Luke Deshotels

dblp:120/6314 · DBLP profile ↗
← Back
3ranked-venue papers
3as first author
0since 2021 · last 2020
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Web and mobile security · 42% Authentication and access control · 29% Systems and software security · 29%
Software engineering, system software, and programming languages
1 paper
Program analysis · 87% Operating systems · 13%

Topics — the 7 heaviest of 7, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Authentication and access control
access control
0.412020
Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOS · SP 2020
Systems and software security › operating system security
inter-process communication security
0.412020
Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOS · SP 2020
Web and mobile security › mobile security
iOS security
0.422020
SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles · CCS 2016
Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOS · SP 2020
Web and mobile security
mobile security
0.212016
SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles · CCS 2016
Program analysis › static analysis
logic program analysis
0.212016
SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles · CCS 2016
Program analysis
static analysis
0.212016
SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles · CCS 2016
Operating systems › system security › operating system security › protection mechanism › isolation
sandboxing
0.112016
SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles · CCS 2016

Methods — techniques the papers use, named apart from their topics

prolog · 0.5logic programming · 0.5formal modeling · 0.5decompilation · 0.5static analysis · 0.4dynamic analysis · 0.4
YearPublicationVenuePosition
2020 Kobold: Evaluating Decentralized Access Control for Remote NSXPC Methods on iOS
abstract
Apple uses several access control mechanisms to prevent third party applications from directly accessing security sensitive resources, including sandboxing and file access control. However, third party applications may also indirectly access these resources using inter-process communication (IPC) with system daemons. If these daemons fail to properly enforce access control on IPC, confused deputy vulnerabilities may result. Identifying such vulnerabilities begins with an enumeration of all IPC services accessible to third party applications. However, the IPC interfaces and their corresponding access control policies are unknown and must be reverse engineered at a large scale. In this paper, we present the Kobold framework to study NSXPC-based system services using a combination of static and dynamic analysis. Using Kobold, we discovered multiple NSXPC services with confused deputy vulnerabilities and daemon crashes. Our findings include the ability to activate the microphone, disable access to all websites, and leak private data stored in iOS File Providers.
Luke Deshotels, Costin Carabas, Jordan Beichler, Razvan Deaconescu, William Enck
SP1
2018 iOracle: Automated Evaluation of Access Control Policies in iOS
abstract
Modern operating systems, such as iOS, use multiple access control policies to define an overall protection system. However, the complexity of these policies and their interactions can hide policy flaws that compromise the security of the protection system. We propose iOracle, a framework that logically models the iOS protection system such that queries can be made to automatically detect policy flaws. iOracle models policies and runtime context extracted from iOS firmware images, developer resources, and jailbroken devices, and iOracle significantly reduces the complexity of queries by modeling policy semantics. We evaluate iOracle by using it to successfully triage executables likely to have policy flaws and comparing our results to the executables exploited in four recent jailbreaks. When applied to iOS 10, iOracle identifies previously unknown policy flaws that allow attackers to modify or bypass access control policies. For compromised system processes, consequences of these policy flaws include sandbox escapes (with respect to read/write file access) and changing the ownership of arbitrary files. By automating the evaluation of iOS access control policies, iOracle provides a practical approach to hardening iOS security by identifying policy flaws before they are exploited.
Luke Deshotels, Razvan Deaconescu, Costin Carabas, Iulia Manda, William Enck, Mihai-Daniel Chiroiu, Ninghui Li 0001, Ahmad-Reza Sadeghi
AsiaCCS1
2016 SandScout: Automatic Detection of Flaws in iOS Sandbox Profiles
abstract
Recent literature on iOS security has focused on the malicious potential of third-party applications, demonstrating how developers can bypass application vetting and code-level protections. In addition to these protections, iOS uses a generic sandbox profile called "container" to confine malicious or exploited third-party applications. In this paper, we present the first systematic analysis of the iOS container sandbox profile. We propose the SandScout framework to extract, decompile, formally model, and analyze iOS sandbox profiles as logic-based programs. We use our Prolog-based queries to evaluate file-based security properties of the container sandbox profile for iOS 9.0.2 and discover seven classes of exploitable vulnerabilities. These attacks affect non-jailbroken devices running later versions of iOS. We are working with Apple to resolve these attacks, and we expect that SandScout will play a significant role in the development of sandbox profiles for future versions of iOS.
Luke Deshotels, Razvan Deaconescu, Mihai-Daniel Chiroiu, Lucas Davi, William Enck, Ahmad-Reza Sadeghi
CCS1