activity
20182022
most citedHotFuzz: Discovering Algorithmic Denial-of-Service Vulnerabilities Through Guided Micro-Fuzzing

15 citations · 35 across the 5 of their papers we have counts for

collaborators
Showing cs.CRShow all

12 papers · 1 filter

cs.CR20221 cited

Experience Report on the Challenges and Opportunities in Securing Smartphones Against Zero-Click Attacks

Narmeen Shafqat, Cem Topcuoglu, Engin Kirda +1

Zero-click attacks require no user interaction and typically exploit zero-day (i.e., unpatched) vulnerabilities in instant chat applications (such as WhatsApp and iMessage) to gain…

cs.CR202214 cited

D-Box: DMA-enabled Compartmentalization for Embedded Applications

Alejandro Mera, Yi Hui Chen, Ruimin Sun +2

Embedded and Internet-of-Things (IoT) devices have seen an increase in adoption in many domains. The security of these devices is of great importance as they are often used to cont…

cs.CR2021

SoK: Cryptojacking Malware

Ege Tekiner, Abbas Acar, A. Selcuk Uluagac +2

Emerging blockchain and cryptocurrency-based technologies are redefining the way we conduct business in cyberspace. Today, a myriad of blockchain and cryptocurrency systems, applic…

cs.CR2020

DICE: Automatic Emulation of DMA Input Channels for Dynamic Firmware Analysis

Alejandro Mera, Bo Feng, Long Lu +1

Microcontroller-based embedded devices are at the core of Internet-of-Things and Cyber-Physical Systems. The security of these devices is of paramount importance. Among the approac…

cs.CR2020

Bypassing memory safety mechanisms through speculative control flow hijacks

Andrea Mambretti, Alexandra Sandulescu, Alessandro Sorniotti +3

The prevalence of memory corruption bugs in the past decades resulted in numerous defenses, such as stack canaries, control flow integrity (CFI), and memory safe languages. These d…

cs.CR202015 cited

HotFuzz: Discovering Algorithmic Denial-of-Service Vulnerabilities Through Guided Micro-Fuzzing

William Blair, Andrea Mambretti, Sajjad Arshad +4

Contemporary fuzz testing techniques focus on identifying memory corruption vulnerabilities that allow adversaries to achieve either remote code execution or information disclosure…