EDBT 2026 Demo / reviewers in the wild / expert
Andrei Homescu
dblp:78/10907
· DBLP profile ↗
10ranked-venue papers
4as first author
0since 2021 · last 2017
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-authorSystems, architecture and hardware · 3 · 1 first-authorSoftware engineering, systems software and programming languages · 2 · 2 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
7 papers |
Systems and software security · 81% Network security · 13% Hardware security and side channels · 6% | |
| Software engineering, system software, and programming languages
4 papers |
Compilers and program optimization · 49% Software maintenance and evolution · 32% Runtime systems and virtual machines · 19% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Distributed systems · 100% |
Topics — the 14 heaviest of 16, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security
software diversity |
0.5 | 3 | 2017 | Large-Scale Automated Software Diversity - Program Evolution Redux · IEEE Trans. Dependable Secur. Comput. 2017 SoK: Automated Software Diversity · IEEE Symposium on Security and Privacy 2014 Thwarting Cache Side-Channel Attacks Through Dynamic Software Diversity · NDSS 2015 |
Systems and software security › exploitation
code reuse attack |
0.5 | 2 | 2017 | Large-Scale Automated Software Diversity - Program Evolution Redux · IEEE Trans. Dependable Secur. Comput. 2017 Readactor: Practical Code Randomization Resilient to Memory Disclosure · IEEE Symposium on Security and Privacy 2015 |
Systems and software security
exploitation |
0.4 | 2 | 2016 | Subversive-C: Abusing and Protecting Dynamic Message Dispatch · USENIX ATC 2016 Librando: transparent code randomization for just-in-time compilers · CCS 2013 |
Systems and software security
code randomization |
0.4 | 2 | 2015 | Readactor: Practical Code Randomization Resilient to Memory Disclosure · IEEE Symposium on Security and Privacy 2015 Librando: transparent code randomization for just-in-time compilers · CCS 2013 |
Network security › attack resilience
attack mitigation |
0.3 | 1 | 2017 | Large-Scale Automated Software Diversity - Program Evolution Redux · IEEE Trans. Dependable Secur. Comput. 2017 |
Systems and software security › exploitation
control-flow hijacking |
0.2 | 1 | 2016 | Subversive-C: Abusing and Protecting Dynamic Message Dispatch · USENIX ATC 2016 |
Systems and software security
memory safety |
0.2 | 1 | 2016 | Subversive-C: Abusing and Protecting Dynamic Message Dispatch · USENIX ATC 2016 |
Hardware security and side channels › side-channel countermeasures
cache side-channel defense |
0.2 | 1 | 2015 | Thwarting Cache Side-Channel Attacks Through Dynamic Software Diversity · NDSS 2015 |
Systems and software security › exploitation › code reuse attack
return-oriented programming |
0.2 | 1 | 2015 | Readactor: Practical Code Randomization Resilient to Memory Disclosure · IEEE Symposium on Security and Privacy 2015 |
Network security
moving target defense |
0.2 | 1 | 2014 | SoK: Automated Software Diversity · IEEE Symposium on Security and Privacy 2014 |
Software maintenance and evolution › software evolution
program evolution |
0.1 | 1 | 2017 | Large-Scale Automated Software Diversity - Program Evolution Redux · IEEE Trans. Dependable Secur. Comput. 2017 |
Distributed systems
fault tolerance |
0.1 | 1 | 2016 | Secure and Efficient Application Monitoring and Replication · USENIX ATC 2016 |
Distributed systems
replication |
0.1 | 1 | 2016 | Secure and Efficient Application Monitoring and Replication · USENIX ATC 2016 |
Runtime systems and virtual machines › dynamic compilation
just-in-time compilation |
0.0 | 1 | 2013 | Librando: transparent code randomization for just-in-time compilers · CCS 2013 |
Methods — techniques the papers use, named apart from their topics
measurement of diversity effectiveness · 0.6automated software diversity · 0.6secure monitoring · 0.5replication · 0.5execute-only memory · 0.4dynamic software diversity · 0.4code pointer hiding · 0.4code randomization · 0.3systematic literature review · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2017 | Large-Scale Automated Software Diversity - Program Evolution ReduxabstractThe software monoculture favors attackers over defenders, since it makes all target environments appear similar. Code-reuse attacks, for example, rely on target hosts running identical software. Attackers use this assumption to their advantage by automating parts of creating an attack. This article presents large-scale automated software diversification as a means to shore up this vulnerability implied by our software monoculture. Besides describing an industrial-strength implementation of automated software diversity, we introduce methods to objectively measure the effectiveness of diversity in general, and its potential to eliminate code-reuse attacks in particular. Andrei Homescu, Todd Jackson, Stephen Crane, Stefan Brunthaler 0001, Per Larsen, Michael Franz |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2016 | Subversive-C: Abusing and Protecting Dynamic Message Dispatch
Julian Lettner, Benjamin Kollenda, Andrei Homescu, Per Larsen, Felix Schuster, Lucas Davi, Ahmad-Reza Sadeghi, Thorsten Holz, Michael Franz |
USENIX ATC | 3 |
| 2016 | Secure and Efficient Application Monitoring and Replication
Stijn Volckaert, Bart Coppens 0001, Alexios Voulimeneas, Andrei Homescu, Per Larsen, Bjorn De Sutter, Michael Franz |
USENIX ATC | 4 |
| 2016 | Selfrando: Securing the Tor Browser against De-anonymization ExploitsabstractAbstract Tor is a well-known anonymous communication system used by millions of users, including journalists and civil rights activists all over the world. The Tor Browser gives non-technical users an easy way to access the Tor Network. However, many government organizations are actively trying to compromise Tor not only in regions with repressive regimes but also in the free world, as the recent FBI incidents clearly demonstrate. Exploiting software vulnerabilities in general, and browser vulnerabilities in particular, constitutes a clear and present threat to the Tor software. The Tor Browser shares a large part of its attack surface with the Firefox browser. Therefore, Firefox vulnerabilities (even patched ones) are highly valuable to attackers trying to monitor users of the Tor Browser. In this paper, we present selfrando-an enhanced and practical load-time randomization technique for the Tor Browser that defends against exploits, such as the one FBI allegedly used against Tor users. Our solution significantly improves security over standard address space layout randomization (ASLR) techniques currently used by Firefox and other mainstream browsers. Moreover, we collaborated closely with the Tor Project to ensure that selfrando is fully compatible with AddressSanitizer (ASan), a compiler feature to detect memory corruption. ASan is used in a hardened version of Tor Browser for test purposes. The Tor Project decided to include our solution in the hardened releases of the Tor Browser, which is currently undergoing field testing. Mauro Conti, Stephen Crane, Tommaso Frassetto, Andrei Homescu, Georg Koppen, Per Larsen, Christopher Liebchen, Mike Perry, Ahmad-Reza Sadeghi |
Proc. Priv. Enhancing Technol. | 4 |
| 2015 | Thwarting Cache Side-Channel Attacks Through Dynamic Software Diversity
Stephen Crane, Andrei Homescu, Stefan Brunthaler 0001, Per Larsen, Michael Franz |
NDSS | 2 |
| 2015 | Readactor: Practical Code Randomization Resilient to Memory DisclosureabstractCode-reuse attacks such as return-oriented programming (ROP) pose a severe threat to modern software. Designing practical and effective defenses against code-reuse attacks is highly challenging. One line of defense builds upon fine-grained code diversification to prevent the adversary from constructing a reliable code-reuse attack. However, all solutions proposed so far are either vulnerable to memory disclosure or are impractical for deployment on commodity systems. In this paper, we address the deficiencies of existing solutions and present the first practical, fine-grained code randomization defense, called Read actor, resilient to both static and dynamic ROP attacks. We distinguish between direct memory disclosure, where the attacker reads code pages, and indirect memory disclosure, where attackers use code pointers on data pages to infer the code layout without reading code pages. Unlike previous work, Read actor resists both types of memory disclosure. Moreover, our technique protects both statically and dynamically generated code. We use a new compiler-based code generation paradigm that uses hardware features provided by modern CPUs to enable execute-only memory and hide code pointers from leakage to the adversary. Finally, our extensive evaluation shows that our approach is practical -- we protect the entire Google Chromium browser and its V8 JIT compiler -- and efficient with an average SPEC CPU2006 performance overhead of only 6.4%. Stephen Crane, Christopher Liebchen, Andrei Homescu, Lucas Davi, Per Larsen, Ahmad-Reza Sadeghi, Stefan Brunthaler 0001, Michael Franz |
IEEE Symposium on Security and Privacy | 3 |
| 2014 | SoK: Automated Software DiversityabstractThe idea of automatic software diversity is at least two decades old. The deficiencies of currently deployed defenses and the transition to online software distribution (the "App store" model) for traditional and mobile computers has revived the interest in automatic software diversity. Consequently, the literature on diversity grew by more than two dozen papers since 2008. Diversity offers several unique properties. Unlike other defenses, it introduces uncertainty in the target. Precise knowledge of the target software provides the underpinning for a wide range of attacks. This makes diversity a broad rather than narrowly focused defense mechanism. Second, diversity offers probabilistic protection similar to cryptography-attacks may succeed by chance so implementations must offer high entropy. Finally, the design space of diversifying program transformations is large. As a result, researchers have proposed multiple approaches to software diversity that vary with respect to threat models, security, performance, and practicality. In this paper, we systematically study the state-of-the-art in software diversity and highlight fundamental trade-offs between fully automated approaches. We also point to open areas and unresolved challenges. These include "hybrid solutions", error reporting, patching, and implementation disclosure attacks on diversified software. Per Larsen, Andrei Homescu, Stefan Brunthaler 0001, Michael Franz |
IEEE Symposium on Security and Privacy | 2 |
| 2013 | Librando: transparent code randomization for just-in-time compilersabstractJust-in-time compilers (JITs) are here to stay. Unfortunately, they also provide new capabilities to cyber attackers, namely the ability to supply input programs (in languages such as JavaScript) that will then be compiled to executable code. Once this code is placed and marked as executable, it can then be leveraged by the attacker. Andrei Homescu, Stefan Brunthaler 0001, Per Larsen, Michael Franz |
CCS | 1 |
| 2013 | Profile-guided automated software diversityabstractCode-reuse attacks are notoriously hard to defeat, and most current solutions to the problem focus on automated software diversity. This is a promising area of research, as diversity attacks the common denominator enabling code-reuse attacksthe software monoculture. Recent research in this area provides security, but at an unfortunate price: performance overhead. Leveraging previously collected profiling information, compilers can substantially improve subsequent code generation. Traditionally, profile-guided optimization focuses on hot program code, where a program spends most of its execution time. Optimizing rarely executed code does not significantly impact performance, so few optimizations focus on this code. We use profile-guided optimization to reduce the performance overhead of software diversity. The primary insight is that we are free to diversify cold code, but restrict our diversification efforts in hot code. Our work investigates the impact of profiling on an expensive diversification technique: NOP insertion. By differentiating between hot cold and cold code, we optimize NOP insertion overheads from a maximum of 25% down to a negligible 1%, while preserving the security properties of the original defense. Consequently, using our profile-guided diversification technique, even randomization techniques having a high performance overhead become practical. Andrei Homescu, Steven Neisius, Per Larsen, Stefan Brunthaler 0001, Michael Franz |
CGO | 1 |
| 2011 | HappyJIT: a tracing JIT compiler for PHPabstractCurrent websites are a combination of server-generated dynamic content with client-side interactive programs. Dynamically - typed languages have gained a lot of ground in both of these domains. The growth of Web 2.0 has introduced a myriad of websites which contain personalized content, which is specific to the user. PHP or Python programs generate the actual HTML page after querying a database and processing the results, which are then presented by the browser. It is becoming more and more vital to accelerate the execution of these programs, as this is a significant part of the total time needed to present the page to the user. Andrei Homescu, Alex Suhan |
DLS | 1 |