EDBT 2026 Demo / reviewers in the wild / expert
Ramya Jayaram Masti
dblp:19/10639
· DBLP profile ↗
8ranked-venue papers
3as first author
0since 2021 · last 2019
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-authorSystems, architecture and hardware · 1Computer networks · 1Human-computer interaction and ubiquitous computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
4 papers |
Network security · 58% Cryptographic protocols and secure computation · 15% Usable security · 15% | |
| Computer architecture, parallel and distributed computing, and storage systems
2 papers |
Electronic design automation · 92% Processor architecture and microarchitecture · 8% |
Topics — the 9 heaviest of 12, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Electronic design automation › hardware verification and test
formal verification |
0.4 | 1 | 2019 | Formal Verification of Security Critical Hardware-Firmware Interactions in Commercial SoCs · DAC 2019 |
Electronic design automation
hardware verification and test |
0.4 | 1 | 2019 | Formal Verification of Security Critical Hardware-Firmware Interactions in Commercial SoCs · DAC 2019 |
Cryptographic protocols and secure computation › key management › public key infrastructure
certificate validation |
0.2 | 1 | 2016 | SALVE: server authentication with location verification · MobiCom 2016 |
Network security › wireless network security
secure localization |
0.2 | 1 | 2016 | SALVE: server authentication with location verification · MobiCom 2016 |
Network security
covert channel |
0.2 | 1 | 2015 | Thermal Covert Channels on Multi-core Platforms · USENIX Security Symposium 2015 |
Network security › covert channel
thermal covert channel |
0.2 | 1 | 2015 | Thermal Covert Channels on Multi-core Platforms · USENIX Security Symposium 2015 |
Hardware security and side channels › integrated circuit security
system-on-chip security |
0.1 | 1 | 2019 | Formal Verification of Security Critical Hardware-Firmware Interactions in Commercial SoCs · DAC 2019 |
Internet of things and sensor networks
location service |
0.1 | 1 | 2016 | SALVE: server authentication with location verification · MobiCom 2016 |
Processor architecture and microarchitecture
multicore design |
0.1 | 1 | 2015 | Thermal Covert Channels on Multi-core Platforms · USENIX Security Symposium 2015 |
Methods — techniques the papers use, named apart from their topics
software model checking · 0.8property-specific abstraction · 0.8secure DNS resolution · 0.5TLS extension · 0.5user study · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2019 | Formal Verification of Security Critical Hardware-Firmware Interactions in Commercial SoCsabstractWe present an effective methodology for formally verifying security-critical flows in a commercial System-on-Chip (SoC) which involve extensive interaction between firmware (FW) and hardware (HW). We describe several HW-FW interaction scenarios that are typical in commercial SoCs. We highlight unique challenges associated with formal verification of security properties of such interactions and discuss our approach of property-specific abstraction and software model checking to circumvent those challenges. To the best of our knowledge, this is the first exposition on formal co-verification of security-specific HW-FW interactions in the context and scale of a commercial SoCs. Despite traditional scalability challenges, we demonstrate that many such flows are amenable to effective formal verification. Sayak Ray, Nishant Ghosh, Ramya Jayaram Masti, Arun K. Kanuparthi, Jason M. Fung |
DAC | 3 |
| 2016 | Evaluation of Personalized Security Indicators as an Anti-Phishing Mechanism for Smartphone ApplicationsabstractMobile application phishing happens when a malicious mobile application masquerades as a legitimate one to steal user credentials. Personalized security indicators may help users to detect phishing attacks, but rely on the user's alertness. Previous studies in the context of website phishing have shown that users tend to ignore personalized security indicators and fall victim to attacks despite their deployment. Consequently, the research community has deemed personalized security indicators an ineffective phishing detection mechanism. We revisit the question of personalized security indicator effectiveness and evaluate them in the previously unexplored and increasingly important context of mobile applications. We conducted a user study with 221 participants and found that the deployment of personalized security indicators decreased the phishing attack success rate to 50%. Personalized security indicators can, therefore, help phishing detection in mobile applications and their reputation as an anti-phishing mechanism in the mobile context should be reconsidered. Claudio Marforio, Ramya Jayaram Masti, Claudio Soriente, Kari Kostiainen, Srdjan Capkun |
CHI | 2 |
| 2016 | SALVE: server authentication with location verificationabstractThe Location Service (LCS) proposed by the telecommunication industry is an architecture that allows the location of mobile devices to be accessed in various applications. We explore the use of LCS in location-enhanced server authentication, which traditionally relies on certificates. Given recent incidents involving certificate authorities, various techniques to strengthen server authentication were proposed. They focus on improving the certificate validation process, such as pinning, revocation, or multi-path probing. In this paper, we propose using the server's geographic location as a second factor of its authenticity. Our solution, SALVE, achieves location-based server authentication by using secure DNS resolution and by leveraging LCS for location measurements. We develop a TLS extension that enables the client to verify the server's location in addition to its certificate. Successful server authentication therefore requires a valid certificate and the server's presence at a legitimate geographic location, e.g., on the premises of a data center. SALVE prevents server impersonation by remote adversaries with mis-issued certificates or stolen private keys of the legitimate server. We develop a prototype implementation and our evaluation in real-world settings shows that it incurs minimal impact to the average server throughput. Our solution is backward compatible and can be integrated with existing approaches for improving server authentication in TLS. Der-Yeuan Yu, Aanjhan Ranganathan, Ramya Jayaram Masti, Claudio Soriente, Srdjan Capkun |
MobiCom | 3 |
| 2015 | Logical Partitions on Many-Core PlatformsabstractCloud platforms that use logical partitions to allocate dedicated resources to VMs can benefit from small and therefore secure hypervisors. Many-core platforms, with their abundant resources, are an attractive basis to create and deploy logical partitions on a large scale. However, many-core platforms are designed for efficient cross-core data sharing rather than isolation, which is a key requirement for logical partitions. Typically, logical partitions leverage hardware virtualization extensions that require complex CPU core enhancements. These extensions are not optimal for many-core platforms, where it is preferable to keep the cores as simple as possible. Ramya Jayaram Masti, Claudio Marforio, Kari Kostiainen, Claudio Soriente, Srdjan Capkun |
ACSAC | 1 |
| 2015 | Thermal Covert Channels on Multi-core Platforms
Ramya Jayaram Masti, Devendra Rai, Aanjhan Ranganathan, Lothar Thiele, Srdjan Capkun |
USENIX Security Symposium | 1 |
| 2012 | Enabling trusted scheduling in embedded systemsabstractThe growing complexity and increased networking of security and safety-critical systems expose them to the risk of adversarial compromise through remote attacks. These attacks can result in full system compromise, but often the attacker gains control only over some system components (e.g., a peripheral) and over some applications running on the system. We consider the latter scenario and focus on enabling on-schedule execution of critical applications that are running on a partially compromised system --- we call this trusted scheduling. We identify the essential properties needed for the realization of a trusted scheduling system and we design an embedded system that achieves these properties. We show that our system protects not only against misbehaving applications but also against attacks by compromised peripherals. We evaluate the feasibility and performance of our system through a prototype implementation based on the AVR ATmega103 microcontroller. Ramya Jayaram Masti, Claudio Marforio, Aanjhan Ranganathan, Aurélien Francillon, Srdjan Capkun |
ACSAC | 1 |
| 2012 | Towards Practical Identification of HF RFID DevicesabstractThe deployment of RFID poses a number of security and privacy threats such as cloning, unauthorized tracking, etc. Although the literature contains many investigations of these issues on the logical level, few works have explored the security implications of the physical communication layer. Recently, related studies have shown the feasibility of identifying RFID-enabled devices based on physical-layer fingerprints. In this work, we leverage on these findings and demonstrate that physical-layer identification of HF RFID devices is also practical, that is, can achieve high accuracy and stability. We propose an improved hardware setup and enhanced techniques for fingerprint extraction and matching. Our new system enables device identification with an Equal Error Rate as low as 0.005 (0.5%) on a set 50 HF RFID smart cards of the same manufacturer and type. We further investigate the fingerprint stability over an extended period of time and across different acquisition setups. In the latter case, we propose a solution based on channel equalization that preserves the fingerprint quality across setups. Our results strengthen the practical use of physical-layer identification of RFID devices in product and document anti-counterfeiting solutions. Boris Danev, Srdjan Capkun, Ramya Jayaram Masti, Thomas S. Benjamin |
ACM Trans. Inf. Syst. Secur. | 3 |
| 2011 | Enabling secure VM-vTPM migration in private cloudsabstractThe integration of Trusted Computing technologies into virtualized computing environments enables the hardware-based protection of private information and the detection of malicious software. Their use in virtual platforms, however, requires appropriate virtualization of their main component, the Trusted Platform Module (TPM) by means of virtual TPMs (vTPM). The challenge here is that the use of TPM virtualization should not impede classical platform processes such as virtual machine (VM) migration. Boris Danev, Ramya Jayaram Masti, Ghassan Karame, Srdjan Capkun |
ACSAC | 2 |