EDBT 2026 Demo / reviewers in the wild / expert
Nezer Zaidenberg
dblp:29/10161 · also Nezer J. Zaidenberg, Nezer Jacob Zaidenberg
· DBLP profile ↗
21ranked-venue papers
3as first author
9since 2021 · last 2024
0000-0003-3496-7925ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 3 first-author · 6 since 2021Systems, architecture and hardware · 6 · 1 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Detecting eBPF Rootkits Using Virtualization and Memory Forensics
Nezer Zaidenberg, Michael Kiperberg, Eliav Menachi, Asaf Eitani |
ICISSP | 1 |
| 2024 | Virtualized network packet inspection
Erez Shlingbaum, Raz Ben Yehuda, Michael Kiperberg, Nezer Zaidenberg |
Comput. Networks | 4 |
| 2024 | HyperWallet: cryptocurrency wallet as a secure hypervisor-based applicationabstractWe present VirtSecIO, a hypervisor-based platform for executing secure modules. VirtSecIO provides the modules with secure paths to peripheral devices, which can be shared between the modules and the operating system. Moreover, VirtSecIO is a thin hypervisor with a negligible performance overhead and a minimal attack surface. We demonstrate VirtSecIO’s abilities by developing HyperWallet, a secure module that acts as a hardware crypto-wallet, without requiring any dedicated hardware. Nezer Zaidenberg, Michael Kiperberg |
EURASIP J. Inf. Secur. | 1 |
| 2023 | PDIFT: A Practical Dynamic Information-Flow Tracker
Michael Kiperberg, Aleksei Rozman, Aleksei Kuraev, Nezer Zaidenberg |
ICISSP | 4 |
| 2021 | Efficient DLP-visor: An efficient hypervisor-based DLPabstractMany organization consider insider threat for data theft to be one of the most severe threats. An insider may also leak sensitive information without malicious intent (as a result of social engineering) Data leakage prevention (DLP) systems attempt to prevent intentional or accidental disclosure of sensitive information by monitoring the content or the context in which the information is transferred, for example, in a file system, an email server, instant messengers. We present a context-sensitive DLP system, called Efficient DLP-Visor. We implemented DLP-visor as a thin hypervisor capable of intercepting system calls in Windows operating systems equipped with Kernel Patch Protection. By intercepting system calls that govern the file system, inter-process communications, networking, system register and system clipboard, DLP-Visor guarantees that sensitive information can never leave a predefined set of directories. The performance overhead of Efficient DLP-Visor (7.2%) allows its deployment in real-world applications. Efficient DLP-visor logs were improved for better detection and logging of a DLP event. On idle time Efficient DLP-visor deletes most of the data log while maintaining the important data of leaks and attack. Michael Kiperberg, Guy Amit, Amir Yeshooroon, Nezer Zaidenberg |
CCGRID | 4 |
| 2021 | DLP-Visor: A Hypervisor-based Data Leakage Prevention System
Guy Amit, Amir Yeshooroon, Michael Kiperberg, Nezer Zaidenberg |
ICISSP | 4 |
| 2021 | HyperPass: Secure Password Input Platform
Michael Kiperberg, Nezer Zaidenberg |
ICISSP | 2 |
| 2021 | HERO vs. Zombie: Identifying Zombie Guests in a Virtual Machine Environment
Yael Elinav, Alex Moshinky, Lior Siag, Nezer Zaidenberg |
MODELSWARD | 4 |
| 2021 | Hypervisor-assisted dynamic malware analysisabstractAbstract Malware analysis is a task of utmost importance in cyber-security. Two approaches exist for malware analysis: static and dynamic. Modern malware uses an abundance of techniques to evade both dynamic and static analysis tools. Current dynamic analysis solutions either make modifications to the running malware or use a higher privilege component that does the actual analysis. The former can be easily detected by sophisticated malware while the latter often induces a significant performance overhead. We propose a method that performs malware analysis within the context of the OS itself. Furthermore, the analysis component is camouflaged by a hypervisor, which makes it completely transparent to the running OS and its applications. The evaluation of the system’s efficiency suggests that the induced performance overhead is negligible. Roee Leon, Michael Kiperberg, Anat Anatey Leon Zabag, Nezer Zaidenberg |
Cybersecur. | 4 |
| 2020 | HyperWall: A Hypervisor for Detection and Prevention of Malicious Communication
Michael Kiperberg, Raz Ben Yehuda, Nezer Zaidenberg |
NSS | 3 |
| 2019 | Hypervisor-assisted Atomic Memory Acquisition in Modern SystemsabstractReliable memory acquisition is essential to forensic analysis of a cyber-crime. Various methods of memory acquisition have been proposed, ranging from tools based on a dedicated hardware to software only solutions. Recently, a hypervisor-based method for memory acquisition was proposed (Qi et al., 2017; Martignoni et al., 2010). This method obtains a reliable (atomic) memory image of a running system. The method achieves this by making all memory pages non-writable until they are copied to the memory image, thus preventing uncontrolled modification of these pages. Unfortunately, the proposed method has two deficiencies: (1) the method does not support multiprocessing and (2) the method does not support modern operating systems featuring address space layout randomization (ASLR). We describe a hypervisor-based memory acquisition method that solves the two aforementioned deficiencies. We analyze the memory usage and performance of the proposed method. Michael Kiperberg, Roee Leon, Amit Resh, Asaf Algawi, Nezer Zaidenberg |
ICISSP | 5 |
| 2019 | AI & eBPF based performance anomaly detection systemabstractWe describe means to run eBPF on a production environment for systems inspection. We examine the inspected system outputs in order to train and generate a model for the host. We model the specific application and network traffic usage on the site based on the data collected by eBPF. Our system generates alerts when an anomaly in performance is detected on a specific host. These warnings can be used to discover the root cause for performance problems, cyber-security issues and warn in advance about potential performance peaks. Ido Ben-Yair, Pavel Rogovoy, Nezer Zaidenberg |
SYSTOR | 3 |
| 2019 | Deadversarial multiverse network: a defense architecture against adversarial attacksabstractThis paper presents the concept of a generic deep learning architecture in order to robust deep learning network, especially computer vision network from adversarial examples. The network composed from Deadvarserial decoder that takes images and try to cancel the influence of the attack from those who are infected. Later, pass them to the chosen model that robust by a multiverse layers that try to extend the dimension of the model in order to defend the attack, but still keep the training time less as possible unlike the ensemble method. The deadverserial multiverse architecture can be applied to any model in retrospect. Aviram Berg, Elin Tulchinsky, Nezer Zaidenberg |
SYSTOR | 3 |
| 2019 | Hypervisor-Based Protection of CodeabstractThe code of a compiled program is susceptible to reverse-engineering attacks on the algorithms and the business logic that are contained within the code. The main existing countermeasure to reverse-engineering is obfuscation. Generally, obfuscation methods suffer from two main deficiencies: 1) the obfuscated code is less efficient than the original and 2) with sufficient effort, the original code may be reconstructed. We propose a method that is based on cryptography and virtualization. The most valuable functions are encrypted and remain inaccessible even during their execution, thus preventing their reconstruction. A specially crafted hypervisor is responsible for decryption, execution, and protection of the encrypted functions. We claim that the system can provide protection even if the attacker: 1) has access to the operating system kernel and 2) can intercept communication over the system bus. The evaluation of the system's efficiency suggests that it can compete with and outperform obfuscation-based methods. Michael Kiperberg, Roee Leon, Amit Resh, Asaf Algawi, Nezer Zaidenberg |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2018 | Hyplets - Multi Exception Level Kernel towards Linux RTOSabstractThis paper presents the concept of a Multi-Exception level operating system. We add a hypervisor awareness to the Linux kernel and execute code in hyp exception level. We do that through the use of Hyplets. Hyplets are an innovative way to code interrupt service routines under ARM. Hyplets provide high performance, security, running time predictability, an RPC mechanism and a possible solution for the priority inversion problem. Hyplets uses special features of ARM8va hypervisor memory architecture. Raz Ben Yehuda, Nezer Zaidenberg |
SYSTOR | 2 |
| 2018 | An LP-based hyperparameter optimization model for language modeling
Amir Hossein Akhavan Rahnama, Mehdi Toloo, Nezer Zaidenberg |
J. Supercomput. | 3 |
| 2017 | System for Executing Encrypted Java Programs
Michael Kiperberg, Amit Resh, Asaf Algawi, Nezer Zaidenberg |
ICISSP | 4 |
| 2015 | Remote Attestation of Software and Execution-Environment in Modern MachinesabstractThe research on network security concentrates mainly on securing the communication channels between two endpoints, which is insufficient if the authenticity of one of the endpoints cannot be determined with certainty. Previously presented methods that allow one endpoint, the authentication authority, to authenticate another remote machine. These methods are inadequate for modern machines that have multiple processors, introduce virtualization extensions, have a greater variety of side effects, and suffer from nondeterminism. This paper addresses the advances of modern machines with respect to the method presented by Kennell. The authors describe how a remote attestation procedure, involving a challenge, needs to be structured in order to provide correct attestation of a remote modern target system. Michael Kiperberg, Amit Resh, Nezer Zaidenberg |
CSCloud | 3 |
| 2015 | Detecting Kernel Vulnerabilities During the Development PhaseabstractTesting is one of the major problems in Linux kernel development cycle. Security analysis and ensuring no new vulnerabilities has been introduced is one of the toughest issues of testing. Kernel developers attempt to find as many security issues as possible before merging with the mainline branch. Failure to detect vulnerabilities will result in vulnerable kernel shipped by distribution and vulnerable systems. The kernel developers can choose between several industrial and open source tools to assist in the development process and shorten the development cycle. (Though not as many as user space developers. Kernel tools are limited and rare compared to user space tools) Some of these tools are used to test the reliability of the kernel and detect kernel vulnerabilities. Unfortunately, these tools are not sufficient! LgDb was introduced in [1], [2] in our previous work. LgDb is a proof-of-concept tool that was presented as an innovative framework for kernel profiling, code coverage and simulations. LgDb runs the inspected kernel on a para virtual environment based on Lguest. Most existing tools limitations stem from the nature of the task. A user space tool cannot inspect the kernel on which it runs on. By using virtualization LgDb eliminates most of the existing tools limitations. As far as the host is concerned LgDb runs as a user process and the need for complex kernel space tools is alleviated. In this work we will present an extension to LgDb in order to detect kernel security vulnerabilities. The vulnerabilities detection process is not automatic. However, LgDb allows the developer test the code during the development, similarly to a debugger. The vulnerabilities types that LgDb addresses are proved to be lacking efficient automatic detection tools and manifested in several kernel vulnerabilities. Nezer Zaidenberg, Eviatar Khen |
CSCloud | 1 |
| 2011 | Low Bitrate Asynchronous Replication of Block Devices and Virtual MachinesabstractWe present a system for asynchronous replication of virtual machines (running on top of QEMU-KVM and Lguest). The system uses a home-grown block device replication layer for data replication and includes VM replication components for Lguest and QEMU-KVM. We describe both of these components in this paper. Unlike previous works in the field, we focus on low bit rate systems. We target environments with low band-width that make frequent migration impossible. We put bandwidth preservation and operation continuity at the top of our priorities. To this end we are willing to sacrifice performance in order to preserve decent operation continuity even in low bit rate environments. We focus on SOHO environments as our target market. SOHO environments are often characterized by low requirements for actual performance and disk usage. However, SOHO environments are also limited in bandwidth capacity, especially upstream. All of these are taken into careful consideration throughout this paper. Amir Averbuch, Tomer Margalit, Nezer Zaidenberg, Eviatar Khen |
NAS | 3 |
| 2011 | An efficient VM-based software protectionabstractThis paper presents Truly-protect, a system, incorporating a virtual machine, that enables execution of encrypted programs. Our intention is to form a framework for a conditional access/digital rights management system. We avoid relying on obscurity and rely only on assumptions about the system itself and on cryptographic measures to develop VM-based conditional access/trusted computing environment. Rolles in [18], proposes a general way of breaking systems of type described herein. We claim that Rolles' method fails to defeat our system. Amir Averbuch, Michael Kiperberg, Nezer Zaidenberg |
NSS | 3 |