Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Mirza Basim Baig

dblp:151/5020 · DBLP profile ↗
← Back
3ranked-venue papers
1as first author
0since 2021 · last 2017
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1Databases, data management, data science and information retrieval · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Systems and software security · 100%
Software engineering, system software, and programming languages
1 paper
Operating systems · 100%

Topics — the 6 heaviest of 6, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
semantic gap
0.212014
SoK: Introspections on Trust and the Semantic Gap · IEEE Symposium on Security and Privacy 2014
Systems and software security › trusted computing
trusted computing base
0.212014
SoK: Introspections on Trust and the Semantic Gap · IEEE Symposium on Security and Privacy 2014
Systems and software security
virtualization security
0.212014
SoK: Introspections on Trust and the Semantic Gap · IEEE Symposium on Security and Privacy 2014
Systems and software security › virtualization security
virtual machine introspection
0.212014
SoK: Introspections on Trust and the Semantic Gap · IEEE Symposium on Security and Privacy 2014
Operating systems › virtualization
hypervisor security
0.112014
SoK: Introspections on Trust and the Semantic Gap · IEEE Symposium on Security and Privacy 2014
Operating systems
virtualization
0.112014
SoK: Introspections on Trust and the Semantic Gap · IEEE Symposium on Security and Privacy 2014

Methods — techniques the papers use, named apart from their topics

systematic literature review · 0.4
YearPublicationVenuePosition
2017 A Domain-Agnostic Approach to Spam-URL Detection via Redirects
Heeyoung Kwon, Mirza Basim Baig, Leman Akoglu
PAKDD (2)2
2014 CloudFlow: Cloud-wide Policy Enforcement Using Fast VM Introspection
abstract
Government and commercial enterprises are increasingly considering cloud adoption. Clouds improve overall efficiency by consolidating a number of different clients' software virtual machines onto a smaller set of hardware resources. Unfortunately, this shared hardware also creates inherent side-channel vulnerabilities, which an attacker can use to leak information from a victim VM. Side-channel vulnerabilities are especially concerning when different principals are constrained by regulations. A classic example of these regulations are Chinese Wall policies for financial companies, which aim to protect the financial system from illicit manipulation by separating portions of the business with conflicting interests. Although efficient prevention of side channels is difficult within a single node, there is a unique opportunity within a cloud. This paper proposes a low-overhead approach to cloud wide information flow policy enforcement: identifying side channels which could potentially be used to violate a security policy through run-time introspection, and reactively migrating virtual machines to eliminate node-level side-channels. In this paper we describe CloudFlow-an information flow control extension for OpenStack. CloudFlow includes a novel, virtual machine introspection mechanism that is orders of magnitude faster than previous approaches. CloudFlow efficiently and transparently enforces information flow policies cloud-wide, including information leaks through undesirable side-channels. Additionally, CloudFlow has potential uses for cloud management and resource-efficient virtual machine scheduling.
Mirza Basim Baig, Connor Fitzsimons, Suryanarayanan Balasubramanian, Radu Sion, Donald E. Porter
IC2E1
2014 SoK: Introspections on Trust and the Semantic Gap
abstract
An essential goal of Virtual Machine Introspection (VMI) is assuring security policy enforcement and overall functionality in the presence of an untrustworthy OS. A fundamental obstacle to this goal is the difficulty in accurately extracting semantic meaning from the hypervisor's hardware level view of a guest OS, called the semantic gap. Over the twelve years since the semantic gap was identified, immense progress has been made in developing powerful VMI tools. Unfortunately, much of this progress has been made at the cost of reintroducing trust into the guest OS, often in direct contradiction to the underlying threat model motivating the introspection. Although this choice is reasonable in some contexts and has facilitated progress, the ultimate goal of reducing the trusted computing base of software systems is best served by a fresh look at the VMI design space. This paper organizes previous work based on the essential design considerations when building a VMI system, and then explains how these design choices dictate the trust model and security properties of the overall system. The paper then observes portions of the VMI design space which have been under-explored, as well as potential adaptations of existing techniques to bridge the semantic gap without trusting the guest OS. Overall, this paper aims to create an essential checkpoint in the broader quest for meaningful trust in virtualized environments through VM introspection.
Bhushan Jain, Mirza Basim Baig, Dongli Zhang, Donald E. Porter, Radu Sion
IEEE Symposium on Security and Privacy2