Orit Edelstein

dblp:10/4870 · DBLP profile ↗
← Back
3ranked-venue papers
1as first author
0since 2021 · last 2018
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 1 · 1 first-authorSecurity and privacy · 1Software engineering, systems software and programming languages · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Compilers and program optimization · 70% Program analysis · 23% Programming languages and type systems · 7%

Topics — the 5 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Compilers and program optimization
attribute grammar evaluation
0.011989
Resolving Circularity in Attribute Grammars with Applications to Data Flow Analysis · POPL 1989
Compilers and program optimization › attribute grammar evaluation
circular attribute grammar
0.011989
Resolving Circularity in Attribute Grammars with Applications to Data Flow Analysis · POPL 1989
Compilers and program optimization
compiler construction
0.011989
Resolving Circularity in Attribute Grammars with Applications to Data Flow Analysis · POPL 1989
Program analysis
data flow analysis
0.011989
Resolving Circularity in Attribute Grammars with Applications to Data Flow Analysis · POPL 1989
Programming languages and type systems › grammar formalisms
attribute grammars
0.011989
Resolving Circularity in Attribute Grammars with Applications to Data Flow Analysis · POPL 1989

Methods — techniques the papers use, named apart from their topics

attribute grammar translation · 0.0
YearPublicationVenuePosition
2018 Accurate Malware Detection by Extreme Abstraction
abstract
Modern malware applies a rich arsenal of evasion techniques to render dynamic analysis ineffective. In turn, dynamic analysis tools take great pains to hide themselves from malware; typically this entails trying to be as faithful as possible to the behavior of a real run. We present a novel approach to malware analysis that turns this idea on its head, using an extreme abstraction of the operating system that intentionally strays from real behavior. The key insight is that the presence of malicious behavior is sufficient evidence of malicious intent, even if the path taken is not one that could occur during a real run of the sample. By exploring multiple paths in a system that only approximates the behavior of a real system, we can discover behavior that would often be hard to elicit otherwise. We aggregate features from multiple paths and use a funnel-like configuration of machine learning classifiers to achieve high accuracy without incurring too much of a performance penalty. We describe our system, TAMALES (The Abstract Malware Analysis LEarning System), in detail and present machine learning results using a 330K sample set showing an FPR (False Positive Rate) of 0.10% with a TPR (True Positive Rate) of 99.11%, demonstrating that extreme abstraction can be extraordinarily effective in providing data that allows a classifier to accurately detect malware.
Fady Copty, Matan Danos, Orit Edelstein, Cindy Eisner, Dov Murik, Benjamin Zeltser
ACSAC3
2003 Framework for testing multi-threaded Java programs
abstract
Abstract Finding bugs due to race conditions in multi‐threaded programs is difficult, mainly because there are many possible interleavings, any of which may contain a fault. In this work we present a methodology for testing multi‐threaded programs which has minimal impact on the user and is likely to find interleaving bugs. Our method reruns existing tests in order to detect synchronization faults. We find that a single test executed a number of times in a controlled environment may be as effective in finding synchronization faults as many different tests. A great deal of resources are saved since tests are very expensive to write and maintain. We observe that simply rerunning tests, without ensuring in some way that the interleaving will change, yields almost no benefits. We implement the methodology in our test generation tool—ConTest. ConTest combines the replay algorithm, which is essential for debugging, with our interleaving test generation heuristics. ConTest also contains an instrumentation engine, a coverage analyzer, and a race detector (not finished yet) that enhance bug detection capabilities. The greatest advantage of ConTest, besides finding bugs of course, is its minimal effect on the user. When ConTest is combined into the test harness, the user may not even be aware that ConTest is being used. Copyright © 2003 John Wiley & Sons, Ltd.
Orit Edelstein, Eitan Farchi, Evgeny Goldin, Yarden Nir-Buchbinder, Gil Ratsaby, Shmuel Ur
Concurr. Comput. Pract. Exp.1
1989 Resolving Circularity in Attribute Grammars with Applications to Data Flow Analysis
abstract
Circular attribute grammars appear in many data flow analysis problems. As one way of making the notion useful, an automatic translation of circular attribute grammars to equivalent non-circular attribute grammars is presented. It is shown that for circular attribute grammars that arise in many data flow analysis problems, the translation does not increase the asymptotic complexity of the semantic equations. Therefore, the translation may be used in conjunction with any evaluator generator to automate the development of efficient data flow analysis algorithms. As a result, the integration of such algorithms with other parts of a compiler becomes easier.
Shmuel Sagiv, Orit Edelstein, Nissim Francez, Michael Rodeh
POPL2