Sudhakar Govindavajhala

dblp:51/3156 · DBLP profile ↗
← Back
2ranked-venue papers
1as first author
0since 2021 · last 2005
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Network security · 40% Hardware security and side channels · 30% Systems and software security · 30%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Hardware reliability and fault tolerance · 100%

Topics — the 3 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Hardware security and side channels
fault attacks
0.012003
Using Memory Errors to Attack a Virtual Machine · S&P 2003
Systems and software security
language-based security
0.012003
Using Memory Errors to Attack a Virtual Machine · S&P 2003
Hardware reliability and fault tolerance
soft errors
0.012003
Using Memory Errors to Attack a Virtual Machine · S&P 2003

Methods — techniques the papers use, named apart from their topics

memory error exploitation · 0.1fault injection · 0.1logic programming · 0.1attack graph generation · 0.1
YearPublicationVenuePosition
2005 MulVAL: A Logic-based Network Security Analyzer
Xinming Ou, Sudhakar Govindavajhala, Andrew W. Appel
USENIX Security Symposium2
2003 Using Memory Errors to Attack a Virtual Machine
abstract
We present an experimental study showing that soft memory errors can lead to serious security vulnerabilities in Java and .NET virtual machines, or in any system that relies on type-checking of untrusted programs as a protection mechanism. Our attack works by sending to the JVM a Java program that is designed so that almost any memory error in its address space will allow it to take control of the JVM. All conventional Java and .NET virtual machines are vulnerable to this attack. The technique of the attack is broadly applicable against other language-based security schemes such as proof-carrying code. We measured the attack on two commercial Java virtual machines: Sun's and IBM's. We show that a single-bit error in the Java program's data space can be exploited to execute arbitrary code with a probability of about 70%, and multiple-bit errors with a lower probability. Our attack is particularly relevant against smart cards or tamper-resistant computers, where the user has physical access (to the outside of the computer) and can use various means to induce faults; we have successfully used heat. Fortunately, there are some straightforward defenses against this attack.
Sudhakar Govindavajhala, Andrew W. Appel
S&P1