EDBT 2026 Demo / reviewers in the wild / expert
Yves Bieri
dblp:237/0696
· DBLP profile ↗
2ranked-venue papers
0as first author
1since 2021 · last 2024
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 1Security and privacy · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Network security · 100% | |
| Computer networks
2 papers |
Software-defined and programmable networks · 62% Network management and operations · 38% | |
| Software engineering, system software, and programming languages
1 paper |
Program analysis · 100% |
Topics — the 2 heaviest of 4, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Software-defined and programmable networks
network function |
0.4 | 1 | 2019 | Alembic: Automated Model Inference for Stateful Network Functions · NSDI 2019 |
Network management and operations › configuration verification
firewall verification |
0.2 | 1 | 2024 | Pryde: A Modular Generalizable Workflow for Uncovering Evasion Attacks Against Stateful Firewall Deployments · SP 2024 |
Methods — techniques the papers use, named apart from their topics
model-guided workflow · 1.5black-box fuzzing · 1.5model inference · 0.8
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Pryde: A Modular Generalizable Workflow for Uncovering Evasion Attacks Against Stateful Firewall DeploymentsabstractStateful firewalls (SFW) play a critical role in securing our network infrastructure. Incorrect implementation of the intended stateful semantics can lead to evasion opportunities, even if firewall rules are configured correctly. Uncovering these opportunities is challenging due to the (1) black-box and proprietary nature of firewalls; (2) diversity of deployments; and (3) complex stateful semantics. To tackle these challenges, we present Pryde. Pryde uses a modular model-guided workflow that generalizes across black-box firewall implementations and deployment-specific settings to generate evasion attacks. Pryde infers a behavioral model of the stateful firewall in the presence of potentially non-TCP-compliant packet sequences. It uses this model in conjunction with attacker capabilities and victim behavior to synthesize custom evasion attacks. Using Pryde, we identify more than 6,000 unique attacks against 4 popular firewalls and 4 host networking stacks, many of which cannot be uncovered by prior work on censorship circumvention and black-box fuzzing. Soo-Jin Moon, Milind Srivastava, Yves Bieri, Ruben Martins, Vyas Sekar |
SP | 3 |
| 2019 | Alembic: Automated Model Inference for Stateful Network Functions
Soo-Jin Moon, Jeffrey Helt, Yves Bieri, Sujata Banerjee, Vyas Sekar, Wenfei Wu, Mihalis Yannakakis, Ying Zhang 0022 |
NSDI | 4 |