EDBT 2026 Demo / reviewers in the wild / expert
Prithvi Bisht
dblp:24/1183
· DBLP profile ↗
9ranked-venue papers
6as first author
0since 2021 · last 2014
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 6 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
4 papers |
Systems and software security · 67% Web and mobile security · 33% | |
| Software engineering, system software, and programming languages
1 paper |
Software maintenance and evolution · 100% |
Topics — the 10 heaviest of 10, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
vulnerability discovery |
0.2 | 2 | 2011 | WAPTEC: whitebox analysis of web applications for parameter tampering exploit construction · CCS 2011 NoTamper: automatic blackbox detection of parameter tampering opportunities in web applications · CCS 2010 |
Web and mobile security
web application vulnerability |
0.2 | 2 | 2011 | WAPTEC: whitebox analysis of web applications for parameter tampering exploit construction · CCS 2011 NoTamper: automatic blackbox detection of parameter tampering opportunities in web applications · CCS 2010 |
Systems and software security › exploitation
exploit generation |
0.1 | 1 | 2011 | WAPTEC: whitebox analysis of web applications for parameter tampering exploit construction · CCS 2011 |
Systems and software security
program transformation |
0.1 | 1 | 2010 | TAPS: automatically preparing safe SQL queries · CCS 2010 |
Systems and software security › exploitation › injection attacks
SQL injection |
0.1 | 1 | 2010 | TAPS: automatically preparing safe SQL queries · CCS 2010 |
Systems and software security › vulnerability management
vulnerability mitigation |
0.1 | 1 | 2010 | TAPS: automatically preparing safe SQL queries · CCS 2010 |
Systems and software security › exploitation
injection attacks |
0.1 | 1 | 2007 | CANDID: preventing sql injection attacks using dynamic candidate evaluations · CCS 2007 |
Web and mobile security
SQL injection prevention |
0.1 | 1 | 2007 | CANDID: preventing sql injection attacks using dynamic candidate evaluations · CCS 2007 |
Web and mobile security
web application security |
0.1 | 1 | 2007 | CANDID: preventing sql injection attacks using dynamic candidate evaluations · CCS 2007 |
Software maintenance and evolution › software maintenance
legacy code |
0.0 | 1 | 2010 | TAPS: automatically preparing safe SQL queries · CCS 2010 |
Methods — techniques the papers use, named apart from their topics
program transformation · 0.3prepared statements · 0.2symbolic execution · 0.1static analysis · 0.1input validation analysis · 0.1black-box testing · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2014 | Automated detection of parameter tampering opportunities and vulnerabilities in web applicationsabstractParameter tampering attacks are dangerous to a web application whose server fails to replicate the validation of user-supplied data that is performed by the client in web forms. Malicious users who circumvent the client can capitalize on the missing server validation. In this paper, we provide a formal description of parameter tampering vulnerabilities and a high level approach for their detection. We specialize this high level approach to develop complementary detection solutions in two interesting settings: blackbox (only analyze client-side code in web forms) and whitebox (also analyze server-side code that processes submitted web forms). This paper presents interesting challenges encountered in realizing the high level approach for each setting and novel technical contributions that address these challenges. We also contrast utility, difficulties and effectiveness issues in both settings and provide a quantitative comparison of results. Our experiments with real world and open source applications demonstrate that parameter tampering vulnerabilities are prolific (total 47 in 9 applications), and their exploitation can have serious consequences including unauthorized transactions, account hijacking and financial losses. We conclude this paper with a discussion on countermeasures for parameter tampering attacks and present a detailed survey of existing defenses and their suitability. Prithvi Bisht, Timothy L. Hinrichs, Nazari Skrupsky, V. N. Venkatakrishnan |
J. Comput. Secur. | 1 |
| 2013 | TamperProof: a server-agnostic defense for parameter tampering attacks on web applicationsabstractParameter tampering attacks are dangerous to a web application whose server performs weaker data sanitization than its client. This paper presents TamperProof, a methodology and tool that offers a novel and efficient mechanism to protect Web applications from parameter tampering attacks. TamperProof is an online defense deployed in a trusted environment between the client and server and requires no access to, or knowledge of, the server side codebase, making it effective for both new and legacy applications. The paper reports on experiments that demonstrate TamperProof's power in efficiently preventing all known parameter tampering vulnerabilities on ten different applications. Nazari Skrupsky, Prithvi Bisht, Timothy L. Hinrichs, V. N. Venkatakrishnan, Lenore D. Zuck |
CODASPY | 2 |
| 2012 | SWIPE: eager erasure of sensitive data in large scale systems softwareabstractWe describe SWIPE, an approach to reduce the life time of sensitive, memory resident data in large scale applications written in C. In contrast to prior approaches that used a delayed or lazy approach to the problem of erasing sensitive data, SWIPE uses a novel eager erasure approach that minimizes the risk of accidental sensitive data leakage. SWIPE achieves this by transforming a legacy C program to include additional instructions that erase sensitive data immediately after its intended use. SWIPE is guided by a highly-scalable static analysis technique that precisely identifies the locations to introduce erase instructions in the original program. The programs transformed using SWIPE enjoy several additional benefits: minimization of leaks that arise due to data dependencies; erasure of sensitive data with minimal developer guidance; and negligible performance overheads. Kalpana Gondi, Prithvi Bisht, Praveen Venkatachari, A. Prasad Sistla, V. N. Venkatakrishnan |
CODASPY | 2 |
| 2011 | WAPTEC: whitebox analysis of web applications for parameter tampering exploit constructionabstractParameter tampering attacks are dangerous to a web application whose server fails to replicate the validation of user-supplied data that is performed by the client. Malicious users who circumvent the client can capitalize on the missing server validation. In this paper, we describe WAPTEC, a tool that is designed to automatically identify parameter tampering vulnerabilities and generate exploits by construction to demonstrate those vulnerabilities. WAPTEC involves a new approach to whitebox analysis of the server's code. We tested WAPTEC on six open source applications and found previously unknown vulnerabilities in every single one of them. Prithvi Bisht, Timothy L. Hinrichs, Nazari Skrupsky, V. N. Venkatakrishnan |
CCS | 1 |
| 2010 | NoTamper: automatic blackbox detection of parameter tampering opportunities in web applicationsabstractWeb applications rely heavily on client-side computation to examine and validate form inputs that are supplied by a user (e.g., "credit card expiration date must be valid"). This is typically done for two reasons: to reduce burden on the server and to avoid latencies in communicating with the server. However, when a server fails to replicate the validation performed on the client, it is potentially vulnerable to attack. In this paper, we present a novel approach for automatically detecting potential server-side vulnerabilities of this kind in existing (legacy) web applications through blackbox analysis. We discuss the design and implementation of NoTamper, a tool that realizes this approach. NoTamper has been employed to discover several previously unknown vulnerabilities in a number of open-source web applications and live web sites. Prithvi Bisht, Timothy L. Hinrichs, Nazari Skrupsky, Radoslaw Bobrowicz, V. N. Venkatakrishnan |
CCS | 1 |
| 2010 | TAPS: automatically preparing safe SQL queriesabstractWe present the first sound program transformation approach for automatically transforming the code of a legacy web application to employ PREPARE statements in place of unsafe SQL queries. Our approach therefore opens the way for eradicating the SQL injection threat vector from legacy web applications. This extended abstract is based on our paper[4] that appeared in the Financial Cryptography and Data Security (FC'2010) conference. Prithvi Bisht, A. Prasad Sistla, V. N. Venkatakrishnan |
CCS | 1 |
| 2010 | CANDID: Dynamic candidate evaluations for automatic prevention of SQL injection attacksabstractSQL injection attacks are one of the top-most threats for applications written for the Web. These attacks are launched through specially crafted user inputs, on Web applications that use low-level string operations to construct SQL queries. In this work, we exhibit a novel and powerful scheme for automatically transforming Web applications to render them safe against all SQL injection attacks. A characteristic diagnostic feature of SQL injection attacks is that they change the intended structure of queries issued. Our technique for detecting SQL injection is to dynamically mine the programmer-intended query structure on any input, and detect attacks by comparing it against the structure of the actual query issued. We propose a simple and novel mechanism, called Candid, for mining programmer intended queries by dynamically evaluating runs over benign candidate inputs. This mechanism is theoretically well founded and is based on inferring intended queries by considering the symbolic query computed on a program run. Our approach has been implemented in a tool called Candid that retrofits Web applications written in Java to defend them against SQL injection attacks. We have also implemented Candid by modifying a Java Virtual Machine, which safeguards applications without requiring retrofitting. We report extensive experimental results that show that our approach performs remarkably well in practice. Prithvi Bisht, P. Madhusudan, V. N. Venkatakrishnan |
ACM Trans. Inf. Syst. Secur. | 1 |
| 2008 | XSS-GUARD: Precise Dynamic Prevention of Cross-Site Scripting Attacks
Prithvi Bisht, V. N. Venkatakrishnan |
DIMVA | 1 |
| 2007 | CANDID: preventing sql injection attacks using dynamic candidate evaluationsabstractSQL injection attacks are one of the topmost threats for applications written for the Web. These attacks are launched through specially crafted user input on web applications that use low level string operations to construct SQL queries. In this work, we exhibit a novel and powerful scheme for automatically transforming web applications to render them safe against all SQL injection attacks. Sruthi Bandhakavi, Prithvi Bisht, P. Madhusudan, V. N. Venkatakrishnan |
CCS | 2 |