations. First, they assume explicit boundaries between the guest and the host language to determine inter-language dataflows. Second, they rely on specific analyses of the host and guest languages. The former assumption is impractical concerning recent advancements in polyglot programming techniques, while the latter disregards advances in pointer analysis of the underlying languages. In this work, we propose to extend existing pointer analyses with a novel summary specialization technique that unifies points-to sets across language boundaries. Our novel technique leverages combinations of host and guest analyses with minor modifications. We demonstrate the efficacy and generalizability of our approach by evaluating it with two polyglot language models: Java-C communication via Android's NDK and Java-Python communication in GraalVM.
Jyoti Prakash, Abhishek Tiwari 0001, Christian Hammer 0001
Sci. Comput. Program.3
2024 Towards Anomaly Detection in Embedded Systems Application Using LLVM Passes
abstract
Software security exploits, such as Return-Oriented Programming (ROP) attacks, have persisted for more than a decade. ROP attacks inject malicious behaviors into programs, posing serious risks to computing devices, and they can be par-ticularly challenging to detect in systems with limited resources. In this paper, we introduce an approach that exploits Low-Level Virtual Machine (LLVM) passes, programmatic transformations applied during compilation, to detect ROP attacks in ARM-based embedded systems. By customizing LLVM passes, developers can integrate tailored security checks and optimizations into embedded systems requirements. Our approach is motivated by the use of Hardware Performance Counters (HPCs) for certain mitigations, which are not commonly available on all embedded systems. The experimental evaluation of our approach for de-tecting ROP attacks in real-world applications shows that it is feasible and can be extended to detect new attacks independently of an Operating System (OS). The storage overhead induced by our approach is approximately 55%.
Sirine Ilahi, Adebayo Omotosho, Christian Hammer 0001
COMPSAC3
2023 IDS-MA: Intrusion Detection System for IoT MQTT Attacks Using Centralized and Federated Learning
abstract
Yearly, the number of connected Internet of Things (IoT) devices is growing. The attack surface is also increasing because IoT is generally functionality-centric and security is usually an after-thought. Therefore, memory corruption attacks, man-in-the-middle attacks, and distributed denial of service attacks are a few of the attacks that have been widely exploited on these devices communicating via Message Queue Telemetry Transport (MQTT), which is the most commonly used messaging protocol in IoT. However, much of the research on MQTT intrusion detection has either covered a smaller number of attacks, completely ignored memory attacks, or used inadequate classification evaluation metrics (e.g., only accuracy). In this paper, we design and simulate an MQTT IoT network and present IDS-MA, an intrusion detection system for MQTT attacks by training both centralized and federated learning models. Seven different MQTT attacks were implemented with the models evaluated with metrics such as accuracy, precision, and recall. Our evaluation results show high detection scores on MQTT attacks (including memory attacks). We also obtain an average model detection accuracy of over 80% on 2,210,797 real attacks from the MQTT-IoT-IDS2020 benchmark for both centralized and federated models.
Adebayo Omotosho, Yaman Qendah, Christian Hammer 0001
COMPSAC3
2023 Detecting and Preventing ROP Attacks using Machine Learning on ARM
abstract
As the ARM processor is receiving increased attention due to the fast growth of mobile technologies and the internet-of-things (IoT), it is simultaneously becoming the target of several control flow attacks such as return-oriented programming (ROP), which uses code present in the software system in order to exploit memory bugs. While some research can detect control flow attacks on architectures like x86, the ARM architecture has been neglected. In this paper, we investigate whether ROP attack detection and prevention based on hardware performance counters (HPC) and machine learning can be effectively transferred to the ARM architecture. Given the observation that ROP attacks exhibit different micro-architectural events compared to benign executions of a software, we evaluate whether and which HPCs, which track these hardware events, are indicative on ARM to detect control flow attacks. We collect data exploiting real-world vulnerable applications running on ARM-based Raspberry Pi machines. The collected data then serves as training data for different machine learning techniques. We also implement an online monitor consisting of a modified program loader, kernel module and a classifier, which labels a program’s execution as benign or under attack, and stops its execution once the latter is detected. An evaluation of our approach provides detection accuracy of 92% for the offline training and 75% for the online monitoring, which demonstrates that variations in the HPCs are indicative of attacks on ARM architectures. The performance overhead of online monitoring evaluated on 8 real-world vulnerable applications exhibits a moderate 6.2% slowdown on average. The result of our evaluation indicates that the behavioral changes in micro-architectural events of the ARM platform can play a vital role in detecting memory attacks.
Gebrehiwet Biyane Welearegai, Chenpo Hu, Christian Hammer 0001
COMPSAC3
2023 Evaluating the Hardware Performance Counters of an Xtensa Virtual Prototype
abstract
Embedded systems’ hardware and software stacks are becoming more complex requiring more development time, time to market, and cost, which contributes to delayed delivery of these silicon devices. A virtual prototype (VP) provides an embedded systems architecture simulator for application development and testing purposes. In this paper, we developed and present the first virtual prototype of the Xtensa LX7 microprocessor that evaluates the performance of its emulated hardware performance counters (HPCs) with those collected from an actual Xtensa LX7 hardware. Seven machine learning models were developed and trained to find the relationships between the two different datasets for the sample application of classifiying return-oriented programming (ROP) attacks. Our experiments show that the obtained micro-architectural characteristics on the VP are on average about 70% similar and thus permit early simulation capabilities for developers and testers.
Adebayo Omotosho, Sirine Ilahi, Ernesto Villegas Castillo, Christian Hammer 0001, Christian Sauer 0001
DDECS4
2023 Demand-driven Information Flow Analysis of WebView in Android Hybrid Apps
abstract
Android hybrid apps augment native apps with web and inter-language communication capabilities. These apps facilitate the integration of web components, including JavaScript, into native apps. Besides, they allow a two-way communication where JavaScript can utilize functionality shared by the native side (Java). However, due to operational differences between Java and JavaScript, the semantics of this communication are complex. Tracking information flows via this communication channel, i.e., between these heterogeneous platforms, becomes intricate.Multiple approaches have been proposed to analyze hybrid apps. However, most of them focus on specific classes of web-induced vulnerabilities or provide rudimentary tracking of specific information flows via this communication channel. This work proposes a demand-driven analysis to comprehensively track information flow violations from the native side to JavaScript and vice-versa. To this end, our framework selectively creates data flow summaries of the shared native-side code based on its usage in the corresponding JavaScript code. We demonstrate the efficacy of our approach by applying it to various benchmarks and large-scale apps.
Abhishek Tiwari 0001, Jyoti Prakash, Christian Hammer 0001
ISSRE3
2021 Effects of Program Representation on Pointer Analyses - An Empirical Study
abstract
Abstract Static analysis frameworks, such as Soot and Wala, are used by researchers to prototype and compare program analyses. These frameworks vary on heap abstraction, modeling library classes, and underlying intermediate program representation (IR). Often, these variations pose a threat to the validity of the results as the implications of comparing the same analysis implementation in different frameworks are still unexplored. Earlier studies have focused on the precision, soundness, and recall of the algorithms implemented in these frameworks; however, little to no work has been done to evaluate the effects of program representation. In this work, we fill this gap and study the impact of program representation on pointer analysis. Unfortunately, existing metrics are insufficient for such a comparison due to their inability to isolate each aspect of the program representation. Therefore, we define two novel metrics that measure these analyses’ precision after isolating the influence of class-hierarchy and intermediate representation. Our results establish that the minor differences in the class hierarchy and IR do not impact program analysis significantly. Besides, they reveal the sources of unsoundness that aid researchers in developing program analysis.
Jyoti Prakash, Abhishek Tiwari 0001, Christian Hammer 0001
FASE3
2021 Permissive runtime information flow control in the presence of exceptions
abstract
Information flow control (IFC) has been extensively studied as an approach to mitigate information leaks in applications. A vast majority of existing work in this area is based on static analysis. However, some applications, especially on the Web, are developed using dynamic languages like JavaScript where static analyses for IFC do not scale well. As a result, there has been a growing interest in recent years to develop dynamic or runtime information flow analysis techniques. In spite of the advances in the field, runtime information flow analysis has not been at the helm of information flow security, one of the reasons being that the analysis techniques and the security property related to them (non-interference) over-approximate information flows (particularly implicit flows), generating many false positives. In this paper, we present a sound and precise approach for handling implicit leaks at runtime. In particular, we present an improvement and enhancement of the so-called permissive-upgrade strategy, which is widely used to tackle implicit leaks in dynamic information flow control. We improve the strategy’s permissiveness and generalize it. Building on top of it, we present an approach to handle implicit leaks when dealing with complex features like unstructured control flow and exceptions in higher-order languages. We explain how we address the challenge of handling unstructured control flow using immediate post-dominator analysis. We prove that our approach is sound and precise.
Abhishek Bichhawat, Vineet Rajani, Deepak Garg 0001, Christian Hammer 0001
J. Comput. Secur.4
2020 Revealing injection vulnerabilities by leveraging existing tests
abstract
Code injection attacks, like the one used in the high-profile 2017 Equifax breach, have become increasingly common, now ranking #1 on OWASP's list of critical web application vulnerabilities. Static analyses for detecting these vulnerabilities can overwhelm developers with false positive reports. Meanwhile, most dynamic analyses rely on detecting vulnerabilities as they occur in the field, which can introduce a high performance overhead in production code. This paper describes a new approach for detecting injection vulnerabilities in applications by harnessing the combined power of human developers' test suites and automated dynamic analysis. Our new approach, Rivulet, monitors the execution of developer-written functional tests in order to detect information flows that may be vulnerable to attack. Then, Rivulet uses a white-box test generation technique to repurpose those functional tests to check if any vulnerable flow could be exploited. When applied to the version of Apache Struts exploited in the 2017 Equifax attack, Rivulet quickly identifies the vulnerability, leveraging only the tests that existed in Struts at that time. We compared Rivulet to the state-of-the-art static vulnerability detector Julia on benchmarks, finding that Rivulet outperformed Julia in both false positives and false negatives. We also used Rivulet to detect new vulnerabilities.
Katherine Hough, Gebrehiwet Biyane Welearegai, Christian Hammer 0001, Jonathan Bell 0001
ICSE3
2020 A Large Scale Analysis of Android - Web Hybridization
Abhishek Tiwari 0001, Jyoti Prakash, Sascha Groß, Christian Hammer 0001
J. Syst. Softw.4
2019 LUDroid: A Large Scale Analysis of Android - Web Hybridization
abstract
Many Android applications embed webpages via WebView components and execute JavaScript code within Android. Hybrid applications leverage dedicated APIs to load a resource and render it in WebView. Furthermore, Android objects can be shared with the JavaScript world. However, bridging the interfaces of the Android and JavaScript world might also incur severe security threats: Potentially untrusted webpages and their JavaScript might interfere with the Android environment and its access to native features. No general analysis is currently available to assess the implications of such hybrid apps bridging the two worlds. To understand the semantics and effects of hybrid apps, we perform a large-scale study on the usage of the hybridization APIs in the wild. We analyze and categorize the parameters to hybridization APIs for 7,500 randomly selected applications from the Google Playstore. Our results advance the general understanding of hybrid applications, as well as implications for potential program analyses, and the current security situation: We discover 6,375 flows of sensitive data from Android to JavaScript, out of which 82% could flow to potentially untrustworthy code. Our analysis identified 365 web pages embedding vulnerabilities and we exemplarily exploit them. Additionally, we discover 653 applications in which potentially untrusted Javascript code may interfere with (trusted) Android objects.
Abhishek Tiwari 0001, Jyoti Prakash, Sascha Groß, Christian Hammer 0001
SCAM4
2019 IIFA: Modular Inter-app Intent Information Flow Analysis of Android Applications
Abhishek Tiwari 0001, Sascha Groß, Christian Hammer 0001
SecureComm (2)3
2018 PIAnalyzer: A Precise Approach for PendingIntent Vulnerability Analysis
Sascha Groß, Abhishek Tiwari 0001, Christian Hammer 0001
ESORICS (2)3
2018 A Formal Logic Framework for the Automation of the Right to Be Forgotten
Abhishek Tiwari 0001, Fabian Bendun, Christian Hammer 0001
SecureComm (1)3
2017 WebPol: Fine-Grained Information Flow Policies for Web Browsers
Abhishek Bichhawat, Vineet Rajani, Jinank Jain, Deepak Garg 0001, Christian Hammer 0001
ESORICS (1)5
2017 ThiefTrap - An Anti-theft Framework for Android
Sascha Groß, Abhishek Tiwari 0001, Christian Hammer 0001
SecureComm3
2016 R-Droid: Leveraging Android App Analysis with Static Slice Optimization
abstract
Today's feature-rich smartphone apps intensively rely on access to highly sensitive (personal) data. This puts the user's privacy at risk of being violated by overly curious apps or libraries (like advertisements). Central app markets conceptually represent a first line of defense against such invasions of the user's privacy, but unfortunately we are still lacking full support for automatic analysis of apps' internal data flows and supporting analysts in statically assessing apps' behavior. In this paper we present a novel slice-optimization approach to leverage static analysis of Android applications. Building on top of precise application lifecycle models, we employ a slicing-based analysis to generate data-dependent statements for arbitrary points of interest in an application. As a result of our optimization, the produced slices are, on average, 49% smaller than standard slices, thus facilitating code understanding and result validation by security analysts. Moreover, by re-targeting strings, our approach enables automatic assessments for a larger number of use-cases than prior work. We consolidate our improvements on statically analyzing Android apps into a tool called R-Droid and conducted a large-scale data-leak analysis on a set of 22,700 Android apps from Google Play. R-Droid managed to identify a significantly larger set of potential privacy-violating information flows than previous work, including 2,157 sensitive flows of password-flagged UI widgets in 256 distinct apps.
Michael Backes 0001, Sven Bugiel, Erik Derr, Sebastian Gerling, Christian Hammer 0001
AsiaCCS5
2015 Information Flow Control for Event Handling and the DOM in Web Browsers
abstract
Web browsers routinely handle private information. Owing to a lax security model, browsers and JavaScript in particular, are easy targets for leaking sensitive data. Prior work has extensively studied information flow control (IFC) as a mechanism for securing browsers. However, two central aspects of web browsers - the Document Object Model (DOM) and the event handling mechanism - have so far evaded thorough scrutiny in the context of IFC. This paper advances the state-of-the-art in this regard. Based on standard specifications and the code of an actual browser engine, we build formal models of both the DOM (up to Level 3) and the event handling loop of a typical browser, enhance the models with fine-grained taints and checks for IFC, prove our enhancements sound and test our ideas through an instrumentation of WebKit, an in-production browser engine. In doing so, we observe several channels for information leak that arise due to subtleties of the event loop and its interaction with the DOM.
Vineet Rajani, Abhishek Bichhawat, Deepak Garg 0001, Christian Hammer 0001
CSF4
2015 Boxify: Full-fledged App Sandboxing for Stock Android
Michael Backes 0001, Sven Bugiel, Christian Hammer 0001, Oliver Schranz, Philipp von Styp-Rekowsky
USENIX Security Symposium3
2013 Detecting deadlock in programs with data-centric synchronization
abstract
Previously, we developed a data-centric approach to concurrency control in which programmers specify synchronization constraints declaratively, by grouping shared locations into atomic sets. We implemented our ideas in a Java extension called AJ, using Java locks to implement synchronization. We proved that atomicity violations are prevented by construction, and demonstrated that realistic Java programs can be refactored into AJ without significant loss of performance. This paper presents an algorithm for detecting possible deadlock in AJ programs by ordering the locks associated with atomic sets. In our approach, a type-based static analysis is extended to handle recursive data structures by considering programmer-supplied, compiler-verified lock ordering annotations. In an evaluation of the algorithm, all 10 AJ programs under consideration were shown to be deadlock-free. One program needed 4 ordering annotations and 2 others required minor refactorings. For the remaining 7 programs, no programmer intervention of any kind was required.
Daniel Marino, Christian Hammer 0001, Julian Dolby, Mandana Vaziri, Frank Tip, Jan Vitek
ICSE2
2013 Flexible access control for javascript
abstract
Providing security guarantees for systems built out of untrusted components requires the ability to define and enforce access control policies over untrusted code. In Web 2.0 applications, JavaScript code from different origins is often combined on a single page, leading to well-known vulnerabilities. We present a security infrastructure which allows users and content providers to specify access control policies over subsets of a JavaScript program by leveraging the concept of delimited histories with revocation. We implement our proposal in WebKit and evaluate it with three policies on 50 widely used websites with no changes to their JavaScript code and report performance overheads and violations.
Gregor Richards, Christian Hammer 0001, Francesco Zappa Nardelli, Suresh Jagannathan, Jan Vitek
OOPSLA2
2013 AppGuard - Enforcing User Requirements on Android Apps
Michael Backes 0001, Sebastian Gerling, Christian Hammer 0001, Matteo Maffei, Philipp von Styp-Rekowsky
TACAS3
2012 A data-centric approach to synchronization
abstract
Concurrency-related errors, such as data races, are frustratingly difficult to track down and eliminate in large object-oriented programs. Traditional approaches to preventing data races rely on protecting instruction sequences with synchronization operations. Such control-centric approaches are inherently brittle, as the burden is on the programmer to ensure that all concurrently accessed memory locations are consistently protected. Data-centric synchronization is an alternative approach that offloads some of the work on the language implementation. Data-centric synchronization groups fields of objects into atomic sets to indicate that these fields must always be updated atomically. Each atomic set has associated units of work , that is, code fragments that preserve the consistency of that atomic set. Synchronization operations are added automatically by the compiler. We present an extension to the Java programming language that integrates annotations for data-centric concurrency control. The resulting language, called AJ, relies on a type system that enables separate compilation and supports atomic sets that span multiple objects and that also supports full encapsulation for more efficient code generation. We evaluate our proposal by refactoring classes from standard libraries, as well as a number of multithreaded benchmarks, to use atomic sets. Our results suggest that data-centric synchronization is easy to use and enjoys low annotation overhead, while successfully preventing data races. Moreover, experiments on the SPECjbb benchmark suggest that acceptable performance can be achieved with a modest amount of tuning.
Julian Dolby, Christian Hammer 0001, Daniel Marino, Frank Tip, Mandana Vaziri, Jan Vitek
ACM Trans. Program. Lang. Syst.2
2011 The Eval That Men Do - A Large-Scale Study of the Use of Eval in JavaScript Applications
Gregor Richards, Christian Hammer 0001, Brian Burg, Jan Vitek
ECOOP2
2011 Marathon: Detecting Atomic-Set Serializability Violations with Conflict Graphs
William N. Sumner, Christian Hammer 0001, Julian Dolby
RV2
2010 A Type System for Data-Centric Synchronization
Mandana Vaziri, Frank Tip, Julian Dolby, Christian Hammer 0001, Jan Vitek
ECOOP4
2009 Precise slicing of concurrent programs
Dennis Giffhorn, Christian Hammer 0001
Autom. Softw. Eng.2
2008 Dynamic detection of atomic-set-serializability violations
abstract
Previously we presented atomic sets, memory locations that share some consistency property, and units of work, code fragments that preserve consistency of atomic sets on which they are declared. We also proposed atomic-set serializability as a correctness criterion for concurrent programs, stating that units of work must be serializable for each atomic set. We showed that a set of problematic data access patterns characterize executions that are not atomic-set serializable. Our criterion subsumes data races (single-location atomic sets) and serializability (all locations in one set).
Christian Hammer 0001, Julian Dolby, Mandana Vaziri, Frank Tip
ICSE1
2008 Precise Analysis of Java Programs Using JOANA
abstract
The JOANA project (Java Object-sensitive ANAlysis) is a program analysis infrastructure for the Java language. It contains a wide range of analysis techniques such as dependence graph computation, slicing and chopping for sequential and concurrent programs, computation of path conditions and algorithms for software security. This demonstration presents the JOANA plugin for the Eclipse framework. In the current version, a user can compute and navigate through dependence graphs for full Java bytecode, analyze Java programs with a broad range of slicing and chopping algorithms, and use precise algorithms for language-based security to check programs for information leaks.
Dennis Giffhorn, Christian Hammer 0001
SCAM2
2006 Intransitive Noninterference in Dependence Graphs
abstract
In classic information flow control (IFC), noninterference guarantees that no information flows from secret input channels to public output channels. However, this notion turned out to be overly restrictive as many intuitively secure programs do allow some release. In this paper we define a static analysis that allows intransitive noninterference in combination with context- sensitive analysis for Java bytecode programs. In contrast to type systems that annotate variables, our approach annotates information sources and sinks. To the best of our knowledge this is the first IFC technique which is flow-, context-, and object- sensitive. It allows IFC for realistic languages like Java or C and offers a mechanism for declassification to accommodate some information leakage for cases where traditional noninterference is too restrictive.
Christian Hammer 0001, Jens Krinke, Frank Nodes
ISoLA1
2006 Dynamic path conditions in dependence graphs
abstract
We present a new approach combining dynamic slicing with path conditions in dependence graphs enhanced by dynamic information collected in a program trace. While dynamic slicing can only reveal that certain dependences have been holding during program execution, the combination with dynamic path conditions reveals why, as well.The approach described here has been implemented for full ANSI-C. It uses the static dependence graph to produce a fine-grained variable and dependence trace of an executing program. This information is used for dynamic slicing, yielding significantly smaller sets of statements than static slices, as well as for increasing precision of the path condition between two statements. Such a dynamic path condition contains explicit information about if and how one statement influenced the other.Dynamic path conditions work even when tracing information is incomplete or corrupted e.g. in case of a "damaged flight recorder".
Christian Hammer 0001, Martin Grimme, Jens Krinke
PEPM1
2004 An improved slicer for Java
abstract
We present an improved slicing algorithm for Java. The best algorithm known so far, first presented in [11], is not always precise if nested objects are used as actual parameters. The new algorithm presented in this paper always generates correct and precise slices, but is more expensive in general.We describe the algorithms and their treatment of objects as parameters. In particular, we present a new, safe criterion for termination of unfolding nested parameter objects. We then compare the two algorithms by providing measurements for a benchmark of Java and JavaCard programs.
Christian Hammer 0001, Gregor Snelting
PASTE1