Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Benjamin Kollenda

dblp:153/5832 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
0since 2021 · last 2018
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 2 first-authorSystems, architecture and hardware · 2 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
6 papers
Systems and software security · 60% Hardware security and side channels · 21% Digital forensics and information hiding · 16%
Computer architecture, parallel and distributed computing, and storage systems
3 papers
Processor architecture and microarchitecture · 70% Electronic design automation · 30%

Topics — the 14 heaviest of 15, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
exploitation
0.732016
Subversive-C: Abusing and Protecting Dynamic Message Dispatch · USENIX ATC 2016
Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding · NDSS 2016
You Can Run but You Can't Read: Preventing Disclosure Exploits in Executable Code · CCS 2014
Processor architecture and microarchitecture
microprogramming
0.622018
An Exploratory Analysis of Microcode as a Building Block for System Defenses · CCS 2018
Reverse Engineering x86 Processor Microcode · USENIX Security Symposium 2017
Systems and software security
memory safety
0.532016
Subversive-C: Abusing and Protecting Dynamic Message Dispatch · USENIX ATC 2016
You Can Run but You Can't Read: Preventing Disclosure Exploits in Executable Code · CCS 2014
Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding · NDSS 2016
Hardware security and side channels
trusted execution environments
0.312018
An Exploratory Analysis of Microcode as a Building Block for System Defenses · CCS 2018
Digital forensics and information hiding
information hiding
0.322016
Undermining Information Hiding (and What to Do about It) · USENIX Security Symposium 2016
Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding · NDSS 2016
Electronic design automation › hardware verification and test
reverse engineering
0.312017
Reverse Engineering x86 Processor Microcode · USENIX Security Symposium 2017
Systems and software security › exploitation
control-flow hijacking
0.212016
Subversive-C: Abusing and Protecting Dynamic Message Dispatch · USENIX ATC 2016
Systems and software security
software diversity
0.212016
Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding · NDSS 2016
Digital forensics and information hiding
steganography
0.212016
Undermining Information Hiding (and What to Do about It) · USENIX Security Symposium 2016
Systems and software security › exploitation
code reuse attack
0.212014
You Can Run but You Can't Read: Preventing Disclosure Exploits in Executable Code · CCS 2014
Systems and software security › exploitation › code reuse attack
JIT-ROP
0.212014
You Can Run but You Can't Read: Preventing Disclosure Exploits in Executable Code · CCS 2014
Hardware security and side channels
hardware reverse engineering
0.112017
Reverse Engineering x86 Processor Microcode · USENIX Security Symposium 2017
Network security
traffic analysis
0.112016
Undermining Information Hiding (and What to Do about It) · USENIX Security Symposium 2016
Processor architecture and microarchitecture
instruction set architecture
0.112014
You Can Run but You Can't Read: Preventing Disclosure Exploits in Executable Code · CCS 2014

Methods — techniques the papers use, named apart from their topics

reverse engineering · 0.7microcode update · 0.7software emulation · 0.4
YearPublicationVenuePosition
2018 An Exploratory Analysis of Microcode as a Building Block for System Defenses
abstract
Microcode is an abstraction layer used by modern x86 processors that interprets user-visible CISC instructions to hardware-internal RISC instructions. The capability to update x86 microcode enables a vendor to modify CPU behavior in-field, and thus patch erroneous microarchitectural processes or even implement new features. Most prominently, the recent Spectre and Meltdown vulnerabilities were mitigated by Intel via microcode updates. Unfortunately, microcode is proprietary and closed source, and there is little publicly available information on its inner workings. In this paper, we present new reverse engineering results that extend and complement the public knowledge of proprietary microcode. Based on these novel insights, we show how modern system defenses and tools can be realized in microcode on a commercial, off-the-shelf AMD x86 CPU. We demonstrate how well-established system security defenses such as timing attack mitigations, hardware-assisted address sanitization, and instruction set randomization can be realized in microcode. We also present a proof-of-concept implementation of a microcode-assisted instrumentation framework. Finally, we show how a secure microcode update mechanism and enclave functionality can be implemented in microcode to realize a small trusted execution environment. All microcode programs and the whole infrastructure needed to reproduce and extend our results are publicly available.
Benjamin Kollenda, Philipp Koppe, Marc Fyrbiak, Christian Kison, Christof Paar, Thorsten Holz
CCS1
2018 Position-Independent Code Reuse: On the Effectiveness of ASLR in the Absence of Information Disclosure
abstract
Address-space layout randomization is a wellestablished defense against code-reuse attacks. However, it can be completely bypassed by just-in-time code-reuse attacks that rely on information disclosure of code addresses via memory or side-channel exposure. To address this fundamental weakness, much recent research has focused on detecting and mitigating information disclosure. The assumption being that if we perfect such techniques, we will not only maintain layout secrecy but also stop code reuse. In this paper, we demonstrate that an advanced attacker can mount practical code-reuse attacks even in the complete absence of information disclosure. To this end, we present Position-Independent Code-Reuse Attacks, a new class of codereuse attacks relying on the relative rather than absolute location of code gadgets in memory. By means of memory massaging, the attacker first makes the victim program generate a rudimentary ROP payload (for instance, containing code pointers that target instructions "close" to relevant gadgets). Afterwards, the addresses in this payload are patched with small offsets via relative memory writes. To establish the practicality of such attacks, we present multiple Position-Independent ROP exploits against real-world software. After showing that we can bypass ASLR in current systems without requiring information disclosures, we evaluate the impact of our technique on other defenses, such as fine-grained ASLR, multi-variant execution, execute-only memory and re-randomization. We conclude by discussing potential mitigations.
Enes Göktas, Benjamin Kollenda, Philipp Koppe, Erik Bosman, Georgios Portokalidis, Thorsten Holz, Herbert Bos, Cristiano Giuffrida
EuroS&P2
2017 Towards Automated Discovery of Crash-Resistant Primitives in Binary Executables
abstract
Many modern defenses rely on address space layout randomization (ASLR) to efficiently hide security-sensitive metadata in the address space. Absent implementation flaws, an attacker can only bypass such defenses by repeatedly probing the address space for mapped (security-sensitive) regions, incurring a noisy application crash on any wrong guess. Recent work shows that modern applications contain idioms that allow the construction of crash-resistant code primitives, allowing an attacker to efficiently probe the address space without causing any visible crash. In this paper, we classify different crash-resistant primitives and show that this problem is much more prominent than previously assumed. More specifically, we show that rather than relying on labor-intensive source code inspection to find a few "hidden" application-specific primitives, an attacker can find such primitives semi-automatically, on many classes of real-world programs, at the binary level. To support our claims, we develop methods to locate such primitives in real-world binaries. We successfully identified 29 new potential primitives and constructed proof-of-concept exploits for four of them.
Benjamin Kollenda, Enes Göktas, Tim Blazytko, Philipp Koppe, Robert Gawlik, Radhesh Krishnan Konoth, Cristiano Giuffrida, Herbert Bos, Thorsten Holz
DSN1
2017 Reverse Engineering x86 Processor Microcode
Philipp Koppe, Benjamin Kollenda, Marc Fyrbiak, Christian Kison, Robert Gawlik, Christof Paar, Thorsten Holz
USENIX Security Symposium2
2016 Detile: Fine-Grained Information Leak Detection in Script Engines
Robert Gawlik, Philipp Koppe, Benjamin Kollenda, Andre Pawlowski, Behrad Garmany, Thorsten Holz
DIMVA3
2016 Automated Multi-architectural Discovery of CFI-Resistant Code Gadgets
Patrick Wollgast, Robert Gawlik, Behrad Garmany, Benjamin Kollenda, Thorsten Holz
ESORICS (1)4
2016 Enabling Client-Side Crash-Resistance to Overcome Diversification and Information Hiding
Robert Gawlik, Benjamin Kollenda, Philipp Koppe, Behrad Garmany, Thorsten Holz
NDSS2
2016 Subversive-C: Abusing and Protecting Dynamic Message Dispatch
Julian Lettner, Benjamin Kollenda, Andrei Homescu, Per Larsen, Felix Schuster, Lucas Davi, Ahmad-Reza Sadeghi, Thorsten Holz, Michael Franz
USENIX ATC2
2016 Undermining Information Hiding (and What to Do about It)
Enes Göktas, Robert Gawlik, Benjamin Kollenda, Elias Athanasopoulos, Georgios Portokalidis, Cristiano Giuffrida, Herbert Bos
USENIX Security Symposium3
2014 You Can Run but You Can't Read: Preventing Disclosure Exploits in Executable Code
abstract
Code reuse attacks allow an adversary to impose malicious behavior on an otherwise benign program. To mitigate such attacks, a common approach is to disguise the address or content of code snippets by means of randomization or rewriting, leaving the adversary with no choice but guessing. However, disclosure attacks allow an adversary to scan a process - even remotely - and enable her to read executable memory on-the-fly, thereby allowing the just-in time assembly of exploits on the target site. In this paper, we propose an approach that fundamentally thwarts the root cause of memory disclosure exploits by preventing the inadvertent reading of code while the code itself can still be executed. We introduce a new primitive we call Execute-no-Read (XnR) which ensures that code can still be executed by the processor, but at the same time code cannot be read as data. This ultimately forfeits the self-disassembly which is necessary for just-in-time code reuse attacks (JIT-ROP) to work. To the best of our knowledge, XnR is the first approach to prevent memory disclosure attacks of executable code and JIT-ROP attacks in general. Despite the lack of hardware support for XnR in contemporary Intel x86 and ARM processors, our software emulations for Linux and Windows have a run-time overhead of only 2.2% and 3.4%, respectively.
Michael Backes 0001, Thorsten Holz, Benjamin Kollenda, Philipp Koppe, Stefan Nürnberger, Jannik Pewny
CCS3