Benjamin Holland

dblp:65/9529 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
0since 2021 · last 2019
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 3 first-authorHuman-computer interaction and ubiquitous computing · 3Security and privacy · 1Applied, interdisciplinary, general and emerging computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Systems and software security · 56% Network security · 28% Malware analysis · 16%
Human-computer interaction and pervasive computing
1 paper
Accessibility and assistive technology · 77% Immersive interaction · 23%
Software engineering, system software, and programming languages
1 paper
Program analysis · 100%

Topics — the 5 heaviest of 7, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › vulnerability discovery
algorithmic complexity vulnerabilities
0.412019
DISCOVER: detecting algorithmic complexity vulnerabilities · ESEC/SIGSOFT FSE 2019
Network security › attack strategy
denial-of-service attack
0.412019
DISCOVER: detecting algorithmic complexity vulnerabilities · ESEC/SIGSOFT FSE 2019
Systems and software security
vulnerability discovery
0.412019
DISCOVER: detecting algorithmic complexity vulnerabilities · ESEC/SIGSOFT FSE 2019
Malware analysis › mobile malware detection
android malware detection
0.212015
Security Toolbox for Detecting Novel and Sophisticated Android Malware · ICSE (2) 2015
Immersive interaction
head-mounted display
0.112015
Head-Mounted Display Visualizations to Support Sound Awareness for the Deaf and Hard of Hearing · CHI 2015

Methods — techniques the papers use, named apart from their topics

user study · 0.2design probe · 0.2
YearPublicationVenuePosition
2019 DISCOVER: detecting algorithmic complexity vulnerabilities
abstract
Algorithmic Complexity Vulnerabilities (ACV) are a class of vulnerabilities that enable Denial of Service Attacks. ACVs stem from asymmetric consumption of resources due to complex loop termination logic, recursion, and/or resource intensive library APIs. Completely automated detection of ACVs is intractable and it calls for tools that assist human analysts.
Payas Awadhutkar, Ganesh Ram Santhanam, Benjamin Holland, Suresh C. Kothari
ESEC/SIGSOFT FSE3
2017 Transferring State-of-the-Art Immutability Analyses: Experimentation Toolbox and Accuracy Benchmark
abstract
Immutability analysis is important to software testing, verification and validation (V&V) because it can be used to identify independently testable functions without side-effects. Existing tools for immutability analysis are largely academic prototypes that have not been rigorously tested for accuracy or have not been maintained and are unable to analyze programs written in later versions of Java. In this paper, we re-implement two prominent approaches to inferring the immutability of an object: one that leverages a points-to analysis and another that uses a type-system. In addition to supporting Java 8 source programs, our re-implementations support the analysis of compiled Java bytecode. In order to evaluate the relative accuracy, we create a benchmark that rigorously tests the accuracy boundaries of the respective approaches. We report results of experiments on analyzing the benchmark with the two approaches and compare their scalability to real world applications. Our results from the benchmark reveal that points-to based approach is more accurate than the type inference based approach in certain cases. However, experiments with real world applications show that the points-to based approach does not scale well to very large applications and a type inference based approach may offer a scalable alternative.
Benjamin Holland, Ganesh Ram Santhanam, Suresh C. Kothari
ICST1
2017 Interactive visualization toolbox to detect sophisticated android malware
abstract
Detecting zero-day sophisticated malware is like searching for a needle in the haystack, not knowing what the needle looks like. This paper describes Android Malicious Flow Visualization Toolbox that empowers a human analyst to detect such malware. Detecting sophisticated malware requires systematic exploration of the code to identify potentially malignant code, conceiving plausible malware hypotheses, and gathering evidence from the code to prove or refute each hypothesis. We describe interactive visualizations of program artifacts to understand and analyze complex Android semantics used by an app. The toolbox incorporates visualization capabilities that work together cohesively, and provides a mechanism to easily add new capabilities. We present case studies of detecting Android malware with confidentiality and integrity breaches. We report the accuracy and efficiency achieved by our team of analysts by using the toolbox, while auditing 77 sophisticated Android apps provided by Defense Advanced Research Projects Agency (DARPA). Toolbox URL·: https://kcsl.github.io/AMFVT/.
Ganesh Ram Santhanam, Benjamin Holland, Suresh C. Kothari, Jon Mathews
VizSEC2
2016 Statically-Informed Dynamic Analysis Tools to Detect Algorithmic Complexity Vulnerabilities
abstract
Algorithmic Complexity (AC) vulnerabilities can be exploited to cause a denial of service attack. Specifically, an adversary can design an input to trigger excessive (space/time) resource consumption. It is not possible to build a fully automated tool to detect AC vulnerabilities. Since it is an open-ended problem, a human-in-loop exploration is required to find the program loops that could have AC vulnerabilities. Ascertaining whether an arbitrary loop has an AC vulnerability is itself difficult, which is equivalent to the halting problem. This paper is about a pragmatic engineering approach to detect AC vulnerabilities. It presents a statically-informed dynamic (SID) analysis and two tools that provide critical capabilities for detecting AC vulnerabilities. The first is a static analysis tool for exploring the software to find loops as the potential candidates for AC vulnerabilities. The second is a dynamic analysis tool that can try many different inputs to evaluate the selected loops for excessive resource consumption. The two tools are built and integrated together using the interactive software analysis, transformation, and visualization capabilities provided by the Atlas platform. The paper describes two use cases for the tools, one to detect AC vulnerabilities in Java bytecode and another for students in an undergraduate algorithm class to perform experiments to learn different aspects of algorithmic complexity Tool and Demo Video: https://ensoftcorp.github.io/SID.
Benjamin Holland, Ganesh Ram Santhanam, Payas Awadhutkar, Suresh C. Kothari
SCAM1
2015 Head-Mounted Display Visualizations to Support Sound Awareness for the Deaf and Hard of Hearing
abstract
Persons with hearing loss use visual signals such as gestures and lip movement to interpret speech. While hearing aids and cochlear implants can improve sound recognition, they generally do not help the wearer localize sound necessary to leverage these visual cues. In this paper, we design and evaluate visualizations for spatially locating sound on a head-mounted display (HMD). To investigate this design space, we developed eight high-level visual sound feedback dimensions. For each dimension, we created 3-12 example visualizations and evaluated these as a design probe with 24 deaf and hard of hearing participants (Study 1). We then implemented a real-time proof-of-concept HMD prototype and solicited feedback from 4 new participants (Study 2). Study 1 findings reaffirm past work on challenges faced by persons with hearing loss in group conversations, provide support for the general idea of sound awareness visualizations on HMDs, and reveal preferences for specific design options. Although preliminary, Study 2 further contextualizes the design probe and uncovers directions for future work.
Dhruv Jain, Leah Findlater, Jamie Gilkeson, Benjamin Holland, Ramani Duraiswami, Dmitry N. Zotkin, Christian Vogler, Jon Froehlich
CHI4
2015 Security Toolbox for Detecting Novel and Sophisticated Android Malware
abstract
This paper presents a demo of our Security Toolbox to detect novel malware in Android apps. This Toolbox is developed through our recent research project funded by the DARPA Automated Program Analysis for Cybersecurity (APAC) project. The adversarial challenge ("Red") teams in the DARPA APAC program are tasked with designing sophisticated malware to test the bounds of malware detection technology being developed by the research and development ("Blue") teams. Our research group, a Blue team in the DARPA APAC program, proposed a "human-in-the-loop program analysis" approach to detect malware given the source or Java bytecode for an Android app. Our malware detection apparatus consists of two components: a general-purpose program analysis platform called Atlas, and a Security Toolbox built on the Atlas platform. This paper describes the major design goals, the Toolbox components to achieve the goals, and the workflow for auditing Android apps. The accompanying video illustrates features of the Toolbox through a live audit.
Benjamin Holland, Tom Deering, Suresh C. Kothari, Jon Mathews, Nikhil Ranade
ICSE (2)1
2014 A "Human-in-the-loop" approach for resolving complex software anomalies
abstract
Automated static analysis tools are widely used in identifying software anomalies, such as memory leak, unsafe thread synchronization and malicious behaviors in smartphone applications. Such anomaly-prone scenarios can be bifurcated into: “ordinary” (analysis requires relatively simple automation) and “complex” (analysis poses extraordinary automation challenges). While automated static analysis tools can resolve ordinary scenarios with high accuracy, automating the analysis of complex scenarios can be very challenging and, at times, infeasible. Even when feasible the cost for full automation can be exorbitant: either in implementing the automation or in sifting through the large number of erroneous results manually. Instead, we appeal for a “Human-in-the-loop” approach called “Amplified Reasoning Technique” (ART). While some of the existing approaches do involve human in the analysis process, the roles played by man and machine are mainly segregated. Whereas, ART puts man and machine in a “loop” in an interactive and visualization-based fashion. This paper makes an attempt to convince its readers to make their analysis of software anomalies ART-based by presenting real-world case studies of complex anomalies and how an ART based approach can be very effective in resolving them. The case studies highlight the desired characteristics of an ART based tool and the type of role it plays in amplifying human intelligence.
Suresh C. Kothari, Akshay Deepak, Ahmed Tamrawi, Benjamin Holland, Sandeep Krishnan
SMC4