EDBT 2026 Demo / reviewers in the wild / expert
Meera Sridhar
dblp:74/7731
· DBLP profile ↗
18ranked-venue papers
3as first author
9since 2021 · last 2025
0000-0002-7508-5024ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 5 since 2021Software engineering, systems software and programming languages · 4 · 3 first-authorHuman-computer interaction and ubiquitous computing · 4 · 4 since 2021Systems, architecture and hardware · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Design of a User Study to evaluate the effectiveness of a Software Security Module for Neurodivergent StudentsabstractIn recent work, we developed an educational module for undergraduate computing students, to bring inclusivity and engagement into the advanced cybersecurity education topic of stack smashing attacks and defenses. Our module comprises four guided learning activities, and an active learning exercise that integrates a stack smashing attack visualization tool, DISSAV, developed in prior work. The module was deployed in an undergraduate cybersecurity course across multiple semesters, showing favorable results. In the current work, we outline a plan to evaluate the effectiveness of the module for an underrepresented, underserved community in computing-neurodivergent students, specifically, students with Autism Spectrum Disorder (ASD) or Attention Deficit Hyperactivity Disorder (ADHD). We plan to deploy our module to participants recruited from the AccessComputing group, a cohort of about 600 computing students and recent graduates across the US who have disabilities such as ADHD and ASD. We will evaluate the effectiveness of our stack smashing module in terms of learning, engagement, and accessibility for neurodivergent students through multi-pronged data collection and a mixed-methods analysis. We will use insights from the study to refine our module and to establish guidelines for future course modules and activities, to better serve neurodivergent students while continuing to serve all computing students. Sushma Indrani Dangeti, Harini Ramaprasad, Meera Sridhar, Soham Pradhan |
SIGCSE (2) | 3 |
| 2024 | Poster: TAPChecker: Model Checking in Trigger-Action Rules Generation Using Large Language ModelsabstractThe integration of large language models (LLMs) in smart home systems holds significant promise for automating the generation of Trigger-Action Programming (TAP) rules, potentially streamlining smart home user experiences and enhancing convenience. However, LLMs lack of holistic view of smart home IoT deployments and may introduce TAP rules that result in hazards. This paper explores the application of LLM for generating TAP rules and applying formal verification to validate and ensure the safety of TAP rules generated by LLMs. By systematically analyzing and verifying these rules, we aim to identify and mitigate potential security vulnerabilities. Furthermore, we propose a feedback mechanism to refine the LLM's output, enhancing its reliability and safety in generating automation rules. Through this approach, we seek to bridge the gap between the efficiency of LLMs and the stringent security requirements of smart IoT systems, fostering a safer automation environment. Huan Bui, Harper Lienerth, Chenglong Fu 0002, Meera Sridhar |
CCS | 4 |
| 2024 | Guided Learning and Interactive Visualization for Teaching & Learning Stack Smashing Attacks & Defenses: Experiences and EvaluationabstractThis Innovative Practice paper presents the design, deployment, and evaluation of a software security module that teaches stack smashing attacks and defenses using innovative pedagogical practices. Widely ubiquitous buffer overflow vul-nerabilities and stack smashing attacks that exploit them are critical components in advanced software security curricula, since buffer overflows can arise due to simple programmer oversight, and stack smashing can have dangerous consequences in critical systems. However, these topics are known to be difficult to teach and learn due to the vast amount of background needed, the difficulty of learning type-unsafe languages, and laborious memory address space calculations involved. In this work, we aim to bring innovative pedagogical practices to this advanced cybersecurity education topic through a suite of four guided learning activities that follow the Process Oriented Guided Inquiry Learning (POGIL) style, and DISSAV, an interactive visualization tool for modeling stack smashing attacks. This paper presents an evaluation of the module based on deploying it in multiple sections of an introductory undergraduate cybersecurity course in the UNC Charlotte in Fall 2022, Spring 2023, and Fall 2023. Our study finds that students have mostly positive perceptions about activity structure / design, content, and style, but that improvements may be needed to some aspects, including question phrasing, activity length, and teamwork facilitation. Harini Ramaprasad, Meera Sridhar, Sushma Indrani Dangeti, Soham Pradhan, Islam Obaidat |
FIE | 2 |
| 2023 | Creating a Large-scale Memory Error IoT Botnet Using NS3DockerEmulatorabstractDDoSim, a simulation testbed for mimicking real-world, large-scale botnet DDoS attacks, is presented. DDoSim offers various capabilities, including running user-specified software, testing botnet-recruitment exploits, and measuring the severity of resulting DDoS attacks. DDoSim leverages NS3DockerEmulator's Docker and NS-3 integration to load Docker containers with actual binaries and connect them over a simulated NS-3 network. DDoSim is validated through a comparison with results from real hardware experiments. This paper focuses on the results of an experiment series concerning deploying a memory error botnet on IoT devices. Unlike the Mirai attack, which relies on default credentials, these experiments exploit memory error vulnerabilities to access IoT devices. DDoSim also implements realistic IoT churn, reflecting dynamic network conditions in real-world IoT environments. The results reveal that memory error vulnerabilities enable botnet recruitment, while network conditions, attack size, and duration all have a proportional impact on target servers. DDoSim is publicly available for researchers' use. Islam Obaidat, Bennett Kahn, Fatemeh Tavakoli, Meera Sridhar |
DSN | 4 |
| 2022 | Criminal Investigations: An Interactive Experience to Improve Student Engagement and Achievement in Cybersecurity CoursesabstractThis paper presents Criminal Investigations, a gamified, scalable web-based framework for teaching and assessing Internet-of-Things (IoT) security skills. Criminal Investigations is packaged as a series of stackable IoT security activities; the current version uses React for the front-end development and Python for the back-end, and is deployed as a web application on a university server. Criminal Investigations promotes student engagement and learning by incorporating gamification concepts such as storytelling, experience points, just-in-time learning content delivery and checkpoints into activity design. This paper presents a pilot deployment of Criminal Investigations' first, fully-deployed, prototype activity "Reverse Engineering and Analyzing IoT Firmware''. The results of the pilot deployment indicate that Criminal Investigations provides an engaging, user-friendly, accessible environment, and helps students achieve the learning objectives of the prototype activity. John Grady Hall, Abhinav Mohanty, Pooja Murarisetty, Ngoc Diep Nguyen, Julio César Bahamón, Harini Ramaprasad, Meera Sridhar |
SIGCSE (1) | 7 |
| 2022 | Jadeite: A novel image-behavior-based approach for Java malware detection using deep learning
Islam Obaidat, Meera Sridhar, Khue M. Pham, Phu H. Phung |
Comput. Secur. | 2 |
| 2021 | HIJaX: Human Intent JavaScript XSS Generator
Yaw Frempong, Yates Snyder, Erfan Al-Hossami, Meera Sridhar, Samira Shaikh |
SECRYPT | 4 |
| 2021 | Criminal Investigations: An InteractiveExperience to Improve Student Engagement and Achievement in Cybersecurity coursesabstractThis poster presents Criminal Investigations, a text-based interactive activity designed to teach and assess reverse-engineering and firmware analysis skills in upper-division undergraduate cybersecurity courses. The activity incorporates elements of game design such as storytelling, experience points (XP), and just-in-time learning content delivery to increase student engagement and learning. Criminal Investigations is implemented as an easily accessible web-based application, deployed in a cloud-based environment. Abhinav Mohanty, Pooja Murarisetty, Ngoc Diep Nguyen, Julio César Bahamón, Harini Ramaprasad, Meera Sridhar |
SIGCSE | 6 |
| 2021 | A fine-grained classification and security analysis of web-based virtual machine vulnerabilities
Fadi Yilmaz, Meera Sridhar, Abhinav Mohanty, Vasant Tendulkar, Kevin W. Hamlen |
Comput. Secur. | 2 |
| 2020 | Guide Me to Exploit: Assisted ROP Exploit Generation for ActionScript Virtual MachineabstractAutomatic exploit generation (AEG) is the challenge of determining the exploitability of a given vulnerability by exploring all possible execution paths that can result from triggering the vulnerability. Since typical AEG implementations might need to explore an unbounded number of execution paths, they usually utilize a fuzz tester and a symbolic execution tool to facilitate this task. However, in the case of language virtual machines, such as the ActionScript Virtual Machine (AVM), AEG implementations cannot leverage fuzz testers or symbolic execution tools for generating the exploit script, because of two reasons: (1) fuzz testers cannot efficiently generate grammatically correct executables for the AVM due to the improbability of randomly generating highly-structured executables that follow the complex grammar rules and (2) symbolic execution tools encounter the well-known program-state-explosion problem due to the enormous number of control paths in early processing stages of a language virtual machine (e.g., lexing and parsing). Fadi Yilmaz, Meera Sridhar, Wontae Choi |
ACSAC | 2 |
| 2020 | A multi-party, fine-grained permission and policy enforcement framework for hybrid mobile applicationsabstractIn hybrid mobile applications (apps), the core code of an app is in JavaScript. Any JavaScript code in a hybrid app, local or remote, can access available APIs, including JavaScript bridges provided by a hybrid development framework, to access device resources. This JavaScript inclusion capability is dangerous since there is no mechanism to determine the origin (party) of the code to control access. Moreover, any JavaScript code running in a mobile app can access the device resources through the exposed APIs. Previous solutions are either limited to a particular platform (e.g., Android) or a specific hybrid framework (e.g., Cordova) or only protect the device resources and disregard the sensitive elements in the web environment. Furthermore, most solutions require modification of the base platform. In this article, we propose a novel policy enforcement framework to enforce useful fine-grained security and privacy policies based on permission for each party in hybrid mobile apps. In contrast to the conventional permission model in mobile apps, our permission specification is platform-agnostic and context-aware. This new permission specification allows app developers to customize for different parties over single permission. We integrate our permission specification into an app at the development phase; however, by design, it allows end-users to adjust parameters at runtime to protect their privacy. Together with multi-party permission patterns, we introduce comprehensive classes of expensive fine-grained, stateful policies that developers can deploy in practice. These policy patterns can help to protect the privacy of users and can also mitigate significant types of potential attacks in hybrid apps, evidenced by our real-world evaluation. Our experimental results also demonstrate that the framework is compatible with various hybrid development frameworks over two major mobile platforms, with lightweight overhead. Phu H. Phung, Rakesh S. V. Reddy, Steven Cap, Anthony Pierce, Abhinav Mohanty, Meera Sridhar |
J. Comput. Secur. | 6 |
| 2019 | A Survey of In-Lined Reference Monitors: Policies, Applications and ChallengesabstractThis paper surveys the area of in-lined reference monitors (IRMs), a language-based security enforcement technology that has gained much popularity in the recent past. IRMs enforce given security policies in target applications by inserting dynamic security guards into these applications; the guards check for impending policy violations at runtime. IRMs keep track of security state and can thus enforce rich, history-based policies. This survey discusses IRMs for a variety of programming languages, application execution platforms, and security policy specification languages. The survey also discusses the benefits and importance of adding IRM certification, and the technical and managerial challenges of employing IRMs. Fadi Yilmaz, Meera Sridhar |
AICCSA | 2 |
| 2019 | Exploiting Memory Corruption Vulnerabilities in Connman for IoT DevicesabstractIn the recent past, there has been a rapid increase in attacks on consumer Internet-of-Things (IoT) devices. Several attacks currently focus on easy targets for exploitation, such as weak configurations (weak default passwords). However, with governments, industries, and organizations proposing new laws and regulations to reduce and prevent such easy targets in the IoT space, attackers will move to more subtle exploits in these devices. Memory corruption vulnerabilities are a significant class of vulnerabilities in software security through which attackers can gain control of the entire system. Numerous memory corruption vulnerabilities have been found in IoT firmware already deployed in the consumer market. This paper presents an approach for exploiting stack-based buffer-overflow attacks in IoT firmware, to hijack the device remotely. To show the feasibility of this approach, we demonstrate exploiting a common network software application, Connman, used widely in IoT firmware such as Samsung smart TVs. A series of experiments are reported on, including: crashing and executing arbitrary code in the targeted software application in a controlled environment, adopting the attacks in uncontrolled environments (with standard software defenses such as W⊕X and ASLR enabled), and installing publicly available IoT firmware that uses this software application on a Raspberry Pi. The presented exploits demonstrate the ease in which an adversary can control IoT devices. K. Virgil English, Islam Obaidat, Meera Sridhar |
DSN | 3 |
| 2015 | Between Worlds: Securing Mixed JavaScript/ActionScript Multi-Party Web ContentabstractMixed Flash and JavaScript content has become increasingly prevalent; its purveyance of dynamic features unique to each platform has popularized it for myriad web development projects. Although Flash and JavaScript security has been examined extensively, the security of untrusted content that combines both has received considerably less attention. This article considers this fusion in detail, outlining several practical scenarios that threaten the security of web applications. The severity of these attacks warrants the development of new techniques that address the security of Flash-JavaScript content considered as a whole, in contrast to prior solutions that have examined Flash or JavaScript security individually. Toward this end, the article presents FlashJaX, a cross-platform solution that enforces fine-grained, history-based policies that span both Flash and JavaScript. Using in-lined reference monitoring, FlashJaX safely embeds untrusted JavaScript and Flash content in web pages without modifying browser clients or using special plug-ins. The architecture of FlashJaX, its design and implementation, and a detailed security analysis are exposited. Experiments with advertisements from popular ad networks demonstrate that FlashJaX is transparent to policy-compliant advertisement content, yet blocks many common attack vectors that exploit the fusion of these web platforms. Phu H. Phung, Maliheh Monshizadeh, Meera Sridhar, Kevin W. Hamlen, V. N. Venkatakrishnan |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2014 | Hippocratic binary instrumentation: First do no harm
Meera Sridhar, Richard Wartell, Kevin W. Hamlen |
Sci. Comput. Program. | 1 |
| 2012 | Aspect-Oriented Runtime Monitor Certification
Kevin W. Hamlen, Micah Jones, Meera Sridhar |
TACAS | 3 |
| 2010 | ActionScript In-Lined Reference Monitoring in Prolog
Meera Sridhar, Kevin W. Hamlen |
PADL | 1 |
| 2010 | Model-Checking In-Lined Reference Monitors
Meera Sridhar, Kevin W. Hamlen |
VMCAI | 1 |