EDBT 2026 Demo / reviewers in the wild / expert
Yasser Shalabi
dblp:191/7790
· DBLP profile ↗
2ranked-venue papers
1as first author
0since 2021 · last 2018
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 2 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Systems and software security · 38% Hardware security and side channels · 33% Network security · 29% | |
| Computer architecture, parallel and distributed computing, and storage systems
2 papers |
Processor architecture and microarchitecture · 40% Memory systems · 30% Storage systems · 30% |
Topics — the 8 heaviest of 9, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security › exploitation
control-flow attack |
0.3 | 1 | 2018 | Record-Replay Architecture as a General Security Framework · HPCA 2018 |
Systems and software security
return-oriented programming defense |
0.3 | 1 | 2018 | Record-Replay Architecture as a General Security Framework · HPCA 2018 |
Network security › intrusion detection and prevention › intrusion detection
attack detection |
0.2 | 1 | 2016 | ReplayConfusion: Detecting cache-based covert channel attacks using record and replay · MICRO 2016 |
Network security › covert channel
cache covert channel |
0.2 | 1 | 2016 | ReplayConfusion: Detecting cache-based covert channel attacks using record and replay · MICRO 2016 |
Hardware security and side channels
side channel |
0.2 | 1 | 2016 | ReplayConfusion: Detecting cache-based covert channel attacks using record and replay · MICRO 2016 |
Processor architecture and microarchitecture › branch prediction
return address stack |
0.1 | 1 | 2018 | Record-Replay Architecture as a General Security Framework · HPCA 2018 |
Storage systems › flash and SSD › flash memory management › flash translation layer
address mapping |
0.1 | 1 | 2016 | ReplayConfusion: Detecting cache-based covert channel attacks using record and replay · MICRO 2016 |
Memory systems
cache |
0.1 | 1 | 2016 | ReplayConfusion: Detecting cache-based covert channel attacks using record and replay · MICRO 2016 |
Methods — techniques the papers use, named apart from their topics
hypervisor changes · 0.7checkpointing · 0.7cache miss rate analysis · 0.5record-and-replay · 0.2record and replay · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2018 | Record-Replay Architecture as a General Security FrameworkabstractHardware security features need to strike a careful balance between design intrusiveness and completeness of methods. In addition, they need to be flexible, as security threats continuously evolve. To help address these requirements, this paper proposes a novel framework where Record and Deterministic Replay (RnR) is used to complement hardware security features. We call the framework RnR-Safe. RnR-Safe reduces the cost of security hardware by allowing it to be less precise at detecting attacks, potentially reporting false positives. This is because it relies on on-the-fly replay that transparently verifies whether the alarm is a real attack or a false positive. RnR-Safe uses two replayers: an always-on, fast Checkpoint replayer that periodically creates checkpoints, and a detailed-analysis Alarm replayer that is triggered when there is a threat alarm. As an example application, we use RnR-Safe to thwart Return Oriented Programming (ROP) attacks, including on the Linux kernel. Our design augments the Return Address Stack (RAS) with relatively inexpensive hardware. We evaluate RnR-Safe using a variety of workloads on virtual machines running Linux. We find that RnR-Safe is very effective. Thanks to the judicious RAS hardware extensions and hypervisor changes, the checkpointing replayer has an execution speed comparable to the recorded execution. Also, the alarm replayer needs to handle very few false positives. Yasser Shalabi, Mengjia Yan 0001, Nima Honarmand, Ruby B. Lee, Josep Torrellas |
HPCA | 1 |
| 2016 | ReplayConfusion: Detecting cache-based covert channel attacks using record and replayabstractCache-based covert channel attacks use highly-tuned shared-cache conflict misses to pass information from a trojan to a spy process. Detecting such attacks is very challenging. State of the art detection mechanisms do not consider the general characteristics of such attacks and, instead, focus on specific communication protocols. As a result, they fail to detect attacks using different protocols and, hence, have limited coverage. In this paper, we make the following observation about these attacks: not only are the malicious accesses highly tuned to the mapping of addresses to the caches; they also follow a distinctive cadence as bits are being received. Changing the mapping of addresses to the caches substantially disrupts the conflict miss patterns, but retains the cadence. This is in contrast to benign programs. Based on this observation, we propose a novel, high-coverage approach to detect cache-based covert channel attacks. It is called ReplayConfusion, and is based on Record and deterministic Replay (RnR). After a program's execution is recorded, it is deterministically replayed using a different mapping of addresses to the caches. We then analyze the difference between the cache miss rate timelines of the two runs. If the difference function is both sizable and exhibits a periodic pattern, it indicates that there is an attack. This paper also introduces a new taxonomy of cache-based covert channel attacks, and shows that ReplayConfusion uncovers examples from all the categories. Finally, ReplayConfusion only needs simple hardware. Mengjia Yan 0001, Yasser Shalabi, Josep Torrellas |
MICRO | 2 |