VLDB 2026 Research / reviewers in the wild / expert
Nahid Shahmehri
dblp:s/NahidShahmehri
· DBLP profile ↗
57ranked-venue papers
4as first author
5since 2021 · last 2023
0000-0002-0920-2157ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 17 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 5Human-computer interaction and ubiquitous computing · 4Graphics, computer vision, multimedia, augmented reality and games · 3Systems, architecture and hardware · 2Computer networks · 2Databases, data management, data science and information retrieval · 2Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Characterizing the Use of Code Obfuscation in Malicious and Benign Android AppsabstractObfuscation is frequently used by both benign and malicious Android apps. Since static analysis of obfuscated apps often produces incomplete or misleading results, the problems of identifying and quantifying the use of specific obfuscation techniques in apps has received significant attention. Even though several existing works have addressed these problems, most studies focus on data obfuscation methods such as identifier renaming and string obfuscation, while more advanced code obfuscation methods, such as reflection and control-flow obfuscation, have received less attention. Moreover, existing approaches to detecting Android code obfuscation have significant limitations, as shown by a detailed survey that we present as part of this paper. This is in part due to a fundamental “bootstrapping” problem: since, on one hand, the landscape of Android code obfuscation is poorly known, researchers have very little guidance when designing new detection methods. On the other hand, the lack of detection methods mean that the obfuscation landscape is bound to remain largely unexplored. Ulf Kargén, Noah Mauthe, Nahid Shahmehri |
ARES | 3 |
| 2023 | Android decompiler performance on benign and malicious apps: an empirical studyabstractAbstract Decompilers are indispensable tools in Android malware analysis and app security auditing. Numerous academic works also employ an Android decompiler as the first step in a program analysis pipeline. In such settings, decompilation is frequently regarded as a “solved” problem, in that it is simply expected that source code can be accurately recovered from an app. On the other hand, it is known that, e.g, obfuscation can negatively impact a decompiler’s effectiveness. Therefore, in order to better understand potential failure modes of, e.g., automated analysis pipelines involving decompilation, it is important to characterize the performance of decompilers on both benign and malicious apps. To this end, we have performed what is, to the best of our knowledge, the first large-scale study of Android decompilation failure rates, using three sets of apps; namely, 3,018 open-source apps, 13,601 apps crawled from Google Play, and an existing collection of 24,553 malware samples. In addition to the state-of-the-art Dalvik bytecode decompiler Jadx, we also studied the performance of three popular Java decompilers. Furthermore, this paper also presents the findings from a follow-up study on 54,945 malware apps, where we additionally performed an analysis of the reasons for decompilation failures. Our study revealed that decompilers generally have very low failure rates, and that few failures on benign apps appear to be related to obfuscation. On malware, however, obfuscation appears to be a more prominent cause of failures, although the vast majority of malicious apps could still be fully decompiled by an ensemble of decompilers. Ulf Kargén, Noah Mauthe, Nahid Shahmehri |
Empir. Softw. Eng. | 3 |
| 2023 | desync-cc: A research tool for automatically applying disassembly desynchronization during compilationabstractCode obfuscation is an important topic, both in terms of defense, when trying to prevent intellectual property theft, and from the offensive point of view, when trying to break obfuscation used in malware. Several recent works have discussed techniques for preventing or delaying reverse engineering of binaries. While most works focus on methods that obscure program logic, the complimentary approach of disassembly desynchronization has received relatively little attention, despite being often used by, for example, malware authors. The technique puts another hurdle in the way of attackers by targeting the most fundamental step of the reverse-engineering process: recovering assembly code from a program binary. In the interest of furthering research into this kind of obfuscation, we present desync-cc, a tool for automatic application of disassembly desynchronization. To facilitate maximal ease-of-use, the tool is designed as a drop-in replacement for gcc, and works by intercepting and modifying intermediate assembly-code during compilation. Ulf Kargén, Ivar Härnqvist, Johannes Wilson, Gustav Eriksson, Evelina Holmgren, Nahid Shahmehri |
Sci. Comput. Program. | 6 |
| 2022 | desync-cc: An Automatic Disassembly-Desynchronization ObfuscatorabstractCode obfuscation is an important topic, both in terms of defense, when trying to prevent intellectual property theft, and from the offensive point of view, when trying to break obfuscation used by malware authors to hide their malicious intents. Consequently, several works in recent years have discussed techniques that aim to prevent or delay reverse-engineering of binaries. While most works focus on methods that obscure the program logic from potential attackers, the complimentary approach of disassembly desynchronization has received relatively little attention. This technique puts another hurdle in the way of attackers by targeting the most fundamental step of the reverse-engineering process: recovering assembly code from a program binary. The technique works by tricking a disassembler into decoding the instruction stream at an invalid offset. On CPU architectures with variable-length instructions, this often yields valid albeit meaningless assembly code, while hiding a part of the original code. In the interest of furthering research into disassembly desynchronization, both from a defensive and offensive point of view, we have created desync-cc, a tool for automatic application of disassembly-desynchronization obfuscation. The tool is designed as a drop-in replacement for gcc, and works by intercepting and modifying intermediate assembly code during compilation. By applying obfuscation after the code generation phase, our tool allows a much more granular control over where obfuscation is applied, compared to a source-code level obfuscator. In this paper, we describe the design and implementation of desync-cc, and present a preliminary evaluation of its effectiveness and efficiency on a number of real-world Linux programs. Ulf Kargén, Ivar Härnqvist, Johannes Wilson, Gustav Eriksson, Evelina Holmgren, Nahid Shahmehri |
SANER | 6 |
| 2021 | A Large-Scale Empirical Study of Android App DecompilationabstractDecompilers are indispensable tools in Android malware analysis and app security auditing. Numerous academic works also employ an Android decompiler as the first step in a program analysis pipeline. In such settings, decompilation is frequently regarded as a "solved" problem, in that it is simply expected that source code can be accurately recovered from an app. While a large proportion of methods in an app can typically be decompiled successfully, it is common that at least some methods fail to decompile. In order to better understand the practical applicability of techniques in which decompilation is used as part of an automated analysis, it is important to know the actual expected failure rate of Android decompilation. To this end, we have performed what is, to the best of our knowledge, the first large-scale study of Android decompilation failure rates. We have used three sets of apps, consisting of, respectively, 3,018 open-source apps, 13,601 apps from a recent crawl of Google Play, and a collection of 24,553 malware samples. In addition to the state-of-the-art Dalvik bytecode decompiler jadx, we used three popular Java decompilers. While jadx achieves an impressively low failure rate of only 0.02% failed methods per app on average, we found that it manages to recover source code for all methods in only 21% of the Google Play apps.We have also sought to better understand the degree to which in-the-wild obfuscation techniques can prevent decompilation. Our empirical evaluation, complemented with an indepth manual analysis of a number of apps, indicate that code obfuscation is quite rarely encountered, even in malicious apps. Moreover, decompilation failures mostly appear to be caused by technical limitations in decompilers, rather than by deliberate attempts to thwart source-code recovery by obfuscation. This is an encouraging finding, as it indicates that near-perfect Android decompilation is, at least in theory, achievable, with implementation-level improvements to decompilation tools. Noah Mauthe, Ulf Kargén, Nahid Shahmehri |
SANER | 3 |
| 2018 | Speeding Up Bug Finding using Focused FuzzingabstractGreybox fuzzing has recently emerged as a scalable and practical approach to finding security bugs in software. For example, AFL ---the current state-of-the-art greybox fuzzer --- has found hundreds of vulnerabilities in popular software since its release in 2013. The combination of lightweight coverage instrumentation and a simple evolutionary algorithm allows AFL to quickly generate inputs that exercise new code. AFL also obviates the need to manually set adhoc fuzzing ratios, which has been a major limitation of classical black-box fuzzers. Instead, AFL's first fuzzing pass exhaustively applies a set of mutations to every byte of a program input. While this approach allows for more thorough exploration of the input space, and therefore improves the chances of finding complex bugs, it also drastically slows down the fuzzing progress for "heavyweight" programs, or programs that take large inputs. This makes AFL less suitable for fuzzing input formats with large size overhead, such as various document formats. In this paper, we propose focused fuzzing as a practical trade-off between thoroughness and speed, for fuzzers that employ input mutation. We extend the notion of code coverage to individual bytes of input, and show how forward dynamic slicing can be used to efficiently determine the set of program instructions that are affected by a particular input byte. This information can then be used to restrict expensive mutations to a small subset of input bytes. We implement focused fuzzing on top of AFL, and evaluate it on four "real-life" Linux programs. Our evaluation shows that focused fuzzing noticeably improves bug discovery, compared to vanilla AFL. Ulf Kargén, Nahid Shahmehri |
ARES | 2 |
| 2017 | Towards robust instruction-level trace alignment of binary codeabstractProgram trace alignment is the process of establishing a correspondence between dynamic instruction instances in executions of two semantically similar but syntactically different programs. In this paper we present what is, to the best of our knowledge, the first method capable of aligning realistically long execution traces of real programs. To maximize generality, our method works entirely on the machine code level, i.e. it does not require access to source code. Moreover, the method is based entirely on dynamic analysis, which avoids the many challenges associated with static analysis of binary code, and which additionally makes our approach inherently resilient to e.g. static code obfuscation. Therefore, we believe that our trace alignment method could prove to be a useful aid in many program analysis tasks, such as debugging, reverse-engineering, investigating plagiarism, and malware analysis. We empirically evaluate our method on 11 popular Linux programs, and show that it is capable of producing meaningful alignments in the presence of various code transformations such as optimization or obfuscation, and that it easily scales to traces with tens of millions of instructions. Ulf Kargén, Nahid Shahmehri |
ASE | 2 |
| 2017 | Collaborative framework for protection against attacks targeting BGP and edge networks
Rahul Hiran, Niklas Carlsson, Nahid Shahmehri |
Comput. Networks | 3 |
| 2016 | Towards Accurate Binary Correspondence Using Runtime-Observed ValuesabstractEstablishing binary correspondence is the process of finding corresponding pairs of program elements, e.g., functions or individual instructions, between two semantically equivalent (or nearly-equivalent) but syntactically different program binaries. The binary-correspondence problem has applications in many fields, e.g., plagiarism and clone detection, reverse engineering, and security, and has therefore received significant attention both in industry and academia. Most binary-correspondence methods used in practice today are based on static analysis of the control structure in binaries. Unfortunately, such methods are often highly sensitive to syntactic differences between binaries, and discrepancies in the control structure due to, for example, using different compilers or optimization levels often severely reduce their accuracy. Several recent works have therefore proposed using dynamic analysis and comparing runtime-observed results of computations to establish binary correspondence. In this paper, we study the discriminative power of runtime-values for matching instructions in binaries, and propose several ways to increase the accuracy of value-based analyses. By utilizing techniques from the field of information retrieval combined with dynamic data-flow analysis, we improve matching accuracy by up to 55% in our experiments. Ulf Kargén, Nahid Shahmehri |
ICSME | 2 |
| 2015 | Information Sharing and User Privacy in the Third-party Identity Management LandscapeabstractThird-party identity management services enable cross-site information sharing, making Web access seamless but also raise significant privacy implications for the users. Using a combination of manual analysis of identified third-party identity management relationships and targeted case studies we capture how the protocol usage and third-party selection is changing, profile what information is requested to be shared (and actions to be performed) between websites, and identify privacy issues and practical problems that occur when using multiple accounts (associated with these services). The study highlights differences in the privacy leakage risks associated with different classes of websites, and shows that the use of multiple third-party websites, in many cases, can cause the user to lose (at least) partial control over which information is shared/posted on their behalf. Anna Vapen, Niklas Carlsson, Anirban Mahanti, Nahid Shahmehri |
CODASPY | 4 |
| 2015 | Bandwidth-aware Prefetching for Proactive Multi-video Preloading and Improved HAS PerformanceabstractThis paper considers the problem of providing users playing one streaming video the option of instantaneous and seamless playback of alternative videos. Recommendation systems can easily provide a list of alternative videos, but there is little research on how to best eliminate the startup time for these alternative videos. The problem is motivated by services that want to retain increasingly impatient users, who frequently watch the beginning of multiple videos, before viewing a video to the end. We present the design, implementation, and evaluation of an HTTP-based Adaptive Streaming (HAS) solution that provides careful prefetching and buffer management. We also present the design and evaluation of three fundamental policy classes that provide different tradeoffs between how aggressively new alternative videos are prefetched versus the importance of ensuring high playback quality. We show that our solution allows us to reduce the startup times of alternative videos by an order of magnitude and effectively adapt the quality such as to ensure the highest possible playback quality of the video being viewed. By improving the channel utilization we also address the discrimination problem that HAS clients often suffer from, allowing us to in some cases simultaneously improve the playback quality of the video being viewed and provide the value-added service of allowing instantaneous playback of the prefetched alternative videos. Vengatanathan Krishnamoorthi, Niklas Carlsson, Derek L. Eager, Anirban Mahanti, Nahid Shahmehri |
ACM Multimedia | 5 |
| 2015 | Information Sharing and User Privacy in the Third-Party Identity Management Landscape
Anna Vapen, Niklas Carlsson, Anirban Mahanti, Nahid Shahmehri |
SEC | 4 |
| 2015 | Turning programs against each other: high coverage fuzz-testing using binary-code mutation and dynamic slicingabstractMutation-based fuzzing is a popular and widely employed black-box testing technique for finding security and robustness bugs in software. It owes much of its success to its simplicity; a well-formed seed input is mutated, e.g. through random bit-flipping, to produce test inputs. While reducing the need for human effort, and enabling security testing even of closed-source programs with undocumented input formats, the simplicity of mutation-based fuzzing comes at the cost of poor code coverage. Often millions of iterations are needed, and the results are highly dependent on configuration parameters and the choice of seed inputs. In this paper we propose a novel method for automated generation of high-coverage test cases for robustness testing. Our method is based on the observation that, even for closed-source programs with proprietary input formats, an implementation that can generate well-formed inputs to the program is typically available. By systematically mutating the program code of such generating programs, we leverage information about the input format encoded in the generating program to produce high-coverage test inputs, capable of reaching deep states in the program under test. Our method works entirely at the machine-code level, enabling use-cases similar to traditional black-box fuzzing. We have implemented the method in our tool MutaGen, and evaluated it on 7 popular Linux programs. We found that, for most programs, our method improves code coverage by one order of magnitude or more, compared to two well-known mutation-based fuzzers. We also found a total of 8 unique bugs. Ulf Kargén, Nahid Shahmehri |
ESEC/SIGSOFT FSE | 2 |
| 2014 | Quality-adaptive Prefetching for Interactive Branched Video using HTTP-based Adaptive StreamingabstractInteractive branched video that allows users to select their own paths through the video, provides creative content designers with great personalization opportunities; however, such video also introduces significant new challenges for the system developer. For example, without careful prefetching and buffer management, the use of multiple alternative playback paths can easily result in playback interruptions. In this paper, we present a full implementation of an interactive branched video player using HTTP-based Adaptive Streaming (HAS) that provides seamless playback even when the users defer their branch path choices to the last possible moment. Our design includes optimized prefetching policies that we derive under a simple optimization framework, effective buffer management of prefetched data, and the use of parallel TCP connections to achieve efficient buffer workahead. Through performance evaluation under a wide range of scenarios, we show that our optimized policies can effectively prefetch data of carefully selected qualities along multiple alternative paths such as to ensure seamless playback, offering users a pleasant viewing experience without playback interruptions. Vengatanathan Krishnamoorthi, Niklas Carlsson, Derek L. Eager, Anirban Mahanti, Nahid Shahmehri |
ACM Multimedia | 5 |
| 2014 | Third-Party Identity Management Usage on the Web
Anna Vapen, Niklas Carlsson, Anirban Mahanti, Nahid Shahmehri |
PAM | 4 |
| 2014 | Efficient Utilization of Secondary Storage for Scalable Dynamic SlicingabstractDynamic program slicing is widely recognized as a powerful aid for e.g. Program comprehension during debugging. However, its widespread use has been impeded in part by scalability issues that occur when constructing the dynamic dependence graph necessary to compute dynamic slices. A few seconds of execution time on a modern CPU can easily yield dynamic dependence graphs on the order of tens of gigabytes in size. Existing methods either produce imprecise slices, incur large time overheads during slice computation, or run out of memory for long program executions. By carefully designing our method to take advantage of locality, we are able to efficiently use secondary storage for dynamic dependence graphs, thus allowing our method to scale to long program executions. Our prototype implementation runs directly on x86 executables, eliminating problems with e.g. Binary-only libraries. We show in our experiments that graphs can be constructed for program runs with billions of executed instructions, at slowdowns ranging from 62x to 173x. Our optimized format also allows graphs to be traversed at speeds of several million dependence edges per second. Ulf Kargén, Nahid Shahmehri |
SCAM | 2 |
| 2013 | Helping Hand or Hidden Hurdle: Proxy-Assisted HTTP-Based Adaptive Streaming PerformanceabstractHTTP-based Adaptive Streaming (HAS) has become a widely-used video delivery technology. Use of HTTP enables relatively easy firewall/NAT traversal and content caching. While caching is an important aspect of HAS, there is not much public research on the performance impact proxies and their policies have on HAS. In this paper we build an experimental framework using open source Squid proxies and the most recent Open Source Media Framework (OSMF). A range of content-aware policies can be implemented in the proxies and tested, while the player software can be instrumented to measure performance as seen at the client. Using this framework, the paper makes three main contributions. First, we present a scenario-based performance evaluation of the latest version of the OSMF player. Second, we quantify the benefits using different proxy-assisted solutions, including basic best effort policies and more advanced content quality aware prefetching policies. Finally, we present and evaluate a cooperative framework in which clients and proxies share information to improve performance. In general, the bottleneck location and network conditions play central roles in which policy choices are most advantageous, as they significantly impact the relative performance differences between policy classes. We conclude that careful design and policy selection is important when trying to enhance HAS performance using proxy assistance. Vengatanathan Krishnamoorthi, Niklas Carlsson, Derek L. Eager, Anirban Mahanti, Nahid Shahmehri |
MASCOTS | 5 |
| 2012 | InputTracer: A Data-Flow Analysis Tool for Manual Program Comprehension of x86 BinariesabstractThird-party security analysis of closed-source programs has become an important part of a defense-in-depth approach to software security for many companies. In the absence of efficient tools, the analysis has generally been performed through manual reverse engineering of the machine code. As reverse engineering is an extremely time-consuming and costly task, much research has been performed to develop more powerful methods for analysis of program binaries. One such popular method is dynamic taint analysis (DTA), which is a type of runtime data-flow analysis, where certain input data is marked as tainted. By tracking the flow of tainted data, DTA can, for instance, be used to determine which computations in a program are affected by a certain part of the input. In this paper we present Input Tracer, a tool that utilizes DTA for aiding in manual program comprehension and analysis of unmodified x86 executables running in Linux. A brief overview of dynamic taint analysis is given, followed by a description of the tool and its implementation. We also demonstrate the tool's ability to provide exact information on the origin of tainted data through a detailed use case, where the tool is used to find the root cause of a memory corruption bug. Ulf Kargén, Nahid Shahmehri |
SCAM | 2 |
| 2012 | An advanced approach for modeling and detecting software vulnerabilities
Nahid Shahmehri, Amel Mammar, Edgardo Montes de Oca, David Byers, Ana R. Cavalli, Shanai Ardi, Willy Jimenez |
Inf. Softw. Technol. | 1 |
| 2011 | TRAP: Open Decentralized Distributed Spam Filtering
Nahid Shahmehri, David Byers, Rahul Hiran |
TrustBus | 1 |
| 2010 | 2-clickAuthabstractInternet users today often have usernames and passwords at multiple web sites. To simplify things, many sites support some form of federated identity management, such as OpenID, that enables users to have a single account that allows them to log on to many different sites by authenticating to a single identity provider. Most identity providers perform authentication using a username and password. Should these credentials be compromised, e.g. captured by a key logger or malware on an untrusted computer, all the user's accounts become compromised. Therefore a more secure authentication method is desirable. We have implemented 2-clickAuth, an optical challenge-response solution where a web camera and a camera phone are used for authentication. Two-dimensional barcodes are used for the communication between phone and computer, which allows 2-clickAuth to transfer relatively large amounts of data in a short period of time. 2-clickAuth is considerably more secure than passwords while still being easy to use and easy to distribute to users. This makes 2-clickAuth a viable alternative to passwords in systems where enhanced security is desired, but availability, ease-of-use, and cost cannot be compromised. We have implemented an identity provider in the OpenID federated identity management system that uses 2-clickAuth for authentication, making 2-clickAuth available to all users of sites that support OpenID, including Facebook, Sourceforge and MySpace. Anna Vapen, David Byers, Nahid Shahmehri |
ARES | 3 |
| 2009 | A Post-Mortem Incident Modeling MethodabstractIncident post-mortem analysis after recovery from incidents is recommended by most incident response experts. An analysis of why and how an incident happened is crucial for determining appropriate countermeasures to prevent the recurrence of the incident. Currently, there is a lack of structured methods for such an analysis, which would identify the causes of a security incident. In this paper, we present a structured method to perform the post-mortem analysis and to model the causes of an incident visually in a graph structure. This method is an extension of our earlier work on modeling software vulnerabilities. The goal of modeling incidents is to develop an understanding of what could have caused the security incident and how its recurrence can be prevented in the future. The method presented in this paper is intended to be used during the post-mortem analysis of incidents by incident response teams. Shanai Ardi, Nahid Shahmehri |
ARES | 2 |
| 2009 | Prioritisation and Selection of Software Security ActivitiesabstractSoftware security is accomplished by introducing security-related activities into the software development process or by altering existing activities so that security is taken into account. Since the importance of software security has only relatively recently received the recognition it deserves, security is not ingrained into the development processes in common use today. A variety of approaches to software security have been proposed, but they rarely support developers in determining which security activities are appropriate for them and which they should choose to implement. An exception to this rule is the sustainable software security process (S3P). This paper describes the final step of the S3P, which helps developers estimate the cost of security-related activities and select the combination of security activities that best suits their needs. This is accomplished by applying the analytic hierarchy process and an automated search heuristic, scatter search, to the models created as part of the S3P. David Byers, Nahid Shahmehri |
ARES | 2 |
| 2009 | An Architectural Foundation for Security Model Sharing and ReuseabstractWithin the field of software security we have yet to find efficient ways on how to learn from past mistakes and integrate security as a natural part of software development.This situation can be improved by using an online repository, the SHIELDS SVRS, that facilitates fast and easy interchange of security artefacts between security experts, software developers and their assisting tools. Such security artefacts are embedded in or represented as security models containing the needed information to detect, remove and prevent vulnerabilities in software, independent of the applied development process. The purpose of this paper is to explain the main reference architecture description of the repository and the more general tool stereotypes that can communicate with it. Per Håkon Meland, Shanai Ardi, Jostein Jensen, Erkuden Rios, Txus Sanchez, Nahid Shahmehri, Inger Anne Tøndel |
ARES | 6 |
| 2009 | Introducing Vulnerability Awareness to Common Criteria's Security TargetsabstractSecurity of software systems has become one of the biggest concerns in our everyday life, since software systems are increasingly used by individuals, companies and governments. One way to help software system consumers gain assurance about the security measures of software products is to evaluate and certify these products with standard evaluation processes. The Common Criteria (ISO/IEC 15408) evaluation scheme is a standard that is widely used by software vendors. This process does not include information about already known vulnerabilities, their attack data and lessons learned from them. This has resulted in criticisms concerning the accuracy of this evaluation scheme since it might not address the areas in which actual vulnerabilities might occur. In this paper, we present a methodology that introduces information about threats from vulnerabilities to Common Criteria documents. Our methodology improves the accuracy of the Common Criteria by providing information about known vulnerabilities in Common Criteria's security target. Our methodology also provides documentation about how to fulfill certain security requirements, which can reduce the time for evaluation of the products. Shanai Ardi, Nahid Shahmehri |
ICSEA | 2 |
| 2008 | Integrating a Security Plug-in with the OpenUP/Basic Development ProcessabstractIn this paper we present a security plug-in for the OpenUP/Basic development process. Our security plug-in is based on a structured unified process for secure software development, named S3P (sustainable software security process). This process provides the formalism required to identify the causes of vulnerabilities and the mitigation techniques that prevent these vulnerabilities. We also present the results of an expert evaluation of the security plug-in. The lessons learned from development of the plug-in and the results of the evaluation will be used when adapting S3P to other software development processes. Shanai Ardi, Nahid Shahmehri |
ARES | 2 |
| 2008 | A Cause-Based Approach to Preventing Software VulnerabilitiesabstractSecurity is often an afterthought in software development, sometimes even bolted on during deployment or in maintenance through add-on security software and penetrate-and-patch maintenance. We think that security needs to be an integral part of software development and that preventing vulnerabilities by addressing their causes is as important as detecting and fixing them. In this paper we present a method for determining how to prevent vulnerabilities from being introduced during software development. Our method allows developers to select the set of activities that suits them best while being assured that those activities will prevent vulnerabilities. Our method is based on formal modeling of vulnerability causes and is independent of the software development process being used. David Byers, Nahid Shahmehri |
ARES | 2 |
| 2007 | How can the developer benefit from security modeling?abstractSecurity has become a necessary part of nearly every software development project, as the overall risk from malicious users is constantly increasing, due to increased consequences of failure, security threats and exposure to threats. There are few projects today where software security can be ignored. Despite this, security is still rarely taken into account throughout the entire software lifecycle; security is often an afterthought, bolted on late in development, with little thought to what threats and exposures exist. Little thought is given to maintaining security in the face of evolving threats and exposures. Software developers are usually not security experts. However, there are methods and tools available today that can help developers build more secure software. Security modeling, modeling of e.g., threats and vulnerabilities, is one such method that, when integrated in the software development process, can help developers prevent security problems in software. We discuss these issues, and present how modeling tools, vulnerability repositories and development tools can be connected to provide support for secure software development Shanai Ardi, David Byers, Per Håkon Meland, Inger Anne Tøndel, Nahid Shahmehri |
ARES | 5 |
| 2007 | Design of a Process for Software SecurityabstractSecurity is often an afterthought when developing software, and is often bolted on late in development or even during deployment or maintenance, through activities such as penetration testing, add-on security software and penetrate-and-patch maintenance. We believe that security needs to be built in to the software from the beginning, and that security activities need to take place throughout the software lifecycle. Accomplishing this effectively and efficiently requires structured approach combining a detailed understanding on what causes vulnerabilities, and how to prevent them. In this paper we present a process for software security that is based on vulnerability cause graphs, a formalism we have developed for modeling the causes of software vulnerabilities. The purpose of the software security process is to evolve the software development process so that vulnerabilities are prevented. The process we present differs from most current approaches to software security in its high degree of adaptability and in its ability to evolve in step with changing threats and risks. This paper focuses on how to apply the process and the criteria that have influenced the process design David Byers, Nahid Shahmehri |
ARES | 2 |
| 2007 | Usability and Security of Personal Firewalls
Almut Herzog, Nahid Shahmehri |
SEC | 2 |
| 2007 | An Ontology of Information SecurityabstractWe present a publicly available, OWL-based ontology of information security which models assets, threats, vulnerabilities, countermeasures and their relations. The ontology can be used as a general vocabulary, roadmap, and extensible dictionary of the domain of information security. With its help, users can agree on a common language and definition of terms and relationships. In addition to browsing for information, the ontology is also useful for reasoning about relationships between its entities, for example, threats and countermeasures. The ontology helps answer questions like: Which countermeasures detect or prevent the violation of integrity of data? Which assets are protected by SSH? Which countermeasures thwart buffer overflow attacks? At the moment, the ontology comprises 88 threat classes, 79 asset classes, 133 countermeasure classes and 34 relations between those classes. We provide the means for extending the ontology, and provide examples of the extendibility with the countermeasure classes ‘memory protection’ and ‘source code analysis’. This article describes the content of the ontology as well as its usages, potential for extension, technical implementation and tools for working with it. Almut Herzog, Nahid Shahmehri, Claudiu Duma |
Int. J. Inf. Secur. Priv. | 2 |
| 2007 | Usable set-up of runtime security policiesabstractPurpose This paper aims to present concrete and verified guidelines for enhancing the usability and security of software that delegates security decisions to lay users and captures these user decisions as a security policy. Design/methodology/approach This work is an exploratory study. The authors hypothesised that existing tools for runtime set‐up of security policies are not sufficient. As this proved true, as shown in earlier work, they apply usability engineering with user studies to advance the state‐of‐the‐art. Findings Little effort has been spent on how security policies can be set up by the lay users for whom they are intended. This work identifies what users want and need for a successful runtime set‐up of security policies. Practical implications Concrete and verified guidelines are provided for designers who are faced with the task of delegating security decisions to lay users. Originality/value The devised guidelines focus specifically on the set‐up of runtime security policies and therefore on the design of alert windows. Almut Herzog, Nahid Shahmehri |
Inf. Manag. Comput. Secur. | 2 |
| 2007 | On the Design of Safety Communication Systems for VehiclesabstractStatistics show that the number of casualties due to traffic accidents exceeds one million each year. For the development of systems that prevent vehicle collisions, vehicular communication is considered a promising technology. This paper focuses on design aspects of communication systems that support the development of collaborative active safety systems such as collision warning and collision avoidance. We introduce a design method for safety communication systems that includes a set of analyses and a reasoning system for modeling and analyzing traffic scenarios. An overview of a specific solution for communication is presented in this paper. This solution proposes techniques for network organization and data dissemination that make use of contextual information. This allows the development of a communication system that is adaptable to the specifics of the traffic situation. Ioan Chisalita, Nahid Shahmehri |
IEEE Trans. Syst. Man Cybern. Part A | 2 |
| 2006 | A Platform to Evaluate the Technology for Service Discovery in the Semantic Web
Cécile Aberg, Johan Aberg, Patrick Lambrix, Nahid Shahmehri |
AAAI | 4 |
| 2006 | Semantic Web Policies - A Discussion of Requirements and Research Issues
Piero A. Bonatti, Claudiu Duma, Norbert E. Fuchs, Wolfgang Nejdl, Daniel Olmedilla, Joachim Peer, Nahid Shahmehri |
ESWC | 7 |
| 2006 | Modeling Software VulnerabilitiesWith Vulnerability Cause GraphsabstractWhen vulnerabilities are discovered in software, which often happens after deployment, they must be addressed as part of ongoing software maintenance. A mature software development organization should analyze vulnerabilities in order to determine how they, and similar vulnerabilities, can be prevented in the future. In this paper we present a structured method for analyzing and documenting the causes of software vulnerabilities. Applied during software maintenance, the method generates the information needed for improving the software development process, to prevent similar vulnerabilities in future releases. Our approach is based on vulnerability cause graphs, a structured representation of causes of software vulnerabilities David Byers, Shanai Ardi, Nahid Shahmehri, Claudiu Duma |
ICSM | 3 |
| 2006 | Adaptive Dissemination of Safety Data Among VehiclesabstractIn-vehicle active safety systems are directed towards reducing the number of accidents or at least alleviating their consequences. One of the key technologies for developing these systems is safety vehicular communication. This paper proposes an adaptive approach to dissemination of safety data among vehicles. This data is then used by systems in vehicles for identifying hazards in traffic and reacting to them. We propose a proactive protocol that makes use of contextual information for adapting the communication to the specifics of the traffic situation. Communication performance is investigated via simulations and indicates that efficient vehicular communication can be provided by the proposed protocol Ioan Chisalita, Nahid Shahmehri |
PIMRC | 2 |
| 2006 | A Usability Study of Security Policy ManagementabstractSecurity policy management is a difficult and security-critical task. We have evaluated Java’s policytool with a usability study to see how well it can support users in setting up an appropriate security policy. The Java policytool is a graphical user interface tool integrated into Sun Microsystem Inc.’s Java 5.0 distribution for setting up security policies that can enable e.g. applets with more permissions than the default sandbox. Results show that policytool is in line with other security tools, namely usability is poor. Policytool provides a certain degree of syntax help to novice users but it does not help with semantics, does not cater to expert users and actually does promote the accidental set-up of too lenient a policy. We show specific usability problems in policytool, comment on the differences in the policy files created by our study users, explore ways of solving the error-prone task of setting up a Java policy and relate this to the general subject of usability of security tools. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Almut Herzog, Nahid Shahmehri |
SEC | 2 |
| 2006 | Oscar - File Type Identification of Binary Data in Disk Clusters and RAM Pages
Martin Karresand, Nahid Shahmehri |
SEC | 2 |
| 2005 | What help do older people need?: constructing a functional design space of electronic assistive technology applicationsabstractIn times of ageing populations and shrinking care resources, electronic assistive technology (EAT) has the potential of contributing to guaranteeing frail older people a continued high quality of life. This paper provides users and designers of EAT with an instrument for choosing and producing relevant and useful EAT applications in the form of a functional design space. We present the field study that led to the design space, and give advice on using the tool. Dennis Maciuszek, Johan Aberg, Nahid Shahmehri |
ASSETS | 3 |
| 2005 | Performance of the Java security manager
Almut Herzog, Nahid Shahmehri |
Comput. Secur. | 2 |
| 2004 | A context-based vehicular communication protocolabstractResearch in traffic safety has indicated that active safety systems provide a better service to drivers when they use data about nearby vehicles. For supplying such information inter-vehicle communication is employed. In this paper we propose a distributed communication protocol that allows the vehicles to organize the communication network in a decentralized manner. For information dissemination we use an anonymous context-based broadcast protocol. The receivers determine whether they are the intended destination of sent messages based on knowledge about their local environment. Simulation results indicate that the proposed protocol performs well in terms of communication performance and filtering of the received information. Ioan Chisalita, Nahid Shahmehri |
PIMRC | 2 |
| 2003 | A Flexible Category-Based Collusion-Restistant Key Management Scheme for Multicast
Claudiu Duma, Nahid Shahmehri, Patrick Lambrix |
SEC | 2 |
| 2002 | A Framework for Generating Task Specific Information Extraction Systems
Cécile Aberg, Nahid Shahmehri |
ISMIS | 2 |
| 2002 | Intelligent Software Delivery Using P2PabstractInternet has given software providers possibilities for electronic software distribution (ESD). At the same time bandwidth limitations lead to poor performance and scalability of the delivery process. The problem is even harder when delivering large, resource consuming software packages and media content. We propose an agent-based architectural model as a middleware for intelligent P2P electronic software delivery. We analyze the possibility of applying the peer-to-peer technology to the process of software delivery, relying on the experience and learned lessons of the related technologies. To this effect we analyze the available material on this topic and identify the important criteria that are crucial for the wide acceptance of ESD by both software providers and end-users. We argue that the proposed model can be used in building a system that meets most, if not all, of the identified criteria. The work presented opens a number of interesting research issues and investigation opportunities. Eduard Turcan, Nahid Shahmehri, Ross Lee Graham |
Peer-to-Peer Computing | 2 |
| 2002 | An in-vehicle approach for improving traffic safety through GIS utilizationabstractThis paper focuses on the utilization and integration of geographic information systems (GIS) oriented to tragic safety in vehicles. We have primarily analyzed the benefits of introducing GIS systems that support the driver and provide processed data to collision warning and collision avoidance systems located in vehicles. Further on, we have defined a set of information that is relevant for traffic safety and appropriate to be used within an in-vehicle GIS system. Based on these data, we propose in this paper a specific design for the GIS system. This system integrates the relevant data for traffic safety and takes into consideration the specific requirements of the vehicular domain. The integration of the GIS system within vehicles introduces a series of problems that are discussed in the paper. Ioan Chisalita, Nahid Shahmehri |
SMC (2) | 2 |
| 2001 | An empirical study of human Web assistants: implications for user support in Web information systemsabstractUser support is an important element in reaching the goal of universal usability for Web information systems. Recent developments indicate that human involvement in user support is a step towards this goal. However, most such efforts are currently being pursued on a purely intuitive basis. This, empirical findings about the role of human assistants are important. In this paper we present the findings from a field study of a general user support model for Web information systems. We show that integrating human assistance into Web systems is a way to provide efficient user support. Further, this integration makes a Web site more fun to use and increases the user's trust in the site. The support also improves the site atmosphere. Our findings are summarised as recommendations and design guidelines for decision-makers and developers Web systems. Johan Aberg, Nahid Shahmehri |
CHI | 2 |
| 2001 | User modelling for live help systems: initial resultsabstractThis paper explores the role of user modelling in live help systems for e-commerce web sites. There are several potential benefits with user modelling in this context: 1) Human assistants can use the personal information in the user models to provide the users with efficient support tailored to their personal needs; 2) Assistants can be more comfortable in their supporting role; 3) Consultation resources can be saved, and thus, financial savings can be made for the e-commerce company. A user modelling approach has been implemented and deployed in a real web environment as part of a live help system. Following the deployment we have analysed consultation dialogue logs and answers to a questionnaire for participating assistants. The initial results show that assistants consider user modelling to be helpful and that consultation dialogues can be an important source for user model data collection. Johan Aberg, Nahid Shahmehri, Dennis Maciuszek |
EC | 2 |
| 2000 | Template Generation for Identifying Text Patterns
Cécile Boisson, Nahid Shahmehri |
ISMIS | 2 |
| 2000 | Querying Documents using Content, Structure and Properties
Patrick Lambrix, Nahid Shahmehri |
J. Intell. Inf. Syst. | 2 |
| 1999 | Querying Document Bases by Content, Structure and Properties
Patrick Lambrix, Nahid Shahmehri, Svend Jacobsen |
ISMIS | 2 |
| 1995 | Usability criteria for automated debugging systems
Nahid Shahmehri, Mariam Kamkar, Peter Fritzson |
J. Syst. Softw. | 1 |
| 1994 | Using assertions in declarative and operational models for automated debugging
Peter Fritzson, Mikhail Auguston, Nahid Shahmehri |
J. Syst. Softw. | 3 |
| 1993 | Interprocedural Dynamic Slicing Applied to Interprocedural Data How TestingabstractDuring the past ten years several variants of an analysis technique called program slicing have been developed. Program slicing has applications in maintenance tasks such as debugging, testing, program integration, program verification, etc. and can be characterized as a type of dependence analysis. A program slice can loosely be defined as the subset of a program needed to compute a certain variable value at a certain program position. A novel method for interprocedural dynamic slicing which is more precise than interprocedural static slicing methods and is useful for dependence analysis at the procedural abstraction level was given by M. Kamkar et al. (1992, 1993). It is demonstrated here how interprocedural dynamic slicing can be used to increase the reliability and precision of interprocedural data flow testing. The work on data flow testing reported by E. Duesterwald et al. (1992), which is a novel method for data flow testing through output influences, is generalized.> Mariam Kamkar, Peter Fritzson, Nahid Shahmehri |
ICSM | 3 |
| 1993 | Three approaches to interprocedural dynamic slicing
Mariam Kamkar, Peter Fritzson, Nahid Shahmehri |
Microprocess. Microprogramming | 3 |
| 1991 | Generalized Algorithmic Debugging and TestingabstractThis paper presents a method for semi-automatic bug localization, generalized algorithmic debugging, which has been integrated with the category partition method for functional testing. In this way the efficiency of the algorithmic debugging method for bug localization can be improved by using test specifications and test results. The long-range goal of this work is a semi-automatic debugging and testing system which can be used during large-scale program development of nontrivial programs. The method is generally applicable to procedural languages and is not dependent on any ad hoc assumptions regarding the subject program. The original form of algorithmic debugging, introduced by Shapiro, was however limited to small Prolog programs without side-effects, but has later been generalized to concurrent logic programming languages. Another drawback of the original method is the large number of interactions with the user during bug localization. To our knowledge, this is the first method which uses category partition testing to improve the bug localization properties of algorithmic debugging. The method can avoid irrelevant questions to the programmer by categorizing input parameters and then match these against test cases in the test database. Additionally, we use program slicing, a data flow analysis technique, to Peter Fritzson, Tibor Gyimóthy, Mariam Kamkar, Nahid Shahmehri |
PLDI | 4 |
| 1990 | Semi-automatic bug localization in software maintenanceabstractAn algorithmic program debugger for imperative languages is presented, with Pascal as an example case. This debugger extends the power of existing debuggers by providing an interactive debugging facility where errors can be localized semiautomatically. The debugger is activated on demand when the user discovers a symptom of an error as the result of some computation. This symptom presumably denotes a difference between the intended program behavior and the actual behavior. The proposed approach consists of three phases: program transformation, tracing, and debugging. The first phase transforms the source program into an internal representation which is appropriate, according to the Shapiro model, for algorithmic debugging. This phase produces an intermediate program which is free from side effects and loops. The program tracing phase generates trace information which builds an execution tree for the erroneous program. The debugging phase performs bug localization through a number of user interactions. This phase consists of pure algorithmic program debugging and program slicing.> Nahid Shahmehri, Mariam Kamkar, Peter Fritzson |
ICSM | 1 |