Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Yasser Shalabi

dblp:191/7790 · DBLP profile ↗
← Back
2ranked-venue papers
1as first author
0since 2021 · last 2018
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 2 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Systems and software security · 38% Hardware security and side channels · 33% Network security · 29%
Computer architecture, parallel and distributed computing, and storage systems
2 papers
Processor architecture and microarchitecture · 40% Memory systems · 30% Storage systems · 30%

Topics — the 8 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › exploitation
control-flow attack
0.312018
Record-Replay Architecture as a General Security Framework · HPCA 2018
Systems and software security
return-oriented programming defense
0.312018
Record-Replay Architecture as a General Security Framework · HPCA 2018
Network security › intrusion detection and prevention › intrusion detection
attack detection
0.212016
ReplayConfusion: Detecting cache-based covert channel attacks using record and replay · MICRO 2016
Network security › covert channel
cache covert channel
0.212016
ReplayConfusion: Detecting cache-based covert channel attacks using record and replay · MICRO 2016
Hardware security and side channels
side channel
0.212016
ReplayConfusion: Detecting cache-based covert channel attacks using record and replay · MICRO 2016
Processor architecture and microarchitecture › branch prediction
return address stack
0.112018
Record-Replay Architecture as a General Security Framework · HPCA 2018
Storage systems › flash and SSD › flash memory management › flash translation layer
address mapping
0.112016
ReplayConfusion: Detecting cache-based covert channel attacks using record and replay · MICRO 2016
Memory systems
cache
0.112016
ReplayConfusion: Detecting cache-based covert channel attacks using record and replay · MICRO 2016

Methods — techniques the papers use, named apart from their topics

hypervisor changes · 0.7checkpointing · 0.7cache miss rate analysis · 0.5record-and-replay · 0.2record and replay · 0.2
YearPublicationVenuePosition
2018 Record-Replay Architecture as a General Security Framework
abstract
Hardware security features need to strike a careful balance between design intrusiveness and completeness of methods. In addition, they need to be flexible, as security threats continuously evolve. To help address these requirements, this paper proposes a novel framework where Record and Deterministic Replay (RnR) is used to complement hardware security features. We call the framework RnR-Safe. RnR-Safe reduces the cost of security hardware by allowing it to be less precise at detecting attacks, potentially reporting false positives. This is because it relies on on-the-fly replay that transparently verifies whether the alarm is a real attack or a false positive. RnR-Safe uses two replayers: an always-on, fast Checkpoint replayer that periodically creates checkpoints, and a detailed-analysis Alarm replayer that is triggered when there is a threat alarm. As an example application, we use RnR-Safe to thwart Return Oriented Programming (ROP) attacks, including on the Linux kernel. Our design augments the Return Address Stack (RAS) with relatively inexpensive hardware. We evaluate RnR-Safe using a variety of workloads on virtual machines running Linux. We find that RnR-Safe is very effective. Thanks to the judicious RAS hardware extensions and hypervisor changes, the checkpointing replayer has an execution speed comparable to the recorded execution. Also, the alarm replayer needs to handle very few false positives.
Yasser Shalabi, Mengjia Yan 0001, Nima Honarmand, Ruby B. Lee, Josep Torrellas
HPCA1
2016 ReplayConfusion: Detecting cache-based covert channel attacks using record and replay
abstract
Cache-based covert channel attacks use highly-tuned shared-cache conflict misses to pass information from a trojan to a spy process. Detecting such attacks is very challenging. State of the art detection mechanisms do not consider the general characteristics of such attacks and, instead, focus on specific communication protocols. As a result, they fail to detect attacks using different protocols and, hence, have limited coverage. In this paper, we make the following observation about these attacks: not only are the malicious accesses highly tuned to the mapping of addresses to the caches; they also follow a distinctive cadence as bits are being received. Changing the mapping of addresses to the caches substantially disrupts the conflict miss patterns, but retains the cadence. This is in contrast to benign programs. Based on this observation, we propose a novel, high-coverage approach to detect cache-based covert channel attacks. It is called ReplayConfusion, and is based on Record and deterministic Replay (RnR). After a program's execution is recorded, it is deterministically replayed using a different mapping of addresses to the caches. We then analyze the difference between the cache miss rate timelines of the two runs. If the difference function is both sizable and exhibits a periodic pattern, it indicates that there is an attack. This paper also introduces a new taxonomy of cache-based covert channel attacks, and shows that ReplayConfusion uncovers examples from all the categories. Finally, ReplayConfusion only needs simple hardware.
Mengjia Yan 0001, Yasser Shalabi, Josep Torrellas
MICRO2