Robert Gawlik

dblp:150/5154 · DBLP profile ↗
← Back
15ranked-venue papers
3as first author
0since 2021 · last 2019
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 3 first-authorSystems, architecture and hardware · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
6 papers
Systems and software security · 72% Digital forensics and information hiding · 20% Hardware security and side channels · 3%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Processor architecture and microarchitecture · 50% Electronic design automation · 50%
Software engineering, system software, and programming languages
1 paper
Software testing · 100%

Topics — the 17 heaviest of 17, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
vulnerability discovery
0.522017
kAFL: Hardware-Assisted Feedback Fuzzing for OS Kernels · USENIX Security Symposium 2017
Cross-Architecture Bug Search in Binary Executables · IEEE Symposium on Security and Privacy 2015
Systems and software security
exploitation
0.422016
Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding · NDSS 2016
Dynamic Hooks: Hiding Control Flow Changes within Non-Control Data · USENIX Security Symposium 2014
Software testing
fuzzing
0.412019
REDQUEEN: Fuzzing with Input-to-State Correspondence · NDSS 2019
Digital forensics and information hiding
information hiding
0.322016
Undermining Information Hiding (and What to Do about It) · USENIX Security Symposium 2016
Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding · NDSS 2016
Systems and software security › vulnerability discovery
fuzzing
0.312017
kAFL: Hardware-Assisted Feedback Fuzzing for OS Kernels · USENIX Security Symposium 2017
Systems and software security › vulnerability discovery › fuzzing
kernel fuzzing
0.312017
kAFL: Hardware-Assisted Feedback Fuzzing for OS Kernels · USENIX Security Symposium 2017
Processor architecture and microarchitecture
microprogramming
0.312017
Reverse Engineering x86 Processor Microcode · USENIX Security Symposium 2017
Electronic design automation › hardware verification and test
reverse engineering
0.312017
Reverse Engineering x86 Processor Microcode · USENIX Security Symposium 2017
Systems and software security
software diversity
0.212016
Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding · NDSS 2016
Digital forensics and information hiding
steganography
0.212016
Undermining Information Hiding (and What to Do about It) · USENIX Security Symposium 2016
Systems and software security › exploitation
non-control data attack
0.212014
Dynamic Hooks: Hiding Control Flow Changes within Non-Control Data · USENIX Security Symposium 2014
Software testing › fuzzing
coverage-guided fuzzing
0.112019
REDQUEEN: Fuzzing with Input-to-State Correspondence · NDSS 2019
Hardware security and side channels
hardware reverse engineering
0.112017
Reverse Engineering x86 Processor Microcode · USENIX Security Symposium 2017
Systems and software security
memory safety
0.112016
Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding · NDSS 2016
Network security
traffic analysis
0.112016
Undermining Information Hiding (and What to Do about It) · USENIX Security Symposium 2016
Security and privacy of machine learning › adversarial attack › backdoor attack › backdoor defense
backdoor detection
0.112015
Cross-Architecture Bug Search in Binary Executables · IEEE Symposium on Security and Privacy 2015
Systems and software security
firmware analysis
0.112015
Cross-Architecture Bug Search in Binary Executables · IEEE Symposium on Security and Privacy 2015

Methods — techniques the papers use, named apart from their topics

fuzzing · 0.4hardware tracing · 0.3intermediate representation · 0.2dynamic analysis · 0.2concrete input sampling · 0.2
YearPublicationVenuePosition
2019 Static Detection of Uninitialized Stack Variables in Binary Code
Behrad Garmany, Martin Stoffel, Robert Gawlik, Thorsten Holz
ESORICS (2)3
2019 REDQUEEN: Fuzzing with Input-to-State Correspondence
Cornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik, Thorsten Holz
NDSS4
2018 Towards Automated Generation of Exploitation Primitives for Web Browsers
abstract
The growing dependence on software and the increasing complexity of such systems builds and feeds the attack surface for exploitable vulnerabilities. Security researchers put up a lot of effort to develop exploits and analyze existing exploits with the goal of staying ahead of the state-of-the-art in attacks and defenses. The urge for automated systems that operate at scale, speed and efficiency is therefore undeniable. Given their complexity and large user base, web browsers pose an attractive target. Due to various mitigation strategies, the exploitation of a browser vulnerability became a time consuming, multi-step task: creating a working exploit even from a crashing input is a resource-intensive task that can take a substantial amount of time to complete. In many cases, the input, which triggers a vulnerability follows a crashing path but does not enter an exploitable state.
Behrad Garmany, Martin Stoffel, Robert Gawlik, Philipp Koppe, Tim Blazytko, Thorsten Holz
ACSAC3
2018 On the Weaknesses of Function Table Randomization
Moritz Contag, Robert Gawlik, Andre Pawlowski, Thorsten Holz
DIMVA2
2017 Towards Automated Discovery of Crash-Resistant Primitives in Binary Executables
abstract
Many modern defenses rely on address space layout randomization (ASLR) to efficiently hide security-sensitive metadata in the address space. Absent implementation flaws, an attacker can only bypass such defenses by repeatedly probing the address space for mapped (security-sensitive) regions, incurring a noisy application crash on any wrong guess. Recent work shows that modern applications contain idioms that allow the construction of crash-resistant code primitives, allowing an attacker to efficiently probe the address space without causing any visible crash. In this paper, we classify different crash-resistant primitives and show that this problem is much more prominent than previously assumed. More specifically, we show that rather than relying on labor-intensive source code inspection to find a few "hidden" application-specific primitives, an attacker can find such primitives semi-automatically, on many classes of real-world programs, at the binary level. To support our claims, we develop methods to locate such primitives in real-world binaries. We successfully identified 29 new potential primitives and constructed proof-of-concept exploits for four of them.
Benjamin Kollenda, Enes Göktas, Tim Blazytko, Philipp Koppe, Robert Gawlik, Radhesh Krishnan Konoth, Cristiano Giuffrida, Herbert Bos, Thorsten Holz
DSN5
2017 Reverse Engineering x86 Processor Microcode
Philipp Koppe, Benjamin Kollenda, Marc Fyrbiak, Christian Kison, Robert Gawlik, Christof Paar, Thorsten Holz
USENIX Security Symposium5
2017 kAFL: Hardware-Assisted Feedback Fuzzing for OS Kernels
Sergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel, Thorsten Holz
USENIX Security Symposium3
2016 Detile: Fine-Grained Information Leak Detection in Script Engines
Robert Gawlik, Philipp Koppe, Benjamin Kollenda, Andre Pawlowski, Behrad Garmany, Thorsten Holz
DIMVA1
2016 Automated Multi-architectural Discovery of CFI-Resistant Code Gadgets
Patrick Wollgast, Robert Gawlik, Behrad Garmany, Benjamin Kollenda, Thorsten Holz
ESORICS (1)2
2016 Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding
Robert Gawlik, Benjamin Kollenda, Philipp Koppe, Behrad Garmany, Thorsten Holz
NDSS1
2016 Undermining Information Hiding (and What to Do about It)
Enes Göktas, Robert Gawlik, Benjamin Kollenda, Elias Athanasopoulos, Georgios Portokalidis, Cristiano Giuffrida, Herbert Bos
USENIX Security Symposium2
2015 Cross-Architecture Bug Search in Binary Executables
abstract
With the general availability of closed-source software for various CPU architectures, there is a need to identify security-critical vulnerabilities at the binary level to perform a vulnerability assessment. Unfortunately, existing bug finding methods fall short in that they i) require source code, ii) only work on a single architecture (typically x86), or iii) rely on dynamic analysis, which is inherently difficult for embedded devices. In this paper, we propose a system to derive bug signatures for known bugs. We then use these signatures to find bugs in binaries that have been deployed on different CPU architectures (e.g., x86 vs. MIPS). The variety of CPU architectures imposes many challenges, such as the incomparability of instruction set architectures between the CPU models. We solve this by first translating the binary code to an intermediate representation, resulting in assignment formulas with input and output variables. We then sample concrete inputs to observe the I/O behavior of basic blocks, which grasps their semantics. Finally, we use the I/O behavior to find code parts that behave similarly to the bug signature, effectively revealing code parts that contain the bug. We have designed and implemented a tool for cross architecture bug search in executables. Our prototype currently supports three instruction set architectures (x86, ARM, and MIPS) and can find vulnerabilities in buggy binary code for any of these architectures. We show that we can find Heart bleed vulnerabilities, regardless of the underlying software instruction set. Similarly, we apply our method to find backdoors in closed source firmware images of MIPS- and ARM-based routers.
Jannik Pewny, Behrad Garmany, Robert Gawlik, Christian Rossow, Thorsten Holz
IEEE Symposium on Security and Privacy3
2014 Towards automated integrity protection of C++ virtual function tables in binary programs
abstract
Web browsers are one of the most used, complex, and popular software systems nowadays. They are prone to dangling pointers that result in use-after-free vulnerabilites and this is the de-facto way to exploit them. From a technical point of view, an attacker uses a technique called vtable hijacking to exploit such bugs. More specifically, she crafts bogus virtual tables and lets a freed C++ object point to it in order to gain control over the program at virtual function call sites.
Robert Gawlik, Thorsten Holz
ACSAC1
2014 Automated generation of models for fast and precise detection of HTTP-based malware
abstract
Malicious software and especially botnets are among the most important security threats in the Internet. Thus, the accurate and timely detection of such threats is of great importance. Detecting machines infected with malware by identifying their malicious activities at the network level is an appealing approach, due to the ease of deployment. Nowadays, the most common communication channels used by attackers to control the infected machines are based on the HTTP protocol. To evade detection, HTTP-based malware adapt their behavior to the communication patterns of the benign HTTP clients, such as web browsers. This poses significant challenges to existing detection approaches like signature-based and behavioral-based detection systems. In this paper, we propose BO THO U N D: a novel approach to precisely detect HTTP-based malware at the network level. The key idea is that implementations of the HTTP protocol by different entities have small but perceivable differences. Building on this observation, BO THO U N D automatically generates models for malicious and benign requests and classifies at real time the HTTP traffic of a monitored network. Our evaluation results demonstrate that BO THO U N D outperforms prior work on identifying HTTP-based botnets, being able to detect a large variety of real-world HTTP-based malware, including advanced persistent threats used in targeted attacks, with a very low percentage of classification errors.
Apostolis Zarras, Antonis Papadogiannakis, Robert Gawlik, Thorsten Holz
PST3
2014 Dynamic Hooks: Hiding Control Flow Changes within Non-Control Data
Sebastian Vogl, Robert Gawlik, Behrad Garmany, Thomas Kittel 0001, Jonas Pfoh, Claudia Eckert 0001, Thorsten Holz
USENIX Security Symposium2