44 citations · 85 across the 7 of their papers we have counts for
7 papers · 1 filter
COMMAND: Certifiable Open Measurable Mandates
Adam Hastings, Ryan Piersma, Simha Sethumadhavan
Security mandates today are often in the form of checklists and are generally inflexible and slow to adapt to changing threats. This paper introduces an alternate approach called o…
A New Doctrine for Hardware Security
Adam Hastings, Simha Sethumadhavan
In this paper, we promote the idea that recent woes in hardware security are not because of a lack of technical solutions but rather because market forces and incentives prevent th…
CRYLOGGER: Detecting Crypto Misuses Dynamically
Luca Piccolboni, Giuseppe Di Guglielmo, Luca P. Carloni +1
Cryptographic (crypto) algorithms are the essential ingredients of all secure systems: crypto hash functions and encryption algorithms, for example, can guarantee properties such a…
SPAM: Stateless Permutation of Application Memory
Mohamed Tarek Ibn Ziad, Miguel A. Arroyo, Simha Sethumadhavan
In this paper, we propose the Stateless Permutation of Application Memory (SPAM), a software defense that enables fine-grained data permutation for C programs. The key benefits inc…
Using Name Confusion to Enhance Security
Mohamed Tarek Ibn Ziad, Miguel A. Arroyo, Evgeny Manzhosov +2
We introduce a novel concept, called Name Confusion, and demonstrate how it can be employed to thwart multiple classes of code-reuse attacks. By building upon Name Confusion, we de…
Practical Byte-Granular Memory Blacklisting using Califorms
Hiroshi Sasaki, Miguel A. Arroyo, M. Tarek Ibn Ziad +3
Recent rapid strides in memory safety tools and hardware have improved software quality and security. While coarse-grained memory safety has improved, achieving memory safety at th…