EDBT 2026 Demo / reviewers in the wild / expert
Samira Briongos
dblp:189/1192
· DBLP profile ↗
6ranked-venue papers
4as first author
3since 2021 · last 2026
0000-0001-7671-0242ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | On Securing the Software Development Lifecycle in IoT RISC-V Trusted Execution Environments
Annika Wilde, Samira Briongos, Claudio Soriente, Ghassan Karame |
SenSys | 2 |
| 2023 | No Forking Way: Detecting Cloning Attacks on Intel SGX ApplicationsabstractForking attacks against TEEs like Intel SGX can be carried out either by rolling back the application to a previous state, or by cloning the application and by partitioning its inputs across the cloned instances. Current solutions to forking attacks require Trusted Third Parties (TTP) that are hard to find in real-world deployments. In the absence of a TTP, many TEE applications rely on monotonic counters to mitigate forking attacks based on rollbacks; however, they have no protection mechanism against forking attack based on cloning. In this paper, we analyze 72 SGX applications and show that approximately 20% of those are vulnerable to forking attacks based on cloning—including those that rely on monotonic counters. Samira Briongos, Ghassan Karame, Claudio Soriente, Annika Wilde |
ACSAC | 1 |
| 2021 | Aim, Wait, Shoot: How the CacheSniper Technique Improves Unprivileged Cache AttacksabstractMicroarchitectural side channel attacks have been very prominent in security research over the last few years. Caches proved to be an outstanding side channel, as they provide high resolution and generic cross-core leakage. All major cryptographic libraries provide countermeasures to hinder key extraction via cross-core cache attacks by now. In this paper, we analyze implementations protected by prefetch-based countermeasures aimed at preventing well-known cache attacks, and highlight the circumstances causing them to remain vulnerable. Further, we craft a novel attack technique that precisely synchronizes the attacking and the victim processes, enabling the attacking process to evict the target data from the cache at the desired instants. One key improvement of our approach is that it provides unprivileged attackers with a method to remove specific data from the cache with a single memory access and in absence of shared memory by leveraging the transient capabilities of TSX and relying on the L3 replacement policy. We show the feasibility of our approach by extracting an RSA key from the latest wolfSSL library and an AES key from the T-Table and S-Box implementations included in OpenSSL with CacheSniper. Both libraries implement prefetch-based methods as a protection against cache attacks. Samira Briongos, Ida Bruhns, Pedro Malagón, Thomas Eisenbarth 0001, José Manuel Moya |
EuroS&P | 1 |
| 2020 | RELOAD+REFRESH: Abusing Cache Replacement Policies to Perform Stealthy Cache Attacks
Samira Briongos, Pedro Malagón, José Manuel Moya, Thomas Eisenbarth 0001 |
USENIX Security Symposium | 1 |
| 2018 | CacheShield: Detecting Cache Attacks through Self-ObservationabstractMicroarchitectural attacks pose a great threat to any code running in parallel to other untrusted processes. Especially in public clouds, where system resources such as caches are shared across several tenants, microarchitectural attacks remain an unsolved problem. Cache attacks rely on evictions by the spy process, which alter the execution behavior of the victim process. Similarly, all attacks exploiting shared resource access will influence these resources, thereby influencing the process they are targeting. We show that hardware performance events reveal the presence of such attacks. Based on this observation, we propose CacheShield, a tool to protect legacy code by self-monitoring its execution and detecting the presence of microarchitectural attacks. CacheShield can be run by users and does not require alteration of the OS or hypervisor, while previously proposed software-based countermeasures require cooperation from the hypervisor. Unlike methods that try to detect malicious processes, our approach is lean, as only a fraction of the system needs to be monitored. It also integrates well into today's cloud infrastructure, as concerned users can opt to use CacheShield without support from the cloud service provider. Our results show that CacheShield detects attacks fast, with high reliability, and with few false positives, even in the presence of strong noise. Samira Briongos, Gorka Irazoqui Apecechea, Pedro Malagón, Thomas Eisenbarth 0001 |
CODASPY | 1 |
| 2018 | Applying Cost-Sensitive Classifiers with Reinforcement Learning to IDS
Roberto Blanco, Juan J. Cilla, Samira Briongos, Pedro Malagón, José Manuel Moya |
IDEAL (1) | 3 |