Aditya Pakki

dblp:248/1695 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
2since 2021 · last 2022
0000-0003-4704-2606ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2022 Unleashing Coveraged-Based Fuzzing Through Comprehensive, Efficient, and Faithful Exploitable-Bug Exposing
abstract
Fuzzing has become an essential means of finding software bugs. Bug finding through fuzzing requires two parts—exploring code paths to reach bugs and exposing bugs when they are reached. Existing fuzzing research has primarily focused on improving code coverage but not on exposing bugs. Sanitizers such as AddressSanitizer (ASAN) and MemorySanitizer (MSAN) have been the dominating tools for exposing bugs. However, sanitizer-based bug exposing has the following limitations. (1) sanitizers are not compatible with each other. (2) sanitizers incur significant runtime overhead. (3) sanitizers may generate false positives, and (4) exposed bugs may not be exploitable. To address these limitations, we proposeExpozzer, a fuzzing system that can expose bugs comprehensively, efficiently, and faithfully. The intuition ofExpozzeris to detect bugs through divergences in a properly diversified dual-execution environment, which does not require maintaining or checking execution metadata. We design a practical and deterministic dual-execution engine, a co-design for dual-execution and fuzzers, bug-sensitive diversification, comprehensive, and efficient divergence detection to ensure the effectiveness ofExpozzer. The results of evaluations show thatExpozzercan detect not only CVE-assigned vulnerabilities reliably, but also new vulnerabilities in well-tested real-world programs.Expozzeris 10 times faster than MemorySanitizer and is similar to AddressSanitizer.
Bowen Wang 0014, Kangjie Lu, Qiushi Wu, Aditya Pakki
IEEE Trans. Dependable Secur. Comput.4
2021 Understanding and Detecting Disordered Error Handling with Precise Function Pairing
Qiushi Wu, Aditya Pakki, Navid Emamdoost, Stephen McCamant, Kangjie Lu
USENIX Security Symposium2
2020 Exaggerated Error Handling Hurts! An In-Depth Study and Context-Aware Detection
abstract
Operating system (OS) kernels frequently encounter various errors due to invalid internal states or external inputs. To ensure the security and reliability of OS kernels, developers propose a diverse set of mechanisms to conservatively capture and handle potential errors. Existing research has thus primarily focused on the completeness and adequacy of error handling to not miss the attention. However, we find that handling an error with an over-severe level (e.g., unnecessarily terminating the execution) instead hurts the security and reliability. In this case, the error-handling consequences are even worse than the error it attempts to resolve. We call such a case Exaggerated Error Handling (EEH). The security impacts of EEH bugs vary, including denial-of-service, data losses, broken control-flow integrity, memory leaks, etc. Despite its significance, detecting EEH remains an unexplored topic.
Aditya Pakki, Kangjie Lu
CCS1
2019 Automatically Identifying Security Checks for Detecting Kernel Semantic Bugs
Kangjie Lu, Aditya Pakki, Qiushi Wu
ESORICS (2)2
2019 Detecting Missing-Check Bugs via Semantic- and Context-Aware Criticalness and Constraints Inferences
Kangjie Lu, Aditya Pakki, Qiushi Wu
USENIX Security Symposium2