Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Moritz Contag

dblp:150/7970 · DBLP profile ↗
← Back
8ranked-venue papers
2as first author
1since 2021 · last 2022
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 2 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
4 papers
Systems and software security · 80% Cyber-physical and IoT security · 12% Network security · 7%
Software engineering, system software, and programming languages
2 papers
Program analysis · 56% Software maintenance and evolution · 44%

Topics — the 9 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › software protection
code obfuscation
0.612022
Loki: Hardening Code Obfuscation Against Automated Attacks · USENIX Security Symposium 2022
Cyber-physical and IoT security
automotive security
0.312017
How They Did It: An Analysis of Emission Defeat Devices in Modern Automobiles · IEEE Symposium on Security and Privacy 2017
Software maintenance and evolution
program comprehension
0.312017
MARX: Uncovering Class Hierarchies in C++ Programs · NDSS 2017
Program analysis
static analysis
0.312017
MARX: Uncovering Class Hierarchies in C++ Programs · NDSS 2017
Systems and software security › return-oriented programming defense
code reuse attack defense
0.212016
A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary Level · IEEE Symposium on Security and Privacy 2016
Systems and software security › memory safety
control-flow integrity
0.212016
A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary Level · IEEE Symposium on Security and Privacy 2016
Systems and software security
exploitation
0.212016
A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary Level · IEEE Symposium on Security and Privacy 2016
Network security › intrusion detection and prevention › intrusion detection
anti-evasion
0.212022
Loki: Hardening Code Obfuscation Against Automated Attacks · USENIX Security Symposium 2022
Program analysis
binary analysis
0.112016
A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary Level · IEEE Symposium on Security and Privacy 2016

Methods — techniques the papers use, named apart from their topics

static analysis · 0.6obfuscation · 0.6firmware forensics · 0.6automated attack resistance · 0.6use-def analysis · 0.5liveness analysis · 0.5symbolic execution · 0.3program synthesis · 0.3
YearPublicationVenuePosition
2022 Loki: Hardening Code Obfuscation Against Automated Attacks
Moritz Schloegel, Tim Blazytko, Moritz Contag, Cornelius Aschermann, Julius Basler, Thorsten Holz, Ali Abbasi 0002
USENIX Security Symposium3
2018 On the Weaknesses of Function Table Randomization
Moritz Contag, Robert Gawlik, Andre Pawlowski, Thorsten Holz
DIMVA1
2017 MARX: Uncovering Class Hierarchies in C++ Programs
Andre Pawlowski, Moritz Contag, Victor van der Veen, Chris Ouwehand, Thorsten Holz, Herbert Bos, Elias Athanasopoulos, Cristiano Giuffrida
NDSS2
2017 How They Did It: An Analysis of Emission Defeat Devices in Modern Automobiles
abstract
Modern vehicles are required to comply with a range of environmental regulations limiting the level of emissions for various greenhouse gases, toxins and particulate matter. To ensure compliance, regulators test vehicles in controlled settings and empirically measure their emissions at the tailpipe. However, the black box nature of this testing and the standardization of its forms have created an opportunity for evasion. Using modern electronic engine controllers, manufacturers can programmatically infer when a car is undergoing an emission test and alter the behavior of the vehicle to comply with emission standards, while exceeding them during normal driving in favor of improved performance. While the use of such a defeat device by Volkswagen has brought the issue of emissions cheating to the public's attention, there have been few details about the precise nature of the defeat device, how it came to be, and its effect on vehicle behavior. In this paper, we present our analysis of two families of software defeat devices for diesel engines: one used by the Volkswagen Group to pass emissions tests in the US and Europe, and a second that we have found in Fiat Chrysler Automobiles. To carry out this analysis, we developed new static analysis firmware forensics techniques necessary to automatically identify known defeat devices and confirm their function. We tested about 900 firmware images and were able to detect a potential defeat device in more than 400 firmware images spanning eight years. We describe the precise conditions used by the firmware to detect a test cycle and how it affects engine behavior. This work frames the technical challenges faced by regulators going forward and highlights the important research agenda in providing focused software assurance in the presence of adversarial manufacturers.
Moritz Contag, Vector Guo Li, Andre Pawlowski, Felix Domke, Kirill Levchenko, Thorsten Holz, Stefan Savage
IEEE Symposium on Security and Privacy1
2017 Syntia: Synthesizing the Semantics of Obfuscated Code
Tim Blazytko, Moritz Contag, Cornelius Aschermann, Thorsten Holz
USENIX Security Symposium2
2016 Probfuscation: An Obfuscation Approach Using Probabilistic Control Flows
Andre Pawlowski, Moritz Contag, Thorsten Holz
DIMVA2
2016 A Tough Call: Mitigating Advanced Code-Reuse Attacks at the Binary Level
abstract
Current binary-level Control-Flow Integrity (CFI) techniques are weak in determining the set of valid targets for indirect control flow transfers on the forward edge. In particular, the lack of source code forces existing techniques to resort to a conservative address-taken policy that overapproximates this set. In contrast, source-level solutions can accurately infer the targets of indirect calls and thus detect malicious control-flow transfers more precisely. Given that source code is not always available, however, offering similar quality of protection at the binary level is important, but, unquestionably, more challenging than ever: recent work demonstrates powerful attacks such as Counterfeit Object-oriented Programming (COOP), which made the community believe that protecting software against control-flow diversion attacks at the binary level is rather impossible. In this paper, we propose binary-level analysis techniques to significantly reduce the number of possible targets for indirect branches. More specifically, we reconstruct a conservative approximation of target function prototypes by means of use-def analysis at possible callees. We then couple this with liveness analysis at each indirect callsite to derive a many-to-many relationship between callsites and target callees with a much higher precision compared to prior binary-level solutions. Experimental results on popular server programs and on SPEC CPU2006 show that TypeArmor, a prototype implementation of our approach, is efficient - with a runtime overhead of less than 3%. Furthermore, we evaluate to what extent TypeArmor can mitigate COOP and other advanced attacks and show that our approach can significantly reduce the number of targets on the forward edge. Moreover, we show that TypeArmor breaks published COOP exploits, providing concrete evidence that strict binary-level CFI can still mitigate advanced attacks, despite the absence of source information or C++ semantics.
Victor van der Veen, Enes Göktas, Moritz Contag, Andre Pawlowski, Xi Chen 0038, Sanjay Rawat 0001, Herbert Bos, Thorsten Holz, Elias Athanasopoulos, Cristiano Giuffrida
IEEE Symposium on Security and Privacy3
2014 Evaluating the Effectiveness of Current Anti-ROP Defenses
Felix Schuster, Thomas Tendyck, Jannik Pewny, Andreas Maaß, Martin Steegmanns, Moritz Contag, Thorsten Holz
RAID6