Stewart Sentanoe

dblp:230/1464 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Active and passive virtual machine introspection on AMD and ARM processors
Thomas Dangl, Stewart Sentanoe, Hans P. Reiser
J. Syst. Archit.2
2023 VMIFresh: Efficient and fresh caches for virtual machine introspection
Thomas Dangl, Stewart Sentanoe, Hans P. Reiser
Comput. Secur.2
2022 VMIFresh: Efficient and Fresh Caches for Virtual Machine Introspection
abstract
Virtual machine introspection (VMI) is the process of extracting knowledge about the inner state of a virtual machine from the outside. Traditional passive introspection mechanisms have proved themselves ineffective in many application domains due to their low performance. As a remedy for this issue, caching at the level of the introspection application was introduced. However, this sacrificed the freshness of VMI and led to an inconsistent outside view.
Thomas Dangl, Stewart Sentanoe, Hans P. Reiser
ARES2
2022 "The Need for Speed": Extracting Session Keys From the Main Memory Using Brute-force and Machine Learning
abstract
Digital forensics has become an important topic during this digital devices era. One major problem is extracting critical information from a digital device, and one of such data sources from a digital device is the main memory. The main memory holds many data that can be as simple as a text and a number or as complex as a data structure that holds cryptography keys. In line with the growth of the digital devices era, the need for privacy is also becoming an emerging topic. Encryption is one of the ways to achieve privacy during data transmission. As mentioned, the main memory might hold the session keys to encrypt or decrypt such secure data transmissions. This paper proposes a pure brute-force and a machine learning augmented brute force method to extract session keys from the main memory. In addition, we reduce the training data footprint using a novel entropy-based preprocessing method. We choose the most commonly used secure communication protocols: Secure Shell (SSH) and Transport Layer Security (TLS). With the help of machine learning, our method becomes efficient compared to the brute-force method. Our performance evaluation shows that our methods can extract the keys with high precision and considerably fast run-time.
Stewart Sentanoe, Christofer Fellicious, Hans P. Reiser, Michael Granitzer
TrustCom1