EDBT 2026 Demo / reviewers in the wild / expert
Brendan Saltaformaggio
dblp:150/5240
· DBLP profile ↗
42ranked-venue papers
4as first author
21since 2021 · last 2026
0000-0001-5859-6925ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 38 · 4 first-author · 21 since 2021Systems, architecture and hardware · 5Software engineering, systems software and programming languages · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Achieving Zen: Combining Mathematical and Programmatic Deep Learning Model Representations for Attribution and Reuse
David Oygenblik, Dinko Dermendzhiev, Filippos Sofias, Mingxuan Yao, Haichuan Xu, Jeman Park 0001, Amit Kumar Sikder, Brendan Saltaformaggio |
NDSS | 9 |
| 2026 | Fuzzing the Physical Space: Physics-Aware Testing of Black-Box Industrial Control Systems
Burak Sahin, David Oygenblik, Mingxuan Yao, Brendan Saltaformaggio, Saman A. Zonouz |
SP | 5 |
| 2026 | Recovering and Rehosting Mobile Local LLM Conversations and Contexts via Memory Forensics
Haichuan Xu, David Oygenblik, Mingxuan Yao, Brendan Saltaformaggio |
SP | 6 |
| 2025 | Enhanced Web Application Security Through Proactive Dead Drop Resolver Remediation
Jonathan Fuller 0001, Mingxuan Yao, Saumya Agarwal, Srimanta Barua, Taleb Hirani, Amit Kumar Sikder, Brendan Saltaformaggio |
CCS | 7 |
| 2025 | VillainNet: Targeted Poisoning Attacks Against SuperNets Along the Accuracy-Latency Pareto FrontierabstractState-of-the-art (SOTA) weight-shared SuperNets dynamically activate subnetworks at runtime, enabling robust adaptive inference under varying deployment conditions. However, we find that adversaries can take advantage of the unique training and inference paradigms of SuperNets to selectively implant backdoors that activate only within specific subnetworks, remaining dormant across billions of other subnetworks. We present VillainNet (VNET), a novel poisoning methodology that restricts backdoor activation to attacker-chosen subnetworks, tailored either to specific operational scenarios (e.g., specific vehicle speeds or weather conditions) or to specific subnetwork configurations. VNET's core innovation is a novel, distance-aware optimization process that leverages architectural and computational similarity metrics between subnetworks to ensure that backdoor activation does not occur across non-target subnetworks. This forces defenders to confront a dramatically expanded search space for backdoor detection. We show that across two SOTA SuperNets, trained on the CIFAR10 and GTSRB datasets, VNET can achieve attack success rates comparable to traditional poisoning approaches (approximately 99%), while significantly lowering the chances of attack detection, thereby stealthily hiding the attack. Consequently, defenders face increased computational burdens, requiring on average 66 (and up to 250 for highly targeted attacks) sampled subnetworks to detect the attack, implying a roughly 66-fold increase in compute cost required to test the SuperNet for backdoors. David Oygenblik, Abhinav Vemulapalli, Animesh Agrawal, Debopam Sanyal, Alexey Tumanov, Brendan Saltaformaggio |
CCS | 6 |
| 2025 | Lock the Door But Keep the Window Open: Extracting App-Protected Accessibility Information from Browser-Rendered WebsitesabstractThe Android accessibility (a11y) service has been widely utilized by malware to abuse benign services.To prevent such abuse, developers need to secure a11y content access in both their apps and mobile websites.However, a misalignment of a11y protection mechanisms exists between them.Prior research has focused on attacking and defending a11y information embedded in native Android apps.However, our research found that a11y malware can retrieve app-protected a11y information in its mobile browser-rendered website counterpart, leaving mobile browser users more vulnerable to a11y attacks than app users.To help benign service developers vet this attack surface, we developed SOMBRA, an automated analysis pipeline to vet browser-side leakage of a11y information that is a11y-protected in apps.Using SOMBRA, we analyzed 294 benign services and found 29 of them deploy app-side a11y protection mechanisms to secure 256 views.SOMBRA discovered that 241, 402, 244, and 251 elements corresponding to their protected app-side views are a11y-exposed in their websites rendered by Chrome, Firefox, Brave, and Edge browsers, respectively.The leaked elements contain sensitive personal identifiable information.Finally, SOMBRA discovered that most developers do not adopt browser-side a11y protections because existing mechanisms either have ineffective protection or hinder the usability of their content. Haichuan Xu, Mingxuan Yao, David Oygenblik, Jeman Park 0001, Brendan Saltaformaggio |
CCS | 7 |
| 2025 | Hitchhiking Vaccine: Enhancing Botnet Remediation With Remote Code Deployment Reuse
Mingxuan Yao, Haichuan Xu, Omar Alrawi, Jeman Park 0001, Brendan Saltaformaggio |
NDSS | 6 |
| 2025 | CoinDef: A Comprehensive Code Injection Defense for the Electron FrameworkabstractThe increasing popularity of cross-platform frameworks like Electron underscores the appeal of using familiar web technologies for desktop application development. Electron fuses the web and native environments into one single executable. However, this fusion creates unique vulnerabilities and significantly expands the attack surfaces for Electron applications, rendering traditional web defenses ineffective, as they are not designed to operate across both web and native contexts simultaneously. To address these challenges, we propose Coindef, a centralized defense mechanism that enforces the structural integrity of Abstract Syntax Trees (ASTs) with execution context. Coindef operates within the JavaScript engine, providing rapid, tamper-proof, and comprehensive mitigation against code injection attacks to Electron applications. Coindef employs hybrid profiling to collect AST structural profiles, establishing a baseline of expected behavior. Then, Coindef enforces these profiles for code as it is interpreted at runtime. In an evaluation of Coindef on 20 representative real-world applications, we demonstrate its effectiveness in blocking exploits, incurring a 3.96% runtime overhead during application startup and negligible overhead during user interaction. Comparing Coindef to state-of-the-art defenses for Electron applications, we show that Coindef offers comprehensive protection against sophisticated code injection attacks through DOM manipulations and dynamic code execution. Simon P. Chung, Jizhou Chen, Brendan Saltaformaggio, Wenke Lee |
SP | 5 |
| 2025 | Identifying Incoherent Search Sessions: Search Click Fraud Remediation Under Real-World ConstraintsabstractSearch engines and advertisers continuously suffer substantial financial losses from click fraud, which poses challenges to existing detection algorithms. Even more concerning, despite ongoing advancements, our understanding of click fraud remains limited, leaving room for sophisticated fraudulent techniques to bypass existing detection measures. In this study, we pivot from examining individual search requests to analyzing search sessions, defined as sequences of consecutive search queries made by the same user. We found that benign users exhibit coherent behavior patterns within these sessions, which contrast clearly with those of fraudulent actors. Specifically, legitimate users tend to conduct searches focused on a single topic at a time. In contrast, fraudsters or automated bots often exhibit diverse, illogical, and incoherent search behaviors within a session. To address this behavioral distinction, we propose CoSeC, a system designed to quantify the “incoherence index” of search sessions. CoSeC integrates literal semantic, temporal, and ad-click behavioral features to evaluate sessions' coherence quantitatively. Our evaluation of CoSeC demonstrates high efficacy, achieving a precision of 95.79% and a recall of 92.40% in identifying incoherent sessions, highlighting CoSeC's substantial potential to enhance real-world click fraud detection. Ranjita Pai Sridhar, Mingxuan Yao, David Oygenblik, Haichuan Xu, Vacha Dave, Cormac Herley, Paul England, Brendan Saltaformaggio |
SP | 10 |
| 2024 | Pulling Off The Mask: Forensic Analysis of the Deceptive Creator Wallets Behind Smart Contract FraudabstractCriminals, using crypto wallets referred to as Deceptive Creator Wallets (DCWs), have orchestrated fraudulent activities by luring victims to transfer funds to fraud smart contracts. Since it is almost impossible to reverse the transactions or pinpoint the true identity of the criminals, the industry has turned to flagging such contracts as user warnings. However, current mitigation efforts focus on individual contracts, overlooking the DCWs behind the scenes. Consequently, our research found that this oversight allows fraud to thrive. To address this, we developed CoCo, an automated forensic analysis pipeline that processes a single fraud contract and generates evidence that the legal authorities need to mitigate the fraud. Applying CoCo to 157 confirmed fraud contracts, our research uncovered 1,283,198 associated contracts linked to 91 DCWs, responsible for 2,638,752 ETH ($2,089,504,682) in illicit profits. More alarmingly, CoCo traces the fraudulent activities back to September 2017. In response, we are closely collaborating with Etherscan and the FBI to combat the fraud identified in our study. Mingxuan Yao, Haichuan Xu, Shih-Huan Chou, Paturi Varun Chowdhary, Amit Kumar Sikder, Brendan Saltaformaggio |
SP | 7 |
| 2024 | AI Psychiatry: Forensic Investigation of Deep Learning Networks in Memory Images
David Oygenblik, Carter Yagemann, Joseph Zhang, Arianna Mastali, Jeman Park 0001, Brendan Saltaformaggio |
USENIX Security Symposium | 6 |
| 2024 | DVa: Extracting Victims and Abuse Vectors from Android Accessibility Malware
Haichuan Xu, Mingxuan Yao, Mohamed Moustafa Dawoud, Jeman Park 0001, Brendan Saltaformaggio |
USENIX Security Symposium | 6 |
| 2023 | PUMM: Preventing Use-After-Free Using Execution Unit Partitioning
Carter Yagemann, Simon P. Chung, Brendan Saltaformaggio, Wenke Lee |
USENIX Security Symposium | 3 |
| 2023 | Hiding in Plain Sight: An Empirical Study of Web Application Abuse in Malware
Mingxuan Yao, Jonathan Fuller 0001, Ranjita Pai Kasturi, Saumya Agarwal, Amit Kumar Sikder, Brendan Saltaformaggio |
USENIX Security Symposium | 6 |
| 2022 | Mistrust Plugins You Must: A Large-Scale Study Of Malicious Plugins In WordPress Marketplaces
Ranjita Pai Kasturi, Jonathan Fuller 0001, Yiting Sun, Omar Chabklo, Andres Rodriguez 0005, Jeman Park 0001, Brendan Saltaformaggio |
USENIX Security Symposium | 7 |
| 2022 | This Hacker Knows Physics: Device Physics Aware Mimicry Attacks in Cyber-Physical SystemsabstractRecent work proposed to improve the security of CPSs by authenticating the CPS devices through the device operation times in the response packets from the devices, due to the strong correlation between the timing fingerprints and the physics of the devices. Although such a technique may be effective in defending against naive attackers, an advanced attacker may monitor the operation of the CPS before launching a device physics aware mimicry attack. In this paper, we show how the spoofed response packets can be crafted by an attacker to deceive the CPS device authentication method based on the device operation times. Specifically, we use the timing and physical measurements embedded in the packets to reconstruct the devices in the physical system, which can be used to spoof response packets corresponding to the actual model and configuration of the devices in the CPS. We demonstrate the performance of our technique in realistic testbeds with real devices. Finally, we propose an upgraded defense mechanism that may be used against such mimicry attacks. Qinchen Gu, David Formby, Shouling Ji, Brendan Saltaformaggio, Anu G. Bourgeois, Raheem A. Beyah |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2021 | C3PO: Large-Scale Study Of Covert Monitoring of C&C Servers via Over-Permissioned Protocol InfiltrationabstractCurrent techniques to monitor botnets towards disruption or takedown are likely to result in inaccurate data gathered about the botnet or be detected by C&C orchestrators. Seeking a covert and scalable solution, we look to an evolving pattern in modern malware that integrates standardized over-permissioned protocols, exposing privileged access to C&C servers. We implement techniques to detect and exploit these protocols from over-permissioned bots toward covert C&C server monitoring. Our empirical study of 200k malware captured since 2006 revealed 62,202 over-permissioned bots (nearly 1 in 3) and 443,905 C&C monitoring capabilities, with a steady increase of over-permissioned protocol use over the last 15 years. Due to their ubiquity, we conclude that even though over-permissioned protocols allow for C&C server infiltration, the efficiency and ease of use they provide continue to make them prevalent in the malware operational landscape. This paper presents C3PO, a pipeline that enables our study and empowers incident responders to automatically identify over-permissioned protocols, infiltration vectors to spoof bot-to-C&C communication, and C&C monitoring capabilities that guide covert monitoring post infiltration. Our findings suggest the over-permissioned protocol weakness provides a scalable approach to covertly monitor C&C servers, which is a fundamental enabler of botnet disruptions and takedowns. Jonathan Fuller 0001, Ranjita Pai Kasturi, Amit Kumar Sikder, Haichuan Xu, Berat Arik, Ehsan Asdar, Brendan Saltaformaggio |
CCS | 8 |
| 2021 | Automated Bug Hunting With Data-Driven Symbolic Root Cause AnalysisabstractThe increasing cost of successful cyberattacks has caused a mindset shift, whereby defenders now employ proactive defenses, namely software bug hunting, alongside existing reactive measures (firewalls, IDS, IPS) to protect systems. Unfortunately the path from hunting bugs to deploying patches remains laborious and expensive, requires human expertise, and still misses serious memory corruptions. Motivated by these challenges, we propose bug hunting using symbolically reconstructed states based on execution traces to achieve better detection and root cause analysis of overflow, use-after-free, double free, and format string bugs across user programs and their imported libraries. We discover that with the right use of widely available hardware processor tracing and partial memory snapshots, powerful symbolic analysis can be used on real-world programs while managing path explosion. Better yet, data can be captured from production deployments of live software on end-host systems transparently, aiding in the analysis of user clients and long-running programs like web servers. Carter Yagemann, Simon P. Chung, Brendan Saltaformaggio, Wenke Lee |
CCS | 3 |
| 2021 | Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages
Ruian Duan, Omar Alrawi, Ranjita Pai Kasturi, Ryan Elder, Brendan Saltaformaggio, Wenke Lee |
NDSS | 5 |
| 2021 | Forecasting Malware Capabilities From Cyber Attack Memory Images
Omar Alrawi, Moses Ike, Matthew Pruett, Ranjita Pai Kasturi, Srimanta Barua, Taleb Hirani, Brennan Hill, Brendan Saltaformaggio |
USENIX Security Symposium | 8 |
| 2021 | ARCUS: Symbolic Root Cause Analysis of Exploits in Production Systems
Carter Yagemann, Matthew Pruett, Simon P. Chung, Kennon Bittick, Brendan Saltaformaggio, Wenke Lee |
USENIX Security Symposium | 5 |
| 2020 | On the Feasibility of Automating Stock Market ManipulationabstractThis work presents the first findings on the feasibility of using botnets to automate stock market manipulation. Our analysis incorporates data gathered from SEC case files, security surveys of online brokerages, and dark web marketplace data. We address several technical challenges, including how to adapt existing techniques for automation, the cost of hijacking brokerage accounts, avoiding detection, and more. We consolidate our findings into a working proof-of-concept, man-in-the-browser malware, Bot2Stock, capable of controlling victim email and brokerage accounts to commit fraud. We evaluate our bots and protocol using agent-based market simulations, where we find that a 1.5% ratio of bots to benign traders yields a 2.8% return on investment (ROI) per attack. Given the short duration of each attack (< 1 minute), achieving this ratio is trivial, requiring only 4 bots to target stocks like IBM. 1,000 bots, cumulatively gathered over 1 year, can turn $100,000 into $1,022,000, placing Bot2Stock on par with existing botnet scams. Carter Yagemann, Simon P. Chung, Erkam Uzun, Sai Ragam, Brendan Saltaformaggio, Wenke Lee |
ACSAC | 5 |
| 2020 | TARDIS: Rolling Back The Clock On CMS-Targeting Cyber AttacksabstractOver 55% of the world's websites run on Content Management Systems (CMS). Unfortunately, this huge user population has made CMS-based websites a high-profile target for hackers. Worse still, the vast majority of the website hosting industry has shifted to a "backup and restore" model of security, which relies on error-prone AV scanners to prompt users to roll back to a pre-infection nightly snapshot. This research had the opportunity to study these nightly backups for over 300,000 unique production websites. In doing so, we measured the attack landscape of CMS-based websites and assessed the effectiveness of the backup and restore protection scheme. To our surprise, we found that the evolution of tens of thousands of attacks exhibited clear long-lived multi-stage attack patterns. We now propose TARDIS, an automated provenance inference technique, which enables the investigation and remediation of CMS-targeting attacks based on only the nightly backups already being collected by website hosting companies. With the help of our industry collaborator, we applied TARDIS to the nightly backups of those 300K websites and found 20,591 attacks which lasted from 6 to 1,694 days, some of which were still yet to be detected. Ranjita Pai Kasturi, Yiting Sun, Ruian Duan, Omar Alrawi, Ehsan Asdar, Victor Zhu, Yonghwi Kwon 0001, Brendan Saltaformaggio |
SP | 8 |
| 2019 | Automating Patching of Vulnerable Open-Source Software Versions in Application Binaries
Ruian Duan, Ashish Bijlani, Yang Ji 0002, Omar Alrawi, Yiyuan Xiong, Moses Ike, Brendan Saltaformaggio, Wenke Lee |
NDSS | 7 |
| 2019 | The Betrayal At Cloud City: An Empirical Analysis Of Cloud-Based Mobile Backends
Omar Alrawi, Chaoshun Zuo, Ruian Duan, Ranjita Pai Kasturi, Zhiqiang Lin 0001, Brendan Saltaformaggio |
USENIX Security Symposium | 6 |
| 2018 | Tipped Off by Your Memory Allocator: Device-Wide User Activity Sequencing from Android Memory Images
Rohit Bhatia, Brendan Saltaformaggio, Seung Jei Yang, Aisha I. Ali-Gombe, Xiangyu Zhang 0001, Dongyan Xu, Golden G. Richard III |
NDSS | 2 |
| 2018 | Toward a more dependable hybrid analysis of android malware using aspect-oriented programming
Aisha I. Ali-Gombe, Brendan Saltaformaggio, J. Ramanujam, Dongyan Xu, Golden G. Richard III |
Comput. Secur. | 2 |
| 2018 | Gemini: Guest-transparent honey files via hypervisor-level access redirection
Zhongshu Gu, Brendan Saltaformaggio, Xiangyu Zhang 0001, Dongyan Xu |
Comput. Secur. | 2 |
| 2017 | RevARM: A Platform-Agnostic ARM Binary Rewriter for Security ApplicationsabstractARM is the leading processor architecture in the emerging mobile and embedded market. Unfortunately, there has been a myriad of security issues on both mobile and embedded systems. While many countermeasures of such security issues have been proposed in recent years, a majority of applications still cannot be patched or protected due to run-time and space overhead constraints and the unavailability of source code. More importantly, the rapidly evolving mobile and embedded market makes any platform-specific solution ineffective. In this paper, we propose RevARM, a binary rewriting technique capable of instrumenting ARM-based binaries without limitation on the target platform. Unlike many previous binary instrumentation tools that are designed to instrument binaries based on x86, RevARM must resolve a number of new, ARM-specific binary rewriting challenges. Moreover, RevARM is able to handle stripped binaries, requires no symbolic/semantic information, and supports Mach-O binaries, overcoming the limitations of existing approaches. Finally, we demonstrate the capabilities of RevARM in solving real-world security challenges. Our evaluation results across a variety of platforms, including popular mobile and embedded systems, show that RevARM is highly effective in instrumenting ARM binaries with an average of 3.2% run-time and 1.3% space overhead. Taegyu Kim, Hongjun Choi, Yonghwi Kwon 0001, Brendan Saltaformaggio, Xiangyu Zhang 0001, Dongyan Xu |
ACSAC | 5 |
| 2017 | Self Destructing Exploit Executions via Input Perturbation
Yonghwi Kwon 0001, Brendan Saltaformaggio, I Luk Kim, Kyu Hyung Lee, Xiangyu Zhang 0001, Dongyan Xu |
NDSS | 2 |
| 2016 | HERCULE: attack story reconstruction via community discovery on correlated log graph
Kexin Pei, Zhongshu Gu, Brendan Saltaformaggio, Shiqing Ma, Fei Wang 0001, Luo Si, Xiangyu Zhang 0001, Dongyan Xu |
ACSAC | 3 |
| 2016 | LDX: Causality Inference by Lightweight Dual ExecutionabstractCausality inference, such as dynamic taint anslysis, has many applications (e.g., information leak detection). It determines whether an event e is causally dependent on a preceding event c during execution. We develop a new causality inference engine LDX. Given an execution, it spawns a slave execution, in which it mutates c and observes whether any change is induced at e. To preclude non-determinism, LDX couples the executions by sharing syscall outcomes. To handle path differences induced by the perturbation, we develop a novel on-the-fly execution alignment scheme that maintains a counter to reflect the progress of execution. The scheme relies on program analysis and compiler transformation. LDX can effectively detect information leak and security attacks with an average overhead of 6.08% while running the master and the slave concurrently on separate CPUs, much lower than existing systems that require instruction level monitoring. Furthermore, it has much better accuracy in causality inference. Yonghwi Kwon 0001, Dohyeong Kim, William N. Sumner, Kyungtae Kim, Brendan Saltaformaggio, Xiangyu Zhang 0001, Dongyan Xu |
ASPLOS | 5 |
| 2016 | BASS: Improving I/O Performance for Cloud Block Storage via Byte-Addressable Storage StackabstractIn an Infrastructure-as-a-Service cloud, cloud block storage offers conventional, block-level storage resources via a storage area network. However, compared to local storage, this multilayered cloud storage model imposes considerable I/O overheads due to much longer I/O path in the virtualized cloud. In this paper, we propose a novel byte-addressable storage stack, BASS, to bridge the addressability gap between the storage and network stacks in cloud, and in return boost I/O performance for cloud block storage. Equipped with byte-addressability, BASS not only avails the benefits of using variable-length I/O requests that avoid unnecessary data transfer, but also enables a highly efficient non-blocking approach that eliminates the blocking of write processes. We have developed a generic prototype of BASS based on Linux storage stack, which is applicable to traditional VMs, lightweight containers and physical machines. Our extensive evaluation with micro-benchmarks, I/O traces and real-world applications demonstrates the effectiveness of BASS, with significantly improved I/O performance and reduced storage network usage. Hui Lu 0001, Brendan Saltaformaggio, Cong Xu 0010, Umesh Bellur, Dongyan Xu |
SoCC | 2 |
| 2016 | StorM: Enabling Tenant-Defined Cloud Storage Middle-Box ServicesabstractIn an Infrastructure-as-a-Service cloud, tenants rely on the cloud provider to provide "value-added" services such as data security and reliability. However, this provider-controlled service model is less flexible and cannot be customized to meet individual tenants' needs. In this paper, we present StorM, a novel middle-box service platform that allows each tenant to deploy tenant-specific security and reliability services -- in virtualized middle-boxes -- for their cloud data. With such middle-boxes, StorM divides the responsibilities of service creation between tenants and the provider by allowing tenants to customize their own cloud data polices and the provider to offer corresponding infrastructural support. In developing StorM, we address key challenges including network splicing, platform efficiency, and semantic gap. We implement a StorM prototype on top of OpenStack and demonstrate three tenant-defined security/reliability middle-box services, with low performance overhead (<; 10%). Hui Lu 0001, Abhinav Srivastava, Brendan Saltaformaggio, Dongyan Xu |
DSN | 3 |
| 2016 | Screen after Previous Screens: Spatial-Temporal Recreation of Android App Displays from Memory Images
Brendan Saltaformaggio, Rohit Bhatia, Xiangyu Zhang 0001, Dongyan Xu, Golden G. Richard III |
USENIX Security Symposium | 1 |
| 2015 | iRiS: Vetting Private API Abuse in iOS ApplicationsabstractWith the booming sale of iOS devices, the number of iOS applications has increased significantly in recent years. To protect the security of iOS users, Apple requires every iOS application to go through a vetting process called App Review to detect uses of private APIs that provide access to sensitive user information. However, recent attacks have shown the feasibility of using private APIs without being detected during App Review. To counter such attacks, we propose a new iOS application vetting system, called iRiS, in this paper. iRiS first applies fast static analysis to resolve API calls. For those that cannot be statically resolved, iRiS uses a novel iterative dynamic analysis approach, which is slower but more powerful compared to static analysis. We have ported Valgrind to iOS and implemented a prototype of iRiS on top of it. We evaluated iRiS with 2019 applications from the official App Store. From these, iRiS identified 146 (7%) applications that use a total number of 150 different private APIs, including 25 security-critical APIs that access sensitive user information, such as device serial number. By analyzing iOS applications using iRiS, we also identified a suspicious advertisement service provider which collects user privacy information in its advertisement serving library. Our results show that, contrary to popular belief, a nontrivial number of iOS applications that violate Apple's terms of service exist in the App Store. iRiS is effective in detecting private API abuse missed by App Review. Zhui Deng, Brendan Saltaformaggio, Xiangyu Zhang 0001, Dongyan Xu |
CCS | 2 |
| 2015 | GUITAR: Piecing Together Android App GUIs from Memory ImagesabstractAn Android app's graphical user interface (GUI) displays rich semantic and contextual information about the smartphone's owner and app's execution. Such information provides vital clues to the investigation of crimes in both cyber and physical spaces. In real-world digital forensics however, once an electronic device becomes evidence most manual interactions with it are prohibited by criminal investigation protocols. Hence investigators must resort to "image-and-analyze" memory forensics (instead of browsing through the subject phone) to recover the apps' GUIs. Unfortunately, GUI reconstruction is still largely impossible with state-of-the-art memory forensics techniques, which tend to focus only on individual in-memory data structures. An Android GUI, however, displays diverse visual elements each built from numerous data structure instances. Furthermore, whenever an app is sent to the background, its GUI structure will be explicitly deallocated and disintegrated by the Android framework. In this paper, we present GUITAR, an app-independent technique which automatically reassembles and redraws all apps' GUIs from the multitude of GUI data elements found in a smartphone's memory image. To do so, GUITAR involves the reconstruction of (1) GUI tree topology, (2) drawing operation mapping, and (3) runtime environment for redrawing. Our evaluation shows that GUITAR is highly accurate (80-95% similar to original screenshots) at reconstructing GUIs from memory images taken from a variety of Android apps on popular phones. Moreover, GUITAR is robust in reconstructing meaningful GUIs even when facing GUI data loss. Brendan Saltaformaggio, Rohit Bhatia, Zhongshu Gu, Xiangyu Zhang 0001, Dongyan Xu |
CCS | 1 |
| 2015 | VCR: App-Agnostic Recovery of Photographic Evidence from Android Device Memory ImagesabstractThe ubiquity of modern smartphones means that nearly everyone has easy access to a camera at all times. In the event of a crime, the photographic evidence that these cameras leave in a smartphone's memory becomes vital pieces of digital evidence, and forensic investigators are tasked with recovering and analyzing this evidence. Unfortunately, few existing forensics tools are capable of systematically recovering and inspecting such in-memory photographic evidence produced by smartphone cameras. In this paper, we present VCR, a memory forensics technique which aims to fill this void by enabling the recovery of all photographic evidence produced by an Android device's cameras. By leveraging key aspects of the Android framework, VCR extends existing memory forensics techniques to improve vendor-customized Android memory image analysis. Based on this, VCR targets application-generic artifacts in an input memory image which allow photographic evidence to be collected no matter which application produced it. Further, VCR builds upon the Android framework's existing image decoding logic to both automatically recover and render any located evidence. Our evaluation with commercially available smartphones shows that VCR is highly effective at recovering all forms of photographic evidence produced by a variety of applications across several different Android platforms. Brendan Saltaformaggio, Rohit Bhatia, Zhongshu Gu, Xiangyu Zhang 0001, Dongyan Xu |
CCS | 1 |
| 2015 | vFair: latency-aware fair storage scheduling via per-IO cost-based differentiationabstractIn virtualized data centers, multiple VMs are consolidated to access a shared storage system. Effective storage resource management, however, turns out to be challenging, as VM workloads exhibit various IO patterns and diverse loads. To multiplex the underlying hardware resources among VMs, providing fairness and isolation while maintaining high resource utilization becomes imperative for effective storage resource management. Existing schedulers such as Linux CFQ or SFQ can provide some fairness, but it has been observed that synchronous IO tends to lose fair shares significantly when competing with aggressive VMs. Hui Lu 0001, Brendan Saltaformaggio, Ramana Rao Kompella, Dongyan Xu |
SoCC | 2 |
| 2015 | vRead: Efficient Data Access for Hadoop in Virtualized CloudsabstractWith its unlimited scalability and on-demand access to computation and storage, a virtualized cloud platform is the perfect match for big data systems such as Hadoop. However, virtualization introduces a significant amount of overhead to I/O intensive applications due to device virtualization and VMs or I/O threads scheduling delay. In particular, device virtualization causes significant CPU overhead as I/O data needs to be moved across several protection boundaries. We observe that such overhead especially affects the I/O performance of the Hadoop distributed file system (HDFS). In fact, data read from an HDFS datanode VM must go through virtual devices multiple times --- incurring non-negligible virtualization overhead --- even though both client VM and datanode VM may be running on the same machine. In this paper, we propose vRead, a programmable framework which connects I/O flows from HDFS applications directly to their data. vRead enables direct "reads" to the disk images of datanode VMs from the hypervisor. By doing so, vRead can significantly avoid device virtualization overhead, resulting in improved I/O throughput as well as CPU savings for Hadoop workloads and other applications relying on HDFS. Cong Xu 0010, Brendan Saltaformaggio, Sahan Gamage, Ramana Rao Kompella, Dongyan Xu |
Middleware | 2 |
| 2014 | FACE-CHANGE: Application-Driven Dynamic Kernel View Switching in a Virtual MachineabstractKernel minimization has already been established as a practical approach to reducing the trusted computing base. Existing solutions have largely focused on whole-system profiling - generating a globally minimum kernel image that is being shared by all applications. However, since different applications use only part of the kernel's code base, the minimized kernel still includes an unnecessarily large attack surface. Furthermore, once the static minimized kernel is generated, it is not flexible enough to adapt to an altered execution environment (e.g., new workload). FACE-CHANGE is a virtualization-based system to facilitate dynamic switching at runtime among multiple minimized kernels, each customized for an individual application. Based on precedent profiling results, FACE-CHANGE transparently presents a customized kernel view for each application to confine its reach ability of kernel code. In the event that the application exceeds this boundary, FACE-CHANGE is able to recover the missing code and back trace its attack/exception provenance to analyze the anomalous behavior. Zhongshu Gu, Brendan Saltaformaggio, Xiangyu Zhang 0001, Dongyan Xu |
DSN | 2 |
| 2014 | DSCRETE: Automatic Rendering of Forensic Information from Memory Images via Application Logic Reuse
Brendan Saltaformaggio, Zhongshu Gu, Xiangyu Zhang 0001, Dongyan Xu |
USENIX Security Symposium | 1 |