EDBT 2026 Demo / reviewers in the wild / expert
Thomas Schmitz 0001
dblp:57/4292-1
· DBLP profile ↗
3ranked-venue papers
1as first author
0since 2021 · last 2018
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 2Security and privacy · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
3 papers |
Systems and software security · 95% Web and mobile security · 5% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Cloud and datacenter computing · 100% | |
| Software engineering, system software, and programming languages
1 paper |
Programming languages and type systems · 100% |
Topics — the 9 heaviest of 9, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
information flow control |
0.9 | 3 | 2018 | Secure serverless computing using dynamic information flow control · Proc. ACM Program. Lang. 2018 Faceted Secure Multi Execution · CCS 2018 Multiple Facets for Dynamic Information Flow with Exceptions · ACM Trans. Program. Lang. Syst. 2017 |
Systems and software security › information flow control
dynamic information flow control |
0.3 | 1 | 2018 | Secure serverless computing using dynamic information flow control · Proc. ACM Program. Lang. 2018 |
Systems and software security › information flow control
secure multi-execution |
0.3 | 1 | 2018 | Faceted Secure Multi Execution · CCS 2018 |
Cloud and datacenter computing
serverless computing |
0.3 | 1 | 2018 | Secure serverless computing using dynamic information flow control · Proc. ACM Program. Lang. 2018 |
Cloud and datacenter computing › serverless computing
serverless security |
0.3 | 1 | 2018 | Secure serverless computing using dynamic information flow control · Proc. ACM Program. Lang. 2018 |
Systems and software security › information flow control
noninterference |
0.1 | 1 | 2018 | Secure serverless computing using dynamic information flow control · Proc. ACM Program. Lang. 2018 |
Systems and software security › information flow control › noninterference
termination-sensitive noninterference |
0.1 | 1 | 2018 | Secure serverless computing using dynamic information flow control · Proc. ACM Program. Lang. 2018 |
Programming languages and type systems
language-based security |
0.1 | 1 | 2018 | Faceted Secure Multi Execution · CCS 2018 |
Web and mobile security
javascript security |
0.1 | 1 | 2017 | Multiple Facets for Dynamic Information Flow with Exceptions · ACM Trans. Program. Lang. Syst. 2017 |
Methods — techniques the papers use, named apart from their topics
static labeling · 0.7formal framework · 0.7faceted labeling · 0.7dynamic taint analysis · 0.7microbenchmarking · 0.3micro-benchmarking · 0.3noninterference · 0.3faceted values · 0.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2018 | Faceted Secure Multi ExecutionabstractTo enforce non-interference, both Secure Multi-Execution (SME) and Multiple Facets (MF) rely on the introduction of multi-executions. The attractiveness of these techniques is that they are precise: secure programs running under SME or MF do not change their behavior. Although MF was intended as an optimization for SME, it does provide a weaker security guarantee for termination leaks. This paper presents Faceted Secure Multi Execution (FSME), a novel synthesis of MF and SME that combines the stronger security guarantees of SME with the optimizations of MF. The development of FSME required a unification of the ideas underlying MF and SME into a new multi-execution framework (Multef), which can be parameterized to provide MF, SME, or our new approach FSME, thus enabling an apples-to-apples comparison and benchmarking of all three approaches. Unlike the original work on MF and SME, Multef supports arbitrary (and possibly infinite) lattices necessary for decentralized labeling models---a feature needed in order to make possible the writing of applications where each principal can impose confidentiality and integrity requirements on data. We provide some micro-benchmarks for evaluating Multef and write a file hosting service, called ProtectedBox, whose functionality can be securely extended via third-party plugins. Thomas Schmitz 0001, Maximilian Algehed, Cormac Flanagan, Alejandro Russo |
CCS | 1 |
| 2018 | Secure serverless computing using dynamic information flow controlabstractThe rise of serverless computing provides an opportunity to rethink cloud security. We present an approach for securing serverless systems using a novel form of dynamic information flow control (IFC). We show that in serverless applications, the termination channel found in most existing IFC systems can be arbitrarily amplified via multiple concurrent requests, necessitating a stronger termination-sensitive non-interference guarantee, which we achieve using a combination of static labeling of serverless processes and dynamic faceted labeling of persistent data. We describe our implementation of this approach on top of JavaScript for AWS Lambda and OpenWhisk serverless platforms, and present three realistic case studies showing that it can enforce important IFC security properties with modest overhead. Kalev Alpernas, Cormac Flanagan, Sadjad Fouladi, Leonid Ryzhyk, Shmuel Sagiv, Thomas Schmitz 0001, Keith Winstein |
Proc. ACM Program. Lang. | 6 |
| 2017 | Multiple Facets for Dynamic Information Flow with ExceptionsabstractJavaScript is the source of many security problems, including cross-site scripting attacks and malicious advertising code. Central to these problems is the fact that code from untrusted sources runs with full privileges. Information flow controls help prevent violations of data confidentiality and integrity. This article explores faceted values , a mechanism for providing information flow security in a dynamic manner that avoids the stuck executions of some prior approaches, such as the no-sensitive-upgrade technique. Faceted values simultaneously simulate multiple executions for different security levels to guarantee termination-insensitive noninterference. We also explore the interaction of faceted values with exceptions, declassification, and clearance. Thomas H. Austin, Thomas Schmitz 0001, Cormac Flanagan |
ACM Trans. Program. Lang. Syst. | 2 |