EDBT 2026 Demo / reviewers in the wild / expert
Robert Gawlik
dblp:150/5154
· DBLP profile ↗
15ranked-venue papers
3as first author
0since 2021 · last 2019
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 3 first-authorSystems, architecture and hardware · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
6 papers |
Systems and software security · 72% Digital forensics and information hiding · 20% Hardware security and side channels · 3% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Processor architecture and microarchitecture · 50% Electronic design automation · 50% | |
| Software engineering, system software, and programming languages
1 paper |
Software testing · 100% |
Topics — the 17 heaviest of 17, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
vulnerability discovery |
0.5 | 2 | 2017 | kAFL: Hardware-Assisted Feedback Fuzzing for OS Kernels · USENIX Security Symposium 2017 Cross-Architecture Bug Search in Binary Executables · IEEE Symposium on Security and Privacy 2015 |
Systems and software security
exploitation |
0.4 | 2 | 2016 | Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding · NDSS 2016 Dynamic Hooks: Hiding Control Flow Changes within Non-Control Data · USENIX Security Symposium 2014 |
Software testing
fuzzing |
0.4 | 1 | 2019 | REDQUEEN: Fuzzing with Input-to-State Correspondence · NDSS 2019 |
Digital forensics and information hiding
information hiding |
0.3 | 2 | 2016 | Undermining Information Hiding (and What to Do about It) · USENIX Security Symposium 2016 Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding · NDSS 2016 |
Systems and software security › vulnerability discovery
fuzzing |
0.3 | 1 | 2017 | kAFL: Hardware-Assisted Feedback Fuzzing for OS Kernels · USENIX Security Symposium 2017 |
Systems and software security › vulnerability discovery › fuzzing
kernel fuzzing |
0.3 | 1 | 2017 | kAFL: Hardware-Assisted Feedback Fuzzing for OS Kernels · USENIX Security Symposium 2017 |
Processor architecture and microarchitecture
microprogramming |
0.3 | 1 | 2017 | Reverse Engineering x86 Processor Microcode · USENIX Security Symposium 2017 |
Electronic design automation › hardware verification and test
reverse engineering |
0.3 | 1 | 2017 | Reverse Engineering x86 Processor Microcode · USENIX Security Symposium 2017 |
Systems and software security
software diversity |
0.2 | 1 | 2016 | Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding · NDSS 2016 |
Digital forensics and information hiding
steganography |
0.2 | 1 | 2016 | Undermining Information Hiding (and What to Do about It) · USENIX Security Symposium 2016 |
Systems and software security › exploitation
non-control data attack |
0.2 | 1 | 2014 | Dynamic Hooks: Hiding Control Flow Changes within Non-Control Data · USENIX Security Symposium 2014 |
Software testing › fuzzing
coverage-guided fuzzing |
0.1 | 1 | 2019 | REDQUEEN: Fuzzing with Input-to-State Correspondence · NDSS 2019 |
Hardware security and side channels
hardware reverse engineering |
0.1 | 1 | 2017 | Reverse Engineering x86 Processor Microcode · USENIX Security Symposium 2017 |
Systems and software security
memory safety |
0.1 | 1 | 2016 | Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding · NDSS 2016 |
Network security
traffic analysis |
0.1 | 1 | 2016 | Undermining Information Hiding (and What to Do about It) · USENIX Security Symposium 2016 |
Security and privacy of machine learning › adversarial attack › backdoor attack › backdoor defense
backdoor detection |
0.1 | 1 | 2015 | Cross-Architecture Bug Search in Binary Executables · IEEE Symposium on Security and Privacy 2015 |
Systems and software security
firmware analysis |
0.1 | 1 | 2015 | Cross-Architecture Bug Search in Binary Executables · IEEE Symposium on Security and Privacy 2015 |
Methods — techniques the papers use, named apart from their topics
fuzzing · 0.4hardware tracing · 0.3intermediate representation · 0.2dynamic analysis · 0.2concrete input sampling · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2019 | Static Detection of Uninitialized Stack Variables in Binary Code
Behrad Garmany, Martin Stoffel, Robert Gawlik, Thorsten Holz |
ESORICS (2) | 3 |
| 2019 | REDQUEEN: Fuzzing with Input-to-State Correspondence
Cornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik, Thorsten Holz |
NDSS | 4 |
| 2018 | Towards Automated Generation of Exploitation Primitives for Web BrowsersabstractThe growing dependence on software and the increasing complexity of such systems builds and feeds the attack surface for exploitable vulnerabilities. Security researchers put up a lot of effort to develop exploits and analyze existing exploits with the goal of staying ahead of the state-of-the-art in attacks and defenses. The urge for automated systems that operate at scale, speed and efficiency is therefore undeniable. Given their complexity and large user base, web browsers pose an attractive target. Due to various mitigation strategies, the exploitation of a browser vulnerability became a time consuming, multi-step task: creating a working exploit even from a crashing input is a resource-intensive task that can take a substantial amount of time to complete. In many cases, the input, which triggers a vulnerability follows a crashing path but does not enter an exploitable state. Behrad Garmany, Martin Stoffel, Robert Gawlik, Philipp Koppe, Tim Blazytko, Thorsten Holz |
ACSAC | 3 |
| 2018 | On the Weaknesses of Function Table Randomization
Moritz Contag, Robert Gawlik, Andre Pawlowski, Thorsten Holz |
DIMVA | 2 |
| 2017 | Towards Automated Discovery of Crash-Resistant Primitives in Binary ExecutablesabstractMany modern defenses rely on address space layout randomization (ASLR) to efficiently hide security-sensitive metadata in the address space. Absent implementation flaws, an attacker can only bypass such defenses by repeatedly probing the address space for mapped (security-sensitive) regions, incurring a noisy application crash on any wrong guess. Recent work shows that modern applications contain idioms that allow the construction of crash-resistant code primitives, allowing an attacker to efficiently probe the address space without causing any visible crash. In this paper, we classify different crash-resistant primitives and show that this problem is much more prominent than previously assumed. More specifically, we show that rather than relying on labor-intensive source code inspection to find a few "hidden" application-specific primitives, an attacker can find such primitives semi-automatically, on many classes of real-world programs, at the binary level. To support our claims, we develop methods to locate such primitives in real-world binaries. We successfully identified 29 new potential primitives and constructed proof-of-concept exploits for four of them. Benjamin Kollenda, Enes Göktas, Tim Blazytko, Philipp Koppe, Robert Gawlik, Radhesh Krishnan Konoth, Cristiano Giuffrida, Herbert Bos, Thorsten Holz |
DSN | 5 |
| 2017 | Reverse Engineering x86 Processor Microcode
Philipp Koppe, Benjamin Kollenda, Marc Fyrbiak, Christian Kison, Robert Gawlik, Christof Paar, Thorsten Holz |
USENIX Security Symposium | 5 |
| 2017 | kAFL: Hardware-Assisted Feedback Fuzzing for OS Kernels
Sergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel, Thorsten Holz |
USENIX Security Symposium | 3 |
| 2016 | Detile: Fine-Grained Information Leak Detection in Script Engines
Robert Gawlik, Philipp Koppe, Benjamin Kollenda, Andre Pawlowski, Behrad Garmany, Thorsten Holz |
DIMVA | 1 |
| 2016 | Automated Multi-architectural Discovery of CFI-Resistant Code Gadgets
Patrick Wollgast, Robert Gawlik, Behrad Garmany, Benjamin Kollenda, Thorsten Holz |
ESORICS (1) | 2 |
| 2016 | Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding
Robert Gawlik, Benjamin Kollenda, Philipp Koppe, Behrad Garmany, Thorsten Holz |
NDSS | 1 |
| 2016 | Undermining Information Hiding (and What to Do about It)
Enes Göktas, Robert Gawlik, Benjamin Kollenda, Elias Athanasopoulos, Georgios Portokalidis, Cristiano Giuffrida, Herbert Bos |
USENIX Security Symposium | 2 |
| 2015 | Cross-Architecture Bug Search in Binary ExecutablesabstractWith the general availability of closed-source software for various CPU architectures, there is a need to identify security-critical vulnerabilities at the binary level to perform a vulnerability assessment. Unfortunately, existing bug finding methods fall short in that they i) require source code, ii) only work on a single architecture (typically x86), or iii) rely on dynamic analysis, which is inherently difficult for embedded devices. In this paper, we propose a system to derive bug signatures for known bugs. We then use these signatures to find bugs in binaries that have been deployed on different CPU architectures (e.g., x86 vs. MIPS). The variety of CPU architectures imposes many challenges, such as the incomparability of instruction set architectures between the CPU models. We solve this by first translating the binary code to an intermediate representation, resulting in assignment formulas with input and output variables. We then sample concrete inputs to observe the I/O behavior of basic blocks, which grasps their semantics. Finally, we use the I/O behavior to find code parts that behave similarly to the bug signature, effectively revealing code parts that contain the bug. We have designed and implemented a tool for cross architecture bug search in executables. Our prototype currently supports three instruction set architectures (x86, ARM, and MIPS) and can find vulnerabilities in buggy binary code for any of these architectures. We show that we can find Heart bleed vulnerabilities, regardless of the underlying software instruction set. Similarly, we apply our method to find backdoors in closed source firmware images of MIPS- and ARM-based routers. Jannik Pewny, Behrad Garmany, Robert Gawlik, Christian Rossow, Thorsten Holz |
IEEE Symposium on Security and Privacy | 3 |
| 2014 | Towards automated integrity protection of C++ virtual function tables in binary programsabstractWeb browsers are one of the most used, complex, and popular software systems nowadays. They are prone to dangling pointers that result in use-after-free vulnerabilites and this is the de-facto way to exploit them. From a technical point of view, an attacker uses a technique called vtable hijacking to exploit such bugs. More specifically, she crafts bogus virtual tables and lets a freed C++ object point to it in order to gain control over the program at virtual function call sites. Robert Gawlik, Thorsten Holz |
ACSAC | 1 |
| 2014 | Automated generation of models for fast and precise detection of HTTP-based malwareabstractMalicious software and especially botnets are among the most important security threats in the Internet. Thus, the accurate and timely detection of such threats is of great importance. Detecting machines infected with malware by identifying their malicious activities at the network level is an appealing approach, due to the ease of deployment. Nowadays, the most common communication channels used by attackers to control the infected machines are based on the HTTP protocol. To evade detection, HTTP-based malware adapt their behavior to the communication patterns of the benign HTTP clients, such as web browsers. This poses significant challenges to existing detection approaches like signature-based and behavioral-based detection systems. In this paper, we propose BO THO U N D: a novel approach to precisely detect HTTP-based malware at the network level. The key idea is that implementations of the HTTP protocol by different entities have small but perceivable differences. Building on this observation, BO THO U N D automatically generates models for malicious and benign requests and classifies at real time the HTTP traffic of a monitored network. Our evaluation results demonstrate that BO THO U N D outperforms prior work on identifying HTTP-based botnets, being able to detect a large variety of real-world HTTP-based malware, including advanced persistent threats used in targeted attacks, with a very low percentage of classification errors. Apostolis Zarras, Antonis Papadogiannakis, Robert Gawlik, Thorsten Holz |
PST | 3 |
| 2014 | Dynamic Hooks: Hiding Control Flow Changes within Non-Control Data
Sebastian Vogl, Robert Gawlik, Behrad Garmany, Thomas Kittel 0001, Jonas Pfoh, Claudia Eckert 0001, Thorsten Holz |
USENIX Security Symposium | 2 |