Skip to main content

Code Sanitization for Vulnerability Pruning and Exploitation Mitigation

Deliverables

Data Management Plan

To create and submit a Data Management Plan

Publications

Seed selection for successful fuzzing

Author(s): Adrian Herrera, Hendra Gunadi, Shane Magrath, Michael Norrish, Mathias Payer, Antony L. Hosking
Published in: Proceedings of the 30th ACM SIGSOFT International Symposium on Software Testing and Analysis, 2021, Page(s) 230-243, ISBN 9781450384599
Publisher: ACM
DOI: 10.1145/3460319.3464795

Principal Kernel Analysis: A Tractable Methodology to Simulate Scaled GPU Workloads

Author(s): Cesar Avalos Baddouh, Mahmoud Khairy, Roland N. Green, Mathias Payer, and Timothy G. Rogers.
Published in: International Symposium on Microarchitecture, 2021
Publisher: ACM
DOI: 10.1145/3466752.3480100

Midas: Systematic Kernel TOCTTOU Protection

Author(s): Atri Bhattacharyya, Uros Tesic, Mathias Payer
Published in: 2022
Publisher: Usenix

BLURtooth: Exploiting Cross-Transport Key Derivation in Bluetooth Classic and Bluetooth Low Energy

Author(s): Daniele Antonioli, Nils Tippenhauer, Kasper Rasmussen, and Mathias Payer
Published in: AsiaCCS - Asia Computer and Communication Security, 2022
Publisher: ACM
DOI: 10.1145/3488932.3523258

ProFactory: Improving IoT Security via Formalized Protocol Customization

Author(s): Fei Wang, Jianliang Wu, Yuhong Nan, Yousra Aafer, Xiangyu Zhang, Dongyan Xu, Mathias Payer
Published in: Security Symposium, 2022
Publisher: Usenix

Too Quiet in the Library: An Empirical Study of Security Updates in Android Apps' Native Code

Author(s): Sumaya Almanee, Arda Unal, Mathias Payer, Joshua Garcia
Published in: 2021 IEEE/ACM 43rd International Conference on Software Engineering (ICSE), 2021, Page(s) 1347-1359, ISBN 978-1-6654-0296-5
Publisher: IEEE/ACM
DOI: 10.1109/icse43902.2021.00122

FuZZan: Efficient Sanitizer Metadata Design for Fuzzing

Author(s): Yuseok Jeon, WookHyun Han, Nathan Burow, Mathias Payer
Published in: 2020
Publisher: Usenix

TEEzz: Fuzzing Trusted Applications on COTS Android Devices

Author(s): Marcel Busch, Mathias Payer, Aravind Machiry, Christopher Kruegel, Giovanni Vigna, Chad Spensky
Published in: IEEE Symposium on Security and Privacy, 2023
Publisher: IEEE

HALucinator: Firmware Re-hosting Through Abstraction Layer Emulation

Author(s): Abraham A. Clements, Eric Gustafson, Tobias Scharnowski, David Fritz, Christopher Kruegel, Giovanni Vigna, Saurabh Bagchi, Mathias Payer
Published in: 2020
Publisher: Usenix

PACMem: Enforcing Spatial and Temporal Memory Safety via ARM Pointer Authentication

Author(s): Yuan Li, Wende Tan, Zhizheng Lv, Songtao Yang, Mathias Payer, Ying Liu, Chao Zhang
Published in: ACM CCS, 2022
Publisher: CCS
DOI: 10.1145/3548606.3560598

Evocatio: Conjuring Bug Capabilities from a Single PoC

Author(s): Zhiyuan Jiang, Shuitao Gan, Adrian Herrera, Flavio Toffalini, Lucio Romerio, Chaojing Tang, Manuel Egele, Chao Zhang, Mathias Payer
Published in: ACM CCS, 2022
Publisher: ACM
DOI: 10.1145/3548606.3560575

BreakMi: Reversing, Exploiting and Fixing Xiaomi Fitness Tracking Ecosystem

Author(s): Marco Casagrande, Eleonora Losiouk, Mauro Conti, Mathias Payer, Daniele Antonioli
Published in: IACR Transactions on Cryptographic Hardware and Embedded Systems, 2022
Publisher: IACR

μSCOPE: A Methodology for Analyzing Least-Privilege Compartmentalization in Large Software Artifacts

Author(s): Nick Roessler; Lucas Atayde; Imani Palmer; Derrick McKee; Jai Pandey; Vasileios P. Kemerlis; Mathias Payer; Adam Bates; Jonathan M. Smith; André DeHon; Nathan Dautenhahn
Published in: RAID, 1, 2021
Publisher: ACM
DOI: 10.1145/3471621.3471839

GLeeFuzz: Fuzzing WebGL Through Error-Message-Guided Mutation

Author(s): Hui Peng, Zhihao Yao, Ardalan Amiri Sani, Dave (Jing) Tian, Mathias Payer
Published in: Usenix Security, 2023
Publisher: Usenix

Gramatron: effective grammar-aware fuzzing

Author(s): Prashast Srivastava, Mathias Payer
Published in: Proceedings of the 30th ACM SIGSOFT International Symposium on Software Testing and Analysis, 2021, Page(s) 244-256, ISBN 9781450384599
Publisher: ACM
DOI: 10.1145/3460319.3464814

Igor: Crash Deduplication Through root-Cause Clustering

Author(s): Zhiyuan Jiang, Xiyue Jiang, Ahmad Hazimeh, Chaojing Tang, Chao Zhang, and Mathias Payer
Published in: 2021
Publisher: ACM
DOI: 10.1145/3460120.3485364

Code Specialization through Dynamic Feature Observation

Author(s): Priyam Biswas, Nathan Burow, Mathias Payer
Published in: Proceedings of the Eleventh ACM Conference on Data and Application Security and Privacy, 2021, Page(s) 257-268, ISBN 9781450381437
Publisher: ACM
DOI: 10.1145/3422337.3447844

The Taming of the Stack: Isolating Stack Data from Memory Errors

Author(s): Kaiming Huang, Yongzhe Huang, Mathias Payer, Zhiyun Qian, Jack Sampson, Gang Tan, Trent Jaeger
Published in: Network and Distributed Systems Symposium, 2022
Publisher: Internet Society
DOI: 10.14722/ndss.2022.23060

USBFuzz: A Framework for Fuzzing USB Drivers by Device Emulation

Author(s): Hui Peng, Mathias Payer
Published in: 2020
Publisher: Usenix

LIGHTBLUE: Automatic Profile-Aware Debloating of Bluetooth

Author(s): Jianliang Wu, Ruoyu Wu, Daniele Antonioli, Mathias Payer, Nils Ole Tippenhauer, Dongyan Xu, Dave (Jing) Tian, Antonio Bianchi
Published in: 2021
Publisher: Usenix

Preventing Kernel Hacks with HAKCs

Author(s): Derrick McKee, Yianni Giannaris, Carolina Ortega Perez, Howard Shrobe, Mathias Payer, Hamed Okhravi, Nathan Burow
Published in: Network and Distributed Systems Symposium, 2022
Publisher: Internet Society
DOI: 10.14722/ndss.2022.24026

On the Insecurity of Vehicles Against Protocol-Level Bluetooth Threats

Author(s): Daniele Antonioli, Mathias Payer
Published in: Workshop On Offensive Technologies, 2022
Publisher: IEEE

Minerva: Browser API Fuzzing with Dynamic Mod-Ref Analysis

Author(s): Chijin Zhou, Quan Zhang, Mingzhe Wang, Lihua Guo, Jie Liang, Zhe Liu, Mathias Payer, Yu Jiang
Published in: FSE Foundations of Software Engineering, 2022
Publisher: ACM

Magma

Author(s): Ahmad Hazimeh, Adrian Herrera, Mathias Payer
Published in: Proceedings of the ACM on Measurement and Analysis of Computing Systems, 4/3, 2020, Page(s) 1-29, ISSN 2476-1249
Publisher: ACM
DOI: 10.1145/3428334