EDBT 2026 Demo / reviewers in the wild / expert
Michael Kiperberg
dblp:59/10366
· DBLP profile ↗
16ranked-venue papers
9as first author
10since 2021 · last 2024
0000-0001-8906-5940ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 14 · 8 first-author · 8 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Detecting eBPF Rootkits Using Virtualization and Memory Forensics
Nezer Zaidenberg, Michael Kiperberg, Eliav Menachi, Asaf Eitani |
ICISSP | 2 |
| 2024 | Virtualized network packet inspection
Erez Shlingbaum, Raz Ben Yehuda, Michael Kiperberg, Nezer Zaidenberg |
Comput. Networks | 3 |
| 2024 | HyperWallet: cryptocurrency wallet as a secure hypervisor-based applicationabstractWe present VirtSecIO, a hypervisor-based platform for executing secure modules. VirtSecIO provides the modules with secure paths to peripheral devices, which can be shared between the modules and the operating system. Moreover, VirtSecIO is a thin hypervisor with a negligible performance overhead and a minimal attack surface. We demonstrate VirtSecIO’s abilities by developing HyperWallet, a secure module that acts as a hardware crypto-wallet, without requiring any dedicated hardware. Nezer Zaidenberg, Michael Kiperberg |
EURASIP J. Inf. Secur. | 2 |
| 2023 | PDIFT: A Practical Dynamic Information-Flow Tracker
Michael Kiperberg, Aleksei Rozman, Aleksei Kuraev, Nezer Zaidenberg |
ICISSP | 1 |
| 2022 | Ransomware Detection with Deep Neural Networks
Matan Davidian, Natalia Vanetik, Michael Kiperberg |
ICISSP | 3 |
| 2021 | Efficient DLP-visor: An efficient hypervisor-based DLPabstractMany organization consider insider threat for data theft to be one of the most severe threats. An insider may also leak sensitive information without malicious intent (as a result of social engineering) Data leakage prevention (DLP) systems attempt to prevent intentional or accidental disclosure of sensitive information by monitoring the content or the context in which the information is transferred, for example, in a file system, an email server, instant messengers. We present a context-sensitive DLP system, called Efficient DLP-Visor. We implemented DLP-visor as a thin hypervisor capable of intercepting system calls in Windows operating systems equipped with Kernel Patch Protection. By intercepting system calls that govern the file system, inter-process communications, networking, system register and system clipboard, DLP-Visor guarantees that sensitive information can never leave a predefined set of directories. The performance overhead of Efficient DLP-Visor (7.2%) allows its deployment in real-world applications. Efficient DLP-visor logs were improved for better detection and logging of a DLP event. On idle time Efficient DLP-visor deletes most of the data log while maintaining the important data of leaks and attack. Michael Kiperberg, Guy Amit, Amir Yeshooroon, Nezer Zaidenberg |
CCGRID | 1 |
| 2021 | DLP-Visor: A Hypervisor-based Data Leakage Prevention System
Guy Amit, Amir Yeshooroon, Michael Kiperberg, Nezer Zaidenberg |
ICISSP | 3 |
| 2021 | HyperPass: Secure Password Input Platform
Michael Kiperberg, Nezer Zaidenberg |
ICISSP | 1 |
| 2021 | Hypervisor-assisted dynamic malware analysisabstractAbstract Malware analysis is a task of utmost importance in cyber-security. Two approaches exist for malware analysis: static and dynamic. Modern malware uses an abundance of techniques to evade both dynamic and static analysis tools. Current dynamic analysis solutions either make modifications to the running malware or use a higher privilege component that does the actual analysis. The former can be easily detected by sophisticated malware while the latter often induces a significant performance overhead. We propose a method that performs malware analysis within the context of the OS itself. Furthermore, the analysis component is camouflaged by a hypervisor, which makes it completely transparent to the running OS and its applications. The evaluation of the system’s efficiency suggests that the induced performance overhead is negligible. Roee Leon, Michael Kiperberg, Anat Anatey Leon Zabag, Nezer Zaidenberg |
Cybersecur. | 2 |
| 2021 | Preventing malicious communication using virtualization
Michael Kiperberg |
J. Inf. Secur. Appl. | 1 |
| 2020 | HyperWall: A Hypervisor for Detection and Prevention of Malicious Communication
Michael Kiperberg, Raz Ben Yehuda, Nezer Zaidenberg |
NSS | 1 |
| 2019 | Hypervisor-assisted Atomic Memory Acquisition in Modern SystemsabstractReliable memory acquisition is essential to forensic analysis of a cyber-crime. Various methods of memory acquisition have been proposed, ranging from tools based on a dedicated hardware to software only solutions. Recently, a hypervisor-based method for memory acquisition was proposed (Qi et al., 2017; Martignoni et al., 2010). This method obtains a reliable (atomic) memory image of a running system. The method achieves this by making all memory pages non-writable until they are copied to the memory image, thus preventing uncontrolled modification of these pages. Unfortunately, the proposed method has two deficiencies: (1) the method does not support multiprocessing and (2) the method does not support modern operating systems featuring address space layout randomization (ASLR). We describe a hypervisor-based memory acquisition method that solves the two aforementioned deficiencies. We analyze the memory usage and performance of the proposed method. Michael Kiperberg, Roee Leon, Amit Resh, Asaf Algawi, Nezer Zaidenberg |
ICISSP | 1 |
| 2019 | Hypervisor-Based Protection of CodeabstractThe code of a compiled program is susceptible to reverse-engineering attacks on the algorithms and the business logic that are contained within the code. The main existing countermeasure to reverse-engineering is obfuscation. Generally, obfuscation methods suffer from two main deficiencies: 1) the obfuscated code is less efficient than the original and 2) with sufficient effort, the original code may be reconstructed. We propose a method that is based on cryptography and virtualization. The most valuable functions are encrypted and remain inaccessible even during their execution, thus preventing their reconstruction. A specially crafted hypervisor is responsible for decryption, execution, and protection of the encrypted functions. We claim that the system can provide protection even if the attacker: 1) has access to the operating system kernel and 2) can intercept communication over the system bus. The evaluation of the system's efficiency suggests that it can compete with and outperform obfuscation-based methods. Michael Kiperberg, Roee Leon, Amit Resh, Asaf Algawi, Nezer Zaidenberg |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2017 | System for Executing Encrypted Java Programs
Michael Kiperberg, Amit Resh, Asaf Algawi, Nezer Zaidenberg |
ICISSP | 1 |
| 2015 | Remote Attestation of Software and Execution-Environment in Modern MachinesabstractThe research on network security concentrates mainly on securing the communication channels between two endpoints, which is insufficient if the authenticity of one of the endpoints cannot be determined with certainty. Previously presented methods that allow one endpoint, the authentication authority, to authenticate another remote machine. These methods are inadequate for modern machines that have multiple processors, introduce virtualization extensions, have a greater variety of side effects, and suffer from nondeterminism. This paper addresses the advances of modern machines with respect to the method presented by Kennell. The authors describe how a remote attestation procedure, involving a challenge, needs to be structured in order to provide correct attestation of a remote modern target system. Michael Kiperberg, Amit Resh, Nezer Zaidenberg |
CSCloud | 1 |
| 2011 | An efficient VM-based software protectionabstractThis paper presents Truly-protect, a system, incorporating a virtual machine, that enables execution of encrypted programs. Our intention is to form a framework for a conditional access/digital rights management system. We avoid relying on obscurity and rely only on assumptions about the system itself and on cryptographic measures to develop VM-based conditional access/trusted computing environment. Rolles in [18], proposes a general way of breaking systems of type described herein. We claim that Rolles' method fails to defeat our system. Amir Averbuch, Michael Kiperberg, Nezer Zaidenberg |
NSS | 2 |