Valentin Pistol

dblp:131/6049 · DBLP profile ↗
← Back
4ranked-venue papers
0as first author
0since 2021 · last 2018
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 2Systems, architecture and hardware · 1Security and privacy · 1Software engineering, systems software and programming languages · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Systems and software security · 75% Web and mobile security · 20% Usable security · 5%
Computer architecture, parallel and distributed computing, and storage systems
2 papers
Cloud and datacenter computing · 35% GPUs and heterogeneous computing · 35% Processor architecture and microarchitecture · 18%
Software engineering, system software, and programming languages
1 paper
Operating systems · 100%

Topics — the 9 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › information flow tracking
dynamic information flow tracking
0.312018
SandTrap: Tracking Information Flows On Demand with Parallel Permissions · MobiSys 2018
Operating systems › resource management › memory management
memory protection
0.312018
SandTrap: Tracking Information Flows On Demand with Parallel Permissions · MobiSys 2018
Web and mobile security
mobile security
0.212014
SpanDex: Secure Password Tracking for Android · USENIX Security Symposium 2014
Systems and software security
operating system security
0.212013
ScreenPass: secure password entry on touchscreen devices · MobiSys 2013
Systems and software security › information flow tracking
taint analysis
0.212013
ScreenPass: secure password entry on touchscreen devices · MobiSys 2013
Processor architecture and microarchitecture › multithreading
multithreaded execution
0.112018
SandTrap: Tracking Information Flows On Demand with Parallel Permissions · MobiSys 2018
Systems and software security
memory safety
0.112014
SpanDex: Secure Password Tracking for Android · USENIX Security Symposium 2014
Energy-efficient computing
datacenter energy efficiency
0.112014
Rhythm: harnessing data parallel hardware for server workloads · ASPLOS 2014
Usable security
authentication usability
0.012013
ScreenPass: secure password entry on touchscreen devices · MobiSys 2013

Methods — techniques the papers use, named apart from their topics

parallel permissions · 1.0binary instrumentation · 1.0dynamic taint analysis · 0.2data parallel hardware · 0.2taint tracking · 0.2optical character recognition · 0.2
YearPublicationVenuePosition
2018 SandTrap: Tracking Information Flows On Demand with Parallel Permissions
abstract
The most promising way to improve the performance of dynamic information-flow tracking (DIFT) for machine code is to only track instructions when they process tainted data. Unfortunately, prior approaches to on-demand DIFT are a poor match for modern mobile platforms that rely heavily on parallelism to provide good interactivity in the face of computationally intensive tasks like image processing. The main shortcoming of these prior efforts is that they cannot support an arbitrary mix of parallel threads due to the limitations of page protections.
Ali Razeen, Alvin R. Lebeck, David H. Liu, Alexander Meijer, Valentin Pistol, Landon P. Cox
MobiSys5
2014 Rhythm: harnessing data parallel hardware for server workloads
abstract
Trends in increasing web traffic demand an increase in server throughput while preserving energy efficiency and total cost of ownership. Present work in optimizing data center efficiency primarily focuses on the data center as a whole, using off-the-shelf hardware for individual servers. Server capacity is typically increased by adding more machines, which is cheap, though inefficient in the long run in terms of energy and area.
Sandeep R. Agrawal, Valentin Pistol, Jun Pang 0001, David Tarjan, Alvin R. Lebeck
ASPLOS2
2014 SpanDex: Secure Password Tracking for Android
Landon P. Cox, Peter Gilbert, Geoffrey Lawler, Valentin Pistol, Ali Razeen, Sai Cheemalapati
USENIX Security Symposium4
2013 ScreenPass: secure password entry on touchscreen devices
abstract
Users routinely access cloud services through third-party apps on smartphones by giving apps login credentials (i.e., a username and password). Unfortunately, users have no assurance that their apps will properly handle this sensitive information. In this paper, we describe the design and implementation of ScreenPass, which significantly improves the security of passwords on touchscreen devices. ScreenPass secures passwords by ensuring that they are entered securely, and uses taint-tracking to monitor where apps send password data. The primary technical challenge addressed by ScreenPass is guaranteeing that trusted code is always aware of when a user is entering a password. ScreenPass provides this guarantee through two techniques. First, ScreenPass includes a trusted software keyboard that encourages users to specify their passwords' domains as they are entered (i.e., to tag their passwords). Second, ScreenPass performs optical character recognition (OCR) on a device's screenbuffer to ensure that passwords are entered only through the trusted software keyboard. We have evaluated ScreenPass through experiments with a prototype implementation, two in-situ user studies, and a small app study. Our prototype detected a wide range of dynamic and static keyboard-spoofing attacks and generated zero false positives. As long as a screen is off, not updated, or not tapped, our prototype consumes zero additional energy; in the worst case, when a highly interactive app rapidly updates the screen, our prototype under a typical configuration introduces only 12% energy overhead. Participants in our user studies tagged their passwords at a high rate and reported that tagging imposed no additional burden. Finally, a study of malicious and non-malicious apps running under ScreenPass revealed several cases of password mishandling.
Dongtao Liu, Eduardo Cuervo Laffaye, Valentin Pistol, Ryan Scudellari, Landon P. Cox
MobiSys3