Sam L. Thomas

dblp:201/9322 · DBLP profile ↗
← Back
6ranked-venue papers
3as first author
3since 2021 · last 2026
0000-0002-4321-1129ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 3 since 2021
YearPublicationVenuePosition
2026 Practical Type Inference: High-Throughput Recovery of Real-World Structures and Function Signatures
abstract
The recovery of types from stripped binaries is a key to exact decompilation, yet its practical realization suffers. For composite structures in particular, both layout and semantic fidelity are required to enable end-to-end reconstruction. Many existing approaches either synthesize layouts or infer names post-hoc, which weakens downstream usability. This is further aggravated by an excessive runtime overhead that is especially prohibitive in automated environments. We present XTRIDE, an improved n-gram-based approach that focuses on practicality: highly optimized throughput and actionable confidence scores allow for deployment in automated pipelines. When compared to the state of the art in struct recovery, our method achieves comparable performance while being between 70 and 2300x faster. As our inference is grounded in real-world types, we achieve the highest ratio of fully-correct struct layouts. With an optimized training regimen, our model outperforms the current state of the art on the DIRT dataset by 5.09 percentage points, achieving 90.15% type inference accuracy overall. Furthermore, we show that n-gram-based type prediction generalizes to function signature recovery: conducting a case study on embedded firmware, we show that this efficient approach to function similarity can assist in typical reverse engineering tasks.
Lukas Seidel, Sam L. Thomas, Konrad Rieck
CODASPY2
2022 MetaEmu: An Architecture Agnostic Rehosting Framework for Automotive Firmware
abstract
In this paper we present MetaEmu, an architecture-agnostic framework geared towards rehosting and security analysis of automotive firmware. MetaEmu improves over existing rehosting environments in two ways: Firstly, it solves the hitherto open-problem of a lack of generic Virtual Execution Environments (VXEs) by synthesizing processor simulators from Ghidra's language definitions. Secondly, MetaEmu can rehost and analyze multiple targets, each of different architecture, simultaneously, and share analysis facts between each target's analysis environment, a technique we call inter-device analysis.
Zitai Chen, Sam L. Thomas, Flavio D. Garcia
CCS2
2022 The Closer You Look, The More You Learn: A Grey-box Approach to Protocol State Machine Learning
abstract
We propose a new approach to infer state machine models from protocol implementations. Our new tool, StateInspector, learns protocol states by using novel program analyses to combine observations of run-time memory and I/O. It requires no access to source code and only lightweight execution monitoring of the implementation under test. We demonstrate and evaluate StateInspector's effectiveness on numerous TLS and WPA/2 implementations. In the process, we show StateInspector enables deeper state discovery, increased learning efficiency, and more insight compared to existing approaches. Our method led us to discover several concerning deviations from the standards and vulnerabilities in IWD and WolfSSL, both of which were assigned CVEs.
Chris McMahon Stone, Sam L. Thomas, Mathy Vanhoef, Nicolas Bailluet, Tom Chothia
CCS2
2018 Backdoors: Definition, Deniability and Detection
Sam L. Thomas, Aurélien Francillon
RAID1
2017 HumIDIFy: A Tool for Hidden Functionality Detection in Firmware
Sam L. Thomas, Flavio D. Garcia, Tom Chothia
DIMVA1
2017 Stringer: Measuring the Importance of Static Data Comparisons to Detect Backdoors and Undocumented Functionality
Sam L. Thomas, Tom Chothia, Flavio D. Garcia
ESORICS (2)1