Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Yeoul Na

dblp:37/9431 · DBLP profile ↗
← Back
13ranked-venue papers
2as first author
1since 2021 · last 2022
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8Systems, architecture and hardware · 4 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
5 papers
Systems and software security · 83% Web and mobile security · 17%
Software engineering, system software, and programming languages
5 papers
Program analysis · 47% Compilers and program optimization · 39% Runtime systems and virtual machines · 8%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Parallel and multicore computing · 77% GPUs and heterogeneous computing · 23%

Topics — the 10 heaviest of 13, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
memory safety
1.232022
PKRU-safe: automatically locking down the heap between safe and unsafe languages · EuroSys 2022
SoK: Sanitizing for Security · IEEE Symposium on Security and Privacy 2019
Venerable Variadic Vulnerabilities Vanquished · USENIX Security Symposium 2017
Web and mobile security › web security
javascript engine security
0.412020
NoJITsu: Locking Down JavaScript Engines · NDSS 2020
Program analysis › binary analysis
dynamic binary analysis
0.412020
BinRec: dynamic binary lifting and recompilation · EuroSys 2020
Systems and software security › memory safety
memory sanitizer
0.412019
SoK: Sanitizing for Security · IEEE Symposium on Security and Privacy 2019
Program analysis
dynamic analysis
0.412019
SoK: Sanitizing for Security · IEEE Symposium on Security and Privacy 2019
Compilers and program optimization › parallelization
automatic parallelization
0.212016
JavaScript Parallelizing Compiler for Exploiting Parallelism from Data-Parallel HTML5 Applications · ACM Trans. Archit. Code Optim. 2016
Parallel and multicore computing
data-parallel programming
0.212016
JavaScript Parallelizing Compiler for Exploiting Parallelism from Data-Parallel HTML5 Applications · ACM Trans. Archit. Code Optim. 2016
Systems and software security › memory protection
hardware-assisted memory protection
0.212022
PKRU-safe: automatically locking down the heap between safe and unsafe languages · EuroSys 2022
Operating systems › system security › operating system security
kernel security
0.112019
PeriScope: An Effective Probing and Fuzzing Framework for the Hardware-OS Boundary · NDSS 2019
GPUs and heterogeneous computing
GPU computing
0.112016
JavaScript Parallelizing Compiler for Exploiting Parallelism from Data-Parallel HTML5 Applications · ACM Trans. Archit. Code Optim. 2016

Methods — techniques the papers use, named apart from their topics

JIT hardening · 0.9systematic literature review · 0.8fuzzing · 0.8memory protection keys · 0.6PKRU · 0.6speculation · 0.5idempotence · 0.5affine loop analysis · 0.5dynamic disassembly · 0.4compiler hardening · 0.3
YearPublicationVenuePosition
2022 PKRU-safe: automatically locking down the heap between safe and unsafe languages
abstract
After more than twenty-five years of research, memory safety violations remain one of the major causes of security vulnerabilities in real-world software. Memory-safe languages, like Rust, have demonstrated that compiler technology can assist developers in writing efficient low-level code without the risk of memory corruption. However, many memory-safe languages still have to interface with unsafe code to some extent, which opens up the possibility for attackers to exploit memory-corruption vulnerabilities in the unsafe part of the system and subvert the safety guarantees provided by the memory-safe language.
Paul Kirth, Mitchel Dickerson, Stephen Crane, Per Larsen, Adrian Dabrowski, David Gens, Yeoul Na, Stijn Volckaert, Michael Franz
EuroSys7
2020 CoDaRR: Continuous Data Space Randomization against Data-Only Attacks
abstract
The widespread deployment of exploit mitigations such as CFI and shadow stacks are making code-reuse attacks increasingly difficult. This has forced adversaries to consider data-only attacks against which the venerable ASLR remains the primary deployed defense.Data-Space Randomization (DSR) techniques raise the bar against data-only attacks by making it harder for adversaries to inject malicious data flows into vulnerable applications. DSR works by masking memory load and store instructions. Masks are chosen (i) to not interfere with intended data flows and (ii) such that masking likely interferes with unintended flows introduced by malicious program inputs.
Prabhu Rajasekaran, Stephen Crane, David Gens, Yeoul Na, Stijn Volckaert, Michael Franz
AsiaCCS4
2020 Distributed Heterogeneous N-Variant Execution
Alexios Voulimeneas, Dokyung Song, Fabian Parzefall, Yeoul Na, Per Larsen, Michael Franz, Stijn Volckaert
DIMVA4
2020 BinRec: dynamic binary lifting and recompilation
abstract
Binary lifting and recompilation allow a wide range of install-time program transformations, such as security hardening, deobfuscation, and reoptimization. Existing binary lifting tools are based on static disassembly and thus have to rely on heuristics to disassemble binaries.
Anil Altinay, Joseph Nash, Taddeus Kroes, Prabhu Rajasekaran, Dixin Zhou, Adrian Dabrowski, David Gens, Yeoul Na, Stijn Volckaert, Cristiano Giuffrida, Herbert Bos, Michael Franz
EuroSys8
2020 NoJITsu: Locking Down JavaScript Engines
Taemin Park, Karel Dhondt, David Gens, Yeoul Na, Stijn Volckaert, Michael Franz
NDSS4
2019 PeriScope: An Effective Probing and Fuzzing Framework for the Hardware-OS Boundary
Dokyung Song, Felicitas Hetzelt, Dipanjan Das 0002, Chad Spensky, Yeoul Na, Stijn Volckaert, Giovanni Vigna, Christopher Krügel, Jean-Pierre Seifert, Michael Franz
NDSS5
2019 SoK: Sanitizing for Security
abstract
The C and C++ programming languages are notoriously insecure yet remain indispensable. Developers therefore resort to a multi-pronged approach to find security issues before adversaries. These include manual, static, and dynamic program analysis. Dynamic bug finding tools-henceforth "sanitizers"-can find bugs that elude other types of analysis because they observe the actual execution of a program, and can therefore directly observe incorrect program behavior as it happens. A vast number of sanitizers have been prototyped by academics and refined by practitioners. We provide a systematic overview of sanitizers with an emphasis on their role in finding security issues. Specifically, we taxonomize the available tools and the security vulnerabilities they cover, describe their performance and compatibility properties, and highlight various trade-offs.
Dokyung Song, Julian Lettner, Prabhu Rajasekaran, Yeoul Na, Stijn Volckaert, Per Larsen, Michael Franz
IEEE Symposium on Security and Privacy4
2018 Bytecode Corruption Attacks Are Real - And How to Defend Against Them
Taemin Park, Julian Lettner, Yeoul Na, Stijn Volckaert, Michael Franz
DIMVA3
2018 Accelerating Dynamically-Typed Languages on Heterogeneous Platforms Using Guards Optimization
abstract
Scientific applications are ideal candidates for the "heterogeneous computing" paradigm, in which parts of a computation are "offloaded" to available accelerator hardware such as GPUs. However, when such applications are written in dynamic languages such as Python or R, as they increasingly are, things become less straightforward. The same flexibility that makes these languages so appealing to programmers also significantly complicates the problem of automatically and transparently partitioning a program's execution between a CPU and available accelerator hardware without having to rely on programmer annotations. A common way of handling the features of dynamic languages is by introducing speculation in conjunction with guards to ascertain the validity of assumptions made in the speculative computation. Unfortunately, a single guard violation during the execution of "offloaded" code may result in a huge performance penalty and necessitate the complete re-execution of the offloaded computation. In the case of dynamic languages, this problem is compounded by the fact that a full compiler analysis is not always possible ahead of time. This paper presents MegaGuards, a new approach for speculatively executing dynamic languages on heterogeneous platforms in a fully automatic and transparent manner. Our method translates each target loop into a single static region devoid of any dynamic type features. The dynamic parts are instead handled by a construct that we call a mega guard which checks all the speculative assumptions ahead of its corresponding static region. Notably, the advantage of MegaGuards is not limited to heterogeneous computing; because it removes guards from compute-intensive loops, the approach also improves sequential performance. We have implemented MegaGuards along with an automatic loop parallelization backend in ZipPy, a Python Virtual Machine. The results of a careful and detailed evaluation reveal very significant speedups of an order of magnitude on average with a maximum speedup of up to two orders of magnitudes when compared to the original ZipPy performance as a baseline. These results demonstrate the potential for applying heterogeneous computing to dynamic languages.
Mohaned Qunaibit, Stefan Brunthaler 0001, Yeoul Na, Stijn Volckaert, Michael Franz
ECOOP3
2018 Hardware Assisted Randomization of Data
Brian Belleville, Hyungon Moon, Jangseop Shin, Dongil Hwang, Joseph Nash, Seonhwa Jung, Yeoul Na, Stijn Volckaert, Per Larsen, Yunheung Paek, Michael Franz
RAID7
2017 Venerable Variadic Vulnerabilities Vanquished
Priyam Biswas, Alessandro Di Federico, Scott A. Carr, Prabhu Rajasekaran, Stijn Volckaert, Yeoul Na, Michael Franz, Mathias Payer
USENIX Security Symposium6
2016 JavaScript Parallelizing Compiler for Exploiting Parallelism from Data-Parallel HTML5 Applications
abstract
With the advent of the HTML5 standard, JavaScript is increasingly processing computationally intensive, data-parallel workloads. Thus, the enhancement of JavaScript performance has been emphasized because the performance gap between JavaScript and native applications is still substantial. Despite this urgency, conventional JavaScript compilers do not exploit much of parallelism even from data-parallel JavaScript applications, despite contemporary mobile devices being equipped with expensive parallel hardware platforms, such as multicore processors and GPGPUs. In this article, we propose an automatically parallelizing JavaScript compiler that targets emerging, data-parallel HTML5 applications by leveraging the mature affine loop analysis of conventional static compilers. We identify that the most critical issues when parallelizing JavaScript with a conventional static analysis are ensuring correct parallelization, minimizing compilation overhead, and conducting low-cost recovery when there is a speculation failure during parallel execution. We propose a mechanism for safely handling the failure at a low cost, based on compiler techniques and the property of idempotence. Our experiment shows that the proposed JavaScript parallelizing compiler detects most affine parallel loops. Also, we achieved a maximum speedup of 3.22 times on a quad-core system, while incurring negligible compilation and recovery overheads with various sets of data-parallel HTML5 applications.
Yeoul Na, Seon Wook Kim, Youngsun Han
ACM Trans. Archit. Code Optim.1
2010 Hierarchical data structure-based timing controller design for plasma display panels
abstract
In this paper, we propose a timing controller design to use a hierarchical structure of control signals for plasma display panels (PDPs). Also, we used a double buffering and a repeatable FIFO in order to reduce the workload of memory accesses for control data, and provided a graphical user interface program for easy control data management. Our prototype system runs at 83 MHz on Spartan-3A DSP FPGA, and the new design achieves the reduction of 73 % in resource usage from the previous implementation.
Yeoul Na, Seokjoong Hwang, Giseong Bak, Seon Wook Kim, Cheol Ho Lee, Junkyu Min
ISCAS1