Stelios Sidiroglou-Douskos

dblp:37/1475 · also Stelios Sidiroglou · DBLP profile ↗
← Back
27ranked-venue papers
9as first author
0since 2021 · last 2017
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 14 · 3 first-authorSoftware engineering, systems software and programming languages · 12 · 5 first-authorSystems, architecture and hardware · 4 · 3 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
10 papers
Systems and software security · 95% Network security · 3% Digital forensics and information hiding · 2%
Software engineering, system software, and programming languages
12 papers
Debugging and program repair · 31% Software maintenance and evolution · 22% Program analysis · 20%
Computer architecture, parallel and distributed computing, and storage systems
4 papers
Performance modeling and evaluation · 50% Cloud and datacenter computing · 25% Emerging computing paradigms · 22%
Databases, data mining, and information retrieval
1 paper
Data mining · 77% Machine learning and data management · 23%

Topics — the 30 heaviest of 44, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › exploitation
control-flow hijacking
0.422015
Missing the Point(er): On the Effectiveness of Code Pointer Integrity · IEEE Symposium on Security and Privacy 2015
Control Jujutsu: On the Weaknesses of Fine-Grained Control Flow Integrity · CCS 2015
Systems and software security
exploitation
0.422015
Missing the Point(er): On the Effectiveness of Code Pointer Integrity · IEEE Symposium on Security and Privacy 2015
Targeted Automatic Integer Overflow Discovery Using Goal-Directed Conditional Branch Enforcement · ASPLOS 2015
Systems and software security › exploitation
memory corruption attack
0.422015
Missing the Point(er): On the Effectiveness of Code Pointer Integrity · IEEE Symposium on Security and Privacy 2015
Control Jujutsu: On the Weaknesses of Fine-Grained Control Flow Integrity · CCS 2015
Systems and software security
vulnerability discovery
0.322015
Targeted Automatic Integer Overflow Discovery Using Goal-Directed Conditional Branch Enforcement · ASPLOS 2015
Automatically patching errors in deployed software · SOSP 2009
Debugging and program repair
automated program repair
0.322015
Automatic error elimination by horizontal code transfer across multiple applications · PLDI 2015
Automatically patching errors in deployed software · SOSP 2009
Software maintenance and evolution
code reuse
0.312017
CodeCarbonCopy · ESEC/SIGSOFT FSE 2017
Compilers and program optimization › program transformation
code transplantation
0.312017
CodeCarbonCopy · ESEC/SIGSOFT FSE 2017
Program analysis
static analysis
0.312017
CodeCarbonCopy · ESEC/SIGSOFT FSE 2017
Data mining
anomaly detection
0.212015
Principled Sampling for Anomaly Detection · NDSS 2015
Systems and software security › memory protection
code-pointer integrity
0.212015
Missing the Point(er): On the Effectiveness of Code Pointer Integrity · IEEE Symposium on Security and Privacy 2015
Systems and software security › memory safety
control-flow integrity
0.212015
Control Jujutsu: On the Weaknesses of Fine-Grained Control Flow Integrity · CCS 2015
Systems and software security
memory safety
0.212015
Missing the Point(er): On the Effectiveness of Code Pointer Integrity · IEEE Symposium on Security and Privacy 2015
Systems and software security › vulnerability discovery
integer overflow vulnerabilities
0.212014
Sound input filter generation for integer overflow errors · POPL 2014
Debugging and program repair › failure recovery
runtime repair
0.212014
Automatic runtime error repair and containment via recovery shepherding · PLDI 2014
Debugging and program repair
failure recovery
0.222009
ASSURE: automatic software self-healing using rescue points · ASPLOS 2009
Using Rescue Points to Navigate Software Recovery · S&P 2007
Systems and software security › vulnerability management
vulnerability mitigation
0.112012
Automatic input rectification · ICSE 2012
Program analysis › static analysis › constraint-based analysis
constraint inference
0.112012
Automatic input rectification · ICSE 2012
Compilers and program optimization
approximate computing
0.112011
Managing performance vs. accuracy trade-offs with loop perforation · SIGSOFT FSE 2011
Cloud and datacenter computing › configuration tuning
configuration auto-tuning
0.112011
Dynamic knobs for responsive power-aware computing · ASPLOS 2011
Emerging computing paradigms
approximate computing
0.112010
Patterns and statistical analysis for understanding reduced resource computing · OOPSLA 2010
Performance modeling and evaluation
simulation
0.112010
Patterns and statistical analysis for understanding reduced resource computing · OOPSLA 2010
Debugging and program repair › automated program repair
patch generation
0.112009
Automatically patching errors in deployed software · SOSP 2009
Debugging and program repair
program repair
0.112009
ASSURE: automatic software self-healing using rescue points · ASPLOS 2009
Software maintenance and evolution › software evolution › software adaptation
self-healing systems
0.112009
ASSURE: automatic software self-healing using rescue points · ASPLOS 2009
Wireless networking
wireless security
0.112007
Proximity Breeds Danger: Emerging Threats in Metro-area Wireless Networks · USENIX Security Symposium 2007
Programming languages and type systems › control structures
exception handling
0.112007
Using Rescue Points to Navigate Software Recovery · S&P 2007
Digital forensics and information hiding
information hiding
0.112015
Missing the Point(er): On the Effectiveness of Code Pointer Integrity · IEEE Symposium on Security and Privacy 2015
Program analysis › control flow analysis
control flow graph construction
0.112015
Control Jujutsu: On the Weaknesses of Fine-Grained Control Flow Integrity · CCS 2015
Program analysis
dynamic analysis
0.112015
Targeted Automatic Integer Overflow Discovery Using Goal-Directed Conditional Branch Enforcement · ASPLOS 2015
Systems and software security
binary instrumentation
0.112014
Automatic runtime error repair and containment via recovery shepherding · PLDI 2014

Methods — techniques the papers use, named apart from their topics

static analysis · 0.7proof-of-concept exploit · 0.7fuzzing · 0.5binary instrumentation · 0.4dynamic instrumentation · 0.4binary rewriting · 0.4input mutation · 0.3constraint learning · 0.3paired execution · 0.3static isolation analysis · 0.2static program analysis · 0.2control systems · 0.1control system · 0.1statistical analysis · 0.1simulation · 0.1profiling · 0.1measurement study · 0.1
YearPublicationVenuePosition
2017 CodeCarbonCopy
abstract
We present CodeCarbonCopy (CCC), a system for transferring code from a donor application into a recipient application. CCC starts with functionality identified by the developer to transfer into an insertion point (again identified by the developer) in the recipient. CCC uses paired executions of the donor and recipient on the same input file to obtain a translation between the data representation and name space of the recipient and the data representation and name space of the donor. It also implements a static analysis that identifies and removes irrelevant functionality useful in the donor but not in the recipient. We evaluate CCC on eight transfers between six applications. Our results show that CCC can successfully transfer donor functionality into recipient applications.
Stelios Sidiroglou-Douskos, Eric Lahtinen, Anthony Eden, Fan Long, Martin C. Rinard
ESEC/SIGSOFT FSE1
2016 AutoRand: Automatic Keyword Randomization to Prevent Injection Attacks
Jeff H. Perkins, Jordan Eikenberry, Alessandro Coglio, Daniel Willenson, Stelios Sidiroglou-Douskos, Martin C. Rinard
DIMVA5
2015 Targeted Automatic Integer Overflow Discovery Using Goal-Directed Conditional Branch Enforcement
abstract
We present a new technique and system, DIODE, for auto- matically generating inputs that trigger overflows at memory allocation sites. DIODE is designed to identify relevant sanity checks that inputs must satisfy to trigger overflows at target memory allocation sites, then generate inputs that satisfy these sanity checks to successfully trigger the overflow. DIODE works with off-the-shelf, production x86 binaries. Our results show that, for our benchmark set of applications, and for every target memory allocation site exercised by our seed inputs (which the applications process correctly with no overflows), either 1) DIODE is able to generate an input that triggers an overflow at that site or 2) there is no input that would trigger an overflow for the observed target expression at that site.
Stelios Sidiroglou-Douskos, Eric Lahtinen, Nathan Rittenhouse, Paolo Piselli, Fan Long, Deokhwan Kim, Martin C. Rinard
ASPLOS1
2015 Control Jujutsu: On the Weaknesses of Fine-Grained Control Flow Integrity
abstract
Control flow integrity (CFI) has been proposed as an approach to defend against control-hijacking memory corruption attacks. CFI works by assigning tags to indirect branch targets statically and checking them at runtime. Coarse-grained enforcements of CFI that use a small number of tags to improve the performance overhead have been shown to be ineffective. As a result, a number of recent efforts have focused on fine-grained enforcement of CFI as it was originally proposed. In this work, we show that even a fine-grained form of CFI with unlimited number of tags and a shadow stack (to check calls and returns) is ineffective in protecting against malicious attacks. We show that many popular code bases such as Apache and Nginx use coding practices that create flexibility in their intended control flow graph (CFG) even when a strong static analyzer is used to construct the CFG. These flexibilities allow an attacker to gain control of the execution while strictly adhering to a fine-grained CFI. We then construct two proof-of-concept exploits that attack an unlimited tag CFI system with a shadow stack. We also evaluate the difficulties of generating a precise CFG using scalable static analysis for real-world applications. Finally, we perform an analysis on a number of popular applications that highlights the availability of such attacks.
Isaac Evans, Fan Long, Ulziibayar Otgonbaatar, Howard E. Shrobe, Martin C. Rinard, Hamed Okhravi, Stelios Sidiroglou-Douskos
CCS7
2015 Principled Sampling for Anomaly Detection
Brendan Juba, Christopher Musco, Fan Long, Stelios Sidiroglou-Douskos, Martin C. Rinard
NDSS4
2015 Automatic error elimination by horizontal code transfer across multiple applications
abstract
We present Code Phage (CP), a system for automatically transferring correct code from donor applications into recipient applications that process the same inputs to successfully eliminate errors in the recipient. Experimental results using seven donor applications to eliminate ten errors in seven recipient applications highlight the ability of CP to transfer code across applications to eliminate out of bounds access, integer overflow, and divide by zero errors. Because CP works with binary donors with no need for source code or symbolic information, it supports a wide range of use cases. To the best of our knowledge, CP is the first system to automatically transfer code across multiple applications.
Stelios Sidiroglou-Douskos, Eric Lahtinen, Fan Long, Martin C. Rinard
PLDI1
2015 Missing the Point(er): On the Effectiveness of Code Pointer Integrity
abstract
Memory corruption attacks continue to be a major vector of attack for compromising modern systems. Numerous defenses have been proposed against memory corruption attacks, but they all have their limitations and weaknesses. Stronger defenses such as complete memory safety for legacy languages (C/C++) incur a large overhead, while weaker ones such as practical control flow integrity have been shown to be ineffective. A recent technique called code pointer integrity (CPI) promises to balance security and performance by focusing memory safety on code pointers thus preventing most control-hijacking attacks while maintaining low overhead. CPI protects access to code pointers by storing them in a safe region that is protected by instruction level isolation. On x86-32, this isolation is enforced by hardware, on x86-64 and ARM, isolation is enforced by information hiding. We show that, for architectures that do not support segmentation in which CPI relies on information hiding, CPI's safe region can be leaked and then maliciously modified by using data pointer overwrites. We implement a proof-of-concept exploit against Nginx and successfully bypass CPI implementations that rely on information hiding in 6 seconds with 13 observed crashes. We also present an attack that generates no crashes and is able to bypass CPI in 98 hours. Our attack demonstrates the importance of adequately protecting secrets in security mechanisms and the dangers of relying on difficulty of guessing without guaranteeing the absence of memory leaks.
Isaac Evans, Sam Fingeret, Julian Gonzalez, Ulziibayar Otgonbaatar, Tiffany Tang, Howard E. Shrobe, Stelios Sidiroglou-Douskos, Martin C. Rinard, Hamed Okhravi
IEEE Symposium on Security and Privacy7
2014 Automatic runtime error repair and containment via recovery shepherding
abstract
We present a system, RCV, for enabling software applications to survive divide-by-zero and null-dereference errors. RCV operates directly on off-the-shelf, production, stripped x86 binary executables. RCV implements recovery shepherding, which attaches to the application process when an error occurs, repairs the execution, tracks the repair effects as the execution continues, contains the repair effects within the application process, and detaches from the process after all repair effects are flushed from the process state. RCV therefore incurs negligible overhead during the normal execution of the application.
Fan Long, Stelios Sidiroglou-Douskos, Martin C. Rinard
PLDI2
2014 Sound input filter generation for integer overflow errors
abstract
We present a system, SIFT, for generating input filters that nullify integer overflow errors associated with critical program sites such as memory allocation or block copy sites. SIFT uses a static pro- gram analysis to generate filters that discard inputs that may trigger integer overflow errors in the computations of the sizes of allocated memory blocks or the number of copied bytes in block copy operations. Unlike all previous techniques of which we are aware, SIFT is sound -- if an input passes the filter, it will not trigger an integer overflow error at any analyzed site. Our results show that SIFT successfully analyzes (and therefore generates sound input filters for) 56 out of 58 memory allocation and block memory copy sites in analyzed input processing modules from five applications (VLC, Dillo, Swfdec, Swftools, and GIMP). These nullified errors include six known integer overflow vulnerabilities. Our results also show that applying these filters to 62895 real-world inputs produces no false positives. The analysis and filter generation times are all less than a second.
Fan Long, Stelios Sidiroglou-Douskos, Deokhwan Kim, Martin C. Rinard
POPL2
2012 Automatic input rectification
abstract
We present a novel technique, automatic input rectification, and a prototype implementation, SOAP. SOAP learns a set of constraints characterizing typical inputs that an application is highly likely to process correctly. When given an atypical input that does not satisfy these constraints, SOAP automatically rectifies the input (i.e., changes the input so that it satisfies the learned constraints). The goal is to automatically convert potentially dangerous inputs into typical inputs that the program is highly likely to process correctly. Our experimental results show that, for a set of benchmark applications (Google Picasa, ImageMagick, VLC, Swfdec, and Dillo), this approach effectively converts malicious inputs (which successfully exploit vulnerabilities in the application) into benign inputs that the application processes correctly. Moreover, a manual code analysis shows that, if an input does satisfy the learned constraints, it is incapable of exploiting these vulnerabilities. We also present the results of a user study designed to evaluate the subjective perceptual quality of outputs from benign but atypical inputs that have been automatically rectified by SOAP to conform to the learned constraints. Specifically, we obtained benign inputs that violate learned constraints, used our input rectifier to obtain rectified inputs, then paid Amazon Mechanical Turk users to provide their subjective qualitative perception of the difference between the outputs from the original and rectified inputs. The results indicate that rectification can often preserve much, and in many cases all, of the desirable data in the original input.
Fan Long, Vijay Ganesh 0001, Michael Carbin, Stelios Sidiroglou-Douskos, Martin C. Rinard
ICSE4
2011 Dynamic knobs for responsive power-aware computing
abstract
We present PowerDial, a system for dynamically adapting application behavior to execute successfully in the face of load and power fluctuations. PowerDial transforms static configuration parameters into dynamic knobs that the PowerDial control system can manipulate to dynamically trade off the accuracy of the computation in return for reductions in the computational resources that the application requires to produce its results. These reductions translate directly into performance improvements and power savings.
Henry Hoffmann, Stelios Sidiroglou-Douskos, Michael Carbin, Sasa Misailovic, Anant Agarwal, Martin C. Rinard
ASPLOS2
2011 Managing performance vs. accuracy trade-offs with loop perforation
abstract
Many modern computations (such as video and audio encoders, Monte Carlo simulations, and machine learning algorithms) are designed to trade off accuracy in return for increased performance. To date, such computations typically use ad-hoc, domain-specific techniques developed specifically for the computation at hand. Loop perforation provides a general technique to trade accuracy for performance by transforming loops to execute a subset of their iterations. A criticality testing phase filters out critical loops (whose perforation produces unacceptable behavior) to identify tunable loops (whose perforation produces more efficient and still acceptably accurate computations). A perforation space exploration algorithm perforates combinations of tunable loops to find Pareto-optimal perforation policies. Our results indicate that, for a range of applications, this approach typically delivers performance increases of over a factor of two (and up to a factor of seven) while changing the result that the application produces by less than 10%.
Stelios Sidiroglou-Douskos, Sasa Misailovic, Henry Hoffmann, Martin C. Rinard
SIGSOFT FSE1
2010 Quality of service profiling
abstract
Many computations exhibit a trade off between execution time and quality of service. A video encoder, for example, can often encode frames more quickly if it is given the freedom to produce slightly lower quality video. A developer attempting to optimize such computations must navigate a complex trade-off space to find optimizations that appropriately balance quality of service and performance.
Sasa Misailovic, Stelios Sidiroglou-Douskos, Henry Hoffmann, Martin C. Rinard
ICSE (1)2
2010 Patterns and statistical analysis for understanding reduced resource computing
abstract
We present several general, broadly applicable mechanisms that enable computations to execute with reduced resources, typically at the cost of some loss in the accuracy of the result they produce.We identify several general computational patterns that interact well with these resource reduction mechanisms, present a concrete manifestation of these patterns in the form of simple model programs, perform simulationbased explorations of the quantitative consequences of applying these mechanisms to our model programs, and relate the model computations (and their interaction with the resource reduction mechanisms) to more complex benchmark applications drawn from a variety of fields.
Martin C. Rinard, Henry Hoffmann, Sasa Misailovic, Stelios Sidiroglou-Douskos
OOPSLA4
2010 BotSwindler: Tamper Resistant Injection of Believable Decoys in VM-Based Hosts for Crimeware Detection
Brian M. Bowen, Pratap V. Prabhu, Vasileios P. Kemerlis, Stelios Sidiroglou-Douskos, Angelos D. Keromytis, Salvatore J. Stolfo
RAID4
2009 ASSURE: automatic software self-healing using rescue points
abstract
Software failures in server applications are a significant problem for preserving system availability. We present ASSURE, a system that introduces rescue points that recover software from unknown faults while maintaining both system integrity and availability, by mimicking system behavior under known error conditions. Rescue points are locations in existing application code for handling a given set of programmer-anticipated failures, which are automatically repurposed and tested for safely enabling fault recovery from a larger class of (unanticipated) faults. When a fault occurs at an arbitrary location in the program, ASSURE restores execution to an appropriate rescue point and induces the program to recover execution by virtualizing the program's existing error-handling facilities. Rescue points are identified using fuzzing, implemented using a fast coordinated checkpoint-restart mechanism that handles multi-process and multi-threaded applications, and, after testing, are injected into production code using binary patching. We have implemented an ASSURE Linux prototype that operates without application source code and without base operating system kernel changes. Our experimental results on a set of real-world server applications and bugs show that ASSURE enabled recovery for all of the bugs tested with fast recovery times, has modest performance overhead, and provides automatic self-healing orders of magnitude faster than current human-driven patch deployment methods.
Stelios Sidiroglou-Douskos, Oren Laadan, Carlos Perez, Nicolas Viennot, Jason Nieh, Angelos D. Keromytis
ASPLOS1
2009 Automatically patching errors in deployed software
abstract
We present ClearView, a system for automatically patching errors in deployed software. ClearView works on stripped Windows x86 binaries without any need for source code, debugging information, or other external information, and without human intervention.
Jeff H. Perkins, Sunghun Kim 0001, Samuel Larsen, Saman P. Amarasinghe, Jonathan Bachrach, Michael Carbin, Carlos Pacheco, Frank Sherwood, Stelios Sidiroglou-Douskos, Gregory T. Sullivan, Weng-Fai Wong, Yoav Zibin, Michael D. Ernst, Martin C. Rinard
SOSP9
2007 Using Rescue Points to Navigate Software Recovery
abstract
We present a new technique that enables software recovery in legacy applications by retrofitting exception-handling capabilities, error virtualization using rescue points. We introduce the idea of "rescue points" as program locations to which an application can recover its execution in the presence of failures. The use of rescue points reduces the chance of unanticipated execution paths thereby making recovery more robust by mimicking system behavior under controlled error conditions. These controlled error conditions can be thought of as a set erroneous inputs, like the ones used by most quality-assurance teams during software development, designed to stress-test an application. To discover rescue points applications are profiled and monitored during tests that bombard the program with bad/random inputs. The intuition is that by monitoring application behavior during these runs, we gain insight into how programmer-tested program points are used to propagate faults gracefully.
Stelios Sidiroglou-Douskos, Oren Laadan, Angelos D. Keromytis, Jason Nieh
S&P1
2007 Proximity Breeds Danger: Emerging Threats in Metro-area Wireless Networks
Periklis Akritidis, Wee-Yung Chin, Vinh The Lam, Stelios Sidiroglou-Douskos, Kostas G. Anagnostakis
USENIX Security Symposium4
2006 Software Self-Healing Using Collaborative Application Communities
Michael E. Locasto, Stelios Sidiroglou-Douskos, Angelos D. Keromytis
NDSS2
2006 Privacy as an Operating System Service
Sotiris Ioannidis, Stelios Sidiroglou-Douskos, Angelos D. Keromytis
HotSec2
2005 Highlights from the 2005 New Security Paradigms Workshop
abstract
This panel highlights a selection of the most interesting and provocative papers from the 2005 New Security Paradigms Workshop. This workshop was held September 2005 - the URL for more information is http://www.nspw.org. The panel consists of authors of the selected papers, and the session is moderated by the workshop's general chairs. We present selected papers focusing on exciting major themes that emerged from the workshop. These are the papers that will provoke the most interesting discussion at ACSAC.
Simon N. Foley, Abe Singer, Michael E. Locasto, Stelios Sidiroglou-Douskos, Angelos D. Keromytis, John P. McDermott, Julie Thorpe, Paul C. van Oorschot, Anil Somayaji, Richard Ford, Mark Bush, Alex Boulatov
ACSAC4
2005 An Email Worm Vaccine Architecture
Stelios Sidiroglou-Douskos, John Ioannidis, Angelos D. Keromytis, Salvatore J. Stolfo
ISPEC1
2005 A Dynamic Mechanism for Recovering from Buffer Overflow Attacks
Stelios Sidiroglou-Douskos, Giannis Giovanidis, Angelos D. Keromytis
ISC1
2005 Speculative virtual verification: policy-constrained speculative execution
abstract
A key problem facing current computing systems is the inability to autonomously manage security vulnerabilities as well as more mundane errors. Since the design of computer architectures is usually performance-driven, hardware often lacks primitives for tasks in which raw speed is not the primary goal. There is little architectural support for monitoring execution at the instruction level, and no mechanisms for assisting an automated response.This paper advocates modifying general-purpose processors to provide both program supervision and automatic response via a policy-driven monitoring mechanism and instruction stream rewriting, respectively. These capabilities form the basis of speculative virtual verification (SVV).SVV is a model for the speculative execution of code based on high-level security and safety constraints. We introduce architectural enhancements to support this framework, including the ability to supply an automated response by rewriting the instruction stream. Finally, given the novelty of the SVV approach to executing software, we briefly consider some important challenges for SVV-based systems.
Michael E. Locasto, Stelios Sidiroglou-Douskos, Angelos D. Keromytis
NSPW2
2005 Building a Reactive Immune System for Software Services
Stelios Sidiroglou-Douskos, Michael E. Locasto, Stephen W. Boyd, Angelos D. Keromytis
USENIX ATC, General Track1
2005 Detecting Targeted Attacks Using Shadow Honeypots
Kostas G. Anagnostakis, Stelios Sidiroglou-Douskos, Periklis Akritidis, Konstantinos Xinidis, Evangelos P. Markatos, Angelos D. Keromytis
USENIX Security Symposium2