EDBT 2026 Demo / reviewers in the wild / expert
Christoph Kerschbaumer
dblp:41/8026
· DBLP profile ↗
5ranked-venue papers
3as first author
1since 2021 · last 2022
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Systems and software security · 87% Web and mobile security · 13% | |
| Software engineering, system software, and programming languages
1 paper |
Runtime systems and virtual machines · 100% |
Topics — the 4 heaviest of 4, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
information flow tracking |
0.2 | 1 | 2013 | Information flow tracking meets just-in-time compilation · ACM Trans. Archit. Code Optim. 2013 |
Systems and software security
javascript engine |
0.2 | 1 | 2013 | Information flow tracking meets just-in-time compilation · ACM Trans. Archit. Code Optim. 2013 |
Runtime systems and virtual machines › dynamic compilation
just-in-time compilation |
0.2 | 1 | 2013 | Information flow tracking meets just-in-time compilation · ACM Trans. Archit. Code Optim. 2013 |
Web and mobile security › web security
cross-site scripting |
0.0 | 1 | 2013 | Information flow tracking meets just-in-time compilation · ACM Trans. Archit. Code Optim. 2013 |
Methods — techniques the papers use, named apart from their topics
just-in-time compilation · 0.3information flow tracking · 0.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | SoK: All or Nothing - A Postmortem of Solutions to the Third-Party Script Inclusion Permission Model and a Path ForwardabstractThe web execution model allows third-party JavaScript to be leveraged in a single execution context. Access control for these scripts is currently all or nothing. It has been this way for over a decade despite the knowledge that this model allows for privacy violations and even user data exfiltration. Consequently, users have little to no control over which third-parties operate on their Personally Identifying Information (PII) when interacting with a web application. In this work we aim to explain the lack of solutions to this problem, and to suggest more promising future directions. We first survey past proposed solutions and their trade-offs. We then create a monitoring system in the Firefox browser which captures third-party script access to user supplied PII in HTML Form Elements. We proceed to inspect 100,000 websites with our Monitor and custom web crawler to highlight the complexity of use cases of third-party scripts operating on user PII. Our findings inform the creation of a grading rubric and systematization for solutions in this space, which we then apply to many previous works. The complexity exposed through this effort allows us to start a discussion around why current technological and policy solutions fail adoption. Ultimately we propose a research direction that allows web applications to take advantage of the interoperability of the web execution model while also respecting an end user's privacy and security. Steven Sprecher, Christoph Kerschbaumer, Engin Kirda |
EuroS&P | 2 |
| 2017 | Extending the Same Origin Policy with Origin Attributes
Tanvi Vyas, Andrea Marchesini, Christoph Kerschbaumer |
ICISSP | 3 |
| 2016 | Injecting CSP for Fun and Security
Christoph Kerschbaumer, Sid Stamm, Stefan Brunthaler 0001 |
ICISSP | 1 |
| 2013 | CrowdFlow: Efficient Information Flow Security
Christoph Kerschbaumer, Eric Hennigan, Per Larsen, Stefan Brunthaler 0001, Michael Franz |
ISC | 1 |
| 2013 | Information flow tracking meets just-in-time compilationabstractWeb applications are vulnerable to cross-site scripting attacks that enable data thefts. Information flow tracking in web browsers can prevent communication of sensitive data to unintended recipients and thereby stop such data thefts. Unfortunately, existing solutions have focused on incorporating information flow into browsers’ JavaScript interpreters, rather than just-in-time compilers, rendering the resulting performance noncompetitive. Few users will switch to a safer browser if it comes at the cost of significantly degrading web application performance. We present the first information flow tracking JavaScript engine that is based on a true just-in-time compiler, and that thereby outperforms all previous interpreter-based information flow tracking JavaScript engines by more than a factor of two. Our JIT-based engine (i) has the same coverage as previous interpreter- based solutions, (ii) requires reasonable implementation effort, and (iii) introduces new optimizations to achieve acceptable performance. When evaluated against three industry-standard JavaScript benchmark suites, there is still an average slowdown of 73% over engines that do not support information flow, but this is now well within the range that many users will find an acceptable price for obtaining substantially increased security. Christoph Kerschbaumer, Eric Hennigan, Per Larsen, Stefan Brunthaler 0001, Michael Franz |
ACM Trans. Archit. Code Optim. | 1 |