EDBT 2026 Demo / reviewers in the wild / expert
Ali Abbasi 0002
dblp:73/2297-2
· DBLP profile ↗
22ranked-venue papers
5as first author
12since 2021 · last 2026
0000-0003-4220-6560ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 5 first-author · 11 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HoneySat: A Network-based Satellite Honeypot Framework
Efrén López-Morales, Ulysse Planta, Gabriele Marra, Carlos Gonzalez-Cortes, Jacob Hopkins, Majid Garoosi, Elías Obreque, Carlos E. Rubio-Medrano, Ali Abbasi 0002 |
NDSS | 9 |
| 2026 | Anota: Identifying Business Logic Vulnerabilities via Annotation-Based Sanitization
Meng Wang 0071, Philipp Görz, Joschua Schilling, Keno Hassler, Thorsten Holz, Ali Abbasi 0002 |
NDSS | 7 |
| 2026 | SatBleed: Security of Commoditized Communication Modules in Satellites
Ulysse Planta, Julian Rederlechner, Martin Strohmeier, Mathias Fischer 0001, Ali Abbasi 0002 |
SP | 5 |
| 2026 | SmuFuzz: Enable Deep System Management Mode Fuzzing in Fully Featured UEFI Runtime Environment
Meng Wang 0071, Qinying Wang, Ali Abbasi 0002, Thorsten Holz |
SP | 5 |
| 2025 | TWINFUZZ: Differential Testing of Video Hardware Acceleration Stacks
Matteo Leonelli, Addison Crump, Meng Wang 0071, Florian Bauckholt, Keno Hassler, Ali Abbasi 0002, Thorsten Holz |
NDSS | 6 |
| 2025 | A Comprehensive Memory Safety Analysis of Bootloaders
Meng Wang 0071, Qinying Wang, Nils Langius, Ali Abbasi 0002, Thorsten Holz |
NDSS | 6 |
| 2024 | SoK: Security of Programmable Logic Controllers
Efrén López-Morales, Ulysse Planta, Carlos E. Rubio-Medrano, Ali Abbasi 0002, Alvaro A. Cárdenas |
USENIX Security Symposium | 4 |
| 2023 | Space Odyssey: An Experimental Software Security Analysis of Satellites
Johannes Willbold, Moritz Schloegel, Manuel Vögele, Maximilian Gerhardt, Thorsten Holz, Ali Abbasi 0002 |
SP | 6 |
| 2022 | Nyx-net: network fuzzing with incremental snapshotsabstractCoverage-guided fuzz testing ("fuzzing") has become mainstream and we have observed lots of progress in this research area recently. However, it is still challenging to efficiently test network services with existing coverage-guided fuzzing methods. In this paper, we introduce the design and implementation of Nyx-Net, a novel snapshot-based fuzzing approach that can successfully fuzz a wide range of targets spanning servers, clients, games, and even Firefox's Inter-Process Communication (IPC) interface. Compared to state-of-the-art methods, Nyx-Net improves test throughput by up to 300x and coverage found by up to 70%. Additionally, Nyx-Net is able to find crashes in two of ProFuzzBench's targets that no other fuzzer found previously. When using Nyx-Net to play the game Super Mario, Nyx-Net shows speedups of 10--30x compared to existing work. Moreover, Nyx-Net is able to find previously unknown bugs in servers such as Lighttpd, clients such as MySQL client, and even Firefox's IPC mechanism---demonstrating the strength and versatility of the proposed approach. Lastly, our prototype implementation was awarded a $20.000 bug bounty for enabling fuzzing on previously unfuzzable code in Firefox and solving a long-standing problem at Mozilla. Sergej Schumilo, Cornelius Aschermann, Andrea Jemmett, Ali Abbasi 0002, Thorsten Holz |
EuroSys | 4 |
| 2022 | Fuzzware: Using Precise MMIO Modeling for Effective Firmware Fuzzing
Tobias Scharnowski, Nils Bars, Moritz Schloegel, Eric Gustafson, Marius Muench, Giovanni Vigna, Christopher Krügel, Thorsten Holz, Ali Abbasi 0002 |
USENIX Security Symposium | 9 |
| 2022 | Loki: Hardening Code Obfuscation Against Automated Attacks
Moritz Schloegel, Tim Blazytko, Moritz Contag, Cornelius Aschermann, Julius Basler, Thorsten Holz, Ali Abbasi 0002 |
USENIX Security Symposium | 7 |
| 2021 | Nyx: Greybox Hypervisor Fuzzing using Fast Snapshots and Affine Types
Sergej Schumilo, Cornelius Aschermann, Ali Abbasi 0002, Simon Wörner, Thorsten Holz |
USENIX Security Symposium | 3 |
| 2020 | HYPER-CUBE: High-Dimensional Hypervisor Fuzzing
Sergej Schumilo, Cornelius Aschermann, Ali Abbasi 0002, Simon Wörner, Thorsten Holz |
NDSS | 3 |
| 2020 | Ijon: Exploring Deep State Spaces via FuzzingabstractAlthough current fuzz testing (fuzzing) methods are highly effective, there are still many situations such as complex state machines where fully automated approaches fail. State-of-the-art fuzzing methods offer very limited ability for a human to interact and aid the fuzzer in such cases. More specifically, most current approaches are limited to adding a dictionary or new seed inputs to guide the fuzzer. When dealing with complex programs, these mechanisms are unable to uncover new parts of the code base.In this paper, we propose Ijon, an annotation mechanism that a human analyst can use to guide the fuzzer. In contrast to the two aforementioned techniques, this approach allows a more systematic exploration of the program's behavior based on the data representing the internal state of the program. As a consequence, using only a small (usually one line) annotation, a user can help the fuzzer to solve previously unsolvable challenges. We extended various AFL-based fuzzers with the ability to annotate the source code of the target application with guidance hints. Our evaluation demonstrates that such simple annotations are able to solve problems that-to the best of our knowledge- no other current fuzzer or symbolic execution based tool can overcome. For example, with our extension, a fuzzer is able to play and solve games such as Super Mario Bros. or resolve more complex patterns such as hash map lookups. To further demonstrate the capabilities of our annotations, we use AFL combined with Ijon to uncover both novel security issues and issues that previously required a custom and comprehensive grammar to be uncovered. Lastly, we show that using Ijon and AFL, one can solve many challenges from the CGC data set that resisted all fully automated and human guided attempts so far. Cornelius Aschermann, Sergej Schumilo, Ali Abbasi 0002, Thorsten Holz |
SP | 3 |
| 2020 | AURORA: Statistical Crash Analysis for Automated Root Cause Explanation
Tim Blazytko, Moritz Schloegel, Cornelius Aschermann, Ali Abbasi 0002, Joel Frank, Simon Wörner, Thorsten Holz |
USENIX Security Symposium | 4 |
| 2019 | Challenges in Designing Exploit Mitigations for Deeply Embedded SystemsabstractMemory corruption vulnerabilities have been around for decades and rank among the most prevalent vulnerabilities in embedded systems. Yet this constrained environment poses unique design and implementation challenges that significantly complicate the adoption of common hardening techniques. Combined with the irregular and involved nature of embedded patch management, this results in prolonged vulnerability exposure windows and vulnerabilities that are relatively easy to exploit. Considering the sensitive and critical nature of many embedded systems, this situation merits significant improvement. In this work, we present the first quantitative study of exploit mitigation adoption in 42 embedded operating systems, showing the embedded world to significantly lag behind the general-purpose world. To improve the security of deeply embedded systems, we subsequently present μArmor, an approach to address some of the key gaps identified in our quantitative analysis. μArmor raises the bar for exploitation of embedded memory corruption vulnerabilities, while being adoptable on the short term without incurring prohibitive extra performance or storage costs. Ali Abbasi 0002, Jos Wetzels, Thorsten Holz, Sandro Etalle |
EuroS&P | 1 |
| 2019 | GRIMOIRE: Synthesizing Structure while Fuzzing
Tim Blazytko, Cornelius Aschermann, Moritz Schloegel, Ali Abbasi 0002, Sergej Schumilo, Simon Wörner, Thorsten Holz |
USENIX Security Symposium | 4 |
| 2019 | AntiFuzz: Impeding Fuzzing Audits of Binary Executables
Emre Güler, Cornelius Aschermann, Ali Abbasi 0002, Thorsten Holz |
USENIX Security Symposium | 3 |
| 2017 | ECFI: Asynchronous Control Flow Integrity for Programmable Logic ControllersabstractProgrammable Logic Controllers (PLCs) are a family of embedded devices that are being used to control physical processes in critical infrastructures. Similar to other embedded devices, PLCs are vulnerable to memory corruption and control-flow hijacking attacks. Because PLCs are being used for critical control applications, compromised PLCs constitute a significant security and safety risk. Ali Abbasi 0002, Thorsten Holz, Emmanuele Zambon, Sandro Etalle |
ACSAC | 1 |
| 2017 | \mu Shield - Configurable Code-Reuse Attacks Mitigation For Embedded Systems
Ali Abbasi 0002, Jos Wetzels, Wouter Bokslag, Emmanuele Zambon, Sandro Etalle |
NSS | 1 |
| 2016 | Stealth Low-Level Manipulation of Programmable Logic Controllers I/O by Pin Control Exploitation
Ali Abbasi 0002, Majid Hashemi, Emmanuele Zambon, Sandro Etalle |
CRITIS | 1 |
| 2014 | On Emulation-Based Network Intrusion Detection Systems
Ali Abbasi 0002, Jos Wetzels, Wouter Bokslag, Emmanuele Zambon, Sandro Etalle |
RAID | 1 |