Fadi Yilmaz

dblp:26/9596 · DBLP profile ↗
← Back
4ranked-venue papers
4as first author
2since 2021 · last 2026
0000-0002-3591-3606ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 3 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 Silent Shield: Dynamic Instrumentation of Privacy Breaches in Oculus VR Applications
Fadi Yilmaz, Bilge Kelesoglu, Kursat Korkmaz, Beyza Karakurt, Gurkan Agir
ICISSP (1)1
2021 A fine-grained classification and security analysis of web-based virtual machine vulnerabilities
Fadi Yilmaz, Meera Sridhar, Abhinav Mohanty, Vasant Tendulkar, Kevin W. Hamlen
Comput. Secur.1
2020 Guide Me to Exploit: Assisted ROP Exploit Generation for ActionScript Virtual Machine
abstract
Automatic exploit generation (AEG) is the challenge of determining the exploitability of a given vulnerability by exploring all possible execution paths that can result from triggering the vulnerability. Since typical AEG implementations might need to explore an unbounded number of execution paths, they usually utilize a fuzz tester and a symbolic execution tool to facilitate this task. However, in the case of language virtual machines, such as the ActionScript Virtual Machine (AVM), AEG implementations cannot leverage fuzz testers or symbolic execution tools for generating the exploit script, because of two reasons: (1) fuzz testers cannot efficiently generate grammatically correct executables for the AVM due to the improbability of randomly generating highly-structured executables that follow the complex grammar rules and (2) symbolic execution tools encounter the well-known program-state-explosion problem due to the enormous number of control paths in early processing stages of a language virtual machine (e.g., lexing and parsing).
Fadi Yilmaz, Meera Sridhar, Wontae Choi
ACSAC1
2019 A Survey of In-Lined Reference Monitors: Policies, Applications and Challenges
abstract
This paper surveys the area of in-lined reference monitors (IRMs), a language-based security enforcement technology that has gained much popularity in the recent past. IRMs enforce given security policies in target applications by inserting dynamic security guards into these applications; the guards check for impending policy violations at runtime. IRMs keep track of security state and can thus enforce rich, history-based policies. This survey discusses IRMs for a variety of programming languages, application execution platforms, and security policy specification languages. The survey also discusses the benefits and importance of adding IRM certification, and the technical and managerial challenges of employing IRMs.
Fadi Yilmaz, Meera Sridhar
AICCSA1