Aastha Mehta

dblp:161/0164 · DBLP profile ↗
← Back
9ranked-venue papers
2as first author
5since 2021 · last 2025
0009-0005-3416-5254ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 2 first-author · 4 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Comparing Isolation Mechanisms with OSmosis
abstract
There exist many mechanisms, ranging from processes to virtual machines, for isolating untrusted computations from each other. Each mechanism explicitly isolates certain resources while, either implicitly or explicitly, sharing the rest. Unfortunately, we lack a comprehensive way to formally and systematically reason about which resources are shared, to what extent they are shared, and how this sharing determines the degree of isolation between any two computations.
Sidhartha Agrawal, Shaurya Patel, Arya Stevinson, Ilias Karimalis, Hugo Lefeuvre, Aastha Mehta, Reto Achermann, Margo I. Seltzer
PLOS@SOSP7
2025 Growlithe: A Developer-Centric Compliance Tool for Serverless Applications
abstract
Serverless applications consist of functions written in heterogeneous programming languages, use diverse data stores and communication services, and evolve rapidly. Consequently, it is challenging for serverless tenants to protect their application data from inadvertent leaks due to bugs, misconfigurations, and human errors. Cloud security tools, such as Identity and Access Management (IAM), lack observability into a tenant's application, whereas the state-of-the-art dataflow tracking tools require support from the cloud platform and incur significant runtime overheads. We present Growlithe, a tool that integrates with the serverless application development toolchain and enables continuous compliance with data policies by design. Growlithe allows declarative specification of access and data flow control policies over a language- and platform-independent dataflow graph abstraction of a serverless application, and enforces these policies through a combination of static analysis and runtime enforcement. We used Growlithe with applications using Python and JavaScript functions that can be hosted on AWS Lambda and Google Cloud Functions platforms. We empirically demonstrate that Growlithe is cross-cutting, portable and efficient, and enables developers to easily adapt their application and policies to evolving requirements.
Arshia Moghimi, Devam Sisodraker, Mohammad Shahrad, Aastha Mehta
SP5
2025 Relocate-Vote: Using Sparsity Information to Exploit Ciphertext Side-Channels
Yuqin Yan, Wei Huang 0027, Ilya Grishchenko, Gururaj Saileshwar, Aastha Mehta, David Lie
USENIX Security Symposium5
2024 NetShaper: A Differentially Private Network Side-Channel Mitigation System
Amir Sabzi, Rut Vora, Swati Goswami, Margo I. Seltzer, Mathias Lécuyer, Aastha Mehta
USENIX Security Symposium6
2022 Pacer: Comprehensive Network Side-Channel Mitigation in the Cloud
Aastha Mehta, Mohamed Alzayat, Roberta De Viti, Björn B. Brandenburg, Peter Druschel, Deepak Garg 0001
USENIX Security Symposium1
2017 Qapla: Policy compliance for database-backed systems
Aastha Mehta, Eslam Elnikety, Katura Harvey, Deepak Garg 0001, Peter Druschel
USENIX Security Symposium1
2016 Thoth: Comprehensive Policy Compliance in Data Retrieval Systems
Eslam Elnikety, Aastha Mehta, Anjo Vahldiek-Oberwagner, Deepak Garg 0001, Peter Druschel
USENIX Security Symposium2
2016 Oblivious Multi-Party Machine Learning on Trusted Processors
Olga Ohrimenko, Felix Schuster, Cédric Fournet, Aastha Mehta, Sebastian Nowozin, Kapil Vaswani, Manuel Costa
USENIX Security Symposium4
2015 Guardat: enforcing data policies at the storage layer
abstract
In today's data processing systems, both the policies protecting stored data and the mechanisms for their enforcement are spread over many software components and configuration files, increasing the risk of policy violation due to bugs, vulnerabilities and misconfigurations. Guardat addresses this problem. Users, developers and administrators specify file protection policies declaratively, concisely and separate from code, and Guardat enforces these policies by mediating I/O in the storage layer. Policy enforcement relies only on the integrity of the Guardat controller and any external policy dependencies. The semantic gap between the storage layer enforcement and per-file policies is bridged using cryptographic attestations from Guardat. We present the design and prototype implementation of Guardat, enforce example policies in a Web server, and show experimentally that its overhead is low.
Anjo Vahldiek-Oberwagner, Eslam Elnikety, Aastha Mehta, Deepak Garg 0001, Peter Druschel, Rodrigo Rodrigues 0001, Johannes Gehrke, Ansley Post
EuroSys3