<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Papers I have read and you should too.</title>
	<atom:link href="http://uread.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://uread.wordpress.com</link>
	<description>An attempt to exchange pointers on interesting research in Computer Systems and Security</description>
	<lastBuildDate>Fri, 27 Mar 2009 22:40:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='uread.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Papers I have read and you should too.</title>
		<link>http://uread.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://uread.wordpress.com/osd.xml" title="Papers I have read and you should too." />
	<atom:link rel='hub' href='http://uread.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Parallelizing security checks on commodity hardware</title>
		<link>http://uread.wordpress.com/2009/03/28/parallelizing-security-checks-on-commodity-hardware/</link>
		<comments>http://uread.wordpress.com/2009/03/28/parallelizing-security-checks-on-commodity-hardware/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 22:39:55 +0000</pubDate>
		<dc:creator>herbertb</dc:creator>
				<category><![CDATA[Intrusion Detection]]></category>
		<category><![CDATA[manycore]]></category>
		<category><![CDATA[Systems Security]]></category>

		<guid isPermaLink="false">http://uread.wordpress.com/?p=68</guid>
		<description><![CDATA[www.eecs.umich.edu/~dpeek/asplos.pdf by Edmund B. Nightingale et al. (ASPLOS&#8217;08) These guys decouple security check from the normal run (which continues speculatively). Doing this, they accelerate taint analysis 1.6x-2x. Nice work.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=68&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>www.eecs.umich.edu/~dpeek/asplos.pdf</p>
<p>by Edmund B. Nightingale et al. (ASPLOS&#8217;08)</p>
<p>These guys decouple security check from the normal run (which continues speculatively). Doing this, they accelerate taint analysis 1.6x-2x. Nice work.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/uread.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/uread.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/uread.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/uread.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/uread.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/uread.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/uread.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/uread.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/uread.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/uread.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/uread.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/uread.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/uread.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/uread.wordpress.com/68/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=68&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://uread.wordpress.com/2009/03/28/parallelizing-security-checks-on-commodity-hardware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e4fcaf39eb171c2e89e41efa7937fb7d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">herbertb</media:title>
		</media:content>
	</item>
		<item>
		<title>Digging for datastructures (to identify malware)</title>
		<link>http://uread.wordpress.com/2008/12/08/digging-for-datastructures-to-identify-malware/</link>
		<comments>http://uread.wordpress.com/2008/12/08/digging-for-datastructures-to-identify-malware/#comments</comments>
		<pubDate>Mon, 08 Dec 2008 10:20:11 +0000</pubDate>
		<dc:creator>willemvu</dc:creator>
				<category><![CDATA[Systems Security]]></category>

		<guid isPermaLink="false">http://uread.wordpress.com/?p=60</guid>
		<description><![CDATA[Anthony Cozzie has built a system for detecting datastructures in applications&#8217; heap memory. In this paper he presents the method and applies it to malware detection. His premise is that data layout is much harder to vary automatically than instructions (polymorphism). Therefore, data offers a better signature than instructions. He verifies this intuition by comparing [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=60&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Anthony Cozzie has built a system for detecting datastructures in applications&#8217; heap memory. In this paper he presents the method and applies it to malware detection. His premise is that data layout is much harder to vary automatically than instructions (polymorphism). Therefore, data offers a better signature than instructions. He verifies this intuition by comparing multiple versions of Kraken and Storm (among others). A great example of generic system&#8217;s work applied to security. <a href="http://www.usenix.org/events/osdi08/tech/full_papers/cozzie/cozzie_html/index.html">The full paper at OSDI 2008 can be found here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/uread.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/uread.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/uread.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/uread.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/uread.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/uread.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/uread.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/uread.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/uread.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/uread.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/uread.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/uread.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/uread.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/uread.wordpress.com/60/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=60&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://uread.wordpress.com/2008/12/08/digging-for-datastructures-to-identify-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/a7c733998f8bae38c138cdaa440c7eb5?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">willemvu</media:title>
		</media:content>
	</item>
		<item>
		<title>Ether: Malware Analysis via Hardware Virtualization Extensions</title>
		<link>http://uread.wordpress.com/2008/11/25/ether-malware-analysis-via-hardware-virtualization-extensions/</link>
		<comments>http://uread.wordpress.com/2008/11/25/ether-malware-analysis-via-hardware-virtualization-extensions/#comments</comments>
		<pubDate>Tue, 25 Nov 2008 13:21:05 +0000</pubDate>
		<dc:creator>asia18</dc:creator>
				<category><![CDATA[Systems Security]]></category>
		<category><![CDATA[Virtual Machines]]></category>

		<guid isPermaLink="false">http://uread.wordpress.com/?p=53</guid>
		<description><![CDATA[By A. Dinaburg, P. Royal, M. Sharif and W. Lee Proceedings of the 15th ACM Conference on Computer and Communications Security 2008 (CCS&#8217;08) Ether is a malware analysis framework which leverages hardware virtualization extensions (specifically Intel VT) to remain transparent to malicious software. It supports both fine- (single instruction) and coarse- (system call) granularity tracing. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=53&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>By A. Dinaburg, P. Royal, M. Sharif and W. Lee</p>
<p>Proceedings of the 15th ACM Conference on Computer and Communications Security 2008 (CCS&#8217;08)</p>
<p>Ether is a malware analysis framework which leverages hardware virtualization extensions (specifically <a href="http://www.intel.com/technology/virtualization/">Intel VT</a>) to remain transparent to malicious software. It supports both fine- (single instruction) and coarse- (system call) granularity tracing. (I&#8217;m curious what the performance penalty for the fine-grain tracing is. The authors only say that it&#8217;s &#8220;significant&#8221;.)</p>
<p>Both the GPL&#8217;ed source code for Ether and the paper are available for download at <a href="http://ether.gtisc.gatech.edu">http://ether.gtisc.gatech.edu.</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/uread.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/uread.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/uread.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/uread.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/uread.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/uread.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/uread.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/uread.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/uread.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/uread.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/uread.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/uread.wordpress.com/53/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/uread.wordpress.com/53/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/uread.wordpress.com/53/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=53&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://uread.wordpress.com/2008/11/25/ether-malware-analysis-via-hardware-virtualization-extensions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0eddafe498678d3102402994ffe8e685?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">asia18</media:title>
		</media:content>
	</item>
		<item>
		<title>Dataflow Anomaly Detection</title>
		<link>http://uread.wordpress.com/2008/11/24/dataflow-anomaly-detection/</link>
		<comments>http://uread.wordpress.com/2008/11/24/dataflow-anomaly-detection/#comments</comments>
		<pubDate>Mon, 24 Nov 2008 13:08:09 +0000</pubDate>
		<dc:creator>asia18</dc:creator>
				<category><![CDATA[Systems Security]]></category>
		<category><![CDATA[information flow control]]></category>

		<guid isPermaLink="false">http://uread.wordpress.com/?p=50</guid>
		<description><![CDATA[By S. Bhatkar, A. Chaturvedi and R. Sekar Proceedings of the 2006 IEEE Symposium on Security and Privacy Usually intrusion detection system based on modeling behaviours of programs in terms of system call sequences focus on control flows, with little emphasis on data flow involving system call arguments. In contrast, this paper presents an intrusion [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=50&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>By S. Bhatkar, A. Chaturvedi and R. Sekar</p>
<p>Proceedings of the 2006 IEEE Symposium on Security and Privacy</p>
<p>Usually intrusion detection system based on modeling behaviours of programs in terms of system call sequences focus on control flows, with little emphasis on data flow involving system call arguments. In contrast, this paper presents an intrusion detection technique that is based on learning temporal properties involving arguments of different system calls, thus capturing the flow of security-sensitive data through the program. Basically, the approach hypothesizes the flows that may be present, based on relationships observed between the parameters of different system calls. Dataflow properties are categorized into unary relations that involve properties of a single system call argument, and binary relations that involve arguments of two different system calls.</p>
<p>The paper can be found <a href="http://www2.computer.org/portal/web/csdl/doi/10.1109/SP.2006.12">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/uread.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/uread.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/uread.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/uread.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/uread.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/uread.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/uread.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/uread.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/uread.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/uread.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/uread.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/uread.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/uread.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/uread.wordpress.com/50/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=50&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://uread.wordpress.com/2008/11/24/dataflow-anomaly-detection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0eddafe498678d3102402994ffe8e685?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">asia18</media:title>
		</media:content>
	</item>
		<item>
		<title>Improving software security via runtime instruction-level taint checking</title>
		<link>http://uread.wordpress.com/2008/11/20/improving-software-security-via-runtime-instruction-level-taint-checking/</link>
		<comments>http://uread.wordpress.com/2008/11/20/improving-software-security-via-runtime-instruction-level-taint-checking/#comments</comments>
		<pubDate>Thu, 20 Nov 2008 14:29:57 +0000</pubDate>
		<dc:creator>porto79</dc:creator>
				<category><![CDATA[Systems Security]]></category>
		<category><![CDATA[hardware tagging]]></category>
		<category><![CDATA[taint-analysis]]></category>

		<guid isPermaLink="false">http://uread.wordpress.com/?p=48</guid>
		<description><![CDATA[Back from 2006, published in ASPLOS. An extension to dynamic taint-analysis to capture non-control flow data attacks. Somewhat limited because it&#8217;s based on doing some binary analysis beforehand, but still interesting. http://www.cs.ucf.edu/~jfkong/ASID06.pdf<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=48&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Back from 2006, published in ASPLOS.</p>
<p>An extension to dynamic taint-analysis to capture non-control flow data attacks.</p>
<p>Somewhat limited because it&#8217;s based on doing some binary analysis beforehand, but still interesting.</p>
<p><a href="http://www.cs.ucf.edu/~jfkong/ASID06.pdf" target="_blank">http://www.cs.ucf.edu/~jfkong/ASID06.pdf<br />
</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/uread.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/uread.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/uread.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/uread.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/uread.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/uread.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/uread.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/uread.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/uread.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/uread.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/uread.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/uread.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/uread.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/uread.wordpress.com/48/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=48&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://uread.wordpress.com/2008/11/20/improving-software-security-via-runtime-instruction-level-taint-checking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/db6a60fb23024621b2ce3d38523ec846?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">porto79</media:title>
		</media:content>
	</item>
		<item>
		<title>Exploring Multiple Execution Paths for Malware Analysis</title>
		<link>http://uread.wordpress.com/2008/11/14/exploring-multiple-execution-paths-for-malware-analysis/</link>
		<comments>http://uread.wordpress.com/2008/11/14/exploring-multiple-execution-paths-for-malware-analysis/#comments</comments>
		<pubDate>Fri, 14 Nov 2008 12:28:13 +0000</pubDate>
		<dc:creator>asia18</dc:creator>
				<category><![CDATA[Systems Security]]></category>

		<guid isPermaLink="false">http://uread.wordpress.com/?p=46</guid>
		<description><![CDATA[By Andreas Moser and Christopher Kruegel and Engin Kirda Proceedings of the 2007 IEEE Symposium on Security and Privacy Authors of the paper address the problem of malware which doesn&#8217;t display malicious behaviour unless certain trigger conditions are present. Dynamic taint-tracking is used to discover conditionals in the program that are dependent on tainted inputs. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=46&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>By Andreas Moser and Christopher Kruegel and Engin Kirda</p>
<p>Proceedings of the 2007 IEEE Symposium on Security and Privacy</p>
<p>Authors of the paper address the problem of malware which doesn&#8217;t display malicious behaviour unless certain trigger conditions are present. Dynamic taint-tracking is used to discover conditionals in the program that are dependent on tainted inputs. When one of the two branches of such a conditional is about to be taken, they create a checkpoint and a snapshot of the analyzed process, and keeps exploring one of the branch. Subsequently, when the exploration of the taken branch ends or after a timeout threshold is reached, they force the execution of the unexplored branch.</p>
<p>The paper can be found <a title="explore_multiple_paths" href="http://www.cs.ucsb.edu/~chris/research/doc/oakland07_explore.pdf">here</a>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/uread.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/uread.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/uread.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/uread.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/uread.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/uread.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/uread.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/uread.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/uread.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/uread.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/uread.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/uread.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/uread.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/uread.wordpress.com/46/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=46&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://uread.wordpress.com/2008/11/14/exploring-multiple-execution-paths-for-malware-analysis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0eddafe498678d3102402994ffe8e685?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">asia18</media:title>
		</media:content>
	</item>
		<item>
		<title>Securing software by enforcing data-flow integrity</title>
		<link>http://uread.wordpress.com/2008/11/14/securing-software-by-enforcing-data-flow-integrity/</link>
		<comments>http://uread.wordpress.com/2008/11/14/securing-software-by-enforcing-data-flow-integrity/#comments</comments>
		<pubDate>Fri, 14 Nov 2008 11:01:08 +0000</pubDate>
		<dc:creator>porto79</dc:creator>
				<category><![CDATA[Systems Security]]></category>
		<category><![CDATA[compilers]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://uread.wordpress.com/?p=43</guid>
		<description><![CDATA[A somewhat older paper. DFI goes beyond detecting control flow attacks to also handle criticial variables being overwritten (look at the SSH exploit). This solution requires source code and recompilation, but despite some limitations it&#8217;s very impressive. http://research.microsoft.com/~manuelc/MS/dfiOSDI.pdf<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=43&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A somewhat older paper. DFI goes beyond detecting control flow attacks to also handle criticial variables being overwritten (look at the <a title="SSH exploit" href="http://www.securityfocus.com/bid/2347" target="_blank">SSH exploit</a>). This solution requires source code and recompilation, but despite some limitations it&#8217;s very impressive.</p>
<p><a href="http://research.microsoft.com/~manuelc/MS/dfiOSDI.pdf" target="_blank">http://research.microsoft.com/~manuelc/MS/dfiOSDI.pdf</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/uread.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/uread.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/uread.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/uread.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/uread.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/uread.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/uread.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/uread.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/uread.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/uread.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/uread.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/uread.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/uread.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/uread.wordpress.com/43/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=43&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://uread.wordpress.com/2008/11/14/securing-software-by-enforcing-data-flow-integrity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/db6a60fb23024621b2ce3d38523ec846?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">porto79</media:title>
		</media:content>
	</item>
		<item>
		<title>Device Driver Safety Through a Reference Validation Mechanism</title>
		<link>http://uread.wordpress.com/2008/11/14/device-driver-safety-through-a-reference-validation-mechanism/</link>
		<comments>http://uread.wordpress.com/2008/11/14/device-driver-safety-through-a-reference-validation-mechanism/#comments</comments>
		<pubDate>Fri, 14 Nov 2008 01:37:01 +0000</pubDate>
		<dc:creator>herbertb</dc:creator>
				<category><![CDATA[iommu]]></category>
		<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Systems Security]]></category>

		<guid isPermaLink="false">http://uread.wordpress.com/?p=40</guid>
		<description><![CDATA[Paper can be found here By Dan Williams, Patrick Reynolds, Kevin Walsh, Emin Gün Sirer, and Fred B. Schneider OSDI 2008 This paper describes how the Nexus OS can be protected by malicious drivers by running drivers in userspace, and use of reference monitor. The system supports a software iommu, rate limiting for interrupts, and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=40&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Paper can be found <a href="www.cs.cornell.edu/~kwalsh/Research/nexus-ddrm-tr.pdf">here</a></p>
<p>By Dan Williams, Patrick Reynolds, Kevin Walsh, Emin Gün Sirer, and Fred B. Schneider<br />
OSDI 2008</p>
<p>This paper describes how the Nexus OS can be protected by malicious drivers by running drivers in userspace, and use of reference monitor. The system supports a software iommu, rate limiting for interrupts, and various other mechanisms.  </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/uread.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/uread.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/uread.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/uread.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/uread.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/uread.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/uread.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/uread.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/uread.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/uread.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/uread.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/uread.wordpress.com/40/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/uread.wordpress.com/40/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/uread.wordpress.com/40/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=40&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://uread.wordpress.com/2008/11/14/device-driver-safety-through-a-reference-validation-mechanism/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e4fcaf39eb171c2e89e41efa7937fb7d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">herbertb</media:title>
		</media:content>
	</item>
		<item>
		<title>Real-World Buffer Overflow Protection for Userspace &amp; Kernelspace</title>
		<link>http://uread.wordpress.com/2008/11/10/real-world-buffer-overflow-protection-for-userspace-kernelspace/</link>
		<comments>http://uread.wordpress.com/2008/11/10/real-world-buffer-overflow-protection-for-userspace-kernelspace/#comments</comments>
		<pubDate>Sun, 09 Nov 2008 23:16:06 +0000</pubDate>
		<dc:creator>herbertb</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Systems Security]]></category>

		<guid isPermaLink="false">http://uread.wordpress.com/?p=36</guid>
		<description><![CDATA[(paper can be found here) by Michael Dalton, Hari Kannan, Christos Kozyraki (Stanford) Proceedings of USENIX Security&#8217;08. This paper is a follow-up of the Raksha paper at ISCA&#8217;07 and I think it represents a huge improvement. The most interesting aspect of it is that they use a technique that detects the injection of pointers (by [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=36&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>(paper can be found <a href="www.usenix.org/events/sec/tech/full_papers/dalton/dalton.pdf">here</a>)</p>
<p>by Michael Dalton, Hari Kannan, Christos Kozyraki (Stanford)</p>
<p>Proceedings of USENIX Security&#8217;08.</p>
<p>This paper is a follow-up of the Raksha paper at ISCA&#8217;07 and I think it represents a huge improvement. The most interesting aspect of it is that they use a technique that detects the injection of pointers (by attackers), by marking all legitimate pointers of the system and all pointers derived from these pointers. Any dereference of a pointer that is not marked as a legitimate pointer triggers an alert. They are not the first to propose detection of ptr injection, but they are the first to come up with a practical way of doing so. Although it requires a lot of hard work (scanning ELF binaries, tracking dynamic allocations, etc.), the runtime overhead can be kept small. False positives are unlikely (although false negatives may still occur). Their method does appear to be somewhat tied to an architecture like SPARC and an open source OS like Linux (I would expect the number of FNs to  be quite large on x86/Windows). Still, it is one of the few applications of pointer tainting that look practical.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/uread.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/uread.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/uread.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/uread.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/uread.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/uread.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/uread.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/uread.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/uread.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/uread.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/uread.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/uread.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/uread.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/uread.wordpress.com/36/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=36&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://uread.wordpress.com/2008/11/10/real-world-buffer-overflow-protection-for-userspace-kernelspace/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e4fcaf39eb171c2e89e41efa7937fb7d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">herbertb</media:title>
		</media:content>
	</item>
		<item>
		<title>Panorama: capturing system-wide information flow for malware detection and analysis</title>
		<link>http://uread.wordpress.com/2008/10/13/panorama-capturing-system-wide-information-flow-for-malware-detection-and-analysis/</link>
		<comments>http://uread.wordpress.com/2008/10/13/panorama-capturing-system-wide-information-flow-for-malware-detection-and-analysis/#comments</comments>
		<pubDate>Mon, 13 Oct 2008 02:22:32 +0000</pubDate>
		<dc:creator>herbertb</dc:creator>
				<category><![CDATA[Systems Security]]></category>

		<guid isPermaLink="false">http://uread.wordpress.com/?p=34</guid>
		<description><![CDATA[http://bitblaze.cs.berkeley.edu/papers/panorama.pdf by Heng Yin and Dawn Song and Manuel Egele and Christopher Kruegel and Engin Kirda (Proceedings of CCS&#8217;07). The paper describes how potential malware can be monitored to see if it misbehaves, using a variety of clever tricks (one of which is pointer tainting). Note that non-control data attacks have the potential to  become  [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=34&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>http://bitblaze.cs.berkeley.edu/papers/panorama.pdf</p>
<p>by Heng Yin and Dawn Song and Manuel Egele and Christopher Kruegel and Engin Kirda (Proceedings of CCS&#8217;07).</p>
<p>The paper describes how potential malware can be monitored to see if it misbehaves, using a variety of clever tricks (one of which is pointer tainting). Note that non-control data attacks have the potential to  become  bigger problems than attacks that divert control, because they are harder to detect. As they use full pointer tainting, I wonder how they contain the propagation of taint.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/uread.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/uread.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/uread.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/uread.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/uread.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/uread.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/uread.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/uread.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/uread.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/uread.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/uread.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/uread.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/uread.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/uread.wordpress.com/34/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=uread.wordpress.com&amp;blog=4686462&amp;post=34&amp;subd=uread&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://uread.wordpress.com/2008/10/13/panorama-capturing-system-wide-information-flow-for-malware-detection-and-analysis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e4fcaf39eb171c2e89e41efa7937fb7d?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">herbertb</media:title>
		</media:content>
	</item>
	</channel>
</rss>
