EDBT 2026 Demo / reviewers in the wild / expert
Rigel Gjomemo
dblp:88/4984
· DBLP profile ↗
19ranked-venue papers
2as first author
8since 2021 · last 2025
0009-0001-3715-077XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 7 since 2021Artificial intelligence and machine learning · 2Software engineering, systems software and programming languages · 2 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Citar: Cyberthreat Intelligence-driven Attack ReconstructionabstractSecurity Operation Centers (SOCs) are the first line of defense against an increasingly complex and sophisticated environment of advanced persistent threats (APTs). Inside SOCs, analysts deal with thousands of alerts every day and have to make real-time decisions about whether alerts are worth investigating further. However, they face several challenges in efficiently investigating a significant number of alerts daily and reconstructing attack scenarios from those alerts. In this paper, we present Citar, an approach for leveraging cyber threat intelligence (CTI) to facilitate attack scenario reconstruction. Citar enhances alert investigation by attributing alerts to potential attacker groups and examining audit logs for related attack instances. Utilizing a new correlation analysis developed for this purpose, we identify potential connections between flagged alerts and known attack behaviors present in a system. Citar is evaluated using a DARPA public dataset and 10 new attack scenarios (five real-world APT groups and five popular malwares). Our evaluation shows that augmenting existing detection mechanisms with Citar improves detection performance by up to 57%, significantly aiding SOC analysts in alert investigations and attack reconstructions. Sutanu Kumar Ghosh, Rigel Gjomemo, V. N. Venkatakrishnan |
CODASPY | 2 |
| 2025 | SemFinder: A Semantics-Based Approach to Enhance Vulnerability Analysis in Web ApplicationsabstractModern web applications are becoming increasingly complex. They include multiple dynamic runtime constructs that are difficult to analyze by static application security testing (SAST) tools. These tools often use a graph representation of the code for their analysis. However, built statically, such graphs may miss important data and control flows dependent on runtime information. In addition, the presence of difficult-to-analyze code patterns in modern web applications, referred to as testability tarpits, further reduces the accuracy of statically built graphs. As a result, current SAST tools have several false negatives because of 'hidden' paths, which are not present in the graphs. In this paper, we present SemFinder, an approach designed to automatically detect such hidden paths. SemFinder uses natural language semantics to hypothesize connections between different locations in the code based on the meaning and similarity of the variables in those locations and test those hypotheses dynamically. We evaluate SemFinder on 30 PHP applications and discover 215 new exploitable hidden paths with respect to existing SAST tools, leading to the submission of 31 new CVEs. Neil P. Thimmaiah, Rigel Gjomemo, V. N. Venkatakrishnan |
CODASPY | 2 |
| 2025 | FIXX: FInding eXploits from eXamples
Neil P. Thimmaiah, Yashashvi J. Dave, Rigel Gjomemo, V. N. Venkatakrishnan |
USENIX Security Symposium | 3 |
| 2024 | ReactAppScan: Mining React Application Vulnerabilities via Component GraphabstractReact, a single-page application framework, has recently become popular among web developers due to its flexible and convenient management of web application states via a syntax extension to JavaScript, called JSX (JavaScript and XML). Despite its abundant functionalities, the security of React, especially vulnerability detection, still lags: many existing vulnerability detection works do not support JSX let alone React Data Flow introduced by React components. The only exception is CodeQL, which supports JSX syntax. However, CodeQL cannot properly track React Data Flow across different components for detecting vulnerabilities. Mingqing Kang, V. N. Venkatakrishnan, Rigel Gjomemo, Yinzhi Cao |
CCS | 4 |
| 2024 | TIPCE: A Longitudinal Threat Intelligence Platform Comprehensiveness AnalysisabstractThreat Intelligence (TI) serves as a vital component of cybersecurity, empowering organizations to combat cyber threats proactively. While existing research primarily focuses on analyzing threat intelligence feeds from Threat Intelligence Sharing Platforms (TISPs), the extensive data available within TISPs knowledge bases remains largely unexplored. This study aims to fill this gap by proposing a novel approach to perform the first in-depth empirical study of prominent TISPs' databases. To achieve this, we propose an innovative approach to construct a ground truth dataset of Indicators of Compromise (IOCs) derived from threat reports. We implement our approach in a tool called TIPCE, which processes over 50,000 threat reports, extracting more than 182K IOCs with high accuracy. TIPCE leverages this dataset to measure and study different features of four known TISP databases, including their coverage, overlap, and timeliness. Our results provide novel longitudinal insights into TISPs, including their distinct performance per IOC type and considerable overlap between TISP databases. Kiavash Satvat, Rigel Gjomemo, V. N. Venkatakrishnan |
CODASPY | 2 |
| 2023 | Scaling JavaScript Abstract Interpretation to Detect and Exploit Node.js Taint-style VulnerabilityabstractTaint-style vulnerabilities, such as OS command injection and path traversal, are common and severe software weaknesses. There exists an inherent trade-off between analysis scalability and accuracy in detecting such vulnerabilities. On one hand, existing syntax-directed approaches often make compromises in the analysis accuracy on dynamic features like bracket syntax. On the other hand, existing abstract interpretation often faces the issue of state explosion in the abstract domain, thus leading to a scalability problem.In this paper, we present a novel approach, called FAST, to scale the vulnerability discovery of JavaScript packages via a novel abstract interpretation approach that relies on two new techniques, called bottom-up and top-down abstract interpretation. The former abstractly interprets functions based on scopes instead of call sequences to construct dynamic call edges. Then, the latter follows specific control-flow paths and prunes the program to skip statements unrelated to the sink. If an end-to-end data-flow path is found, FAST queries the satisfiability of constraints along the path and verifies the exploitability to reduce human efforts.We implement a prototype of FAST and evaluate it against real-world Node.js packages. We show that FAST is able to find 242 zero-day vulnerabilities in NPM with 21 CVE identifiers being assigned. Our evaluation also shows that FAST can scale to real-world applications such as NodeBB and popular frameworks such as total.js and strapi in finding legacy vulnerabilities that no prior works can. Mingqing Kang, Yichao Xu, Song Li 0006, Rigel Gjomemo, Jianwei Hou, V. N. Venkatakrishnan, Yinzhi Cao |
SP | 4 |
| 2023 | Understanding Indicators of Compromise against Cyber-attacks in Industrial Control Systems: A Security PerspectiveabstractNumerous sophisticated and nation-state attacks on Industrial Control Systems (ICSs) have increased in recent years, exemplified by Stuxnet and Ukrainian Power Grid. Measures to be taken post-incident are crucial to reduce damage, restore control, and identify attack actors involved. By monitoring Indicators of Compromise (IOCs), the incident responder can detect malicious activity triggers and respond quickly to a similar intrusion at an earlier stage. However, to implement IOCs in critical infrastructures, we need to understand their contexts and requirements. Unfortunately, there is no survey paper in the literature on IOC in the ICS environment, and only limited information is provided in research articles. In this article, we describe different standards for IOC representation and discuss the associated challenges that restrict security investigators from developing IOCs in the industrial sectors. We also discuss the potential IOCs against cyber-attacks in ICS systems. Furthermore, we conduct a critical analysis of existing works and available tools in this space. We evaluate the effectiveness of identified IOCs’ by mapping these indicators to the most frequently targeted attacks in the ICS environment. Finally, we highlight the lessons to be learned from the literature and the future problems in the domain along with the approaches that might be taken. Mohammed Asiri, Neetesh Saxena, Rigel Gjomemo, Pete Burnap |
ACM Trans. Cyber Phys. Syst. | 3 |
| 2021 | Extractor: Extracting Attack Behavior from Threat ReportsabstractThe knowledge on attacks contained in Cyber Threat Intelligence (CTI) reports is very important to effectively identify and quickly respond to cyber threats. However, this knowledge is often embedded in large amounts of text, and therefore difficult to use effectively. To address this challenge, we propose a novel approach and tool called Extractor that allows precise automatic extraction of concise attack behaviors from CTI reports. Extractor makes no strong assumptions about the text and is capable of extracting attack behaviors as provenance graphs from unstructured text. We evaluate Extractor using real-world incident reports from various sources as well as reports of DARPA adversarial engagements that involve several attack campaigns on various OS platforms of Windows, Linux, and FreeBSD. Our evaluation results show that Extractor can extract concise provenance graphs from CTI reports and show that these graphs can successfully be used by cyber-analytics tools in threat-hunting. Kiavash Satvat, Rigel Gjomemo, V. N. Venkatakrishnan |
EuroS&P | 2 |
| 2019 | POIROT: Aligning Attack Behavior with Kernel Audit Records for Cyber Threat HuntingabstractCyber threat intelligence (CTI) is being used to search for indicators of attacks that might have compromised an enterprise network for a long time without being discovered. To have a more effective analysis, CTI open standards have incorporated descriptive relationships showing how the indicators or observables are related to each other. However, these relationships are either completely overlooked in information gathering or not used for threat hunting. In this paper, we propose a system, called POIROT, which uses these correlations to uncover the steps of a successful attack campaign. We use kernel audits as a reliable source that covers all causal relations and information flows among system entities and model threat hunting as an inexact graph pattern matching problem. Our technical approach is based on a novel similarity metric which assesses an alignment between a query graph constructed out of CTI correlations and a provenance graph constructed out of kernel audit log records. We evaluate POIROT on publicly released real-world incident reports as well as reports of an adversarial engagement designed by DARPA, including ten distinct attack campaigns against different OS platforms such as Linux, FreeBSD, and Windows. Our evaluation results show that POIROT is capable of searching inside graphs containing millions of nodes and pinpoint the attacks in a few minutes, and the results serve to illustrate that CTI correlations could be used as robust and reliable artifacts for threat hunting. Sadegh M. Milajerdi, Birhanu Eshete, Rigel Gjomemo, V. N. Venkatakrishnan |
CCS | 3 |
| 2019 | HOLMES: Real-Time APT Detection through Correlation of Suspicious Information FlowsabstractIn this paper, we present HOLMES, a system that implements a new approach to the detection of Advanced and Persistent Threats (APTs). HOLMES is inspired by several case studies of real-world APTs that highlight some common goals of APT actors. In a nutshell, HOLMES aims to produce a detection signal that indicates the presence of a coordinated set of activities that are part of an APT campaign. One of the main challenges addressed by our approach involves developing a suite of techniques that make the detection signal robust and reliable. At a high-level, the techniques we develop effectively leverage the correlation between suspicious information flows that arise during an attacker campaign. In addition to its detection capability, HOLMES is also able to generate a high-level graph that summarizes the attacker's actions in real-time. This graph can be used by an analyst for an effective cyber response. An evaluation of our approach against some real-world APTs indicates that HOLMES can detect APT campaigns with high precision and low false alarm rate. The compact high-level graphs produced by HOLMES effectively summarizes an ongoing attack campaign and can assist real-time cyber-response operations. Sadegh M. Milajerdi, Rigel Gjomemo, Birhanu Eshete, R. Sekar 0001, V. N. Venkatakrishnan |
IEEE Symposium on Security and Privacy | 2 |
| 2018 | NAVEX: Precise and Scalable Exploit Generation for Dynamic Web Applications
Abeer Alhuzali, Rigel Gjomemo, Birhanu Eshete, V. N. Venkatakrishnan |
USENIX Security Symposium | 2 |
| 2017 | SLEUTH: Real-time Attack Scenario Reconstruction from COTS Audit Data
Md Nahid Hossain, Sadegh M. Milajerdi, Junao Wang, Birhanu Eshete, Rigel Gjomemo, R. Sekar 0001, Scott D. Stoller, V. N. Venkatakrishnan |
USENIX Security Symposium | 5 |
| 2016 | Chainsaw: Chained Automated Workflow-based Exploit GenerationabstractWe tackle the problem of automated exploit generation for web applications. In this regard, we present an approach that significantly improves the state-of-art in web injection vulnerability identification and exploit generation. Our approach for exploit generation tackles various challenges associated with typical web application characteristics: their multi-module nature, interposed user input, and multi-tier architectures using a database backend. Our approach develops precise models of application workflows, database schemas, and native functions to achieve high quality exploit generation. We implemented our approach in a tool called Chainsaw. Chainsaw was used to analyze 9 open source applications and generated over 199 first- and second-order injection exploits combined, significantly outperforming several related approaches. Abeer Alhuzali, Birhanu Eshete, Rigel Gjomemo, V. N. Venkatakrishnan |
CCS | 3 |
| 2016 | Leveraging Static Analysis Tools for Improving Usability of Memory Error Sanitization CompilersabstractMemory errors such as buffer overruns are notorious security vulnerabilities. There has been considerable interest in having a compiler to ensure the safety of compiled code either through static verification or through instrumented runtime checks. While certifying compilation has shown much promise, it has not been practical, leaving code instrumentation as the next best strategy for compilation. We term such compilers Memory Error Sanitization Compilers (MESCs). MESCs are available as part of GCC, LLVM and MSVC suites. Due to practical limitations, MESCs typically apply instrumentation indiscriminately to every memory access, and are consequently prohibitively expensive and practical to only small code bases. This work proposes a methodology that applies state-of-the-art static analysis techniques to eliminate unnecessary runtime checks, resulting in more efficient and scalable defenses. The methodology was implemented on LLVM's Safecode, Integer Overflow, and Address Sanitizer passes, using static analysis of Frama-C and Codesurfer. The benchmarks demonstrate an improvement in runtime performance that makes incorporation of runtime checks a viable option for defenses. Rigel Gjomemo, Phu H. Phung, Edmund Ballou, Kedar S. Namjoshi, V. N. Venkatakrishnan, Lenore D. Zuck |
QRS | 1 |
| 2015 | Practical Exploit Generation for Intent Message Vulnerabilities in AndroidabstractAndroid's Inter-Component Communication (ICC) mechanism strongly relies on Intent messages. Unfortunately, due to the lack of message origin verification in Intents, application security completely relies on the programmer's skill and attention. In this paper, we advance the state of the art by developing a method to automatically detect potential vulnerabilities and, most importantly, demonstrate whether they can be exploited or not. To this end, we adopt a formal approach to automatically produce malicious payloads that can trigger dangerous behavior in vulnerable applications. We test our methods on a representative sample of applications, and we find that 29 out of 64 tested applications are potentially vulnerable, while 26 of them are automatically proven to be exploitable. Daniele Gallingani, Rigel Gjomemo, V. N. Venkatakrishnan, Stefano Zanero |
CODASPY | 2 |
| 2015 | From Verification to Optimizations
Rigel Gjomemo, Kedar S. Namjoshi, Phu H. Phung, V. N. Venkatakrishnan, Lenore D. Zuck |
VMCAI | 1 |
| 2008 | A Constraint and Attribute Based Security Framework for Dynamic Role Assignment in Collaborative Environments
Isabel F. Cruz, Rigel Gjomemo, Benjamin Lin, Mirko Orsini |
CollaborateCom | 2 |
| 2008 | A location aware role and attribute based access control systemabstractIn this paper, we follow the role-based access control (RBAC) approach and extend it to provide for the dynamic association of roles with users. In our framework, privileges associated with resources are assigned depending on the attribute values of the resources, attribute values associated with users determine the association of users with privileges, and a location mapping function between physical and logical locations allows to enable/disable roles depending on the logical location of the users and thus preserve the privacy of the location. We use Semantic Web technologies and a graphical user interface based on the Google Maps API. Isabel F. Cruz, Rigel Gjomemo, Benjamin Lin, Mirko Orsini |
GIS | 2 |
| 2008 | A Secure Mediator for Integrating Multiple Level Access Control Policies
Isabel F. Cruz, Rigel Gjomemo, Mirko Orsini |
KES (2) | 2 |