EDBT 2026 Demo / reviewers in the wild / expert
Alireza Nazari
dblp:191/7811
· DBLP profile ↗
5ranked-venue papers
1as first author
0since 2021 · last 2020
0000-0002-6392-2251ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 5 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
4 papers |
Hardware security and side channels · 43% Malware analysis · 21% Cyber-physical and IoT security · 18% | |
| Computer architecture, parallel and distributed computing, and storage systems
4 papers |
Performance modeling and evaluation · 51% Memory systems · 37% Embedded and real-time systems · 13% |
Topics — the 13 heaviest of 13, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Hardware security and side channels › side-channel attack
electromagnetic side channel |
0.7 | 2 | 2020 | REMOTE: Robust External Malware Detection Framework by Using Electromagnetic Signals · IEEE Trans. Computers 2020 EDDIE: EM-Based Detection of Deviations in Program Execution · ISCA 2017 |
Performance modeling and evaluation
profiling |
0.6 | 2 | 2018 | EMPROF: Memory Profiling Via EM-Emanation in IoT and Hand-Held Devices · MICRO 2018 Spectral profiling: Observer-effect-free profiling by monitoring EM emanations · MICRO 2016 |
Malware analysis
malware detection |
0.4 | 1 | 2020 | REMOTE: Robust External Malware Detection Framework by Using Electromagnetic Signals · IEEE Trans. Computers 2020 |
Cyber-physical and IoT security
embedded device attestation |
0.4 | 1 | 2019 | EMMA: Hardware/Software Attestation Framework for Embedded Systems Using Electromagnetic Signals · MICRO 2019 |
Memory systems
cache |
0.3 | 1 | 2018 | EMPROF: Memory Profiling Via EM-Emanation in IoT and Hand-Held Devices · MICRO 2018 |
Memory systems › cache
last-level cache miss |
0.3 | 1 | 2018 | EMPROF: Memory Profiling Via EM-Emanation in IoT and Hand-Held Devices · MICRO 2018 |
Performance modeling and evaluation › profiling
memory profiling |
0.3 | 1 | 2018 | EMPROF: Memory Profiling Via EM-Emanation in IoT and Hand-Held Devices · MICRO 2018 |
Network security › intrusion detection and prevention › intrusion detection
anomaly detection |
0.3 | 1 | 2017 | EDDIE: EM-Based Detection of Deviations in Program Execution · ISCA 2017 |
Hardware security and side channels › side-channel attack
electromagnetic emanation |
0.2 | 2 | 2019 | EMMA: Hardware/Software Attestation Framework for Embedded Systems Using Electromagnetic Signals · MICRO 2019 Spectral profiling: Observer-effect-free profiling by monitoring EM emanations · MICRO 2016 |
Embedded and real-time systems › cyber-physical systems
cyber-physical system security |
0.1 | 1 | 2020 | REMOTE: Robust External Malware Detection Framework by Using Electromagnetic Signals · IEEE Trans. Computers 2020 |
Embedded and real-time systems › networked embedded systems
iot devices |
0.1 | 1 | 2018 | EMPROF: Memory Profiling Via EM-Emanation in IoT and Hand-Held Devices · MICRO 2018 |
Internet of things and sensor networks › security
embedded device security |
0.1 | 1 | 2017 | EDDIE: EM-Based Detection of Deviations in Program Execution · ISCA 2017 |
Network security › intrusion detection and prevention › intrusion detection › attack detection
code injection attack detection |
0.1 | 1 | 2017 | EDDIE: EM-Based Detection of Deviations in Program Execution · ISCA 2017 |
Methods — techniques the papers use, named apart from their topics
electromagnetic signal analysis · 0.8attestation · 0.8machine learning · 0.6electromagnetic emanation analysis · 0.6spectral analysis · 0.5EM emanation monitoring · 0.5EM emanation analysis · 0.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2020 | REMOTE: Robust External Malware Detection Framework by Using Electromagnetic SignalsabstractCyber-physical systems (CPS) are controlling many critical and sensitive aspects of our physical world while being continuously exposed to potential cyber-attacks. These systems typically have limited performance, memory, and energy reserves, which limits their ability to run existing advanced malware protection, and that, in turn, makes securing them very challenging. To tackle these problems, this paper proposes, REMOTE, a new robust framework to detect malware by externally observing Electromagnetic (EM) signals emitted by an electronic computing device (e.g., a microprocessor) while running a known application, in real-time and with a low detection latency, and without any a priori knowledge of the malware. REMOTE does not require any resources or infrastructure on, or any modifications to, the monitored system itself, which makes REMOTE especially suitable for malware detection on resource-constrained devices such as embedded devices, CPSs, and Internet of Things (IoT) devices where hardware and energy resources may be limited. To demonstrate the usability of REMOTE in real-world scenarios, we port two real-world programs (an embedded medical device and an industrial PID controller), each with a meaningful attack (a code-reuse and a code-injection attack), to four different hardware platforms. We also port shellcode-based DDoS and Ransomware attacks to five different standard applications on an embedded system. To further demonstrate the applicability of REMOTE to commercial CPS, we use REMOTE to monitor a Robotic Arm. Our results on all these different hardware platforms show that, for all attacks on each of the platforms, REMOTE successfully detects each instance of an attack and has99.9 percent true positive rates) under all these conditions. We also compare REMOTE to prior work EDDIE [1] and SYNDROME [2], and demonstrate that these prior work are unable to achieve high accuracy under these variations. Nader Sehatbakhsh, Alireza Nazari, Monjur Alam, Frank Werner 0005, Yuanda Zhu, Alenka G. Zajic, Milos Prvulovic |
IEEE Trans. Computers | 2 |
| 2019 | EMMA: Hardware/Software Attestation Framework for Embedded Systems Using Electromagnetic SignalsabstractEstablishing trust for an execution environment is an important problem, and practical solutions for it rely on attestation, where an untrusted system (prover) computes a response to a challenge sent by the trusted system (verifier). The response typically is a checksum of the prover's program, which the verifier checks against expected values for a "clean" (trustworthy) system. The main challenge in attestation is that, in addition to checking the response, the verifier also needs to verify the integrity of the response computation. On higher-end processors, this integrity is verified cryptographically, using dedicated trusted hardware. On embedded systems, however, constraints prevent the use of such hardware support. Instead, a popular approach is to use the request-to-response time as a way to establish confidence. However, the overall request-to-response time provides only one coarse-grained measurement from which the integrity of the attestation is to be inferred, and even that is noisy because it includes the network latency and/or variations due to micro-architectural events. Thus, the attestation is vulnerable to attacks where the adversary has tampered with response computation, but the resulting additional computation time is small relative to the overall request-to-response time. Nader Sehatbakhsh, Alireza Nazari, Haider Adnan Khan, Alenka G. Zajic, Milos Prvulovic |
MICRO | 2 |
| 2018 | EMPROF: Memory Profiling Via EM-Emanation in IoT and Hand-Held DevicesabstractThis paper presents EMPROF, a new method for profiling the performance impact of the memory subsystem without any support on, or interference with, the profiled system. Rather than rely on hardware support and/or software instrumentation on the profiled system, EMPROF analyzes the system's EM emanations to identify processor stalls that are associated with last-level cache (LLC) misses. This enables EMPROF to accurately pinpoint LLC misses in the execution timeline and to measure the cost (stall time) of each miss. Since EMPROF has zero "observer effect", so it can be used to profile applications that adjust their activity to their performance. It has no overhead on target machine, so it can be used for profiling embedded, hand-held, and IoT devices which usually have limited support for collecting, and limited resources for storing, the profiling data. Finally, since EMPROF can profile the system as-is, its profiling of boot code and other hard-to-profile software components is as accurate as its profiling of application code. To illustrate the effectiveness of EMPROF, we first validate its results using microbenchmarks with known memory behavior, and also on SPEC benchmarks running a cycle-accurate simulator that can provide detailed ground-truth data about LLC misses and processor stalls. We then demonstrate the effectiveness of EMPROF on real systems, including profiling of boot activity, show how its results can be attributed to the specific parts of the application code when that code is available, and provide additional insight on the statistics reported by EMPROF and how they are affected by the EM signal bandwidth provided to EMPROF. Moumita Dey, Alireza Nazari, Alenka G. Zajic, Milos Prvulovic |
MICRO | 2 |
| 2017 | EDDIE: EM-Based Detection of Deviations in Program ExecutionabstractThis paper describes EM-Based Detection of Deviations in Program Execution (EDDIE), a new method for detecting anomalies in program execution, such as malware and other code injections, without introducing any overheads, adding any hardware support, changing any software, or using any resources on the monitored system itself. Monitoring with EDDIE involves receiving electromagnetic (EM) emanations that are emitted as a side effect of execution on the monitored system, and it relies on spikes in the EM spectrum that are produced as a result of periodic (e.g. loop) activity in the monitored execution. During training, EDDIE characterizes normal execution behavior in terms of peaks in the EM spectrum that are observed at various points in the program execution, but it does not need any characterization of the malware or other code that might later be injected. During monitoring, EDDIE identifies peaks in the observed EM spectrum, and compares these peaks to those learned during training. Since EDDIE requires no resources on the monitored machine and no changes to the monitored software, it is especially well suited for security monitoring of embedded and IoT devices. We evaluate EDDIE on a real IoT system and in a cycle-accurate simulator, and find that even relatively brief injected bursts of activity (a few milliseconds) are detected by EDDIE with high accuracy, and that it also accurately detects when even a few instructions are injected into an existing loop within the application. Alireza Nazari, Nader Sehatbakhsh, Monjur Alam, Alenka G. Zajic, Milos Prvulovic |
ISCA | 1 |
| 2016 | Spectral profiling: Observer-effect-free profiling by monitoring EM emanationsabstractThis paper presents Spectral Profiling, a new method for profiling program execution without instrumenting or otherwise affecting the profiled system. Spectral Profiling monitors EM emanations unintentionally produced by the profiled system, looking for spectral “spikes” produced by periodic program activity (e.g. loops). This allows Spectral Profiling to determine which parts of the program have executed at what time. By analyzing the frequency and shape of the spectral “spike”, Spectral Profiling can obtain additional information such as the per-iteration execution time of a loop. The key advantage of Spectral Profiling is that it can monitor a system as-is, without program instrumentation, system activity, etc. associated with the profiling itself, i.e. it completely eliminates the “Observer's Effect” and allows profiling of programs whose execution is performance-dependent and/or programs that run on even the simplest embedded systems that have no resources or support for profiling. We evaluate the effectiveness of Spectral Profiling by applying it to several benchmarks from MiBench suite on a real system, and also on a cycle-accurate simulator. Our results confirm that Spectral Profiling yields useful information about the runtime behavior of a program, allowing Spectral Profiling to be used for profiling in systems where profiling infrastructure is not available, or where profiling overheads may perturb the results too much (“Observer's Effect”). Nader Sehatbakhsh, Alireza Nazari, Alenka G. Zajic, Milos Prvulovic |
MICRO | 2 |