Javid Habibi

dblp:162/8516 · DBLP profile ↗
← Back
4ranked-venue papers
3as first author
0since 2021 · last 2017
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-authorSystems, architecture and hardware · 1 · 1 first-authorComputer networks · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Systems and software security · 100%

Topics — the 5 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
code randomization
0.212015
Marlin: Mitigating Code Reuse Attacks Using Code Randomization · IEEE Trans. Dependable Secur. Comput. 2015
Systems and software security › return-oriented programming defense
code reuse attack defense
0.212015
Marlin: Mitigating Code Reuse Attacks Using Code Randomization · IEEE Trans. Dependable Secur. Comput. 2015
Systems and software security
memory safety
0.212015
Marlin: Mitigating Code Reuse Attacks Using Code Randomization · IEEE Trans. Dependable Secur. Comput. 2015
Systems and software security
exploitation
0.112015
Marlin: Mitigating Code Reuse Attacks Using Code Randomization · IEEE Trans. Dependable Secur. Comput. 2015
Systems and software security › exploitation › code reuse attack
return-oriented programming
0.112015
Marlin: Mitigating Code Reuse Attacks Using Code Randomization · IEEE Trans. Dependable Secur. Comput. 2015

Methods — techniques the papers use, named apart from their topics

function block shuffling · 0.2fine-grained randomization · 0.2
YearPublicationVenuePosition
2017 Heimdall: Mitigating the Internet of Insecure Things
abstract
The Internet of Things (IoT) is built of many small smart objects continuously connected to the Internet. This makes these devices an easy target for attacks exploiting vulnerabilities at the network, application, and mobile level. With that it comes as no surprise that distributed denial of service attacks leveraging these vulnerable devices have become a new standard for effective botnets. In this paper, we propose Heimdall, a whitelist-based intrusion detection technique tailored to IoT devices. Heimdall operates on routers acting as gateways for IoT as a homogeneous defense for all devices behind the router. Our experimental results show that our defense mechanism is effective and has minimal overhead.
Javid Habibi, Daniele Midi, Anand Mudgerikar, Elisa Bertino
IEEE Internet Things J.1
2015 MAVR: Code Reuse Stealthy Attacks and Mitigation on Unmanned Aerial Vehicles
abstract
As embedded systems have increased in performance and reliability, their applications have expanded into new domains such as automated drone-based delivery mechanisms. Security of these drones, also referred to as unmanned aerial vehicles (UAVs), is crucial due to their use in many different domains. In this paper, we present a stealthy attack strategy that allows the attacker to change sensor values and modify the UAV navigation path. As the attack is stealthy, the system will continue to execute normally and thus the ground station or other monitoring entities and systems will not be able to detect that an attack is undergoing. With respect to defense, we propose a strategy that combines software and hardware techniques. At software level, we propose a fine grained randomization based approach that modifies the layout of the executable code and hinders code-reuse attack. To strengthen the security of our defense, we leverage a custom hardware platform designed and built by us. The platform isolates the code binary and randomized binary in such a way that the actual code being executed is never exposed for an attacker to analyze. We have implemented a prototype of this defense technique and present results to demonstrate the effectiveness and efficiency of this defense strategy.
Javid Habibi, Aditi Gupta 0002, Stephen Carlsony, Ajay Panicker, Elisa Bertino
ICDCS1
2015 DisARM: Mitigating Buffer Overflow Attacks on Embedded Devices
Javid Habibi, Ajay Panicker, Aditi Gupta 0002, Elisa Bertino
NSS1
2015 Marlin: Mitigating Code Reuse Attacks Using Code Randomization
abstract
Code-reuse attacks, such as return-oriented programming (ROP), are a class of buffer overflow attacks that repurpose existing executable code towards malicious purposes. These attacks bypass defenses against code injection attacks by chaining together sequence of instructions, commonly known as gadgets, to execute the desired attack logic. A common feature of these attacks is the reliance on the knowledge of memory layout of the executable code. We propose a fine grained randomization based approach that breaks these assumptions by modifying the layout of the executable code and hinders code-reuse attack. Our solution, Marlin, randomizes the internal structure of the executable code by randomly shuffling the function blocks in the target binary. This denies the attacker the necessary a priori knowledge of instruction addresses for constructing the desired exploit payload. Our approach can be applied to any ELF binary and every execution of this binary uses a different randomization. We have integrated Marlin into the bash shell that randomizes the target executable before launching it. Our work shows that such an approach incurs low overhead and significantly increases the level of security against code-reuse based attacks.
Aditi Gupta 0002, Javid Habibi, Michael S. Kirkpatrick, Elisa Bertino
IEEE Trans. Dependable Secur. Comput.2