EDBT 2026 Demo / reviewers in the wild / expert
Md Sakib Anwar
dblp:358/3435
· DBLP profile ↗
3ranked-venue papers
3as first author
3since 2021 · last 2025
0009-0000-0242-0904ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | VerDiff: Vulnerability Presence Verification for Comprehensive Reporting Using Constraint ProgrammingabstractSecurity practitioners often rely on a collaborative ecosystem of analysts and authorities to publicly disclose and track program vulnerabilities. Vital to these disclosures is the list of affected program versions, which stakeholders depend on to assess their security posture and plan appropriate responses. It is vital that these lists be accurate and exhaustive because 81.5% of industry systems rely on outdated dependencies and the average time to develop a patch is 256 days. Unfortunately, existing solutions for determining affected program versions do not scale to analyzing the entire release history. This paper presents VERDIFF, a framework that leverages a novel payload-guided, semantically enriched signature isomorphism matching specifically designed for swift, comprehensive vulnerability detection across all versions of a software program. Utilizing the initial vulnerable version found by an analyst and their crafted triggering input, VERDIFF formulates a distinct multi-level signature that is grounded in a strong correlation between dynamic binary analysis and source code signature matching, enabling a rapid high-level triage while accounting for nuanced low-level behaviors. Evaluating 27 CVEs spanning 11 programs, VERDIFF correctly pinpoints 265 misclassifications contained in official advisories. Md Sakib Anwar, Carter Yagemann, Zhiqiang Lin 0001 |
ACSAC | 1 |
| 2025 | GoSonar: Detecting Logical Vulnerabilities in Memory Safe Language Using Inductive Constraint ReasoningabstractAs the global community advocates for the adoption of memory-safe programming languages, a significant research gap persists in identifying the critical vulnerabilities that follow. Logical vulnerabilities represent the most formidable threat to these programs, in the absence of memory safety related vulnerabilities such as buffer overflow. Go, a prevalent memory-safe language for cloud-based applications where resource availability is paramount, is especially susceptible to nonter-minating, resource-exhaustive vulnerabilities. We present a novel approach to the problem, inductive constraint reasoning, designed to evaluate nontermination in complex, real-world programs, demonstrating superior performance compared to contemporary tools on a standardized dataset. Our methodology employs binary-level underconstrained symbolic execution to gather the constraints necessary for multiple recursive iterations. By applying a first-order derivative to these constraints, we model and classify various recursive functions, determining whether their subgoals converge to a global objective. This study addresses numerous challenges in the analysis of Go programs while simultaneously developing and implementing a practical solution to detect uncontrolled recursion, which has revealed 5 new vulnerabilities in the Go standard library. Md Sakib Anwar, Carter Yagemann, Zhiqiang Lin 0001 |
SP | 1 |
| 2023 | Extracting Threat Intelligence From Cheat Binaries For Anti-CheatingabstractRampant cheating remains a serious concern for game developers who fear losing loyal customers and revenue. While numerous anti-cheating techniques have been proposed, cheating persists in a vibrant (and profitable) illicit market. Inspired by novel insights into the economics behind cheat development and recent techniques for defending against advanced persistent threats (APTs), we propose a fully automated methodology for extracting “cheat intelligence” from widely distributed cheat binaries to produce a “memory access graph” that guides selective data randomization to yield immune game clients. We have implemented a prototype system for Android and Windows games, CheatFighter, and evaluated it on 86 cheats collected from a variety of real-world sources, including Telegram channels and online forums. CheatFighter successfully counteracts 80 of the real-world cheats in under a minute, demonstrating practical end-to-end protection against widespread cheating. Md Sakib Anwar, Chaoshun Zuo, Carter Yagemann, Zhiqiang Lin 0001 |
RAID | 1 |