Alexander Bulekov

dblp:294/4488 · DBLP profile ↗
← Back
5ranked-venue papers
4as first author
5since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 4 first-author · 5 since 2021
YearPublicationVenuePosition
2024 HYPERPILL: Fuzzing for Hypervisor-bugs by leveraging the Hardware Virtualization Interface
Alexander Bulekov, Qiang Liu 0034, Manuel Egele, Mathias Payer
USENIX Security Symposium1
2023 No Grammar, No Problem: Towards Fuzzing the Linux Kernel without System-Call Descriptions
Alexander Bulekov, Bandan Das, Stefan Hajnoczi, Manuel Egele
NDSS1
2022 Morphuzz: Bending (Input) Space to Fuzz Virtual Devices
Alexander Bulekov, Bandan Das, Stefan Hajnoczi, Manuel Egele
USENIX Security Symposium1
2021 SoK: Enabling Security Analyses of Embedded Systems via Rehosting
abstract
Closely monitoring the behavior of a software system during its execution enables developers and analysts to observe, and ultimately understand, how it works. This kind of dynamic analysis can be instrumental to reverse engineering, vulnerability discovery, exploit development, and debugging. While these analyses are typically well-supported for homogeneous desktop platforms (e.g., x86 desktop PCs), they can rarely be applied in the heterogeneous world of embedded systems. One approach to enable dynamic analyses of embedded systems is to move software stacks from physical systems into virtual environments that sufficiently model hardware behavior. This process which we call "rehosting" poses a significant research challenge with major implications for security analyses. Although rehosting has traditionally been an unscientific and ad-hoc endeavor undertaken by domain experts with varying time and resources at their disposal, researchers are beginning to address rehosting challenges systematically and in earnest. In this paper, we establish that emulation is insufficient to conduct large-scale dynamic analysis of real-world hardware systems and present rehosting as a firmware-centric alternative. Furthermore, we taxonomize preliminary rehosting efforts, identify the fundamental components of the rehosting process, and propose directions for future research.
Andrew Fasano, Tiemoko Ballo, Marius Muench, Tim Leek, Alexander Bulekov, Brendan Dolan-Gavitt, Manuel Egele, Aurélien Francillon, Long Lu, Nick Gregory, Davide Balzarotti, William K. Robertson
AsiaCCS5
2021 Saphire: Sandboxing PHP Applications with Tailored System Call Allowlists
Alexander Bulekov, Rasoul Jahanshahi, Manuel Egele
USENIX Security Symposium1