Zerksis Umrigar

dblp:336/3747 · DBLP profile ↗
← Back
2ranked-venue papers
0as first author
2since 2021 · last 2025
0009-0001-4881-9002ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Systems and software security · 65% Authentication and access control · 35%
Software engineering, system software, and programming languages
2 papers
Compilers and program optimization · 100%
Computer architecture, parallel and distributed computing, and storage systems
2 papers
Processor architecture and microarchitecture · 100%

Topics — the 8 heaviest of 8, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › memory safety
control-flow integrity
1.522025
COGENT: Adaptable Compiler Toolchain for Tagging RISC-V Binaries · ASPLOS (3) 2025
Control Flow and Pointer Integrity Enforcement in a Secure Tagged Architecture · SP 2023
Authentication and access control › access control › capability-based security
tagged architecture
1.522025
COGENT: Adaptable Compiler Toolchain for Tagging RISC-V Binaries · ASPLOS (3) 2025
Control Flow and Pointer Integrity Enforcement in a Secure Tagged Architecture · SP 2023
Compilers and program optimization
compiler toolchain
0.912025
COGENT: Adaptable Compiler Toolchain for Tagging RISC-V Binaries · ASPLOS (3) 2025
Systems and software security
memory safety
0.712023
Control Flow and Pointer Integrity Enforcement in a Secure Tagged Architecture · SP 2023
Systems and software security › memory safety
pointer integrity
0.712023
Control Flow and Pointer Integrity Enforcement in a Secure Tagged Architecture · SP 2023
Processor architecture and microarchitecture
instruction set architecture
0.522025
COGENT: Adaptable Compiler Toolchain for Tagging RISC-V Binaries · ASPLOS (3) 2025
Control Flow and Pointer Integrity Enforcement in a Secure Tagged Architecture · SP 2023
Processor architecture and microarchitecture › instruction set architecture
RISC-V
0.312025
COGENT: Adaptable Compiler Toolchain for Tagging RISC-V Binaries · ASPLOS (3) 2025
Compilers and program optimization
compiler security
0.212023
Control Flow and Pointer Integrity Enforcement in a Secure Tagged Architecture · SP 2023

Methods — techniques the papers use, named apart from their topics

tag integrity checking · 2.6static analysis · 2.6
YearPublicationVenuePosition
2025 COGENT: Adaptable Compiler Toolchain for Tagging RISC-V Binaries
abstract
Tags, or metadata, enrich software with domain-specific information that is consumed by hardware to enforce security and testing policies during runtime. However, given a target architecture, developing custom compilers that encode tags can be tedious and time-consuming. We present COGENT, a highly flexible and feature-rich compiler toolchain for instruction tag generation on the RISC-V architecture. Central to this effort is a LLVM-based compiler that is supplemented with a tag-aware disassembler and a tag integrity checker. COGENT is capable of: (a) generating tags at one or more of varying granularity (per function, per basic block, or per instruction), and (b) associating variable-width tags (1-32 bits) to instructions, and arbitrary-width tags to each function or basic block. Additionally, COGENT is capable of emitting control-flow labels, which are crucial in asserting control-flow integrity (CFI), a runtime property that aids in detecting bugs and exploits that violate control flow. We evaluate the correctness of tags generated by COGENT's compiler and the associated performance penalties, along with how well COGENT preserves IR-level tags at the lower level. We provide three exemplar applications-Control Flow Integrity, Adaptive Tracing, and Hardware-Level Function Tracing that can leverage COGENT. The tagged code incurs an average cycle count overhead from 5.24% to 0.94% in the worst and best cases, respectively, making it ideal for debugging and testing applications, including fuzzing.
David Demicco, Matthew Cole, Gokturk Yuksek, Ravi Theja Gollapudi, Aravind Prakash, Kanad Ghose, Zerksis Umrigar
ASPLOS (3)7
2023 Control Flow and Pointer Integrity Enforcement in a Secure Tagged Architecture
abstract
Control flow attacks exploit software vulnerabilities to divert the flow of control into unintended paths to ultimately execute attack code. This paper explores the use of instruction and data tagging as a general means of thwarting such control flow attacks, including attacks that rely on violating pointer integrity. Using specific types of narrow-width data tags along with narrow-width instruction tags embedded within the binary facilitates the security policies required to protect against such attacks, leading to a practically viable solution. Co-locating instruction tags close to their corresponding instructions within cache lines eliminates the need for separate mechanisms for instruction tag accesses. Information gleaned from the analysis phase of a compiler is augmented and used to generate the instruction and data tags. A full-stack implementation that consists of a modified LLVM compiler, modified Linux OS support for tags and a FPGA-implemented CPU hardware prototype for enforcing CFI, data pointer and code pointer integrity is demonstrated. With a modest hardware enhancement, the execution time of benchmark applications on the prototype system is shown to be limited to low, single-digit percentages of a baseline system without tagging.
Ravi Theja Gollapudi, Gokturk Yuksek, David Demicco, Matthew Cole, Gaurav Kothari, Rohit Kulkarni, Kanad Ghose, Aravind Prakash, Zerksis Umrigar
SP10