Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Dongseok Jang

dblp:12/483 · DBLP profile ↗
← Back
4ranked-venue papers
3as first author
0since 2021 · last 2014
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-authorSoftware engineering, systems software and programming languages · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Systems and software security · 80% Privacy and data protection · 14% Web and mobile security · 6%
Software engineering, system software, and programming languages
3 papers
Program verification · 95% Program analysis · 5%

Topics — the 11 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
memory safety
0.212014
SafeDispatch: Securing C++ Virtual Calls from Memory Corruption Attacks · NDSS 2014
Systems and software security › software protection
virtual call protection
0.212014
SafeDispatch: Securing C++ Virtual Calls from Memory Corruption Attacks · NDSS 2014
Program verification
proof assistants
0.212014
Automating formal proofs for reactive systems · PLDI 2014
Program verification › proof assistants
proof automation
0.212014
Automating formal proofs for reactive systems · PLDI 2014
Program verification
reactive system verification
0.212014
Automating formal proofs for reactive systems · PLDI 2014
Systems and software security › information flow control
information flow policies
0.112010
An empirical study of privacy-violating information flows in JavaScript web applications · CCS 2010
Privacy and data protection
web privacy
0.112010
An empirical study of privacy-violating information flows in JavaScript web applications · CCS 2010
Systems and software security
exploitation
0.112014
SafeDispatch: Securing C++ Virtual Calls from Memory Corruption Attacks · NDSS 2014
Systems and software security › exploitation
memory corruption attack
0.112014
SafeDispatch: Securing C++ Virtual Calls from Memory Corruption Attacks · NDSS 2014
Web and mobile security
browser security
0.012012
Establishing Browser Security Guarantees through Formal Shim Verification · USENIX Security Symposium 2012
Program analysis › dynamic analysis
dynamic information-flow tracking
0.012010
An empirical study of privacy-violating information flows in JavaScript web applications · CCS 2010

Methods — techniques the papers use, named apart from their topics

shim verification · 0.3rewriting-based information flow engine · 0.2proof assistant · 0.2coq · 0.2control-flow integrity · 0.2
YearPublicationVenuePosition
2014 SafeDispatch: Securing C++ Virtual Calls from Memory Corruption Attacks
Dongseok Jang, Zachary Tatlock, Sorin Lerner
NDSS1
2014 Automating formal proofs for reactive systems
abstract
Implementing systems in proof assistants like Coq and proving their correctness in full formal detail has consistently demonstrated promise for making extremely strong guarantees about critical software, ranging from compilers and operating systems to databases and web browsers. Unfortunately, these verifications demand such heroic manual proof effort, even for a single system, that the approach has not been widely adopted.
Daniel Ricketts 0001, Valentin Robert, Dongseok Jang, Zachary Tatlock, Sorin Lerner
PLDI3
2012 Establishing Browser Security Guarantees through Formal Shim Verification
Dongseok Jang, Zachary Tatlock, Sorin Lerner
USENIX Security Symposium1
2010 An empirical study of privacy-violating information flows in JavaScript web applications
abstract
The dynamic nature of JavaScript web applications has given rise to the possibility of privacy violating information flows. We present an empirical study of the prevalence of such flows on a large number of popular websites. We have (1) designed an expressive, fine-grained information flow policy language that allows us to specify and detect different kinds of privacy-violating flows in JavaScript code,(2) implemented a new rewriting-based JavaScript information flow engine within the Chrome browser, and (3) used the enhanced browser to conduct a large-scale empirical study over the Alexa global top 50,000 websites of four privacy-violating flows: cookie stealing, location hijacking, history sniffing, and behavior tracking. Our survey shows that several popular sites, including Alexa global top-100 sites, use privacy-violating flows to exfiltrate information about users' browsing behavior. Our findings show that steps must be taken to mitigate the privacy threat from covert flows in browsers.
Dongseok Jang, Ranjit Jhala, Sorin Lerner, Hovav Shacham
CCS1