Andrei Homescu

dblp:78/10907 · DBLP profile ↗
← Back
10ranked-venue papers
4as first author
0since 2021 · last 2017
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 2 first-authorSystems, architecture and hardware · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 2 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
7 papers
Systems and software security · 81% Network security · 13% Hardware security and side channels · 6%
Software engineering, system software, and programming languages
4 papers
Compilers and program optimization · 49% Software maintenance and evolution · 32% Runtime systems and virtual machines · 19%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Distributed systems · 100%

Topics — the 14 heaviest of 16, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security
software diversity
0.532017
Large-Scale Automated Software Diversity - Program Evolution Redux · IEEE Trans. Dependable Secur. Comput. 2017
SoK: Automated Software Diversity · IEEE Symposium on Security and Privacy 2014
Thwarting Cache Side-Channel Attacks Through Dynamic Software Diversity · NDSS 2015
Systems and software security › exploitation
code reuse attack
0.522017
Large-Scale Automated Software Diversity - Program Evolution Redux · IEEE Trans. Dependable Secur. Comput. 2017
Readactor: Practical Code Randomization Resilient to Memory Disclosure · IEEE Symposium on Security and Privacy 2015
Systems and software security
exploitation
0.422016
Subversive-C: Abusing and Protecting Dynamic Message Dispatch · USENIX ATC 2016
Librando: transparent code randomization for just-in-time compilers · CCS 2013
Systems and software security
code randomization
0.422015
Readactor: Practical Code Randomization Resilient to Memory Disclosure · IEEE Symposium on Security and Privacy 2015
Librando: transparent code randomization for just-in-time compilers · CCS 2013
Network security › attack resilience
attack mitigation
0.312017
Large-Scale Automated Software Diversity - Program Evolution Redux · IEEE Trans. Dependable Secur. Comput. 2017
Systems and software security › exploitation
control-flow hijacking
0.212016
Subversive-C: Abusing and Protecting Dynamic Message Dispatch · USENIX ATC 2016
Systems and software security
memory safety
0.212016
Subversive-C: Abusing and Protecting Dynamic Message Dispatch · USENIX ATC 2016
Hardware security and side channels › side-channel countermeasures
cache side-channel defense
0.212015
Thwarting Cache Side-Channel Attacks Through Dynamic Software Diversity · NDSS 2015
Systems and software security › exploitation › code reuse attack
return-oriented programming
0.212015
Readactor: Practical Code Randomization Resilient to Memory Disclosure · IEEE Symposium on Security and Privacy 2015
Network security
moving target defense
0.212014
SoK: Automated Software Diversity · IEEE Symposium on Security and Privacy 2014
Software maintenance and evolution › software evolution
program evolution
0.112017
Large-Scale Automated Software Diversity - Program Evolution Redux · IEEE Trans. Dependable Secur. Comput. 2017
Distributed systems
fault tolerance
0.112016
Secure and Efficient Application Monitoring and Replication · USENIX ATC 2016
Distributed systems
replication
0.112016
Secure and Efficient Application Monitoring and Replication · USENIX ATC 2016
Runtime systems and virtual machines › dynamic compilation
just-in-time compilation
0.012013
Librando: transparent code randomization for just-in-time compilers · CCS 2013

Methods — techniques the papers use, named apart from their topics

measurement of diversity effectiveness · 0.6automated software diversity · 0.6secure monitoring · 0.5replication · 0.5execute-only memory · 0.4dynamic software diversity · 0.4code pointer hiding · 0.4code randomization · 0.3systematic literature review · 0.2
YearPublicationVenuePosition
2017 Large-Scale Automated Software Diversity - Program Evolution Redux
abstract
The software monoculture favors attackers over defenders, since it makes all target environments appear similar. Code-reuse attacks, for example, rely on target hosts running identical software. Attackers use this assumption to their advantage by automating parts of creating an attack. This article presents large-scale automated software diversification as a means to shore up this vulnerability implied by our software monoculture. Besides describing an industrial-strength implementation of automated software diversity, we introduce methods to objectively measure the effectiveness of diversity in general, and its potential to eliminate code-reuse attacks in particular.
Andrei Homescu, Todd Jackson, Stephen Crane, Stefan Brunthaler 0001, Per Larsen, Michael Franz
IEEE Trans. Dependable Secur. Comput.1
2016 Subversive-C: Abusing and Protecting Dynamic Message Dispatch
Julian Lettner, Benjamin Kollenda, Andrei Homescu, Per Larsen, Felix Schuster, Lucas Davi, Ahmad-Reza Sadeghi, Thorsten Holz, Michael Franz
USENIX ATC3
2016 Secure and Efficient Application Monitoring and Replication
Stijn Volckaert, Bart Coppens 0001, Alexios Voulimeneas, Andrei Homescu, Per Larsen, Bjorn De Sutter, Michael Franz
USENIX ATC4
2016 Selfrando: Securing the Tor Browser against De-anonymization Exploits
abstract
Abstract Tor is a well-known anonymous communication system used by millions of users, including journalists and civil rights activists all over the world. The Tor Browser gives non-technical users an easy way to access the Tor Network. However, many government organizations are actively trying to compromise Tor not only in regions with repressive regimes but also in the free world, as the recent FBI incidents clearly demonstrate. Exploiting software vulnerabilities in general, and browser vulnerabilities in particular, constitutes a clear and present threat to the Tor software. The Tor Browser shares a large part of its attack surface with the Firefox browser. Therefore, Firefox vulnerabilities (even patched ones) are highly valuable to attackers trying to monitor users of the Tor Browser. In this paper, we present selfrando-an enhanced and practical load-time randomization technique for the Tor Browser that defends against exploits, such as the one FBI allegedly used against Tor users. Our solution significantly improves security over standard address space layout randomization (ASLR) techniques currently used by Firefox and other mainstream browsers. Moreover, we collaborated closely with the Tor Project to ensure that selfrando is fully compatible with AddressSanitizer (ASan), a compiler feature to detect memory corruption. ASan is used in a hardened version of Tor Browser for test purposes. The Tor Project decided to include our solution in the hardened releases of the Tor Browser, which is currently undergoing field testing.
Mauro Conti, Stephen Crane, Tommaso Frassetto, Andrei Homescu, Georg Koppen, Per Larsen, Christopher Liebchen, Mike Perry, Ahmad-Reza Sadeghi
Proc. Priv. Enhancing Technol.4
2015 Thwarting Cache Side-Channel Attacks Through Dynamic Software Diversity
Stephen Crane, Andrei Homescu, Stefan Brunthaler 0001, Per Larsen, Michael Franz
NDSS2
2015 Readactor: Practical Code Randomization Resilient to Memory Disclosure
abstract
Code-reuse attacks such as return-oriented programming (ROP) pose a severe threat to modern software. Designing practical and effective defenses against code-reuse attacks is highly challenging. One line of defense builds upon fine-grained code diversification to prevent the adversary from constructing a reliable code-reuse attack. However, all solutions proposed so far are either vulnerable to memory disclosure or are impractical for deployment on commodity systems. In this paper, we address the deficiencies of existing solutions and present the first practical, fine-grained code randomization defense, called Read actor, resilient to both static and dynamic ROP attacks. We distinguish between direct memory disclosure, where the attacker reads code pages, and indirect memory disclosure, where attackers use code pointers on data pages to infer the code layout without reading code pages. Unlike previous work, Read actor resists both types of memory disclosure. Moreover, our technique protects both statically and dynamically generated code. We use a new compiler-based code generation paradigm that uses hardware features provided by modern CPUs to enable execute-only memory and hide code pointers from leakage to the adversary. Finally, our extensive evaluation shows that our approach is practical -- we protect the entire Google Chromium browser and its V8 JIT compiler -- and efficient with an average SPEC CPU2006 performance overhead of only 6.4%.
Stephen Crane, Christopher Liebchen, Andrei Homescu, Lucas Davi, Per Larsen, Ahmad-Reza Sadeghi, Stefan Brunthaler 0001, Michael Franz
IEEE Symposium on Security and Privacy3
2014 SoK: Automated Software Diversity
abstract
The idea of automatic software diversity is at least two decades old. The deficiencies of currently deployed defenses and the transition to online software distribution (the "App store" model) for traditional and mobile computers has revived the interest in automatic software diversity. Consequently, the literature on diversity grew by more than two dozen papers since 2008. Diversity offers several unique properties. Unlike other defenses, it introduces uncertainty in the target. Precise knowledge of the target software provides the underpinning for a wide range of attacks. This makes diversity a broad rather than narrowly focused defense mechanism. Second, diversity offers probabilistic protection similar to cryptography-attacks may succeed by chance so implementations must offer high entropy. Finally, the design space of diversifying program transformations is large. As a result, researchers have proposed multiple approaches to software diversity that vary with respect to threat models, security, performance, and practicality. In this paper, we systematically study the state-of-the-art in software diversity and highlight fundamental trade-offs between fully automated approaches. We also point to open areas and unresolved challenges. These include "hybrid solutions", error reporting, patching, and implementation disclosure attacks on diversified software.
Per Larsen, Andrei Homescu, Stefan Brunthaler 0001, Michael Franz
IEEE Symposium on Security and Privacy2
2013 Librando: transparent code randomization for just-in-time compilers
abstract
Just-in-time compilers (JITs) are here to stay. Unfortunately, they also provide new capabilities to cyber attackers, namely the ability to supply input programs (in languages such as JavaScript) that will then be compiled to executable code. Once this code is placed and marked as executable, it can then be leveraged by the attacker.
Andrei Homescu, Stefan Brunthaler 0001, Per Larsen, Michael Franz
CCS1
2013 Profile-guided automated software diversity
abstract
Code-reuse attacks are notoriously hard to defeat, and most current solutions to the problem focus on automated software diversity. This is a promising area of research, as diversity attacks the common denominator enabling code-reuse attacksthe software monoculture. Recent research in this area provides security, but at an unfortunate price: performance overhead. Leveraging previously collected profiling information, compilers can substantially improve subsequent code generation. Traditionally, profile-guided optimization focuses on hot program code, where a program spends most of its execution time. Optimizing rarely executed code does not significantly impact performance, so few optimizations focus on this code. We use profile-guided optimization to reduce the performance overhead of software diversity. The primary insight is that we are free to diversify cold code, but restrict our diversification efforts in hot code. Our work investigates the impact of profiling on an expensive diversification technique: NOP insertion. By differentiating between hot cold and cold code, we optimize NOP insertion overheads from a maximum of 25% down to a negligible 1%, while preserving the security properties of the original defense. Consequently, using our profile-guided diversification technique, even randomization techniques having a high performance overhead become practical.
Andrei Homescu, Steven Neisius, Per Larsen, Stefan Brunthaler 0001, Michael Franz
CGO1
2011 HappyJIT: a tracing JIT compiler for PHP
abstract
Current websites are a combination of server-generated dynamic content with client-side interactive programs. Dynamically - typed languages have gained a lot of ground in both of these domains. The growth of Web 2.0 has introduced a myriad of websites which contain personalized content, which is specific to the user. PHP or Python programs generate the actual HTML page after querying a database and processing the results, which are then presented by the browser. It is becoming more and more vital to accelerate the execution of these programs, as this is a significant part of the total time needed to present the page to the user.
Andrei Homescu, Alex Suhan
DLS1